Complylty — KYC/AML Συμμόρφωση για Λογιστές, Δικηγόρους & Συμβούλους

Πλατφόρμα δέουσας επιμέλειας KYC/KYB για Έλληνες επαγγελματίες βάσει Ν.4557/2018, AMLD5/6 και GDPR. Αυτόματο CDD, risk scoring, αρχεία 5ετίας, AI ανάλυση.

KYC/AML ανά Επάγγελμα

Οδηγοί KYC/AML

Τιμολόγηση

Starter €19/μήνα (έως 20 πελάτες) · Professional €49/μήνα (έως 100 πελάτες) · Business €99/μήνα (απεριόριστοι). 14 ημέρες δωρεάν δοκιμή.

GDPR and AML: How They Work Together — What Professionals Need to Know

GDPR says 'data minimisation' and 'right to be forgotten'. L.4557/2018 says 'keep records for 5 years'. How do these two requirements combine? What applies to Greek professionals?

The Core Dilemma: GDPR vs AML

Every professional applying KYC/CDD faces an apparent conflict: GDPR (Regulation 2016/679, L.4624/2019) requires: • Data minimisation principle — collect only what is necessary • Storage limitation principle — keep data only for as long as needed • Right to erasure — the client may request deletion L.4557/2018 (AML) requires: • Retention of CDD files for 5 years after the end of the relationship (Article 25) • Preservation of identification documents and risk assessments • Ability to provide records to supervisory authorities immediately Which law "wins"? The answer: both — but in the right way.

The Legal Basis for Processing AML Data

GDPR does not prohibit data processing — it requires a lawful basis. For AML/KYC obligations, the lawful basis is clear: Article 6(1)(c) GDPR: "Legal Obligation" — Processing is necessary for compliance with a legal obligation to which the controller is subject. L.4557/2018 is precisely that "legal obligation". Therefore, collecting and retaining CDD data is entirely lawful under GDPR — provided it is done within the scope of AML obligations. Practical implication: You do not need the client's consent for KYC data. You do, however, need to inform them (Privacy Policy / Article 13 notice).

What About the Right to Erasure?

A client requests erasure of their data (Article 17 GDPR). What do you do? During the business relationship: You cannot delete KYC data — it is necessary for your lawful service and for AML compliance. After the relationship ends (but within 5 years): L.4557/2018 requires retention for 5 years. The right to erasure is "suspended" due to legal obligation (Article 17(3)(b) GDPR). After 5 years: The legal obligation has been fulfilled. If there is no other lawful basis, the data must be deleted. Important: Refusal to erase must be documented — send the client a written reply explaining the lawful basis.

The Professional as Data Controller

A critical point that many overlook: the professional (accountant, lawyer) is the Data Controller for the KYC data of their clients. This means they must: • Maintain a Record of Processing Activities (ROPA) • Inform clients under Article 13 GDPR • Be responsible for the security of the data • Handle data subject requests (access, rectification, erasure) If they use a platform such as Complylty, the platform acts as the Data Processor — a fact reflected in the applicable Data Processing Agreement (DPA).

Practical GDPR + AML Checklist for Professionals

To be compliant with both sets of rules: ☐ Privacy Policy (Article 13 notice) — informing clients about CDD processing ☐ Documented lawful basis ("legal obligation") ☐ Record of Processing Activities (ROPA) ☐ Process for responding to data subject requests (within 30 days) ☐ Automatic deletion of data after 5+1 years (safety buffer) ☐ DPA with every external processor (cloud, software) ☐ Security breach notification within 72 hours to the Hellenic DPA

The 5 Most Common GDPR Errors in KYC Processes

1. Collecting more data than CDD requires: Requesting information not needed for AML — violation of the minimisation principle. 2. Not informing the client about CDD: The client must know you are processing their data for AML purposes. 3. Keeping data after 5 years without justification: Once the legal obligation has expired, further retention is unlawful. 4. Insecure storage: Unprotected Excel files, emailed identity scans, unlocked archives — a data security violation. 5. No DPA with KYC software: If you use third-party software for CDD and have no DPA, you are in breach of GDPR.