Skip to Content
ANALYSISMEMBER

How the EU's new AML regulation will change personal data processing

The EU's anti-money laundering regulation will add GDPR-relevant safeguards for personal data processing in the AML context.

Published
Subscribe to IAPP newsletters

Contributors:

František Nonnemann

Compliance, cybersecurity and operational risk consultant

Myriad AI

The European Union's new anti-money laundering regulation becomes directly applicable 10 July 2027, introducing a more harmonized AML framework across the EU. While the regulation is primarily aimed at strengthening the fight against money laundering and terrorist financing, it also introduces important rules on how AML-obliged entities use, share and store personal data.

The AML regulation does not create a separate data protection regime. Instead, it supplements the EU General Data Protection Regulation by establishing more specific requirements for processing personal data in the AML context, particularly regarding automated processing, the further use of AML-related information and safeguards for affected individuals — such as data subjects.

The regulation applies to a broad range of obliged entities, including financial institutions, insurers, crypto-asset service providers, lawyers, notaries, real estate agents and trust or company service providers. As of 10 July 2029, it also extends AML obligations to certain professional football clubs and football agents.

The AML regulation is part of a broader legislative package that also established the Anti-Money Laundering Authority, which will coordinate supervision, support national financial intelligence units and promote consistent AML practices across the EU. For privacy professionals, however, the most significant changes are found directly in the AML regulation's provisions on data usage and processing.

Automated processing requires human oversight

Automated processing has become essential for modern AML compliance. Customer onboarding, transaction monitoring and ongoing customer due diligence increasingly rely on systems capable of analyzing large volumes of information quickly and consistently. For large financial institutions, manual review of every customer or transaction is no longer realistic.

Contributors:

František Nonnemann

Compliance, cybersecurity and operational risk consultant

Myriad AI

MEMBER

Unlock this exclusive content and more

Join the IAPPAlready a member? Sign in

Membership opens up a world of resources

In-depth knowledge

From original research reports and daily news coverage to legislative trackers and infographics, we have the information you need to stay ahead of change.

A global network

Make valuable professional connections through more than 160 local IAPP KnowledgeNet chapters in 70 countries.

Access to the experts

Connect with top thinkers in privacy, AI governance and cybersecurity for fresh ideas and insights.

Learn what you get from membership