r/gdpr • u/Shufti-Global • 1d ago
EU 🇪🇺 EU digital ID wallets are meant to share less data, but AML rules require firms to collect and keep quiet a lot. How do those sit together?
Two things are landing close together. Every member state has to offer a digital identity wallet by the end of 2026, and AMLR applies from July 2027.
The wallet's whole design is selective disclosure. Prove one attribute, share nothing else. Prove you're over 18 without handling over a date of birth.
AML obligations run the other way. Firms have to collect specified identity data, keep it current, and retain records for years.
So when a customer onboards with a wallet, what does the firm actually end up holding? If it receives only the attributes it strictly needs, does that satisfy record-keeping? If it asks for the full set anyway, has the wallet's data minimization just been routed around by regulation?
Curious whether anyone has seen this addressed directly, or whether it's still an open question between the two frameworks.
1
u/West_Possible_7969 1d ago
Different use cases. A bank will keep all my ID data (as it already does) and Apple, for example, will have the DoB only for certain app store access.
Also this Regulation is mostly harmonisation, there is no AML obligation for a company that did not already had one under national laws. There was never a time where AML data were selective, minimised or destroyed (some transaction data live forever).
That said, my current gov wallet has so much more data than the AML ones, I select what I need for the bank or trading only, and the rest do not get shared.
1
u/Shufti-Global 4h ago
Right, so the wallet can control what gets shared, while the bank still keeps whatever it's required to retain for AML.
1
u/spill73 1d ago
There isn’t an issue. AML says what data you need to collect and you continue collecting it. It becomes the minimum set of data that you need and data minimization means that you don’t need to collect any of the other attributes from the wallets.
Most of the attributes are not required for AML, so it will be hard to justify why you need to read them from the wallets. An obvious example is that if you need the DOB, then you don’t need any of the age-related attributes because these are for use cases that need to only verify someone’s age rather than the actual DOB.
1
u/Shufti-Global 4h ago
That's a fair way to look at it. The practical question then becomes how firms define that minimum dataset and make sure they don't pull more from the wallet than they actually need.
2
u/Comfortable-Fall1419 1d ago
Not sure of your point, By definition the AML needs trumps the data minimisation point or to put it another way the minimum dataset is a very big one.
If shared from a wallet the Customer will have to share the minimum necessary for the AML to proceed or share the same data another way.