Skip to main content

LUP Student Papers

LUND UNIVERSITY LIBRARIES

Rätten till integritet vid bekämpning av penningtvätt - En undersökning av motstridiga krav mellan AML-regleringen och dataskyddsförordningen

Andersson, Sara LU (2026) HARH13 20252
Department of Business Law
Abstract (Swedish)
Bekämpningen av penningtvätt utgör ett centralt samhällsintresse inom Europeiska unionen och har gett upphov till ett omfattande regelverk som ställer långtgående krav på att verksamhetsutövare behandlar och lagrar personuppgifter. Samtidigt har skyddet för den personliga integriteten stärkts genom EU:s allmänna dataskyddsförordning (GDPR). Regelverken är inte direkt motstridiga, men förutsätter en löpande rättslig avvägning eftersom de ska tillämpas parallellt på samma personuppgiftsbehandlingar. Frågan aktualiseras särskilt inom digitala finansiella tjänster, där kreditinstitut, betalningsinstitut och andra aktörer genomför automatiserade kundkännedoms- och övervakningsåtgärder i stor skala. Syftet med uppsatsen är att analysera hur... (More)
Bekämpningen av penningtvätt utgör ett centralt samhällsintresse inom Europeiska unionen och har gett upphov till ett omfattande regelverk som ställer långtgående krav på att verksamhetsutövare behandlar och lagrar personuppgifter. Samtidigt har skyddet för den personliga integriteten stärkts genom EU:s allmänna dataskyddsförordning (GDPR). Regelverken är inte direkt motstridiga, men förutsätter en löpande rättslig avvägning eftersom de ska tillämpas parallellt på samma personuppgiftsbehandlingar. Frågan aktualiseras särskilt inom digitala finansiella tjänster, där kreditinstitut, betalningsinstitut och andra aktörer genomför automatiserade kundkännedoms- och övervakningsåtgärder i stor skala. Syftet med uppsatsen är att analysera hur kraven på personuppgiftsbehandling enligt penningtvättsregelverket (Anti-Money Laundering, AML) ska tillämpas i förhållande till GDPR:s skydd för den personliga integriteten. Fokus ligger på bevarande av kundkännedomsuppgifter och begränsningar av informationsskyldigheten vid rapportering av misstänkta transaktioner. Analysen utgår från EU-rätten och svensk rätt samt prövar dessa åtgärder mot EU:s stadga om de grundläggande rättigheterna. Uppsatsen använder en rättsdogmatisk metod. Resultatet visar att penningtvättsregelverket i grunden innebär legitima inskränkningar av den personliga integriteten som motiveras av ett betydande allmänintresse. Samtidigt framkommer att generella lagringstider och omfattande sekretessundantag riskerar att gå längre än vad som är nödvändigt i enskilda fall, särskilt i förhållande till lågriskkunder. Detta aktualiserar behovet av en mer nyanserad tilllämpning där effektiv brottsbekämpning förenas med ett reellt dataskydd. (Less)
Abstract
The fight against money laundering constitutes a central public interest within the European Union and has resulted in an extensive regulatory framework imposing far-reaching obligations on obliged entities to process and retain personal data. At the same time, the protection of personal privacy has been strengthened through the EU General Data Protection Regulation (GDPR). Although these regulatory frameworks are not inherently contradictory, their parallel application to the same personal data processing requires an ongoing legal balancing. The issue is particularly evident in digital financial services, where credit institutions, payment institutions, and other actors carry out large-scale automated customer due diligence and monitoring... (More)
The fight against money laundering constitutes a central public interest within the European Union and has resulted in an extensive regulatory framework imposing far-reaching obligations on obliged entities to process and retain personal data. At the same time, the protection of personal privacy has been strengthened through the EU General Data Protection Regulation (GDPR). Although these regulatory frameworks are not inherently contradictory, their parallel application to the same personal data processing requires an ongoing legal balancing. The issue is particularly evident in digital financial services, where credit institutions, payment institutions, and other actors carry out large-scale automated customer due diligence and monitoring measures. The purpose of this thesis is to analyse how the requirements for personal data processing under the anti-money laundering (AML) framework should be applied in relation to the privacy protections established by the GDPR. The analysis focuses on the retention of customer due diligence data and limitations to the duty to provide information when reporting suspicious transactions. The study is based on EU law and Swedish law and evaluates these measures in light of the EU Charter of Funda-mental Rights. A legal dogmatic method is applied. The findings show that the AML framework, in principle, entails legitimate restrictions on personal privacy justified by a significant public interest. However, the analysis also demonstrates that general retention periods and broad confidentiality exceptions risk exceeding what is necessary in individual cases, particularly with regard to low-risk customers. This highlights the need for a more nuanced application in which effective crime prevention is balanced with meaningful data protection. (Less)
Please use this url to cite or link to this publication:
author
Andersson, Sara LU
supervisor
organization
course
HARH13 20252
year
type
M2 - Bachelor Degree
subject
keywords
penningtvätt, AML, GDPR, dataskydd, öppenhetsprincipen, fintech, kundkännedom, informationsskyldighet, Anti-Money Laundering, data protection, the principle of proportionality, Customer Due Diligence.
language
Swedish
id
9223960
date added to LUP
2026-03-10 15:50:14
date last changed
2026-03-10 15:50:14
@misc{9223960,
  abstract     = {{The fight against money laundering constitutes a central public interest within the European Union and has resulted in an extensive regulatory framework imposing far-reaching obligations on obliged entities to process and retain personal data. At the same time, the protection of personal privacy has been strengthened through the EU General Data Protection Regulation (GDPR). Although these regulatory frameworks are not inherently contradictory, their parallel application to the same personal data processing requires an ongoing legal balancing. The issue is particularly evident in digital financial services, where credit institutions, payment institutions, and other actors carry out large-scale automated customer due diligence and monitoring measures. The purpose of this thesis is to analyse how the requirements for personal data processing under the anti-money laundering (AML) framework should be applied in relation to the privacy protections established by the GDPR. The analysis focuses on the retention of customer due diligence data and limitations to the duty to provide information when reporting suspicious transactions. The study is based on EU law and Swedish law and evaluates these measures in light of the EU Charter of Funda-mental Rights. A legal dogmatic method is applied. The findings show that the AML framework, in principle, entails legitimate restrictions on personal privacy justified by a significant public interest. However, the analysis also demonstrates that general retention periods and broad confidentiality exceptions risk exceeding what is necessary in individual cases, particularly with regard to low-risk customers. This highlights the need for a more nuanced application in which effective crime prevention is balanced with meaningful data protection.}},
  author       = {{Andersson, Sara}},
  language     = {{swe}},
  note         = {{Student Paper}},
  title        = {{Rätten till integritet vid bekämpning av penningtvätt - En undersökning av motstridiga krav mellan AML-regleringen och dataskyddsförordningen}},
  year         = {{2026}},
}