当前位置: X-MOL 学术Journal of Money Laundering Control › 论文详情
Our official English website, www.x-mol.net, welcomes your feedback! (Note: you will need to create a separate account there.)
Implementation of the personal data minimization principle in financial institutions: Lithuania’s case
Journal of Money Laundering Control Pub Date : 2021-07-22 , DOI: 10.1108/jmlc-11-2020-0128
Marius Laurinaitis 1 , Darius Štitilis 1 , Egidijus Verenius 2
Affiliation  

Purpose

The purpose of this paper is to assess such processing of personal data for identification purposes from the point of view of the principle of data minimisation, as set out in the EU’s General Data Protection Regulation (GDPR) and examine whether the processing of personal data for these purposes can be considered proportionate, i.e. whether it is performed for the purposes defined and only as much as is necessary.

Design/methodology/approach

In this paper, the authors discuss and present the relevant legal regulation and examine the goals and implementation of such regulation in Lithuania. This paper also examines the conditions for the lawful processing of personal data and their application for the above-mentioned purposes.

Findings

This paper addresses the problem that, on the one hand, financial institutions must comply with the objectives of collecting as much personal data as possible under the AML Directive (this practice is supported by the supervisory authority, the Bank of Lithuania), and, on the other hand, they must comply with the principle of data minimisation established by the GDPR.

Originality/value

Financial institutions process large amounts of personal data. These data are processed for different purposes. One of the purposes of processing personal data is (or may be) related to the prevention of money laundering and terrorist financing. In implementing the Know Your Customer principle and the relevant legal framework derived from the EU AML Directive, financial institutions collect various data, including projected account turnovers, account holders' relatives involved in politics, etc.



中文翻译:

在金融机构中实施个人数据最小化原则:立陶宛案例

目的

本文的目的是从数据最小化原则的角度评估此类出于身份识别目的的个人数据处理,如欧盟通用数据保护条例 (GDPR) 中规定的那样,并检查个人数据的处理是否出于这些目的可以被认为是相称的,即它是否是为了所定义的目的而进行的,并且只在必要的情况下进行。

设计/方法/方法

在本文中,作者讨论并介绍了相关的法律法规,并考察了立陶宛此类法规的目标和实施情况。本文还研究了合法处理个人数据的条件及其用于上述目的的应用。

发现

本文解决的问题是,一方面,金融机构必须遵守 AML 指令下收集尽可能多的个人数据的目标(这一做法得到监管机构立陶宛银行的支持),并且,另一方面,他们必须遵守 GDPR 确立的数据最小化原则。

原创性/价值

金融机构处理大量个人数据。这些数据被处理用于不同的目的。处理个人数据的目的之一是(或可能)与防止洗钱和恐怖主义融资有关。在实施“了解你的客户”原则和源自欧盟反洗钱指令的相关法律框架时,金融机构会收集各种数据,包括预计的账户营业额、账户持有人的亲属参与政治等。

更新日期:2021-07-22
down
wechat
bug