Ask an Irish designated person how long they keep AML records and you will hear either "five years" or "forever, just in case". The first is roughly right. The second is a data protection problem waiting to be found.
From 10 July 2027, Regulation (EU) 2024/1624 (AMLR) — the EU's directly applicable AML rulebook — replaces the substantive requirements your firm currently works under via the Criminal Justice (Money Laundering and Terrorist Financing) Act 2010. Among its changes is a record-keeping approach that is deliberately two-sided: retain records for five years, then delete them. Not "retain for at least five years and archive indefinitely". Retain, then delete.
That second half is where AML compliance and GDPR finally meet in the same sentence — and where many firms' current filing habits fall short.
What the AMLR expects from your records
Under the AMLR, obliged entities (the regulation's term for what Irish law calls designated persons) must keep the records that evidence their compliance: customer due diligence documentation, identification and verification evidence, and records of transactions and business relationships.
The headline points for your firm:
- Five years is the retention period. You must be able to produce your CDD file and transaction records throughout that window — for your supervisor, and for FIU Ireland, which under the AMLR can expect answers to information requests within five working days.
- Deletion follows retention. Once the retention period ends, the personal data should go. Holding it longer needs a lawful justification — it is no longer covered by your AML obligations.
- The clock has a trigger point. Retention runs from a defined point (broadly, the end of the relationship or the relevant transaction), so your system needs to know when each relationship actually ended. Verify the precise trigger against the text of the regulation on EUR-Lex before you finalise your policy — this is a detail worth getting exactly right.
If your current practice is a shared drive of scanned passports going back to 2011, both halves of that rule are a problem.
Why "keep everything forever" breaks GDPR
Irish firms sometimes assume AML law gives them cover to hold client identity data indefinitely. It does not. GDPR's storage limitation principle says personal data may be kept only as long as necessary for the purpose it was collected for. Your AML obligations are a strong lawful basis for holding CDD data — passports, proofs of address, beneficial ownership information, screening results — during the retention period. Once that period expires, the lawful basis you were relying on expires with it.
That leaves firms holding some of the most sensitive commercial data there is — identity documents, wealth information, ownership structures — with no clear justification. In a data breach, every stale file you did not need to hold becomes part of the incident. The Data Protection Commission publishes general guidance on retention and storage limitation at dataprotection.ie, and it applies to designated persons like anyone else.
The AMLR removes the ambiguity by writing the delete step into the AML rulebook itself. After 10 July 2027, over-retention is not just a GDPR issue — it sits inside your AML compliance framework too, which is exactly where your supervisor (the PSRA, the Law Society of Ireland, your designated accountancy body, the AMLCU or the Central Bank of Ireland, depending on your sector) will be looking.
What records are actually in scope
Map what your firm holds before deciding how long to hold it. For a typical Irish practice, AML-relevant records include:
- Client identification and verification documents (passports, driving licences, utility bills)
- Beneficial ownership information, including RBO extracts obtained before onboarding and any discrepancy-reporting records
- Risk assessments for individual clients and your Business-Wide Risk Assessment versions
- Transaction records and supporting documents for the services you provided
- Screening results — sanctions and PEP checks, including the "no match" results that prove you looked
- Records connected with any Suspicious Transaction Reports, filed in Ireland to FIU Ireland via goAML and to the Revenue Commissioners
- Training records and internal compliance sign-offs
Not all of these start their clock on the same day — a CDD file for a ten-year client relationship stays live for the whole relationship plus the retention period, while records for a one-off transaction have a much shorter life.
A retention schedule beats a retention habit
The practical fix is a written retention schedule: a simple table listing each record category, the retention trigger, the retention period, and what happens at expiry. A hypothetical extract might look like this:
| Record category | Trigger | Action at expiry |
|---|---|---|
| CDD file — ongoing client | End of business relationship | Delete after retention period |
| CDD file — occasional transaction | Completion of transaction | Delete after retention period |
| BWRA versions | Superseded by new version | Retain per policy, then delete |
| Training log entries | Date of training | Retain per policy, then delete |
The point is not the exact rows — your firm's schedule should reflect your services and your supervisor's guidance. The point is that "what happens at expiry" is a defined action someone owns, not an empty column.
Deletion is a process, not a delete key
The hardest part of retain-then-delete is the delete. Common failure points:
- Nobody records end dates. If your system does not capture when a relationship ended, no retention clock ever starts.
- Copies everywhere. The CDD file is deleted, but the passport scan still sits in an inbox, a paper file and a backup.
- Third parties. If a KYC provider or software vendor holds client data on your behalf, your retention schedule has to reach them too — that is what your processor agreements are for.
- No log. When a supervisor asks why a file is gone, "our retention policy required deletion on this date, and here is the log entry" is a complete answer. Silence is not.
Deletion done properly is evidenced deletion: a record that the file existed, was held for the required period, and was disposed of under policy.
What to do now
- Inventory where AML records actually live — practice management system, shared drives, email, paper, third-party providers.
- Start capturing relationship end dates and transaction completion dates today, so retention clocks can run.
- Draft a retention schedule covering every AML record category, with a named owner for disposal.
- Verify the AMLR's retention provisions against the regulation text on EUR-Lex before finalising, and check your sector supervisor's guidance.
- Align your GDPR documentation — records of processing and privacy notices — with the same periods, so your AML and data protection stories match.
- Set a diary point well before 10 July 2027 to switch your policy from the CJA 2010 framework to the AMLR wording.
Where CompliDesk fits
CompliDesk Ireland is being built with retention and deletion as a product feature, not an afterthought — retention clocks, expiry queues and evidenced disposal, designed around the AMLR from day one. See the AMLR explainer for how the wider rulebook changes for Irish firms.
General information, not legal advice. This article provides general information about EU and Irish anti-money-laundering requirements. It is not legal, tax or compliance advice. Regulatory detail is still evolving through 2026–27 — verify against primary sources (EUR-Lex, AMLA, and your sector’s Irish supervisor) and seek qualified advice before acting.