Promethean

KYC, AML and Data Protection in Malta: When Can You Say No to a Request for Information?

  • News
  • 8 mins read

Requests for personal and financial information have become an ordinary part of doing business in Malta.

Banks, financial institutions, lawyers, accountants and Company Service Providers (“CSPs”) routinely request identification documents, corporate records, beneficial ownership information and, in appropriate circumstances, evidence concerning Source of Wealth (“SOW”) and Source of Funds (“SOF”).

For clients, however, an increasingly common question is whether they are legally required to provide everything that is requested.

The answer is not necessarily yes.

The fact that a request is described as a Know Your Customer (“KYC”) or Anti-Money Laundering (“AML”) requirement does not, by itself, give a business an unlimited right to collect personal information. At the same time, data protection legislation cannot be used to refuse information which a regulated business is legally required to obtain.

The balance between these two regimes is therefore becoming increasingly important.

The Maltese AML and Data Protection Framework

The Maltese AML framework is principally based on the Prevention of Money Laundering Act (Chapter 373 of the Laws of Malta), the Prevention of Money Laundering and Funding of Terrorism Regulations (“PMLFTR”) and the Implementing Procedures issued by the Financial Intelligence Analysis Unit (“FIAU”).

The FIAU’s Implementing Procedures are binding on subject persons and are intended to assist them in fulfilling their statutory AML and Countering the Financing of Terrorism (“CFT”) obligations.

Personal information collected in the course of these activities is also subject to the General Data Protection Regulation (“GDPR”) and the Data Protection Act (Chapter 586 of the Laws of Malta).

These regimes do not operate in competition with one another.

A subject person may be required to collect and verify information under AML legislation while remaining under an obligation to process that information lawfully, securely and proportionately under data protection legislation.

When AML Requires Information

Customer Due Diligence (“CDD”) obligations may require a subject person to identify and verify its customer, establish beneficial ownership, understand the purpose and intended nature of the relationship and conduct appropriate ongoing monitoring.

The extent of those obligations depends upon the circumstances and risk associated with the relationship.

This is important because AML compliance does not mean collecting the maximum amount of information available.

It means obtaining sufficient information to understand and manage the relevant risk.

The FIAU’s revised Implementing Procedures Part I, issued in April 2026, expressly recognise a degree of proportionality and flexibility in the implementation of AML/CFT measures. The procedures are intended to promote a proportionate risk-based approach, taking into account the size, type and complexity of the relevant business.

The GDPR Does Not Create a General Right to Refuse KYC

It is sometimes suggested that a customer can refuse to provide information simply by relying upon the GDPR.

That is not correct.

Where a subject person is legally required to identify and verify a customer or beneficial owner, the processing of the relevant personal data may be based upon compliance with a legal obligation rather than the customer’s consent.

A customer cannot therefore prevent mandatory AML processing merely by stating that he does not consent to it.

The position is different, however, where the information requested goes beyond what is reasonably necessary for the relevant compliance purpose.

This is where the GDPR principle of data minimisation becomes important.

KYC Does Not Mean Unlimited Disclosure

A request for information should have a legitimate purpose and an appropriate legal basis.

For example, there may be a clear justification for requesting evidence of identity, beneficial ownership or the origin of funds involved in a particular transaction.

The position is less straightforward where a customer is asked to provide extensive personal financial information which has no obvious connection with the relevant relationship or risk.

The words “AML”, “KYC” or “compliance” do not automatically answer that question.

A customer may reasonably ask what particular regulatory requirement the information is intended to satisfy and why the requested documentation is necessary.

This does not amount to refusing compliance.

It amounts to asking that the compliance request itself be properly justified.

Source of Wealth and Source of Funds

This distinction becomes particularly relevant in relation to SOW and SOF.

Source of Wealth concerns the origin of a person’s overall wealth, while Source of Funds concerns the origin of the particular funds involved in the relationship or transaction.

Depending on the risk profile, a subject person may need documentary evidence rather than simply relying upon a customer’s statement.

This is not merely theoretical. Recent FIAU supervisory activity has continued to identify weaknesses in the establishment and verification of customers’ Source of Wealth and Source of Funds, particularly in higher-risk situations.

The practical consequence is that a customer may legitimately be asked for independent supporting evidence where the circumstances justify enhanced scrutiny.

It does not follow, however, that every customer can automatically be required to disclose every aspect of his personal financial history.

When a Request May Be Excessive

The question should always be whether the information requested is necessary and proportionate to the purpose for which it is being collected.

This becomes particularly relevant where the information concerns third parties.

A request for information concerning a spouse, family member, shareholder or other individual should be capable of being connected to the relevant AML assessment.

If a third party is a beneficial owner, contributor of funds or otherwise relevant to the transaction, additional information may be justified.

If that person has no relevant connection with the relationship, the requesting party should be able to explain why his or her personal information is necessary.

The mere existence of a family or corporate connection is not an unlimited justification for disclosure.

Collection Is Not the Same as Disclosure

Another important distinction is between collecting information and disclosing it.

A bank or professional adviser may have a lawful basis to collect personal documents for AML purposes. This does not mean that the same documents can subsequently be provided to any third party who requests them.

The identity and legal status of the recipient matter.

A disclosure to a competent authority acting within its statutory powers is fundamentally different from disclosure to another commercial party with no independent entitlement to the information.

The GDPR therefore remains relevant even where the underlying information was originally collected for AML purposes.

The 2026 Regulatory Developments

The Maltese AML framework is currently undergoing further development.

In April 2026, the FIAU issued amendments to its Implementing Procedures Part I. Among other changes, the revised procedures removed a previous exception concerning the identification of beneficial owners through legal persons or arrangements, reinforcing the requirement to identify the natural person or persons who ultimately qualify as beneficial owners.

In June 2026, the FIAU also launched a consultation concerning amendments to the Prevention of Money Laundering Act, the PMLFTR and other legislation as part of Malta’s implementation of the European Union’s new AML Package.

At European Union (“EU”) level, Regulation (EU) 2024/1624, the new Anti-Money Laundering Regulation (“AMLR”), will apply from 10 July 2027. It represents a significant move towards greater harmonisation of AML rules throughout the European Union.

These developments reinforce the importance of a properly documented, risk-based approach to customer information.

When Can You Say No?

There is therefore no absolute rule that a customer must provide every document requested by a regulated business.

A request may legitimately be challenged where its legal or regulatory basis is unclear, where the information appears unrelated to the stated purpose, where the request is disproportionate to the identified risk or where it concerns third-party information for which no adequate justification has been provided.

The appropriate response is not necessarily an outright refusal.

In many cases, the better approach is to ask the requesting party to identify the regulatory basis for the request, explain its purpose and clarify the specific documentation required.

Conversely, where the information is genuinely required to enable a subject person to satisfy its statutory AML/CFT obligations, refusing to provide it may prevent the relationship or transaction from proceeding.

The key distinction is therefore between information which must be provided by law and information which is merely being requested as a matter of convenience or excessive internal policy.

The Importance of Professional Advice

The interaction between AML/CFT obligations and data protection is becoming increasingly relevant for businesses and individuals operating in Malta.

Particular care may be required where a relationship involves complex corporate structures, beneficial owners, international transactions, trusts, politically exposed persons (“PEPs”) or substantial Source of Wealth and Source of Funds documentation.

A properly structured compliance process should protect both objectives. It should allow a subject person to obtain the information necessary to comply with AML legislation while ensuring that personal data is not collected or disclosed unnecessarily.

Understanding where that boundary lies can be particularly important when responding to extensive KYC requests or when establishing internal compliance procedures.

How Promethean Can Assist You

Promethean advises businesses, regulated professionals, entrepreneurs and international clients on Maltese AML/CFT, regulatory and data protection matters.

Our services include advising on KYC, CDD, SOW and SOF requirements, reviewing AML and privacy policies, assessing the proportionality of information requests and advising on the lawful collection, retention and disclosure of personal information.

Promethean assists clients in navigating Malta’s evolving regulatory environment, ensuring that necessary compliance obligations are satisfied while protecting clients against unnecessary or disproportionate disclosure of personal information.

For further information regarding AML/CFT obligations, KYC requirements, data protection or the handling of personal and financial information in Malta, please contact us.