← Back to list

“Verify More, Hold Less”: Privacy Principles Reshaping CDD in Australia, NZ, Spain, the UK and US

Regulators are sending a consistent message: strong customer due diligence (CDD) does not require hoarding identification data forever. It…

AML Guru · 2026-03-22 13:10 · 0 claps · 7.0 min read
#aml-ctf #privacy
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

“Verify More, Hold Less”: Privacy Principles Reshaping CDD in Australia, NZ, Spain, the UK and US

Regulators are sending a consistent message: strong customer due diligence (CDD) does not require hoarding identification data forever. It requires targeted collection, robust controls and disciplined deletion.

1. Australia: OAIC’s New Line in the Sand

In February 2026, the Office of the Australian Information Commissioner (OAIC) released updated privacy guidance for reporting entities under the Anti‑Money Laundering and Counter‑Terrorism Financing Act 2006 (AML/CTF Act). The guidance clarifies what CDD personal information may be collected, how it must be protected, and when it must be deleted.​

Key points for compliance and risk teams:

  • Collect only what is “reasonably necessary” The OAIC stresses that AML/CTF does not justify open‑ended data collection; personal information must be limited to what is reasonably necessary to meet AML/CTF obligations and broader organisational functions.
  • No more default retention of full ID copies From 31 March 2026 (and from 1 July 2026 for tranche 2 entities), reporting entities should not retain copies of full identification documents for AML/CTF record‑keeping unless another law requires it. The AML/CTF regime itself does not mandate keeping full ID copies.
  • Data minimisation as a security control OAIC has explicitly linked unnecessary retention of ID documents to heightened privacy and security risk, warning that large repositories of IDs increase the impact of data breaches for both individuals and businesses.
  • AML vs privacy: complement, not conflict The guidance confirms that privacy obligations do not prevent entities from complying with AML/CTF; they operate in parallel. Firms can collect, use and disclose personal information necessary for AML compliance, but must assess necessity, be transparent and secure the data.​

For CDD process owners, this means re‑engineering KYC playbooks: avoid “scan everything” defaults, rely more on sighting/verification and structured attributes, and implement event‑based deletion for CDD datasets that are no longer required.

2. New Zealand: CDD Under a Strengthening Privacy Framework

New Zealand’s AML/CFT Act 2009 has long required risk‑based CDD, with updated guidance from the DIA, FMA and RBNZ in 2024–26 tightening expectations on risk assessments, CDD, account monitoring and record‑keeping. Those expectations now sit alongside a Privacy Act regime that is becoming more explicit about indirect collection and biometric processing.

AML/CDD expectations:

  • Updated CDD guidance New guidance for limited partnerships (2024) and for sole traders and partnerships (2025) clarifies how to identify customers, beneficial owners and controllers, and how to tailor CDD to business structures. Standard CDD requires verification of names, dates of birth, addresses and beneficial owners via reliable, independent sources, plus understanding the nature and purpose of the relationship and adding enhanced measures where risk demands it.
  • Biometric Processing Privacy Code The 2025 Biometric Processing Privacy Code, issued by the Office of the Privacy Commissioner, introduces stricter rules on collecting and using biometric data (for example, facial recognition) used in AML identity verification. It requires transparency about what biometric data is collected, how it is used, and the availability of alternative verification methods, and obliges agencies to justify biometric processing against proportionality tests.​
  • Enhanced transparency about indirect collection Amendments to the Privacy Act create a new IPP 3A for indirect collection, requiring agencies that collect personal information from sources other than the individual to take reasonable steps to ensure individuals are aware of key matters (similar to direct collection notices).​

The result is a CDD environment where firms can continue to use advanced verification tools but must:

  • Document why biometric methods are necessary for AML purposes and why less intrusive options are insufficient.​
  • Update privacy notices and AML programme documentation to reflect specific AML/CFT CDD purposes, third‑party data sources and retention periods.

3. Spain: AML CDD in a High‑Enforcement Data Protection Culture

Spain’s AML/CFT framework — centered on Law 10/2010 and Royal Decree 304/2014 — requires robust CDD and beneficial ownership verification. At the same time, Spain’s data protection authority (AEPD) is one of the most active enforcers in Europe, and its expectations around risk assessment and AI‑enabled processing go beyond the GDPR baseline.

AML and privacy touchpoints:

  • CDD and beneficial ownership Obliged entities must identify customers, build accurate risk profiles, and verify beneficial owners before establishing relationships or executing operations. CDD information typically includes names, addresses, birth certificates and corporate documents, with enhanced due diligence for higher‑risk customers or structures.
  • GDPR compliance checklists AEPD’s regulatory compliance checklist emphasises transparency, data subject rights, records of processing and security measures for all personal data processing, including AML/KYC contexts.​
  • Elevated scrutiny for high‑risk processing AEPD’s 2024 AI guidance requires Data Protection Impact Assessments (DPIAs) for any AI system that processes personal data, going beyond the GDPR’s “likely high risk” threshold. For firms using AI or advanced analytics in monitoring AML risk or automating CDD, a DPIA becomes mandatory in Spain.​

For Spanish institutions, the practical effect is:

  • CDD programmes must be tightly mapped to GDPR principles: purpose limitation, data minimisation, storage limitation and security.
  • AI‑driven transaction monitoring or identity verification must undergo formal DPIAs and incorporate safeguards for explainability and bias controls.​

4. United Kingdom: Aligning AML, CDD and UK GDPR

In the UK, financial firms operate under AML and CDD rules supervised by the FCA, while the Information Commissioner’s Office (ICO) enforces UK GDPR and the Data Protection Act 2018. Recent commentary from regulators and industry advisers has focused on aligning KYC/CDD with privacy expectations to avoid dual exposure to AML and data protection penalties.

Key themes in the UK:

  • Joint regulatory expectations The FCA and ICO have both stressed that financial services firms must align AML processes — especially KYC and CDD — with UK GDPR principles on lawful basis, data minimisation, storage limitation and security.​
  • Special category data and biometrics ICO guidance and sector commentary highlight that biometric data used for identity verification constitutes special category data under UK GDPR, requiring a clear legal basis under Article 6 and a relevant condition under Article 9. Firms must conduct careful assessments of their legal basis and safeguards before deploying biometric CDD tools.​
  • Risk of “double jeopardy” Non‑compliant CDD processes can attract sanctions from both financial and data protection regulators, incentivising firms to design “privacy‑by‑design” AML programmes rather than layering privacy controls after the fact.​

In practice, UK firms are:

  • Trimming CDD data capture to what is truly necessary for AML risk assessment and regulatory record‑keeping.
  • Implementing retention rules that distinguish between mandatory record‑keeping periods and legacy “keep everything” habits that no longer have a legal basis.​

5. United States: FinCEN Modernisation and the Privacy Trade‑offs

The US AML regime is driven by the Bank Secrecy Act and rules administered by the Financial Crimes Enforcement Network (FinCEN). While the US lacks an EU‑style omnibus privacy law, FinCEN’s CDD rules and recent reforms show increasing awareness of data volume, duplication and security in AML programmes.

Core CDD requirements:

  • CDD Rule and risk‑based procedures FinCEN’s CDD Rule requires financial institutions to adopt risk‑based procedures for verifying customer identities, monitoring transactions and identifying beneficial owners of legal entities. These measures support up‑to‑date risk profiles, including factors like adverse media.​
  • Modernisation and streamlined CDD In 2026, FinCEN provided exceptive relief from having to re‑identify and re‑verify beneficial owners at each account opening, easing some of the operational burden while maintaining core safeguards. FinCEN has emphasised that institutions must still retain records of customer confirmations and comply with all other BSA obligations, including SAR monitoring, written AML programmes, risk‑based monitoring and record‑keeping.
  • Data‑privacy aware technology Commentators note that FinCEN is entering a “data age” where the goal is to “verify more while exposing less”, encouraging privacy‑preserving technologies that allow collaboration on AML detection and beneficial ownership verification without overexposing personal data.​

US firms therefore face a different but converging pressure: minimise redundant and duplicative CDD data, invest in secure analytics and information‑sharing tools, and anticipate the trajectory towards stronger consumer privacy expectations even in the absence of a single national privacy statute.

6. Cross‑Jurisdiction Comparison: Converging on “Verify More, Hold Less”

Below is a high‑level comparison you can use directly in LinkedIn or Medium posts.

JurisdictionAML/CDD focusPrivacy / data‑protection emphasisRecent trend for CDD dataAustraliaRisk‑based CDD under AML/CTF Act; clear guidance that full ID copies are not required for AML record‑keeping.Privacy Act plus OAIC guidance stress data minimisation, secure handling and timely deletion; AML and privacy obligations must be reconciled.Shift away from retaining full ID images by default; stronger deletion and minimisation obligations from March/July 2026.New ZealandAML/CFT Act 2009 with updated CDD guidance for various business structures; emphasis on beneficial ownership and risk‑based CDD.Privacy Act 2020, new IPP 3A for indirect collection, and Biometric Processing Privacy Code with strict transparency and proportionality tests.Continued use of digital and biometric verification, but with higher transparency and justification thresholds and updated notices/assessments.SpainLaw 10/2010 and Royal Decree 304/2014 require thorough CDD and beneficial ownership verification; enhanced due diligence for high‑risk customers.GDPR enforced aggressively by AEPD, which uses detailed compliance checklists and mandates DPIAs for all AI systems processing personal data.Strong push toward formal DPIAs and robust controls for AI‑driven AML tools, with high enforcement risk for over‑collection or opaque processing.​United KingdomFCA‑supervised AML and CDD obligations for financial services, including KYC and ongoing monitoring.UK GDPR and DPA 2018, enforced by ICO; special scrutiny for biometric identity verification and alignment of AML and privacy programmes.Movement towards integrated AML‑privacy governance to avoid dual penalties; tighter scoping and retention for CDD datasets.United StatesFinCEN’s CDD Rule and broader BSA framework requiring identity verification, beneficial ownership, monitoring and SARs.No single federal GDPR equivalent, but growing emphasis on data security and smarter, less redundant CDD data handling.Streamlined CDD obligations to reduce repetition while keeping core safeguards; interest in privacy‑preserving AML technologies.

7. Practical Takeaways for Compliance, Risk and Product Teams

Across these jurisdictions, a consistent design blueprint is emerging for CDD processes:

  • Build AML and privacy together Treat privacy principles — data minimisation, purpose limitation, transparency and storage limitation — as design inputs to CDD, not after‑the‑fact controls.
  • Minimise and justify what you collect Challenge “just in case” collection of full IDs or biometrics, particularly where guidance explicitly discourages retention (Australia, New Zealand).
  • Use structured attributes, not raw documents, where possible Whenever regulations allow, retain only the data fields and evidence needed to demonstrate compliance, not full document images.
  • Formalise risk assessments and DPIAs for advanced tools In Spain and the UK, DPIAs and legal basis assessments for AI and biometric verification are now essential, and similar expectations are emerging in other markets.
  • Refresh retention and deletion schedules Align retention periods with explicit AML record‑keeping requirements, then default to deletion, particularly for sensitive identifiers and biometric templates.

For compliance leaders, CROs, product owners and engineers — the message is clear: future‑proof CDD programs will be those that treat privacy not as a constraint on AML, but as a way to reduce breach impact, simplify technology stacks and build trust with customers and regulators alike.


메타데이터
post_id
e9df030fbf23
slug
verify-more-hold-less-privacy-principles-reshaping-cdd-in-australia-nz-spain-the-uk-and-us-e9df030fbf23
url
https://medium.com/@amlguru/verify-more-hold-less-privacy-principles-reshaping-cdd-in-australia-nz-spain-the-uk-and-us-e9df030fbf23
canonical_url
https://medium.com/@amlguru/verify-more-hold-less-privacy-principles-reshaping-cdd-in-australia-nz-spain-the-uk-and-us-e9df030fbf23
author_url
https://medium.com/@amlguru
status
ok
fetched_at
2026-06-12 18:14:10