Compliance & Standards
Is Integrity First, Data Protection Second a Wise Approach?
A CGAP blog by Ivo Jeník and Louis De Koker critiquing FATF's draft implementation guidance for its revised Travel Rule (Recommendation 16), which from 2031 requires additional originator and beneficiary personal data, including addresses, birth dates and legal-person identifiers such as BIC or LEI, to accompany cross-border payments above USD/EUR 1,000. The authors commend the guidance's explicit acknowledgment of data protection and privacy (DPP) frameworks but flag its hierarchy: where integrity and privacy clash, R.16 objectives prevail, and jurisdictions are expected to review DPP rules to support Travel Rule data flows as public-interest exceptions to transfer restrictions. They argue this is double-edged: fraud growth is partly fueled by compromised customer data from weak DPP measures, and expanded cross-border data flows expose more information to interception; resulting trust erosion undermines financial inclusion, which FATF itself treats as an integrity risk. Proposed fixes: global DPP equivalence work, clearer bilateral enforcement expectations, explicit handling of data flows to surveillance-risk countries, and measurable integrity outcomes with breach monitoring.
Raf's lens
This is a design tension in payment messaging. Richer data can improve sanctions and fraud screening, but every additional field widens the breach surface across the payment chain. Putting integrity first risks passing the privacy cost to customers. FATF should have to show what the extra data achieves and how breaches will be measured before the requirement becomes global practice.
Topics: FATF Travel Rule, Recommendation 16, data protection, cross-border payments, financial inclusion, fraud, AML/CFT, privacy guidance