In 2025, the Monetary Motion Job Pressure (FATF) — the worldwide commonplace setter for anti-money laundering and counter-terrorist financing (AML/CFT) — revised its Journey Rule (Rec. 16) to require extra private information of cost originators and beneficiaries to accompany cost and worth transfers. It has now referred to as for public feedback on the draft steering that can help implementation of the brand new measures. Whereas the steering acknowledges the significance of knowledge safety and privateness (DPP), it however establishes an expectation that, the place tensions come up, international locations ought to prioritize FATF goals over DPP goals.
What’s the relationship between AML/CFT goals and DPP goals, and the way would possibly they be higher aligned by the steering?
Enhanced transparency of funds and worth transfers
Within the aftermath of the 9/11 terrorist assaults, FATF launched guidelines requiring private data of the sender and recipient of a cost to accompany the cost message. This has grow to be often called the “Journey Rule”. It has since been prolonged to crypto or digital asset transfers.
The FATF was required to revise the Journey Rule to help the G20 challenge on cross-border funds, and to answer adjustments within the funds market. The rising complexity and fragmentation of cost chains have made it harder for monetary establishments to entry ample data to determine suspicious exercise, forestall fraud, and adjust to sanctions, and for legislation enforcement authorities to entry related data. The brand new data necessities are subsequently meant to help extra environment friendly compliance by monetary establishments in addition to well timed entry to data wanted by monetary intelligence models and legislation enforcement authorities.
From 2031 on the newest, further information (e.g., handle and delivery 12 months of people) might want to accompany the funds above USD/EUR 1,000 (see the abstract desk under).
Required originator and beneficiary information for cross-border transactions of greater than USD/EUR 1,000
| Outdated R.16 Guidelines | Revised R.16 Guidelines (efficient by finish of 2030) |
|---|---|
| Title of originator and beneficiary. | Title of originator and beneficiary. |
| Originator and beneficiary account quantity the place such an account is used to course of the transaction. | Account variety of originator and beneficiary the place used; or distinctive transaction reference quantity. |
| Originator’s handle, OR nationwide ID quantity, OR buyer identification quantity, OR date and hometown. | Originator: Tackle or, within the absence of standardized postal handle data, the nation and city title (or nearest various). Beneficiary: Nation and city title (or the closest various).* |
| If the originator or beneficiary is a authorized particular person, the next data the place it exists: the related enterprise identifier code (BIC), or the Authorized Entity Identifier (LEI), or the distinctive official identifier of that entity. | |
|
If the originator is a person, the date of delivery of the originator, or, if the complete data is just not obtainable, the 12 months of delivery.* *Non-binding FATF steering will probably be offered on handle, date of delivery and different data fields to stop monetary exclusion. |
When applied, giant quantities of private information will journey between monetary establishments and throughout borders as companions to the core cost data. This data will probably be recorded and retained for years beneath AML/CFT and accounting guidelines. This begs the query, what implications does such information sharing have for information safety and privateness?
The Journey Rule and information safety
The steering acknowledges the necessity to adjust to DPP frameworks, stating that “[a]ll chapters ought to be learn alongside Chapter 9 [the chapter covering data protection]. Information safety and privateness concerns aren’t a separate layer however apply all through the gathering, storage, and transmission of R.16 data.” The textual content then continues to notice that “[t]he chapter […] explains how AML/CFT/CPF and DPP frameworks are mutually reinforcing…” In different phrases, the steering clearly acknowledges the necessity to mirror DPP when implementing the Journey Rule.
The clear and specific recognition of the DPP dimension is commendable. With monetary fraud on the rise, defending buyer information ought to be a prime precedence for monetary sector policymakers. The final DPP framing is, nevertheless, restricted. Proper originally of Chapter 9 the writers go away no area for misunderstanding – the place integrity and information safety conflict, the integrity goal should prevail: “R.16 requires obliged entities to gather and transmit originator and beneficiary data. As a result of this data usually contains private information, its processing should adjust to DPP frameworks in a way according to the goals of R.16 implementation.”
The draft steering additionally advises that DPP guidelines ought to be reviewed to make sure they help the Journey Rule goals: “Jurisdictions are anticipated to review present DPP frameworks the place wanted to help the AML/CFT/CPF goals of R.16.”
The place DPP restrictions apply, for instance, if the recipient nation’s information safety legal guidelines are insufficient, international locations are required to articulate guidelines that decrease the limitations to the Journey Rule: “To strengthen the authorized foundation for transferring private information, international locations ought to clearly articulate in home guidelines, rules and steering that transfers of private information for AML/CFT/CPF functions are required beneath relevant legal guidelines for legislation enforcement and nationwide safety functions and represent transfers within the public curiosity, which might present an exception to sure switch restrictions in some authorized frameworks.“
From the FATF’s perspective, the principle goal of the Journey Rule is to help AML/CFT measures, and subsequently DPP measures ought to be amended the place they forestall Journey Rule information from touring. However there’s a larger image price contemplating – and probably a special message to convey.
On the one hand, cross-border illicit monetary flows proceed to threaten the integrity of monetary markets. This risk is now aggravated by the speedy improve in monetary fraud and the usage of monetary rails that assist criminals transfer cash inside seconds out of home legislation enforcement’s attain. However, the expansion in fraud is no less than partially fueled by giant quantities of compromised buyer information obtainable to criminals on account of beforehand weak DPP and cybersecurity measures. On this context, requiring extra private information to be shared throughout borders to facilitate combating crime is a double-edged sword because it exposes extra information to interception and abuse.
When compromised information ends in buyer hurt, belief between the shopper and monetary establishment is undermined. Some clients might resolve to desert the formal monetary system, and a few might resolve by no means to make use of it within the first place. Findex information repeatedly exhibits that the shortage of belief is amongst key limitations to monetary inclusion. To make sure, FATF acknowledges that monetary exclusion – the inverse of monetary inclusion – poses an integrity threat because it facilitates cash laundering and terrorist financing by way of casual channels. Monetary integrity and DPP coverage goals are subsequently aligned, and the FATF and taking part international locations ought to as a substitute be guided on how greatest to align these goals in observe.
Improved steering
What, then, ought to the FATF do as a substitute to make sure that AML/CFT and DPP goals are appropriately superior? Listed below are just a few strategies:
- As an alternative of permitting Journey Rule information to stream into international locations that lack equal DPP protections, the FATF and its steering chould help measures and initiatives to enhance international information safety equivalence. The steering may additionally handle the responses to equivalence the place an obvious equal jurisdiction fails to offer the precise information safety in observe.
- The place the steering depends on establishments negotiating bilateral DPP measures in contracts with international counterparts, it may make clear the expectations concerning enforcement and remediation when information is compromised. This might prolong to the function of the related international locations and their DPP authorities, particularly the place cost channels are systemically necessary.
- The steering ought to explicitly handle the stream of private data to international locations the place there’s a threat of knowledge abuse, surveillance, suppression of political opposition, or discrimination towards minority teams. Ideally, it ought to present particular examples of potential or actual conflicts and the way they might or have been resolved to serve each DPP and AML/CFT goals.
- The steering ought to articulate extra clearly the particular integrity enhancements that the brand new necessities are anticipated to ship, and the way. The steering advises that international locations ought to articulate that “transfers of private information for AML/CFT/CPF functions are required beneath relevant legal guidelines for legislation enforcement and nationwide safety functions and represent transfers within the public curiosity.” However how, when and to what extent will the improved information serve these functions, on condition that elevated information flows additionally create crime dangers? How ought to the anticipated influence be monitored? Better readability will inform nationwide discussions about potential DPP amendments to help the Journey Rule. FATF may then monitor and report on these enhancements and information breaches to help in calibrating nationwide alignment.
It’s encouraging that the steering explicitly acknowledges and positions DPP within the context of its overarching goal of accelerating transparency throughout cost chains. FATF ought to be counseled for searching for to combine DPP concerns all through the steering from the outset. There may be, nevertheless, scope to strengthen the textual content additional to make sure a greater alignment between AML/CFT and DPP goals, significantly in an atmosphere of heightened information safety and fraud dangers.
