Source: OJ L, 2024/2902, 28.11.2024

Current language: FR

Article 5 Durée de conservation des données à caractère personnel par les émetteurs


Summary What does Article 5 of the ITS on non-EU currency reporting say?

This article addresses data retention obligations for issuers in the context of personal data received from crypto-asset service providers.

It directly complements the reporting framework established in earlier articles by setting a clear limit on how long issuers may hold onto personal data on token holders that was submitted to them as part of that reporting chain.

The rule is straightforward: retention must not exceed what is necessary for the reporting obligations, and in any case cannot go beyond 5 years from the date the data was obtained.

Important points:

  • Ensure personal data on holders received from crypto-asset service providers is not retained beyond what is necessary to fulfil your reporting obligations under this regulation.
  • The maximum retention period is 5 years from the date the personal data was obtained by the issuer.
  • This obligation falls on issuers and is directly tied to the data submitted by crypto-asset service providers under Articles 1(2) and 3(2) of this regulation.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

Les émetteurs ne conservent les données à caractère personnel concernant les détenteurs transmises par les prestataires de services sur crypto-actifs conformément à l’article 1er, paragraphe 2, et à l’article 3, paragraphe 2, du présent règlement qu’aussi longtemps que nécessaire pour se conformer aux obligations d’établissement de rapports énoncées à l’article 22, paragraphe 1, du règlement (UE) 2023/1114. La durée de conservation de ces données ne doit pas dépasser cinq ans à compter de la date d’obtention des données à caractère personnel par les émetteurs.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod