Find a lawyerOur capabilitiesYour careerFRAUD WARNING
Locations
Our capabilities
News

Select language:

Locations
Our capabilities
News

Select language:

hamburger menu showcase image
  1. Our thinking
  2. Blogs
  3. Risk and Compliance
  4. Sanctions Compliance Meets Data Privacy: Managing a Structural Tension
7MIN

Sanctions Compliance Meets Data Privacy: Managing a Structural Tension

Oct 9 2026

EU sanctions keep expanding – with the 22nd package against Russia already on the horizon – and continue to place high Know-Your-Customer (KYC) and screening requirements on EU operators. What is often overlooked, however, is that all this compliance-driven data collection and processing must itself comply with the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (CJEU) recently underlined this point in Case C‑798/24 (Jautiva). It held that the GDPR precludes national legislation requiring certain personal data to be made publicly available, inter alia, to implement sanctions, without making access conditional, for example, on demonstrating a legitimate interest. This results in a structural tension: the more rigorously a company screens, the more personal data it collects - and the more personal data it holds, the greater its potential exposure under data protection law. For EU operators, the challenge is therefore to comply with sanctions and data protection laws at the same time. 

This blog post examines where these two regimes pull against each other, and what companies can do to manage the friction.

Two regimes, one dataset

  • Sanctions perspective: 
    • EU asset freeze sanctions require that all funds and economic resources belonging to, owned, held, or controlled by listed persons be frozen, and that no funds or economic resources be made available, directly or indirectly, to or for the benefit of those sanctioned persons. Their reach extends beyond explicitly listed persons: an entity is equally caught where it is considered to be “owned” or “controlled” by one or more sanctioned persons. To ensure sanctions compliance, EU operators must conduct appropriate due diligence, calibrated to their specific business and risk exposure. The European Commission describes this as an “obligation of result” – in plain terms, operators are expected to prevent funds or economic resources from reaching sanctioned persons. Meeting that expectation – as a starting point – means screening counterparties, beneficiaries, and indirect parties in the transaction chain against the relevant sanctions lists. In practice, that requires collecting and processing personal data.
    • Asset freezes are, however, only part of the picture. Particularly under the EU sanctions against Russia and Belarus, certain restrictions apply irrespective of any listing and attach directly to personal characteristics such as nationality or residence. These restrictions are in turn subject to exemptions that depend on further nationalities held or on residence permits. To determine whether a restriction applies, or whether a counterparty benefits from an exemption, operators therefore need information that sanctions list screening alone cannot provide.
       
  • Data protection perspective: 
    • Where an operator runs names through a screening tool, retains a copy of a passport, or records a counterparty’s nationalities and residence status to assess whether a restriction or exemption applies, each of these steps constitutes processing of personal data which is subject to the GDPR. Under Article 6(1) GDPR, such processing is lawful only if and to the extent that it rests on an appropriate legal basis. Identifying the right legal basis is therefore the gateway question for any sanctions compliance process, and the basis relied on determines what information operators must provide to the data subjects, which rights those data subjects can exercise (such as the right to withdraw consent and the right to object), and how long the data may be retained. For example, while the collection of nationality and residence data may generally be justified under Article 6(1)(c) GDPR to the extent that it is legally required under an applicable sanctions restriction or exemption, storing and (further) processing a full nationality and residence profile of every counterparty, irrespective of whether any applicable measure requires it, would require a separate legal basis such as consent (Article 6(1)(a) GDPR) or overriding legitimate interests (Article 6(1)(f) GDPR).

In short, sanctions regulators demand evidence of thorough, documented due diligence, while data protection authorities require equally rigorous justification and documentation of the appropriate legal bases underpinning the processing of personal data in a sanctions compliance context.

Key tension points

  • Data minimisation: 
    • Sanctions compliance generally incentives businesses towards broader data collection, because more data may lower the risk of overlooking a sanctioned person and makes it easier to evidence an effective compliance system. However, the data minimization principle under Article 5(1)(c) GDPR restricts overly broad data collection practices and requires to only process such personal data that are required for a specific purpose. Accordingly, operators should assess whether the same objective could be achieved just as effectively with less personal data. For example, while the processing and retention of ID copies may be helpful or – in some instances - even required to enable accuracy checks, resolution of false positives, re-screening and evidence of due diligence, it increases the risk of identity theft in the event of a personal data breach. A pragmatic approach to reconcile the processing of sensitive data such as ID copies for sanctions screening purposes with the principle of data minimization may therefore be to redact fields that serve no screening or verification purpose (e.g. the document number). Similarly, under the storage limitation principle (Article 5(1)(e) GDPR), such personal data must be retained only for as long as necessary, i.e. must generally be deleted once the business relationship with the data subject ends, unless a statutory retention obligation applies.
       
  • Special category data: 
    • Further legal challenges arise where screening includes special categories of personal data under Article 9 GDPR (such as personal data revealing racial or ethnic origin or biometric data for the purpose of uniquely identifying a natural person), a concept the CJEU generally interprets broadly (Case C‑21/23 – Lindenapotheke). Even though as understood being particularly sensitive by data protection authorities, nationality data do not qualify as special category data as such. However, ID photographs may qualify as biometric data where they undergo specific technical processing enabling unique identification (e.g. automated facial recognition), whereas a manual comparison against an ID copy does not suffice. Operators using automated identity verification tools should therefore assess whether their tools deployed involve biometric matching, as such processing would require an exemption under Article 9(2) GDPR. In a sanctions screening context, such an exemption may apply where the processing is necessary for reasons of substantial public interest (Article 9(2)(g) GDPR). 

Practical takeaways

Operators best positioned to manage this tension are those that approach sanctions compliance and data protection as one integrated compliance framework rather than siloed problems. In practical terms, this means:

  • Calibrate sanctions list screening to the risk profile: Screening scope and depth should reflect the operator’s business model, geographic footprint and counterparty risk, and be subject to ongoing monitoring and routine updates as sanctions lists change.
  • Map GDPR legal bases: Operators should distinguish between processing required by EU sanctions regulations, which may rest on Article 6(1)(c) GDPR, and broader screening or KYC activities, such as screening against third-country lists or retaining full ID copies. The latter likely requires separate justification, for example consent from the data subject or overriding legitimate interests, which should each be documented to comply with the accountability principle under Article 5(2) GDPR (i.e. recording consents obtained or conducting a legitimate interest assessment).
  • Update privacy notices and records: Sanctions screening and KYC compliance should be clearly identified as processing purposes in privacy notices, together with the legal bases and legitimate interests relied upon, and reflected in the records of processing activities (Article 30 GDPR).
  • Assess whether a DPIA is required: Given the systematic nature of screening and the sensitivity of the personal data involved – in particular ID copies – a data protection authority could regard the processing as involving data of a highly personal nature which may trigger the requirement to conduct a data protection impact assessment (DPIA) under Article 35 GDPR.
  • Apply data minimisation in practice: Assess whether the processing and retention of full ID copies are genuinely necessary, and whether individual fields can be redacted.
  • Set retention and deletion schedules: Align retention periods with the relevant legal basis and any statutory retention requirements. EU sanctions law itself does generally not impose specific retention obligations, but documentation of the screening outcome (date, result, reviewer) may be retained to evidence due diligence.

Outlook

The regulatory trajectory points toward increasing complexity. Geopolitical developments continue to drive the expansion of EU sanctions, and new measures typically take effect immediately upon publication. As sanctions regimes become more granular, the amount and type of personal data operators need to apply them correctly is likely to grow. This places pressure on companies to act quickly, often on data that may be incomplete or outdated. A purely reactive approach, collecting data only once a concrete new requirement applies, risks compliance gaps in the interval before affected counterparties can be identified. 

A forward-looking approach, however, sits uneasily with the GDPR’s purpose limitation and data minimisation principles. Collecting data “just in case” cannot rest on Article 6(1)(c) GDPR, which covers only existing legal obligations. Relying on overriding legitimate interests may therefore offer a more flexible legal basis in certain cases, for instance where a sanctions measure has been adopted but does not yet apply, or where a documented risk assessment identifies concrete exposure to an evolving regime. Operators may therefore consider anchoring any forward-looking collection in a documented risk assessment, with a clearly defined purpose and fixed retention periods.

In the absence of detailed supervisory guidance on the intersection of sanctions and data protection, relevant operators should therefore consider evaluating - and potentially updating - their compliance frameworks to ensure they are defensible from both a sanctions and a data protection perspective.

Tags

data cybersecurity and tech regulationsanctions

Authors

Vienna

Stephan Denk

Partner
Düsseldorf

Philipp Roos

Counsel
Vienna

Lukas Pomaroli

Counsel
Vienna

Tensin Studer

Associate
Berlin

Jan Niklas Di Fabio

Associate
Vienna

Julia Sommer

Associate
Latest Insights

Latest Insights

NAVIGATE TO
About usLocations and officesYour careerOur thinkingOur capabilitiesNews
CONNECT
Find a lawyerAlumniContact us
NEED HELP
Fraud and scamsComplaintsTerms and conditions
LEGAL
AccessibilityCookiesLegal noticesTransparency in supply chains statementResponsible procurementPrivacy

Select language:
Select language:
© 2026 Freshfields. Attorney Advertising: prior results do not guarantee a similar outcome