• Link to LinkedIn
  • Link to Youtube
  • Sign In
  • Register
  • Subscribe
  • Contact
Institute for Financial Integrity
  • Training
    • eLearning Courses

      • Suite of interactive e-learning courses to educate and engage staff on core compliance topics

      • Learn More
    • Video Library

      • An online learning journey through the various domains of financial crime, explore our library of expert-led videos

      • Learn More
    • Training Services

      • Trusted compliance training design, development, and delivery tailored to your unique requirements

      • Learn More
    • Certifications
      • Certified Risk Management Specialist – Global Sanctions
      • Certified Financial Integrity Professional Program
  • Technology
    • DOLFIN

      • A platform that equips financial integrity professionals with the continuing education, expert insights, resources and tools needed to protect the integrity of the global financial system.

      • Learn More
    • AskFIN

      • A revolutionary, AI-powered tool seamlessly integrated with DOLFIN® — the world’s largest and most trusted library of curated resources on financial integrity topics.

      • Learn More
  • Insights
    • Insights
      • Articles
      • Reports & White Papers
      • Webinars
      • Subscribe
  • About Us
    • Who We Are
      • Our Story
      • Leadership
      • Press Releases
    • Who We Serve
      • Financial Institutions
      • Jurisdictions
      • Executives
      • Industry Professionals
  • Get a Demo
  • Menu Menu

Data as a Critical Business and Compliance Asset

Consumer Protection and Data Retention

📅 April 15, 2026

Data is an increasingly critical asset. It has a key role in due diligence, identifying and taking action against illicit finance, and identifying fraud, as well as for commercial decisions and business success. Conversely, inadequate protection of personal data can make individuals vulnerable to identity theft and other fraud, and misuse of personal information can damage the reputation of companies and lead to regulatory and legal consequences too.

Data retention is also a regulatory requirement in specific contexts, such as the United States Bank Secrecy Act (BSA), which mandates keeping records relating to customer accounts and compliance for a minimum of five years.

What is Personal Information?

The definition of personally identifiable information varies by jurisdiction. Generally, it refers to any information that identifies an individual or can be linked to an individual. It includes both direct and indirect identifiers. Companies may collect personal information from customers, employees, vendors and suppliers, to name just a few examples.

Examples of personal information include:

  • Personal identifiers such as full name, phone number, address, and date of birth
  • Government identifiers such as social security number or equivalent, passport or license number, or tax identification number
  • Financial information such as bank routing and account number, wallet addresses, evidence of income, or evidence of assets
  • Data collected through automated processes such as IP addresses, device IDs, and geolocation data

Sensitive personal information refers to information where unauthorized use or disclosure places the individual at significant risk of harm such as discrimination. Examples include: genetic, health and biometric data; racial or ethnic origin; sexual orientation and personal life data.

Not all data is “personally identifiable”. Examples of non-personal data include:

  • Aggregated or statistical data, meaning information which has been compiled from multiple sources and summarized to avoid revealing individual details. Examples include regional sales figures or aggregated statistics on the use of products/services.
  • Anonymized data, meaning information where personal identifiers have been removed. Examples include partially/fully masked IP addresses and survey responses with names and contact details removed.
  • Commercial information, which may be commercially sensitive and subject to contractual protections but is not personal data. Examples include non-published revenue projections or a list of corporate clients.

Key Data Protection Regulations

Some jurisdictions provide more extensive consumer data privacy protection than others.

European Union’s General Data Protection Regulation (GDPR)

Organizations are required to comply with GDPR if they are collecting data on individuals in the EU (wherever the organization is located) or if they are established in the EU (regardless of where the data is processed).

The GDPR sets out seven data principles which are best practices for managing personal data. These are:

  1. Lawfulness, Fairness, and Transparency: Data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.
  2. Purpose Limitation: Data must be used for its original, stated purpose, unless permission is requested and provided for other uses.
  3. Data Minimization: Data collection and processing must be limited to what is necessary for the specified purpose.
  4. Data Accuracy: Data must be kept accurate and up to date.
  5. Storage Limitation: Data must only be retained for as long as necessary and must be disposed of securely when no longer needed.
  6. Integrity and Confidentiality: Data must be protected from loss, misuse, and unauthorized activities such as unauthorized access, disclosure, alteration, or destruction.
  7. Accountability: Organizations must be able to demonstrate that they fulfil these principles, for example they must keep individuals informed about how their personal data is collected, used, and protected, and their rights to access, correct, or delete their data.

California Consumer Privacy Act (CCPA)

Data privacy in the United States is governed by a patchwork of federal and state laws. Some of the most stringent protections are imposed by the California Consumer Privacy Act. These impose similar requirements to GDPR. The CCPA was extended in 2023 by the California Privacy Rights Act (CPRA).

Bank Secrecy Act (BSA)

The Bank Secrecy Act (BSA) applies specific data retention requirements to compliance records including filings such as SARs and CTRs, as well as records that document the institution’s compliance program. Records must be maintained for a minimum of five years. Records may be maintained in many forms provided they are accessible in a reasonable period of time.

While BSA requirements are separate from data privacy requirements, there are intersections between them since BSA records may include personal information.

Other Jurisdictions

Other jurisdictions globally, such as Dubai and Singapore, also establish data privacy regimes.

Permitted Uses of Customer Data

Organizations are responsible for communicating to individuals how their data will be used and obtaining consent for these uses.

Examples of the way personal information may be used include:

  • During due diligence to identify and verify the identity of a customer
  • To provide services, such as a financial institution using a wallet address provided by a customer to send or receive funds in accordance with customer instructions, or using bank details provided by an employee for their payroll
  • To detect and prevent fraud, along with fulfilling legal and regulatory obligations such as filing Suspicious Activity Reports (SARs) or Currency Transaction Reports (CTRs)
  • For research, development, or marketing – provided the customer has consented

Data must not be shared with third parties without the individual’s consent.

Example: Amazon Fined for GDPR Violations

Amazon was fined €746 million ($888 million) in 2021 by Luxembourg’s National Commission for Data Protection for violating GDPR rules. The fine was issued because Amazon processed customer data for targeted advertising without obtaining proper user consent.

In addition to the fine, one of the largest imposed on a tech company, Amazon was required to revise its data and consent policies.

Consumer Rights and Protections

While each regulatory regime is different, consumer rights often include rights to:

  • Request a copy of the information held about them
  • Request inaccuracies to be corrected, which an organization must do promptly
  • Object to use of data, for example to “opt out” of marketing
  • Request deletion of their data

Elements of a Data Protection Program

Data protection programs usually include several elements:

  • Organizational teams to identify and assess the applicable regulatory requirements
  • Policies and procedures to set out the requirements applicable within that institution, such as retention and disposal requirements
  • Technical security measures such as encryption, usernames and passwords, and role-based restrictions, to ensure data is adequately protected
  • Reporting lines and email addresses for consumers, staff, and other stakeholders to raise questions or make requests

Morgan Stanley Fined for Improper IT Infrastructure Disposal

Morgan Stanley was fined $60 million by the U.S. Office of the Comptroller of the Currency in 2020 after failing to properly dispose of IT infrastructure. The firm had hired a third-party vendor to decommission two data centers but did not verify proper data deletion, leading to unprotected customer data being left on servers and hardware after they were sold to a recycler.

In addition to the regulatory penalty, a class action lawsuit was brought against Morgan Stanley by individuals whose data had been compromised.

Data Analytics for Enhanced Oversight 

DNFBPs, such as professionals in the real estate sector, are particularly prone to corruption because the sector is often exploited by illicit actors to launder ill-gotten gains due to the stable nature of real estate assets and the substantial sums involved. Furthermore, although DNFBPs operate under stringent regulatory frameworks intended to prevent financial crimes, these can be circumvented through sophisticated schemes or the exploitation of regulatory loopholes. these can be circumvented through sophisticated schemes or the exploitation of regulatory loopholes.  

Data analytics is increasingly vital in the fight against corruption, particularly within designated DNFBPs. This technology enables the examination of vast amounts of financial data to detect patterns and anomalies indicative of corrupt practices. DNFBPs that proactively implement measures to detect and prevent illicit activities can protect themselves and significantly reduce the likelihood of becoming targets of investigations. 

Identification of Anomalies in Financial Flows

In sectors like real estate, where large transactions frequently occur, data analytics plays a crucial role in identifying discrepancies in financial flows. For example, data analytics can highlight inconsistencies in property prices that deviate significantly from market norms, which may suggest under-the-table dealings or money-laundering activities. Similarly, in law firms and accountancies, data analytics can detect irregularities in client accounts or financial statements, pinpointing unusual transaction patterns that warrant further investigation. 

Risk Assessments of Clients and Transactions Based on Historical Data

Data analytics also facilitates comprehensive risk assessments by utilizing historical data to profile and evaluate clients and transactions. This process includes analyzing past behavior patterns of clients and the typical transactional frameworks within specific industries to assess the risk levels of new transactions. High-risk transactions or clients can be flagged automatically for additional scrutiny or for the implementation of more stringent controls. This proactive approach helps DNFBPs comply with regulatory requirements and maintain a proactive stance against potential corruption.

Anti-Money Laundering in the UK Real Estate Sector

In the UK, several real estate firms use data analytics to comply with AML regulations. By using their computer systems to analyze transaction data and client profiles, these companies can identify high-risk transactions and clients, flagging those that may involve proceeds from corruption. This approach has helped ensure regulatory compliance and maintain the integrity of the real estate market.

Consequences of Inadequate Data Protection

Non-compliance can have financial, legal, regulatory, reputational, and commercial implications.

Regulatory penalties include:

  • GDPR: Fines of up to Euro 20 million (USD 22 million) or 4% of global revenue
  • CCPA: Fines of up to $7,500 per intentional violation and $2,500 per unintentional violation

Legal action may be taken including lawsuits from affected individuals seeking damages for identity theft or fraud.

Reputational damage may result from adverse publicity associated with data leaks, security breaches, regulatory penalties, and legal action. This may affect the perception of the organization, resulting in loss of clients and difficulty attracting and retaining staff.

Capital One Fined for Data Breach

Capital One was fined $80 million in 2019 by the Office of the Comptroller of the Currency and agreed to a $190 million class-action settlement, after 100 million U.S. and 6 million Canadian customers’ financial data was compromised.

The breach was caused by a misconfigured firewall in a cloud environment, which allowed a former AWS engineer to access Social Security Numbers, bank account details, and credit scores. The breach went undetected for four months, amplifying the damage.

Consumers entrust organizations with their data and rely on them to process, retain, and dispose of it appropriately and securely. Data retention also fulfils a critical role in ensuring institutions fulfil their counter illicit finance responsibilities – and have the records to demonstrate their compliance to regulators. Both are essential not just to remain compliant, but also for consumer trust and commercial success.

Effective Data Protection Starts with Employee Education

Educate staff on data protection and retention standards and requirements with a tailored e-learning course.

Whether looking to revamp an annual compliance course or to develop a new instructor-led program covering emerging threats, IFI can design, develop and deliver training tailored to your organization’s unique needs.

Explore Training Services

Recommended Blogs

August Monthly Sanctions and Export Controls Report

September 2, 2026
Explore this month’s Sanctions and Export Controls Update, highlighting IFI’s take on key developments from August 2026.
Read more
https://finintegrity.org/wp-content/uploads/2026/09/august-2026-se-report-bg.jpg 888 1184 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-09-02 07:00:562026-09-01 13:19:24August Monthly Sanctions and Export Controls Report

The Judgment Gap in Market Abuse Compliance

August 25, 2026
While banks may know the set of rules outlined in the EU’s Market Abuse Regulation, exposure sits in the judgment calls related to delayed disclosure, information barriers, and market soundings. Dive into where the risk lies in each area.
Read more
https://finintegrity.org/wp-content/uploads/2026/08/judgement-gap-in-market-abuse-compliance-bg.jpg 841 1500 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-08-25 07:00:462026-08-24 11:34:59The Judgment Gap in Market Abuse Compliance

Beyond the Course Library

August 12, 2026
A comprehensive compliance course library doesn’t guarantee prepared staff. Here's how forward-looking teams are moving beyond static course libraries toward learning that keeps pace with risk.
Read more
https://finintegrity.org/wp-content/uploads/2026/08/beyond-the-course-library-bg.jpg 1060 1800 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-08-12 07:00:232026-08-11 12:42:07Beyond the Course Library

July Monthly Sanctions and Export Controls Report

August 4, 2026
Explore this month’s Sanctions and Export Controls Update, highlighting IFI’s take on key developments from July 2026.
Read more
https://finintegrity.org/wp-content/uploads/2026/08/july2026-se-bg.jpg 1177 1800 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-08-04 07:00:452026-08-04 09:42:02July Monthly Sanctions and Export Controls Report

A Financial Institution’s Guide to Updated EU Market Abuse Regulation

July 29, 2026
MAR sounds straightforward until a real case tests it. This guide breaks down what the regulation covers, who it applies to, and the disclosure rules, court rulings, and regulatory guidance that shifted the ground under compliance teams in 2026.
Read more
https://finintegrity.org/wp-content/uploads/2026/07/guide-to-market-abuse-bg.jpg 1067 1600 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-07-29 07:00:472026-07-28 12:45:11A Financial Institution’s Guide to Updated EU Market Abuse Regulation

The Hidden Factor Behind Effective Compliance Training

July 22, 2026
Discover why the success of a compliance training program depends on more than just quality content—it begins with how employees perceive its value. Learn how organizations can improve engagement, drive meaningful behavioral change, and demonstrate measurable training ROI by rethinking the learner experience.
Read more
https://finintegrity.org/wp-content/uploads/2026/07/hiddenfactor-compliance-bg.jpg 1200 1800 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-07-22 07:00:132026-07-21 11:49:18The Hidden Factor Behind Effective Compliance Training

June 2026 Sanctions and Export Controls Report

July 1, 2026
Explore this month’s Sanctions and Export Controls Update, highlighting IFI’s take on key developments from June 2026.
Read more
https://finintegrity.org/wp-content/uploads/2026/06/june2026-se-report-bg.jpg 798 1200 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-07-01 07:00:392026-07-02 10:28:58June 2026 Sanctions and Export Controls Report

Crypto Layering

June 17, 2026
Public blockchains make transactions visible, but that doesn't mean illicit activity is easy to trace. In our latest article, we examine how criminals use crypto layering techniques to obscure fund flows and the practical controls financial institutions can deploy to strengthen their AML programs.
Read more
https://finintegrity.org/wp-content/uploads/2026/06/crypto-layering-bg.jpg 675 1200 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-06-17 07:00:012026-06-15 11:44:11Crypto Layering

Who Owns the Risk?

June 10, 2026
Organizations often take a one-size-fits-all approach to compliance training, despite each line of defense playing a different role in managing risk. Explore how training should be tailored to the responsibilities of the first line, second line, third line, and senior leadership.
Read more
https://finintegrity.org/wp-content/uploads/2026/06/who-owns-bg.png 667 1000 IFI https://live-black-pebble.pantheonsite.io/wp-content/uploads/2023/12/GIFI-Placeholder2.png IFI2026-06-10 07:00:162026-06-10 11:47:15Who Owns the Risk?
Previous Previous Previous Next Next Next
Download IFI Compliance Checklist Report

Follow Us on LinkedIn

Share this article

  • Share on LinkedIn
  • Share by Mail

Recent Articles

  • Dirty Barrels
  • Real Estate, Real Risks
  • Iran and the Sanctions Landscape
  • August Monthly Sanctions and Export Controls Report
  • National Bank of Yemen Launches Enterprise-Wide Compliance Training with IFI

Explore Other Topics

  • Artificial Intelligence
  • Compliance Best Practices
  • Corruption
  • Digital Assets
  • Drug Trafficking
  • European Union
  • Fraud
  • Human Trafficking
  • Investigations
  • Money Laundering
  • Oil and Gas
  • Press Releases
  • Proliferation Finance
  • Regulation
  • Russia
  • Sanctions
  • Strategic Trade Controls / Export Controls
  • Terrorism

View Our Expert Insights

  • Compliance Training Readiness Checklist
  • Inside the Cartels and Chinese Money Laundering Networks Driving Criminal Economies
  • High Stakes – Casinos, Crime, and Cartels
  • From Cost Center to Risk Control
  • Leveraging Artificial Intelligence for Enhanced Financial Compliance
  • The Convergence of Sanctions and AML/CFT Regimes
  • Casinos and Cryptocurrency Driving Illicit Finance in East and Southeast Asia
  • Russia 2024: The Two-Year Anniversary of the Invasion
  • Human Trafficking Crisis after Russia’s Invasion of Ukraine
  • 2024 Trends Report
© DOLFIN Academy LLC 2026
  • Link to LinkedIn
  • Link to Youtube
  • Privacy Policy
Link to: Understanding the FATF: A Guide for Private Sector Stakeholders Link to: Understanding the FATF: A Guide for Private Sector Stakeholders Understanding the FATF: A Guide for Private Sector Stakeholders Link to: From Alerts to Accountability Link to: From Alerts to Accountability From Alerts to Accountability
Scroll to top Scroll to top Scroll to top

This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.

Accept settingsHide notification onlySettings

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Google Analytics Cookies

These cookies collect information that is used either in aggregate form to help us understand how our website is being used or how effective our marketing campaigns are, or to help us customize our website and application for you in order to enhance your experience.

If you do not want that we track your visit to our site you can disable tracking in your browser here:

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy
Accept settingsHide notification only