SardineCon SF/2026

Learn More
Regulation & bodies4 min de lectura

¿Qué es GDPR?

SUBSCRIBE

GDPR is the EU General Data Protection Regulation, the law governing how personal data of people in the EU is collected, used, and stored. It grants strong individual rights and carries heavy penalties, and it constrains how fraud and AML teams handle the identity and monitoring data they depend on.

What is GDPR, in plain English?

GDPR is the European Union's data-protection law. It sets rules for how any organization processes the personal data of people in the EU, and it gives those people rights over their data, including the right to access, correct, and in some cases erase it. It applies to firms outside the EU too, if they handle EU residents' data, and its penalties for serious breaches are large enough to matter at board level.

The core principles are worth knowing because they shape day-to-day design: process data on a lawful basis, collect only what you need under data minimization, use it only for the stated purpose, keep it no longer than necessary, and control cross-border transfers. Each of these touches KYC, transaction monitoring, and sanctions screening, all of which run on large volumes of personal data.

The key thing for operators is that GDPR does not ban financial-crime work. AML obligations generally give you a lawful basis to process and retain the data you need. What GDPR does is set the boundaries: gather and keep what the law requires, but no more, and only for permitted purposes.

Where GDPR meets AML

The two regimes pull in different directions, and the tension is real:

What changes

AML pressure

GDPR pressure

Data collection

Collect enough to verify and monitor

Minimize to what is strictly necessary

Retention

Keep records for mandated periods

Delete when the purpose ends

Individual rights

Do not tip off a subject

Grant access and erasure requests

Transfers

Share across borders for cases

Control and safeguard cross-border flows

Who is involved?

Who

Their role

Data controller

The firm that decides why and how personal data is processed and carries the accountability.

Data processor

A vendor that processes data on the controller's behalf, such as a screening provider.

Data subject

The individual whose data is processed, with rights of access, correction, and erasure.

Supervisory authority

The national data-protection regulator that enforces GDPR and imposes penalties.

What it looks like in practice

In practice

A customer of an EU fintech submits a data-subject access request and a demand to erase everything the firm holds on them. The support team is about to comply in full when compliance flags that the customer is the subject of a filed suspicious-activity report and an open monitoring case.

The firm honors the access request for ordinary account data but withholds the parts that would tip off the subject, and it refuses erasure of records it must retain under AML law, citing its lawful basis and legal-obligation grounds. The response is documented carefully, because the firm has to satisfy both the data-protection regulator and its AML supervisor, and the two want opposite things from the same records.

Why GDPR matters to operators

GDPR shapes the plumbing of every fraud and AML program that touches EU data. You cannot hoard data just in case, you have to justify what you collect and keep, and you have to be ready to answer individual rights requests without breaking your monitoring obligations. Getting the balance wrong in either direction is costly: over-collect and you risk a data-protection penalty, under-collect and you weaken your financial-crime controls.

The practical answer most teams reach is to lean on data minimization and clear retention schedules, tie each dataset to a documented lawful basis, and build carve-outs so that tipping-off risks and mandated retention override a naive erasure. GDPR does not stop the work; it forces you to be deliberate about the data behind it.

What to watch

  • Lawful basis. Every processing activity, from KYC to monitoring, should map to a documented lawful basis, usually legal obligation for AML.
  • Erasure requests on subjects. Do not delete records you must retain, and never tip off the subject of a filing when responding.
  • Retention discipline. Keep data for the mandated period, then delete it; indefinite retention is a GDPR exposure.
  • Cross-border transfers. Moving personal data outside the EU needs appropriate safeguards; check them before sharing case data.
  • Vendor processing. Screening and monitoring vendors are processors; their contracts and safeguards are your responsibility too.

Quick questions

Does GDPR stop me doing AML work?

No. AML obligations generally provide a lawful basis to process and retain personal data, so financial-crime work is permitted. GDPR sets limits on how you do it, not whether you can.

Can a customer force me to delete their KYC records?

Not where you have a legal obligation to retain them. The right to erasure is not absolute, and AML retention requirements can override it. You still document the refusal and its basis.

What is data minimization?

The principle that you collect and keep only the personal data you actually need for a stated purpose. For fraud and AML teams it means resisting the urge to gather extra data just in case.

Does GDPR apply to firms outside the EU?

Yes, if they process the personal data of people in the EU, for example by offering them services. Location of the firm does not exempt it when EU residents' data is involved.

What about tipping off during an access request?

You must not reveal that someone is the subject of a suspicious-activity report or investigation. Access rights are limited where disclosure would prejudice financial-crime work, so those elements are withheld.

How do cross-border transfers work under GDPR?

Transfers of personal data outside the EU require appropriate safeguards, such as approved contractual clauses or an adequacy decision. Sharing case data internationally needs those safeguards in place first.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • FinCEN ↗ — The US financial intelligence unit. Bank Secrecy Act rules, advisories, and SAR and CTR guidance.

Qué saber junto con GDPR