About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

MiFID II vs GDPR: The Delicate Balance Between KYC and Data Privacy

Subscribe to our newsletter

By: Fenergo regulatory consultants Ciara Kennedy and Aoife Harney

Already this year, financial institutions have tackled one significant regulatory hurdle in the form of Markets in Financial Instruments Directive II (MiFID II). In May 2018 they face General Data Protection Regulation (GDPR) that threatens to present banks around the world with conflicting and challenging data collection and protection requirements.

The difficulty lies in balancing the apparent anomalies between protecting investors under MiFID II through the collection of more information about them and their respective activities, while respecting their strengthened data privacy rights under GDPR. This effectively puts banks between a rock and a hard place in terms of managing this delicate balance of requirements.

So how can financial institutions manage MiFID II and GDPR’s data management requirements ahead of the May deadline?

Data collection and protection

MiFID II requires the collection and retention of a large volume of client and counterparty information, including all electronic communications data. This data must be made available to regulators within 72 hours of a request. Conversely, GDPR introduces specific data subject rights around the erasure of data.

Data protection regimes between non-European Economic Area (EEA) jurisdictions can also conflict, further complicating compliance. While firms are responsible primarily to their national regulators under MiFID II, who may well apply the rules fairly and proportionately, GDPR has a responsibility to data subjects, who may use their rights from Day 1 to make onerous demands on firms to show the data held on them and/or erase such data from their systems.

Moreover, the penalties of GDPR non-compliance are significantly tougher than MiFID II, with fines expected to reach up to €20 million or 4% of global turnover for the most significant areas of non-compliance.

Record keeping

The huge scale of MiFID II required the work of regulatory specialist teams for several years, with robust new reporting, operational and technical infrastructures needing to be put in place. GDPR may not consist of the thousands of pages that MiFID II does, but its scope is vast and open to interpretation in certain instances. Put simply, for firms that are not well aligned to existing data requirements, it is a much larger task that MiFID II.

Firms must be accountable for the personal data they hold and consider the purposes and period for which the data is retained. Under MiFID II, client email correspondence must be recorded and archived for up to five years, telephone calls for as long as seven years. Data surrounding suitability of investment recommendations, typically the suitability report, must also be retained by firms for a minimum of five years.

GDPR states that organisations may only process data where there is a legitimate basis for doing so and document this accordingly. The regulation also states that personal data is to be stored only for as long as necessary or within the statutory minimum retention periods specified by other legislation. If a client wishes to have data recorded about them deleted within the timeframe set down by MiFID II, for example, the firm will not be compelled to comply.

Conflicting record-keeping requirements and obligations such as these could easily become a logistical headache for firms. To comply here, organisations need to tread carefully and be able to demonstrate that they have considered the principles of necessity, proportionality and data retention at the time of designing their record retention policies.

Reconciling requirements across two regimes

Finding a solution to manage the internal contradictions between these two bodies of regulation is essential. In order to be able to demonstrate a sufficient degree of GDPR compliance, firms will need to ensure they have tested their systems, processes and newly-implemented policies and procedures to confirm that they can comply with enhanced data subject rights and additional obligations under GDPR. As part of this review process, firms should map current and anticipated client data flows and conduct a data audit to evaluate data lifecycle management within the organisation.

Ensuring compliance with both regimes is not only about policy and procedural change. In larger organisations, specific teams will now be required to collaborate on a regular basis to ensure that the collection and processing of data and the retention of records is conducted in a manner that is compliant with both GDPR and MiFID II.

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: ESG data sourcing and management to meet your ESG strategy, objectives and timeline

Date: 11 June 2024 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes ESG data plays a key role in research, fund product development, fund selection, asset selection, performance tracking, and client and regulatory reporting, yet it is not always easy to source and manage in a complete, transparent and timely manner....

BLOG

New Year’s Resolutions: Get OTC Derivatives Reporting Fit for EMIR Refit

By Thomas Steimann, Head of Regis-TR at SIX. The OTC derivatives markets have faced a slew of new regulations since the 2008 Global Financial Crisis, to which the market has continued to adapt. 2024 will be no different. The EMIR Refit is the latest in a wave of regulatory change for the derivatives markets, with...

EVENT

RegTech Summit New York

Now in its 8th year, the RegTech Summit in New York will bring together the regtech ecosystem to explore how the North American capital markets financial industry can leverage technology to drive innovation, cut costs and support regulatory change.

GUIDE

Regulatory Data Handbook 2023 – Eleventh Edition

Welcome to the eleventh edition of A-Team Group’s Regulatory Data Handbook, a popular publication that covers new regulations in capital markets, tracks regulatory change, and provides advice on the data, data management and implementation requirements of more than 30 regulations across UK, European, US and Asia-Pacific capital markets. This edition of the handbook includes new...