lexiara

Article 26 › 2

Upon expiry of the retention period referred to in paragraph 1, payment service providers and crypto-asset service providers shall ensure that the personal data is deleted, unless otherwise provided for by national law which determines under which circumstances payment service providers and crypto-asset service providers may or shall further retain such data. Member States may allow or require further retention only after they have carried out a thorough assessment of the necessity and proportionality of such further retention, and where they consider it to be justified as necessary for the prevention, detection or investigation of money laundering or terrorist financing. That further retention period shall not exceed five years.

National law under this provision

1 national measure recorded under this provision, in 1 form — sign in to view the analysis.

· All articles ·

Source: EUR-Lex CELLAR · retrieved 2026-09-04