Recital 59
(59) In order to respect privacy and protect personal data, the minimum data necessary for the carrying out of AML/CFT investigations should be held in centralised automated mechanisms for bank accounts or payment accounts, securities accounts and crypto-asset accounts. It should be possible for Member States to determine which additional data it is useful and proportionate to gather. When transposing the provisions relating to those mechanisms, Member States should set out retention periods equivalent to the period for retention of the documentation and information obtained within the application of customer due diligence measures. It should be possible for Member States to exceptionally extend the retention period, provided good reasons are given. The additional retention period should not exceed an additional 5 years. That period should be without prejudice to national law setting out other data retention requirements allowing case-by-case decisions to facilitate criminal or administrative proceedings. Access to those mechanisms should be on a need-to-know basis.
← Recital 58 · All articles · Recital 60 →
Source: EUR-Lex CELLAR · retrieved 2026-09-04 · Text as adopted (Official Journal); later amendments are not incorporated in this text.