<img src="https://certify.alexametrics.com/atrk.gif?account=b2hlr1ah9W20em" style="display:none" height="1" width="1" alt="">
    Login
    Get started

    GDPR – New Fines – New Approach to Data Retention?

    Published on 13 Apr 2018 by Martin Schofield

    data retention

    It has long been accepted that data protection, has by and large been a poor relation in the world of compliance, and in particular never been a good bed fellow of the money laundering regulations, with the two of them often conflicting with one another.

    However, up until now, with the data protection supervising authority’s enforcement powers paling into insignificance when compared to the penalties for breaches of money laundering laws and regulations, the latter has always flexed its muscles and won the day.

    Is that all about to change however, with the implementation of GDPR and its new enforcement powers being made available to the data protection supervising authorities?

    There has always been, and there will remain post GDPR, a fine line to be tread in relation to data retention, with differing and competing pieces of legislation generating different requirements of the financial sector.

    UK  legislation includes:

    • Money Laundering Regulations – 5 years after the transaction has been executed or 5 years after the relationship has ended. This does not include internal and external Suspicious Activity Reports, Court Orders and the like, which should be held indefinitely for a firm’s own protection, as well as the personal protection of the Money Laundering Reporting Officer.
    • Statute of Limitations – a claim can made up to 6 years after an event.
    • Data Protection – data should only be retained for as long as is necessary for the purpose for which it was intended.

    Data retention and GDPR

    However, the conflict here can be simple, yet the consequences of getting it wrong are quite serious.

    For example, a request is received to change a customer’s address, once that request has been verified and actioned, the notification is technically no longer required, as the purpose for which it was intended no longer exists. A statement or other correspondence is subsequently issued with the customer’s name and new address on it, which eventually forms part of a pack of ID&V documents used to fraudulently open a bank account, into which the proceeds of crime are deposited, before being moved onto to another account.

    In time, the customer contacts the firm to advise that they did not at any time notify them of an address change, and thus the firm is left not being able to prove that it acted in good faith, and on the wrong end of a money laundering and fraud investigation, yet alone any other issues regarding its customer’s identity being stolen and the implications of that for the customer.

    In view of this type of scenario, firms have thus far, always retained data for as long as possible, as there was no real stick for the supervising authorities to beat them with for doing so, but now, under GDPR with applicable fines ranging between €10 million or 2% of global annual turnover and €20million or 4% of global annual turnover, will firms now start to take a very different approach to compliance? Will they risk retaining data for longer than can be argued as necessary?

    Time will tell.

    Want to know more about GDPR?

    As well as 30+ free compliance training aids, we regularly publish informative GDPR blogs. And, if you're looking for a training solution, why not visit our GDPR course library.

    If you've any further questions or concerns about GDPR, just leave us a comment below this blog. We are happy to help!

    Leave a comment

    Tick

    Free Trial: Compliance Essentials

    Skillcast Essentials is our best-selling library and there's a reason for that. Essentials library provides comprehensive coverage of the key compliance / conduct issues that companies in the UK face today.

    Request now

    The Biggest Financial Crime Fines

    Monetary fines are the most common punishment for financial crimes. They serve as a powerful tool for encouraging companies to apply best practices to ensure 100% compliance. Yet, despite all the ...

    Read More
    What are the Best Workplace Learning Theories?

    Learning theories have been developing for decades, each has their own merits. We look at six of the most well established theories to explain how you can use them to improve outcomes. When designing ...

    Read More
    Biggest GDPR Fines of 2019

    Penalties for breaching the GDPR can reach up to €20 million or 4% of annual global turnover, whichever is highest. We examine the size and reasons for the biggest GDPR fines of 2019. Ever since ...

    Read More
    Highest FCA Fines of 2019

    The FCA issued a record total of £392 million in fines in 2019. In fact, the two largest fines in 2019 were larger than the 2018 totals. We've analysed they key corporate and individual fines in ...

    Read More