Digital scales of justice weighing blockchain compliance against data erasure rights under GDPR

“Delete My Data”: Why Crypto Businesses Can’t Always Honor GDPR Erasure Requests

Futuristic data vault illustrating GDPR erasure requests balanced against AML data retention obligations

Customer erasure requests are becoming more popular as customers aim to minimize their online data. It usually starts when a customer submits a request to delete their account, invoking the GDPR “right to be forgotten”. For a crypto business serving EU and US customers, the request requires a timely and careful review of which personal data may be erased and which records must be retained under applicable AML and KYC laws. 

For a crypto business serving EU customers, the instinct is often to comply immediately, particularly where the account in question is small, dormant, or shows minimal activity. That instinct is generally mistaken, and acting on it can expose the business to significant regulatory risk.

The Customer’s Right to Erasure vs AML Compliance

Under the GDPR, individuals have a right to erasure of their personal data under Article 17(1). But that right is not absolute. Article 17(3) makes clear that the erasure obligation does not apply where processing is necessary for AML and KYC compliance with a legal obligation which requires processing under EU or Member State law. AML and KYC recordkeeping obligations are the textbook example of that legal obligation.

At the same time, a U.S.-facing money services business (MSB) or a firm with U.S. nexus is separately bound by the Bank Secrecy Act (BSA). Under 31 CFR 1010.430(d),  records required to be retained under the BSA framework must be kept for five years, and a willful violation of applicable BSA recordkeeping requirements may also result in criminal penalties, including fines and imprisonment under 31 U.S.C. § 5322.

This means a business that is subject both to GDPR and to applicable EU or U.S. AML recordkeeping obligations, which describes a large share of crypto platforms, is bound by two independent legal regimes that both say: keep the compliance records.

Takeaway: A customer erasure request can be made, but their transaction and KYC history must be retained, as it’s needed for AML and KYC compliance.

Why a Customer’s Transaction Amount Doesn’t Matter

The size or materiality of the customer relationship has no bearing on the retention obligation. AML recordkeeping rules are not risk-based in the way a business’s commercial judgment might be. They attach to the fact that a transaction or relationship occurred, not to its dollar value.

When considering the erasure right vs compliance issue, the true question is: which specific data points are we legally required to retain, and which aren’t?

Transaction value may determine whether a particular recordkeeping requirement is triggered. Once a record falls within an applicable AML or BSA retention requirement, however, the size of the transaction generally does not shorten the prescribed retention period. The relevant question is therefore not whether the customer or transaction was commercially significant, but whether the particular record is one the business is legally required to retain.

Digital scales of justice weighing blockchain compliance against data erasure rights under GDPR

Three Key Legal Authorities for AML and KYC Compliance

1. U.S. Bank Secrecy Act, 31 CFR 1010.430 

For U.S.-nexus MSBs, exchanges, and similar platforms, 31 CFR 1010.430 requires covered financial institutions to maintain records of certain financial transactions for five years, and this is reinforced by parallel five-year retention rules for related categories of transaction and customer identification records.

Where EU AML law independently requires retention, Article 17(3)(b) provides a clear basis for refusing erasure of the covered records during the applicable retention period. Any separate U.S. retention obligations should also be identified and analyzed, particularly where the controller is subject to both regimes.

2. GDPR, Article 17(3)(b)

A documented data retention policy is what makes a refusal to erase data defensible when a statutory retention period applies. Where a customer is in the EU or EEA and exercising GDPR rights, Article 17(3)(b) is the controlling exception, but it only shields the data that the underlying legal obligation actually requires, not the entire customer file.

3. EU AML Directive, Article 40

Where the business is subject to an EU Member State’s AML laws as an obliged entity, Article 40 of the Fourth AML Directive generally requires obliged entities to retain customer due diligence documents and transaction records for five years after the end of the business relationship or the date of an occasional transaction, and this obligation applies independently of the scope of the customer due diligence measures that were actually applied. Once that five-year period expires, Member States require obliged entities to delete the personal data, unless national law provides for further retention on a case-by-case, necessity-and-proportionality basis.

How a Retention Matrix Can Help

The mistake in either direction (deleting everything, or refusing to delete anything) comes from treating the customer record as a single, indivisible thing. The standard approach used by privacy counsel is to sort the file into two buckets before responding to the request:

A retention matrix solves this by forcing a data-by-data-point decision instead of an all-or-nothing one. Rather than asking “can we delete this customer?” the matrix asks “what is the legal status of each piece of data we hold on this customer?”. 

The matrix answers that question once, consistently, for every erasure request that comes in. Built correctly, it becomes a standing reference: compliance and support teams don’t need to re-litigate the legal analysis every time a request lands. They just apply the matrix.

Retention matrix showing which customer data must be retained under AML/BSA rules versus what can be deleted under a GDPR erasure request

How to Respond to a Customer

Rather than a flat refusal or a full deletion, the defensible middle path looks like this:

  1. Verify identity: before acting on the request at all.
  2. Classify the data: against the retention matrix above.
  3. Delete data for which no continuing lawful basis exists: without undue delay.
  4. Restrict processing of retained data: it should not be used for marketing, profiling, or any purpose beyond compliance, and access should be limited to personnel who need it for that purpose.
  5. Communicate the decision to the customer: explaining what was deleted, what was retained, the legal basis for retention (citing the applicable AML law and GDPR Article 17(3)(b)), and the date on which the retained data is scheduled for deletion.
  6. Document the decision internally: request received, legal basis for partial refusal, retention end date, and which systems (including any third-party processors) are affected.

A non-response, or a response that simply refuses the request without explaining the legal basis, is itself a problem; silence or an unreasoned refusal can be treated as a GDPR violation in its own right.

Who’s Responsible for the Deletion: The Company or the Processor?

Crypto platforms frequently rely on a third-party identity verification vendor to run KYC checks. When an erasure request comes in, a common instinct is to tell the customer to “contact the verification provider directly.” 

Under the GDPR’s controller/processor framework, the platform that determines why and how the data is processed, including setting the retention period, is the data controller. The identity verification vendor may act as the platform’s processor when handling information solely on the platform’s instructions, although the parties’ agreement and actual processing activities should be reviewed because some vendors act as independent or joint controllers for particular purposes.

That means the erasure request belongs with the platform, not the vendor: the platform evaluates the request and instructs its processor accordingly, to retain the data where a legal obligation applies, and to delete it once the retention period expires. Where the vendor acts solely as a processor, the platform remains responsible for evaluating the request and issuing appropriate deletion, restriction, or retention instructions.

EU and US regulatory frameworks converging to illustrate cross-border crypto compliance obligations

Conclusion

An AML-regulated crypto business is not faced with a binary choice between honoring every erasure request and disregarding GDPR on the basis of its regulatory status. 

The appropriate approach lies between these two extremes: retain only the data that is legally required, delete everything else, restrict retained data to compliance purposes, and document the rationale at each step. 

This approach satisfies the expectations of AML examiners while also placing the business in a defensible position should a data protection authority later inquire why a deletion request was not fully honored.


Legal References

  • Regulation (EU) 2016/679 (GDPR), Article 17(1): right to erasure (“right to be forgotten”).
  • Regulation (EU) 2016/679 (GDPR), Article 17(3)(b): exception to erasure where processing is necessary for compliance with a legal obligation under EU or Member State law.
  • Directive (EU) 2015/849 (Fourth AML Directive), as amended by Directive (EU) 2018/843 (Fifth AML Directive), Article 40: obliges entities to retain customer due diligence documentation and transaction records for five years after the end of the business relationship or an occasional transaction.
  • 31 CFR § 1010.430: Bank Secrecy Act regulation setting the general five-year retention period for records required under 31 CFR Chapter X.
  • 31 U.S.C. § 5322: criminal penalties for willful failure to maintain records required under the Bank Secrecy Act.

This post is provided for general informational purposes and does not constitute legal advice. If your business has received a data deletion or erasure request and is uncertain how AML retention obligations apply, contact Hodder Law to discuss your specific facts.

Similar Posts