Statutory AML processing by an obliged entity generally rests on legal obligation rather than revocable consent. Purposes, scope, roles, security and retention still need definition. The same data used in marketing or another service has a different purpose.
Start with a specific purpose
For each field, identify the duty served: identification, due diligence, risk analysis, evidencing actions or statutory retention. Section 17a(1) limits processing to what is necessary. GDPR Article 5 requires purpose limitation, minimisation, accuracy and appropriate duration. AML is not blanket permission to collect unlimited client or family information.
Article 6(1)(c) is relevant for legal obligations. Consent should not obscure that basis: withdrawal does not end statutory retention. Reassess the legal basis if you are not an obliged entity or use data for another purpose. Public registry availability does not itself remove data-protection rules.
Roles depend on the actual service
The obliged entity generally determines its AML-record purpose as controller. A provider may process on its instructions as processor, subject to Article 28. Other provider operations with independent purposes need separate role and legal-basis assessment. A processor label in a contract is insufficient where the provider actually determines further purposes.
Check storage, logs, support, backups and subprocessors. Brief storage or a no-store claim does not itself settle roles, transfers or security. Client queries should not enter URLs, advertising analytics or public search. Grant access by role and need rather than to all employees.
Provide information while respecting special restrictions
Section 24(2) requires pre-relationship or pre-transaction information, including a general AML notice. Section 17a(2) and confidentiality restrict information about specific AML processing. Handle access or erasure requests under GDPR and these special rules; do not disclose internal suspicious-transaction reports without assessment. After statutory retention, assess any evidenced basis for further storage.
Copying a file for another purpose
Do not automatically copy AML evidence into a sales database, marketing system or freely accessible team folder. The same worker may need an invoice for business tasks and only limited AML-file access. Separate purposes and permissions. For statistics or service improvement, assess actual anonymisation or a separate legal basis; removing a name alone may not prevent re-identification.
For client requests, verify the requester’s identity, locate relevant data and assess statutory exceptions. A response must not include protected internal circumstances simply because an export button includes the entire file. Conversely, a general AML label does not justify ignoring every request. Record the legal basis for response scope and continued retention. When the statutory purpose ends, deletion review also covers copies and provider access.
Practical steps
- List purposes and statutory duties.
- Determine roles in actual data flows.
- Minimise collection and restrict access.
- Set notices, retention and request handling.
Illustrative scenario
An office separates statutory AML files from an optional newsletter. Unsubscribing does not delete records during mandatory retention.
When the situation differs
Client consent purportedly permits any provider analysis of the complete AML questionnaire without defining purposes.
What to document
- Map of purposes, categories and legal bases.
- Client notice and processing agreement.
- Access and retention rules.
Common pitfalls
- Blanket consent in place of legal obligation.
- Treating public data as unprotected.
Frequently asked questions
Can withdrawing consent end AML retention?
Statutory retention does not rely on consent. Assess requests against applicable duties and GDPR rather than deleting automatically.
Put this guidance into practice
Choose a record for the step you are working on. Adapt it to your profession and actual case.
- Practice obligations map · PDF / Word
- Risk assessment outline · PDF / Word
- Customers of obliged entities →
Complete client information online
Where to go next
- Document copies: when, why and how to keep them secure — Distinguish mandatory copying, justified copying and unnecessary accumulation of identity documents.
- How to retain and securely transfer AML evidence — Statutory records, retention triggers and secure export from temporary tools.
Sources and legal references
- Zákon č. 253/2008 Sb., znění od 11. 1. 2026 ↗
§ 16–17a, § 18–24, § 26–27, § 38–39; použitelnost podle § 2 · accessed 2026-10-04 - Nařízení (EU) 2016/679 – GDPR ↗
čl. 5–6, 13–14, 17, 24, 28, 32–34 a 44 a násl. · accessed 2026-10-04 - EDPB: Guidelines 07/2020, správce a zpracovatel ↗
skutečné rozdělení rolí a smlouva dle čl. 28 GDPR · accessed 2026-10-04
Editorial work and source checks are not independent legal approval of your particular process. Compare the conditions and exceptions with your own circumstances.
