BLOG

Is Integrity First, Data Protection Second a Wise Approach?

Read Time: 7 minutes

In 2025, the Financial Action Task Force (FATF) — the international standard setter for anti-money laundering and counter-terrorist financing (AML/CFT) — revised its Travel Rule (Rec. 16) to require more personal data of payment originators and beneficiaries to accompany payment and value transfers. It has now called for public comments on the draft guidance that will support implementation of the new measures. While the guidance acknowledges the importance of data protection and privacy (DPP), it nevertheless establishes an expectation that, where tensions arise, countries should prioritize FATF objectives over DPP objectives.

What is the relationship between AML/CFT objectives and DPP objectives, and how might they be better aligned by the guidance?

Enhanced transparency of payments and value transfers

In the aftermath of the 9/11 terrorist attacks, FATF introduced rules requiring personal information of the sender and recipient of a payment to accompany the payment message. This has become known as the “Travel Rule”. It has since been extended to crypto or virtual asset transfers. 

The FATF was required to revise the Travel Rule to support the G20 project on cross-border payments, and to respond to changes in the payments market. The growing complexity and fragmentation of payment chains have made it more difficult for financial institutions to access sufficient information to identify suspicious activity, prevent fraud, and comply with sanctions, and for law enforcement authorities to access relevant information. The new information requirements are therefore intended to support more efficient compliance by financial institutions as well as timely access to information needed by financial intelligence units and law enforcement authorities.

From 2031 at the latest, additional data (e.g., address and birth year of individuals) will need to accompany the payments above USD/EUR 1,000 (see the summary table below).

Required originator and beneficiary data for cross-border transactions of more than USD/EUR 1,000

Old R.16 RulesRevised R.16 Rules (effective by end of 2030)
Name of originator and beneficiary.Name of originator and beneficiary.
Originator and beneficiary account number where such an account is used to process the transaction.Account number of originator and beneficiary where used; or unique transaction reference number.
Originator's address, OR national ID number, OR customer identification number, OR date and place of birth.Originator: Address or, in the absence of standardized postal address information, the country and town name (or nearest alternative). Beneficiary: Country and town name (or the nearest alternative).*
 If the originator or beneficiary is a legal person, the following information where it exists: the connected business identifier code (BIC), or the Legal Entity Identifier (LEI), or the unique official identifier of that entity.
 

If the originator is an individual, the date of birth of the originator, or, if the full information is not available, the year of birth.*

*Non-binding FATF guidance will be provided on address, date of birth and other information fields to prevent financial exclusion.
 

When implemented, large amounts of personal data will travel between financial institutions and across borders as companions to the core payment information. This information will be recorded and retained for years under AML/CFT and accounting rules. This begs the question, what implications does such data sharing have for data protection and privacy?

The Travel Rule and data protection

The guidance recognizes the need to comply with DPP frameworks, stating that “[a]ll chapters should be read alongside Chapter 9 [the chapter covering data protection]. Data protection and privacy considerations are not a separate layer but apply throughout the collection, storage, and transmission of R.16 information.” The text then continues to note that “[t]he chapter […] explains how AML/CFT/CPF and DPP frameworks are mutually reinforcing...”  In other words, the guidance clearly recognizes the need to reflect DPP when implementing the Travel Rule.

The clear and explicit recognition of the DPP dimension is commendable. With financial fraud on the rise, protecting customer data should be a top priority for financial sector policymakers. The general DPP framing is, however, limited. Right at the beginning of Chapter 9 the writers leave no space for misunderstanding – where integrity and data protection clash, the integrity objective must prevail: “R.16 requires obliged entities to collect and transmit originator and beneficiary information. Because this information often includes personal data, its processing must comply with DPP frameworks in a manner consistent with the objectives of R.16 implementation.

The draft guidance also advises that DPP rules should be reviewed to ensure they support the Travel Rule objectives: “Jurisdictions are expected to review existing DPP frameworks where needed to support the AML/CFT/CPF objectives of R.16.

Where DPP restrictions apply, for example, if the recipient country’s data protection laws are inadequate, countries are required to articulate rules that lower the barriers to the Travel Rule: “To reinforce the legal basis for transferring personal data, countries should clearly articulate in domestic rules, regulations and guidance that transfers of personal data for AML/CFT/CPF purposes are required under applicable laws for law enforcement and national security purposes and constitute transfers in the public interest, which can provide an exception to certain transfer restrictions in some legal frameworks."

From the FATF’s perspective, the main objective of the Travel Rule is to support AML/CFT measures, and therefore DPP measures should be amended where they prevent Travel Rule data from traveling. But there is a bigger picture worth considering – and possibly a different message to convey.

On the one hand, cross-border illicit financial flows continue to threaten the integrity of financial markets. This threat is now aggravated by the rapid increase in financial fraud and the use of financial rails that help criminals move money within seconds out of domestic law enforcement’s reach. On the other hand, the growth in fraud is at least partially fueled by large amounts of compromised customer data available to criminals due to previously weak DPP and cybersecurity measures. In this context, requiring more personal data to be shared across borders to facilitate combating crime is a double-edged sword since it exposes more data to interception and abuse.

When compromised data results in customer harm, trust between the customer and financial institution is undermined. Some customers may decide to abandon the formal financial system, and some may decide never to use it in the first place. Findex data repeatedly shows that the lack of trust is among key barriers to financial inclusion. To be sure, FATF recognizes that financial exclusion – the inverse of financial inclusion – poses an integrity risk as it facilitates money laundering and terrorist financing through informal channels. Financial integrity and DPP policy objectives are therefore aligned, and the FATF and participating countries should instead be guided on how best to align these objectives in practice.

Improved guidance

What, then, should the FATF do instead to ensure that AML/CFT and DPP objectives are appropriately advanced? Here are a few suggestions:

  1. Instead of allowing Travel Rule data to flow into countries that lack equivalent DPP protections, the FATF and its guidance chould support measures and initiatives to improve global data protection equivalence. The guidance could also address the responses to equivalence where an apparent equivalent jurisdiction fails to provide the actual data protection in practice.
  2. Where the guidance relies on institutions negotiating bilateral DPP measures in contracts with foreign counterparts, it could clarify the expectations regarding enforcement and remediation when data is compromised. This could extend to the role of the relevant countries and their DPP authorities, especially where payment channels are systemically important.
  3. The guidance should explicitly address the flow of personal information to countries where there is a risk of data abuse, surveillance, suppression of political opposition, or discrimination against minority groups. Ideally, it should provide specific examples of possible or real conflicts and how they could or have been resolved to serve both DPP and AML/CFT objectives.
  4. The guidance should articulate more clearly the specific integrity improvements that the new requirements are expected to deliver, and how. The guidance advises that countries should articulate that “transfers of personal data for AML/CFT/CPF purposes are required under applicable laws for law enforcement and national security purposes and constitute transfers in the public interest.” But how, when and to what extent will the enhanced data serve those purposes, given that increased data flows also create crime risks? How should the expected impact be monitored? Greater clarity will inform national discussions about potential DPP amendments to support the Travel Rule. FATF could  then monitor and report on those improvements and data breaches to assist in calibrating national alignment.


It is encouraging that the guidance explicitly acknowledges and positions DPP in the context of its overarching objective of increasing transparency across payment chains. FATF should be commended for seeking to integrate DPP considerations throughout the guidance from the outset. There is, however, scope to strengthen the text further to ensure a better alignment between AML/CFT and DPP objectives, particularly in an environment of heightened data security and fraud risks.
 

Resources

Blog

Policymakers view financial inclusion and financial integrity as mutually reinforcing policy goals. Since 2011, about 2 billion people have gained access to formal financial services. But how has increased financial inclusion served financial integrity objectives?
Blog

The recently revised FATF Standards create new opportunities to apply proportionate AML/CFT measures that recognize women’s generally lower risk, helping close the gender gap in financial inclusion if policymakers act intentionally.
Blog

The Financial Action Task Force (FATF) recently adopted a revised travel rule for payments and value transfers – known as Recommendation 16 (R.16). The adoption of the rule raises some important questions – why was this revision required and what is the scope of the changes?

Add new comment

CAPTCHA