A provider may technically process an AML file, but the obliged entity’s responsibility remains. Before starting the service, determine roles, access and exit arrangements. A breach and file export need a concrete operational procedure, not merely a general contractual sentence.
Roles and contracts reflect the actual service
The obliged entity is generally controller of its AML data because it determines the statutory processing purpose. A provider acting only on its instructions is a processor for that activity. The provider’s own processing, such as billing or a separate purpose, needs separate assessment. The DPA label alone does not decide roles; actual powers over purpose and essential means matter under GDPR and EDPB guidance.
An Article 28 contract must define subject matter, duration, nature, purpose, data types, categories of individuals and controller rights. It covers documented instructions, confidentiality, security, other processors, assistance, audit information and handling data at exit. Establish actual storage locations, support access and other processors. Assess transfers outside the EEA under Chapter V; a European invoice does not itself ensure European processing.
Security and personal-data breaches
Article 32 requires measures appropriate to risk. For identity-document copies and AML evidence, establish customer separation, access control, authentication, encryption, backups, recovery and traceable administrative actions. Check how public links are prevented, former workers’ accounts removed and support access restricted. A contractual security promise does not replace a verifiable procedure and responsible contacts.
A processor informs the controller of a personal-data breach without undue delay after becoming aware. Under Article 33, the controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, unless risk to individuals’ rights and freedoms is unlikely. High risk also requires consideration of communication to affected individuals under Article 34, subject to its exceptions. Every breach is documented; neither automatic reporting nor automatic concealment fits all cases.
Exit must preserve the statutory file
Before exit, test exporting documents, check results, sources, versions and timestamps. The file must remain readable and traceable throughout the applicable statutory period. An image of the final page does not replace complete evidence. Determine secure transfer, recipient, completeness checks and subsequent storage. Subscription expiry does not change the entity’s Section 16 retention period.
Article 28(3)(g) provides for deletion or return at the controller’s choice after services end and deletion of copies, unless law requires storage. Specify backups, lawful exceptions and confirmation of completion. A technical application’s short pilot retention is not the statutory AML archive. A provider must not unilaterally change purpose and use client files for model training; any further purpose requires separate legal assessment.
Practical steps
- Map roles, data and other processors.
- Conclude the appropriate contract and verify security.
- Arrange breach reporting and controller decisions.
- Verify export, subsequent archiving and provider deletion.
Illustrative scenario
When changing providers, a business receives a readable file including check history, verifies completeness and then documents contractual return or deletion.
When the situation differs
A business treats a DPA as proof of security and discovers at exit that it can download only a summary without original evidence.
What to document
- Roles, contract and other-processor inventory.
- Breach timeline and risk assessment.
- Verified export and exit evidence.
Common pitfalls
- Automatically assigning the 72-hour deadline to the processor.
- Confusing temporary storage with a ten-year archive.
Frequently asked questions
Does the provider assume the client’s AML responsibility?
Not automatically. Allocating technical services and data processing does not remove the obliged entity’s statutory duties.
Put this guidance into practice
Choose a record for the step you are working on. Adapt it to your profession and actual case.
Complete client information online
Where to go next
- AML and GDPR: purposes, roles and proportionate data scope — AML records’ legal basis, transparency and provider roles without blanket consent.
- How to retain and securely transfer AML evidence — Statutory records, retention triggers and secure export from temporary tools.
Sources and legal references
- Nařízení (EU) 2016/679 – GDPR ↗
čl. 5, 6, 28, 32–34, 44 a násl. · accessed 2026-10-04 - EDPB: Guidelines 07/2020 on controller and processor ↗
skutečné rozdělení rolí, pokyny a smlouva se zpracovatelem · accessed 2026-10-04 - Zákon č. 253/2008 Sb., znění od 11. 1. 2026 ↗
§ 16–17a, § 24, § 38–39 · accessed 2026-10-04
Editorial work and source checks are not independent legal approval of your particular process. Compare the conditions and exceptions with your own circumstances.
