How the EU's new AML regulation will change personal data processing

The EU's anti-money laundering regulation will add GDPR-relevant safeguards for personal data processing in the AML context.

Contributors:
František Nonnemann
Compliance, cybersecurity and operational risk consultant
Myriad AI
The European Union's new anti-money laundering regulation becomes directly applicable 10 July 2027, introducing a more harmonized AML framework across the EU. While the regulation is primarily aimed at strengthening the fight against money laundering and terrorist financing, it also introduces important rules on how AML-obliged entities use, share and store personal data.
The AML regulation does not create a separate data protection regime. Instead, it supplements the EU General Data Protection Regulation by establishing more specific requirements for processing personal data in the AML context, particularly regarding automated processing, the further use of AML-related information and safeguards for affected individuals — such as data subjects.
The regulation applies to a broad range of obliged entities, including financial institutions, insurers, crypto-asset service providers, lawyers, notaries, real estate agents and trust or company service providers. As of 10 July 2029, it also extends AML obligations to certain professional football clubs and football agents.
The AML regulation is part of a broader legislative package that also established the Anti-Money Laundering Authority, which will coordinate supervision, support national financial intelligence units and promote consistent AML practices across the EU. For privacy professionals, however, the most significant changes are found directly in the AML regulation's provisions on data usage and processing.
Automated processing requires human oversight
Automated processing has become essential for modern AML compliance. Customer onboarding, transaction monitoring and ongoing customer due diligence increasingly rely on systems capable of analyzing large volumes of information quickly and consistently. For large financial institutions, manual review of every customer or transaction is no longer realistic.
Contributors:
František Nonnemann
Compliance, cybersecurity and operational risk consultant
Myriad AI