Cross-institution reliance is impossible without sharing some data — and data protection law is exactly what makes "just share it" a bad answer. The practical task is to decide what must move with an operation, what may be retrieved on request, and what should never leave its home. Framed that way, privacy and reliance are not opponents.
The tension
To rely on another institution's checks, you need to know those checks happened and to see the evidence when required. But the evidence is personal data, and its movement is governed by GDPR and equivalent regimes. The resolution is not to share everything, but to define precisely what is shared, with whom, and under what condition.
What the reliance agreement fixes
The multilateral agreement sets the boundaries in advance:
- the data that must accompany each operation, following FATF Recommendation 16;
- access to KYC documents on request — by SUPA, by another participant, or by a regulator;
- a minimum standard for KYC, KYB and monitoring regardless of jurisdiction.
This is not a standing right to the whole file. It is defined access, on defined terms.
Practical guardrails
Three habits keep this workable. Keep data with its home entity by default, and retrieve on request. Attribute every operation to a principal, an agent and a policy version, so any share is tied to a specific purpose. And check local-law limits per jurisdiction, because cross-border sharing is not permitted everywhere.
Reliance does not transfer legal responsibility. Each party keeps its own duties, including its data-protection duties. That is why the agreement describes access rather than ownership: the data stays attributable to someone, and any share is tied to a stated purpose.
Handled this way, privacy law and reliance stop competing. The network shares less than it could, moves only what an operation requires, and can show a supervisor why each piece of data crossed a border.
This article is general information, not legal, tax or financial advice.
In short
- Reliance needs data sharing, and data law governs that sharing.
- The agreement defines what moves and what is retrieved on request.
- Default to keeping data at home; share against a defined purpose.
- Cross-border sharing is checked per jurisdiction.
Explore the protocol terms at /protocol/.