The Invisible Refusal: Remedying Erroneous AML Designations in Financial Sector Risk Systems under the GDPR and Polish Banking Law

The Invisible Refusal: Remedying Erroneous AML Designations in Financial Sector Risk Systems under the GDPR and Polish Banking Law

2026-08-23

This article examines a form of financial exclusion that operates without a decision ever being explained: the serial refusal of credit and leasing to entrepreneurs whose records are, by every accessible measure, unblemished, and whose difficulties trace to a false positive in anti money laundering screening systems. The phenomenon sits at the intersection of three bodies of law: the confidentiality regime of the Polish Banking Law (ustawa z dnia 29 sierpnia 1997 r. Prawo bankowe), the tipping-off prohibition of the Polish AML/CFT Act (ustawa z dnia 1 marca 2018 r. o przeciwdziałaniu praniu pieniędzy oraz finansowaniu terroryzmu), and the data subject rights of Regulation (EU) 2016/679 (the GDPR, OJ L 119, 4.5.2016, p. 1). The article argues that Polish law contains an underappreciated asymmetry: Article 106e of the Banking Law excludes the right of access to closed sectoral information systems, yet on its literal wording it does not exclude the right to rectification, and the supervisory powers of the President of the Personal Data Protection Office under Article 58 GDPR reach where the data subject cannot. It proposes a remedial sequence, restriction of processing before rectification, recipient mapping under Article 19, and a distinguishing annotation rather than mere deletion, situating the analysis within the Court of Justice’s SCHUFA judgment (C-634/21), recent Polish commentary, and supervisory practice, and it assesses, with deliberate sobriety, the temporal realism of coercive avenues.

 

Introduction: A Refusal That Cannot Explain Itself

The refusal arrives without reasons, not because reasons are withheld carelessly, but because the law forbids their disclosure. An entrepreneur with a high credit score, clean reports from sectoral registers, a certificate of no criminal record, and years of punctual debt service applies for financing and receives a negative decision; then a second, a third, a fourth, always from a similar class of institution, always unexplained. Regulators describe the aggregate phenomenon as de-risking, which the Financial Action Task Force has characterized as the termination or restriction of business relationships to avoid, rather than manage, risk. The individual dimension of the phenomenon is anything but abstract: this author has examined elsewhere the case of the man who lost three hundred million pounds because his bank got suspicious, a study in how suspicion, once formed, outruns both explanation and proportion. For the individual applicant, however, the aggregate label obscures a more prosaic cause that, it appears, accounts for a substantial share of such cases: an error in the data.

The institution that refuses on AML-related grounds is bound by a double knot of silence. The first strand is banking secrecy and the proprietary character of risk methodologies. The second, and stronger, strand is the tipping-off prohibition: Article 54 of the Polish AML/CFT Act forbids informing anyone, including the person concerned, that information has been transmitted to the General Inspector of Financial Information (Generalny Inspektor Informacji Finansowej, the Polish FIU). The result is a paradox of proportion: the graver the suspicion a system has attached to a client, the less the client is permitted to learn of it. The incentive structure compounds the opacity. A compliance analyst answers internally for admitting a risky client, but answers to no one for refusing an honest one; where doubt exists, refusal is the cheaper option. Cui bono analysis thus predicts precisely the pattern observed: systematic over-refusal at the margin, borne by applicants who have no procedural standing to contest what they cannot see.

 

The Mechanics of False Positives in Screening Systems

Screening engines do not compare identities; they compare strings. Matching is deliberately fuzzy, typically keyed to surname and date of birth with tolerance for transliteration, diminutives, and typographical variance, because an engine tuned to exact matches would wave through precisely those persons who disguise identity. The price of deliberate over-inclusiveness is the mass production of false positives: a person bearing a common surname and a date of birth coincident with that of a figure in criminal proceedings inherits that figure’s risk profile, although nothing connects them beyond the register entry.

The Wolfsberg Group, an association of major global banks, has addressed the problem in its guidance on negative news screening, which recommends resolving such hits through secondary identifiers, inter alia middle names, parents’ given names, place of birth, national identification numbers, and addresses, and discounting a hit where the secondary identifiers diverge. The difficulty is practical rather than conceptual: discounting requires data the system frequently lacks and analyst time the institution is reluctant to spend on an application of moderate margin. The burden of supplying secondary identifiers therefore shifts, de facto if not de jure, to the data subject, a point to which the remedial discussion below returns.

 

Differential Diagnosis: The Refusal Pattern as Evidence

Before legal instruments are deployed, the layer of infrastructure harboring the error must be localized, and the best diagnostic material is, somewhat paradoxically, the distribution of the refusals themselves. Financial institutions differ in compliance architecture: some rely primarily on global screening databases of the World-Check type operated by LSEG, or on comparable products of Dow Jones and LexisNexis, while others rest on the domestic information-exchange infrastructure built around the Banking Law and sectoral bodies. Before one even enters that level, diagnostic hygiene requires the exclusion of the trivial cause: an ordinary entry in the debtor registers. A report on oneself and the register of inquiries, obtained from all four Polish economic information bureaus, close that thread within days, and the path for contesting a disputed entry has been described separately in this author’s text on removing entries from KRD and BIG; the register of inquiries is, moreover, worth preserving, since it will later serve as evidence of the extent of the loss.

Where refusals cluster in entities belonging to domestic banking groups while the very same assets are financed without friction by institutions with foreign compliance structures, the working hypothesis is that the error resides in a domestic interinstitutional system rather than in the global databases. The hypothesis gains strength from a written confirmation, obtainable on request, that no record exists in a given global database. The epistemic status of this reasoning deserves emphasis: it is circumstantial, arguably highly probable, yet requiring verification in the course of the matter; the refusal pattern narrows the field of search but does not close it.

 

Mapping the Terrain: The Commercial Layer and the Closed Sectoral Layer

The data infrastructure in which an erroneous designation may reside divides usefully into two layers, because a different legal route leads to each. The first, commercial and in principle accessible, comprises business intelligence and risk data vendors: entities such as CRIF, Dun & Bradstreet, InfoCredit, Transparent Data, Moody’s with its Orbis database, LexisNexis, Dow Jones, and LSEG with World-Check. Against these, the full complement of GDPR rights applies, beginning with the right of access under Article 15.

The second layer, sectoral and closed, comprises information-exchange systems created on the basis of Article 106d of the Banking Law, which authorizes the listed entities to process and mutually share information, banking secrecy notwithstanding, in cases of justified suspicion of offenses committed to the detriment of the sector or its clients and for the performance of their statutory AML obligations. Its practical embodiments are the systems operated by the Polish Bank Association (Związek Banków Polskich), including the established Threat Warning Exchange System (System Wymiany Ostrzeżeń o Zagrożeniach, SWOZ) and, more prominent among contemporary platforms, the AML Sectoral Services Centre (Sektorowe Centrum Usług AML) operating within the National Clearing House (Krajowa Izba Rozliczeniowa, KIR). To this layer the legislature appended Article 106e of the Banking Law, which disapplies Article 15 GDPR as against the listed entities, among them banks, credit institutions, and certain leasing and factoring undertakings: the data subject shall not inspect the record that circulates about him. The exclusion, it bears emphasis, is confined on its face to Article 15; Articles 16 and 18 remain untouched, a point upon which Part VII builds. Structurally, the exclusion is a national restriction of data subject rights grounded in Article 23(1)(d) and (e) GDPR, and restrictions of fundamental rights are construed strictly; moreover, even the exclusion of Article 15 operates only to the extent necessary for the statutory preventive purposes, not automatically and in full. A third sphere, that of reports to the FIU, lies beyond the reach of any representative by force of the tipping-off prohibition in Article 54 of the AML/CFT Act, and candor requires saying so at the outset. The boundary does not defeat the remedial objective, because credit and leasing decisions are driven by the screening layer, and that layer is reachable.

Two demarcations order the field before the instruments are taken up. First, the GDPR toolkit belongs to natural persons, including sole traders entered in the business register; a company, being a legal person, cannot invoke it (recital 14 GDPR). In screening practice, however, the designation ordinarily hangs on the data of a specific individual, the beneficial owner or a member of the management board, so the route revives through that person’s data, while for the company itself the statutory track of the Act on the Disclosure of Economic Information (ustawa o udostępnianiu informacji gospodarczych) and the protection of personal interests run in parallel. Second, the debtor registers possess their own statutory correction procedure, headed by the objection under Article 21a of that Act, which within their domain displaces recourse to Article 16 GDPR; the systems under Article 106d of the Banking Law provide no procedure whatsoever, and it is precisely for that reason that Article 16 applies to them directly.

 

The GDPR Toolkit: Restriction First, Rectification Second

Intuition counsels beginning with a demand for rectification; practice counsels otherwise. The first move should be restriction of processing. Under Article 18(1)(a) GDPR, the data subject may demand restriction for a period enabling the controller to verify the accuracy of contested data, and the practical effect is immediate and independent of any resolution on the merits: the controller should suspend disclosure of the disputed record to querying institutions. Restriction thus operates faster than correction and purchases the time within which the substantive dispute is conducted.

In parallel, a rectification demand under Article 16 GDPR is submitted, and the provision’s architecture deserves emphasis: the controller is obliged to rectify only where the data subject demonstrates the inaccuracy, understood objectively as the data’s non-correspondence with reality, the burden of that demonstration resting on the applicant; once the burden is discharged, rectification is due without undue delay. The demand’s force therefore depends entirely on the quality of the identity dossier: a full copy of the birth certificate including parents’ given names, the national identification number, a certificate of no criminal record from the National Criminal Register (Krajowy Rejestr Karny), sectoral register reports, and written confirmations of the absence of records in the global databases. This is precisely the set of secondary identifiers contemplated by the Wolfsberg guidance, and the demand should place them before the analyst in a form ready for discounting the hit. The drafting, moreover, should account for the incentive calculus on the other side: correction must present itself to the vendor’s compliance team as the option of least risk, with a documented inaccuracy on one side and the prospect of liability under Article 82 GDPR on the side of refusal. The controller has one month to respond under Article 12(3) GDPR; practitioner accounts of disputes with global providers suggest that standard cases close within 20 to 40 days and complex ones within 60 to 90 days, figures that should be treated as reported experience rather than settled fact.

 

Article 19 GDPR and the Problem of Unknown Databases

The greatest difficulty in matters of this kind is not correcting the record one knows, but the existence of records one does not. An erroneous designation propagates: the vendor sells data to subscribers, the subscriber feeds its own base, and that base feeds the next. The answer lies in Article 19 GDPR, under which a controller that has rectified data must communicate the rectification to each recipient to whom the data were disclosed and must, upon the data subject’s request, inform the data subject about those recipients. Each successful correction therefore generates a map of onward propagation, upon which the demands are repeated. The method is iterative and demands discipline in maintaining a deadline matrix, yet it resolves a problem that at first sight appears insoluble: it reaches databases whose names the injured party did not know at the outset. Candor requires noting the provision’s two statutory safety valves: the duty does not bind the controller where notification proves impossible or would involve disproportionate effort. In a dispute with a professional data vendor, however, the valve will rarely open, because the business model of such an undertaking consists precisely in the systematic disclosure of records to identified, logged subscribers; the circle of recipients is documented, notification reduces to an operation within the system, and the duty, serving the accuracy principle of Article 5(1)(d) GDPR, is to be performed without undue delay.

 

The Closed Layer: A Regulatory Asymmetry Favoring the Data Subject

The legally most interesting knot concerns the closed systems. Article 106e of the Banking Law excludes the right of access, yet on its literal wording it does not exclude the right to rectification under Article 16 GDPR. A rectification demand may therefore be lodged, as it were, blind: the data subject asserts that a record erroneously binding his identity to another person’s history functions within the system and supplies the identity dossier permitting verification of that thesis. And since the exclusion is confined to the right of access, the restriction demand under Article 18(1)(a) may, a fortiori, likewise be directed at the closed layer, freezing onward disclosure while the dispute matures. It must be conceded that the evidentiary posture is awkward, since the controller may take refuge in its inability to disclose the record’s content to the claimant.

Here the lever that closes the construction appears. The supervisory powers of the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) under Article 58 GDPR suffer no limitation analogous to Article 106e: the authority may demand from the controller access to all data and information necessary for the performance of its tasks and may, under Article 58(2)(g), order rectification, corrective powers whose exercise in banking matters is evidenced in the authority’s published decisions. Put figuratively, the authority will see the record the party is forbidden to see. Polish adjudicatory practice confirms the approach; the case law of the Supreme Administrative Court (Naczelny Sąd Administracyjny) concerning banks’ processing of former clients’ data has demonstrated that sectoral secrecy is no shield against data protection supervision. Practitioners further report, and the observation is offered as such rather than as a rule, that the authority’s mere request for explanations often suffices to prompt correction without awaiting an administrative decision.

The picture would be incomplete without noting less favorable practice from the provision’s early years. In a decision of 20 February 2020 (ZKE.440.67.2019), the President of the Office refused a complainant both the disclosure of who had initiated an entry in an interbank database and an order for its deletion, reasoning that the purpose of Article 106d of the Banking Law, the prevention of offenses against banks and their clients, would be defeated were the collection of such data to generate a duty to notify the persons concerned. Yet the same decision corroborates the strategy advanced here on two points. First, the complainant demanded access and erasure, not rectification; it is precisely those demands that founder on Article 106e and on the provision’s purpose, whereas the accuracy principle of Article 5(1)(d) GDPR binds the controller irrespective of the exclusion, and it is upon that principle that one should build. Second, and tellingly, before the decision issued the bank itself had corrected the disputed entry, replacing a categorical annotation with a neutral formula, an illustration of the thesis that the authority’s interest is often more effective than its ruling.

 

Why Deletion Does Not End the Matter: The Distinguishing Annotation

The injured party’s natural objective is deletion of the entry; the objective, however, is arguably misconceived, and it is worth understanding why. Since the screening engine matches fuzzily on surname and date of birth, removal of the record from one database will not prevent a fresh hit upon the next query of another database in which the true figure with coincident particulars continues, lawfully, to appear, his record being accurate. The alert will return like an echo.

The durable remedy is therefore a pair: a distinguishing annotation lodged with controllers, documenting the verified false alarm and identifying the features that separate the two persons, and an unambiguous identification dossier on the client’s side, tendered with every financing application. Nor is the annotation a courtesy of the controller: the second sentence of Article 16 GDPR confers the right to have incomplete personal data completed, including by means of providing a supplementary statement, completeness being assessed having regard to the purposes of the processing; a record that does not permit two persons to be distinguished is, for a preventive purpose, incomplete to an obvious degree. The aim is to enable a compliance analyst to close the alert within minutes, in a manner defensible within his own institution, instead of escalating toward refusal. One prevails here not against the system but against the analyst’s time budget: he must be handed a document that renders approval cheaper than refusal.

 

Remedies Against the Financing Institutions: Article 105a(1a) and Article 70a of the Banking Law in the Light of Article 22 GDPR

Parallel to the dispute with database controllers, work is warranted on the side of the institutions that refused. As against banks, the point of departure is not so much the general Article 22(3) GDPR as its domestic concretization: Article 105a(1a) of the Banking Law permits banks to take creditworthiness decisions based solely on automated processing, including profiling, but only on condition that the person concerned is guaranteed the right to obtain pertinent explanations of the grounds of the decision, to obtain human intervention with a view to a fresh decision, and to express his own position. Automation in Polish banking law is thus conditional; the triad of entitlements arises ex lege, without the need to prevail in a dispute over whether the decision was solely automated within the meaning of the GDPR, and explanations for fully automated assessments are governed, mutatis mutandis, by Article 70a(3a). Structurally, Article 105a(1a) is precisely what Article 22(2)(b) GDPR contemplates as Member State law authorizing automated decisions subject to suitable safeguards, the triad constituting those safeguards. And where an institution defends by invoking human participation, the case law and guidance supply the answer: in its judgment of 7 December 2023 in Case C-634/21, SCHUFA Holding (Scoring) (EU:C:2023:957), the Court of Justice held that the automated establishment by a credit information agency of a probability value is itself automated decision-making within Article 22(1) GDPR where it depends in a decisive manner on that value whether a third party will establish, perform, or terminate a contractual relationship with the person concerned, notwithstanding that one entity profiles and another formally decides (paragraphs 48 to 50). The operative formula thus reaches not only the refusal to contract but the performance and termination of existing relationships, which renders the judgment directly serviceable where de-risking takes the form of terminating an existing agreement. Human involvement created artificially, reduced to the approval of automatically generated outputs without influence upon their content, does not take the process outside Article 22 (Article 29 Working Party Guidelines, WP 251). Three further consequences flow from the qualification. First, Article 22(1) lays down a prohibition in principle upon which the data subject need not individually rely (paragraph 52); it is for the controller performing the scoring to locate itself within an exception under Article 22(2), and as against commercial vendors Polish law contains no evident counterpart of Paragraph 31 of the German Federal Data Protection Act capable of serving as the Member State basis under point (b), which places their position in doubt, although the assessment remains argumentative rather than settled. Second, the qualification opens, as against the vendor itself, the enhanced right of access under Article 15(1)(h) GDPR to meaningful information about the logic involved; the Court observed expressly that absent the qualification a lacuna in protection would arise, the financing institution not possessing that information and the vendor being able to withhold it (paragraphs 61 to 63), the limits of reliance upon trade secrecy having been delineated in the subsequent judgment of 27 February 2025 in Case C-203/22, Dun & Bradstreet Austria. Third, Member State law permitting such decisions must provide safeguards embracing, in the wake of recital 71, adequate mathematical and statistical procedures together with technical and organizational measures minimizing the risk of error and securing the correction of inaccuracies (paragraphs 65 to 66); a fuzzy-matching engine devoid of any mechanism for distinguishing persons is, from that vantage, deficient at the level of the safeguards themselves, which lends further support to the rectification demand and the annotation. For the present problem this means that the automated-decision regime may attach already at the screening layer of the data vendor, not first at the bank, and the evidence of decisive dependence is the very refusal pattern that served the diagnosis: a state of affairs in which a negative designation entails refusal in nearly all cases is precisely the situation the Court described (paragraph 48).

The instrument of Article 70a of the Banking Law is, moreover, stronger than its laconic wording suggests. The right to a written explanation of the creditworthiness assessment belongs to every applicant for credit, natural persons, legal persons, and organizational units alike, and since the amendment in force from 29 September 2023 the lender must, of its own motion, clearly and on a durable medium, instruct the applicant of the right and of the one year time limit for the request; the reply is due without undue delay and at the latest within 30 days. Significantly, the Polish Financial Supervision Authority resolved in its communication of 21 July 2020 that the explanation may not be reduced to general categories of data: it must contain individualized, concrete information on the factors, personal data among them, that determined the assessment, together with an indication of the measures the applicant may take to remove the obstacles; a reply confined to a formula about a scoring outcome is inconsistent with the supervisor’s position and open to challenge. A fee may be charged only to entrepreneurs and must be proportionate to the amount of the credit. The lex lata boundary, finally, runs elsewhere than commonly assumed: by virtue of Article 10(2) of the Consumer Credit Act (ustawa o kredycie konsumenckim), the explanation duty applies mutatis mutandis to consumer credit lenders, including loan institutions, while leasing in professional dealings remains outside it, a gap that, de lege ferenda, merits the legislature’s attention. The aim of these measures is not to compel consent to financing, which cannot be compelled, but to introduce distinguishing material into the institutions’ procedures so that subsequent applications cease to founder on the same automaton.

 

Coercive Avenues and Temporal Realism

Where the amicable route fails, two tracks remain. The first is a complaint to the President of the Personal Data Protection Office, free of charge and armed with the leverage described above as against the closed layer; its weakness is time, since proceedings before the authority run many months and, on occasion, longer. The second is civil: an action for the protection of personal interests under Article 24 of the Polish Civil Code (Kodeks cywilny), those interests encompassing credit reputation and the good name of an enterprise, a proposition the case law confirms expressly: the Supreme Court has held that an entry in a register of unreliable debtors resting on untrue information infringes the good name and dignity of the person entered (judgment of 24 November 2022, I NSNc 520/21), and in its resolution of 3 October 2023, III CZP 22/23, it admitted pecuniary compensation for a legal person for the infringement of personal interests irrespective of proof of material damage, in concurrence with the judicial remedy of Article 79 GDPR, accompanied by an application for interim relief under Article 755 § 1 in conjunction with Article 730 et seq. of the Code of Civil Procedure (Kodeks postępowania cywilnego), Article 755 supplying the specific basis for securing non-monetary claims and permitting the court to regulate the parties’ rights and obligations for the duration of the proceedings, including by suspending disclosure of the disputed data pendente lite. The code itself is not ungenerous here: security may be granted upon a mere substantiation of the claim and of the legal interest in obtaining it (Article 730¹), and applications are as a rule examined in camera, so ex parte relief is available in principle. Sobriety is nonetheless owed in place of salesmanship: in matters touching systems covered by sectoral secrecy, courts tend in practice to seek the controller’s position before ruling, so the realistic horizon for obtaining interim relief is, on practitioner experience, measured in months rather than weeks, and the merits in years. A damages claim under Article 82 GDPR remains the closing option, sensible where the loss flowing from forfeited financing can be demonstrated and quantified.

 

Conclusion

The correct sequence, restated in summary, runs as follows: assembly of the identity dossier and differential diagnosis upon the refusal pattern; access requests under Article 15 GDPR wherever the right has not been excluded, with a rigorously maintained deadline matrix; restriction demands under Article 18(1)(a) against identified controllers, followed by rectification demands under Article 16 with the full set of secondary identifiers and a demand, grounded in the provision’s second sentence, for a distinguishing annotation by way of a supplementary statement; where the vendor itself computes the designation or score, a demand under Article 15(1)(h) GDPR for meaningful information about the logic involved; enforcement of Article 19 after each correction and repetition of the procedure with disclosed recipients; as against the closed layer, rectification and restriction demands notwithstanding the absence of access, with readiness to escalate to the supervisory authority; in parallel, the statutory triad of Article 105a(1a) and assessment explanations under Article 70a on the side of the financiers; and the judicial route held in reserve, its temporal horizon honestly communicated. Matters of this kind are rarely won by a single letter and almost always by architecture: by the proper order of demands, by discipline over deadlines, and by the recognition that the opposing party is not malice but an algorithm and an analyst, for whom agreement must be made the safer option than refusal.

Legal status as of August 21, 2026. This article is of an informational character and does not constitute legal advice in an individual matter.

 

Further reading

The Weaponization of Debt Registries

Trump Sues JPMorgan Chase for Five Billion Dollars

The Man Who Lost Three Hundred Million Pounds Because His Bank Got Suspicious