On 20 September 2026, Human Rights in Finance (EU) submitted its response to the Anti-Money Laundering Authority’s consultation on the draft Implementing Technical Standards under Article 69(3) of the EU Anti-Money Laundering Regulation. The standards will determine the format used by obliged entities to report suspicions and to provide transaction records to Financial Intelligence Units (FIUs).
HRIF.EU’s main concern is that standardisation must not become a route to maximising the amount of personal and financial data routinely pushed into FIU databases.
Article 69 already contains a push and a pull model: use it!
Article 69 AMLR distinguishes between two information flows. Obliged entities must report on their own initiative where they know, suspect or have reasonable grounds to suspect that funds or activities are linked to criminal activity or terrorist financing. FIUs can then request additional information, including transaction records, where necessary.
That distinction matters. The initial “push” report should explain the concrete suspicion and contain the information needed to understand it. Wider account histories, contextual data and other records can be obtained through a targeted FIU request.
If everything that happens to be available is transferred at the outset, the difference between targeted suspicion reporting and general data collection starts to disappear.
In this respect we noted that the Dutch experience – reporting systems built around broad notions of unusualness – lead to the conclusion by the Dutch Court of Audit that the resulting output creates proportionality and discrimination concerns. EU harmonisation should avoid standardising those problems across Member States.
Unusual is not the same as suspicious
HRIF.EU therefore argues that “unusual” should not silently become a substitute for “suspicious”. A statistical deviation, an elevated risk score or behaviour that differs from a customer’s normal pattern may justify internal review. It does not automatically justify external reporting to an FIU.
In a similar vein, the requirement to report ‘activities’ to us seems to be a legislative flaw that in essence opens up the reporting system to be bulk surveillance of any activity. This is insufficiently limited and in our view a category of reports that may not exist as it is ill-defined in scope.
HRIF.EU recognises that an ITS cannot cure a level-1 drafting choice. The converse, however, also holds: an implementing technical standard may specify the format of reporting, not extend its substance. Under Article 291 TFEU and settled case law on the limits of delegated implementing powers, essential elements cannot be determined at level 2. Where a level-1 term is broad and insufficiently defined, the data model should operationalise it restrictively rather than at its maximum reach — otherwise the format becomes the source of the obligation.
The Dutch experience is an important warning in this respect. The Dutch report 2-4 million reports per year, while if our institutions would follow the EU Member State benchmark, this would only be 45.000 reports. This is really overdoing it and in our consultation response, HRIF.EU referred to the March 2026 findings of the Netherlands Court of Audit on proportionality, discrimination and the ineffectiveness of the Dutch anti-money laundering approach.
HRIF.EU’s concern is that EU harmonisation should not reproduce our local problems at European scale, Instead, Member States operating high-volume or data-rich reporting models should align with a minimised level of targeting in the AMLR-formats.
Every data field needs a necessity test
The proposed reporting model contains extensive structured data about identity, nationality and geography, occupation, addresses, electronic identifiers, internal risk classifications, PEP information, adverse information, accounts, transactions and non-transaction activity.
Some of those fields may be necessary in a particular case. That does not make them necessary in every report (see also the Court of Justice ruling in Ligue des droits humains (C-817/19)).
HRIF.EU therefore asks AMLA to assess every field against a simple test: Is the field genuinely relevant to the concrete Article 69 suspicion? Is its transmission necessary and proportionate? Could the same information be obtained later through a targeted FIU request? Does the field contain sensitive information, create a proxy for protected characteristics, or introduce an unsupported adverse inference? Is the information accurate and capable of correction?
This is especially important for internal customer-risk classifications, negative media, PEP information and broad free-text or non-transaction fields. An internal risk score is an institution’s assessment, not proof of criminal conduct. Negative media can consist of allegations rather than verified facts. PEP status is a preventive regulatory category and does not itself imply wrongdoing.
GDPR profiling rules still matter
The AMLR does not create a data-protection-free zone. Where automated processing evaluates aspects such as reliability, behaviour or location, GDPR profiling rules remain relevant. The same applies where apparently neutral variables act as proxies for sensitive or protected characteristics.
HRIF.EU therefore calls for data minimisation, accuracy, proportionality and non-discrimination safeguards to be built into the reporting architecture itself.
That should include an ex-ante assessment of legal basis, necessity, proportionality, false-positive risks, discrimination, retention and less intrusive alternatives. Once the system is operational, AMLA should also monitor false positives, proxy discrimination, unnecessary reporting, inaccurate data and whether individual fields remain necessary.
Better financial intelligence does not require more indiscriminate data
The core principle in our submission is straightforward: inclusion of a field in an ITS cannot itself justify processing that field. Legal necessity and proportionality must come first and must justify its inclusion in the data model.
A more targeted model would not weaken financial intelligence. FIUs should receive the information required to understand a genuine suspicion, with additional information obtained when necessary through targeted requests.
That approach improves the quality of intelligence while reducing unnecessary collection, profiling and retention of personal data. It is also more consistent with the structure of Article 69 AMLR.
Generic HRIF.EU comments
HRIF.EU has published its generic consultation comment alongside this article so that the legal and policy concerns can be assessed directly.
It must be clear that we are not convinced that the draft ITS and supporting analysis have demonstrated necessity and proportionality for all proposed data points and classifications. The existence of an AML/CFT objective does not itself establish that every potentially useful category of personal data is necessary.
AMLA should therefore document this assessment expressly, at data-point and category level, before adoption. In the absence of such demonstration, serious questions remain as to whether the resulting processing can satisfy the GDPR, the AMLR and Articles 7, 8, 21 and 52(1) of the Charter.
HRIF.EU will monitor the developments closely.