Welcome to the latest edition of Privacy Matters, your trusted source for updates on KYC, AML, fraud prevention, and privacy-enhancing technologies. Here’s what’s been happening recently:
In this article, AI and automation are central to AML strategies, driving machine learning-powered fraud detection and process automation; the shift to real time compliance and risk intelligence enables predictive analytics and transaction risk scoring; and the rise of crypto controls demands balancing DeFi innovation with regulatory oversight. It also highlights challenges such as regulatory shifts and global compliance complexities, the deepfake and synthetic identity crisis, and the tension between data privacy and AML compliance, urging institutions to adopt adaptive frameworks and ethical data practices.
AI Age Verification: Big Tech’s Risky GDPR Stopgap Major platforms like Google (YouTube) and TikTok plan to deploy AI-based age estimation, inferring user age from content interactions, from 2025, aiming to curb one-third of GDPR fines tied to children’s data. Yet this measure follows €750k (TikTok) and €405 M (Meta) penalties since 2022, and raises concerns under GDPR’s Article 8 around automated decision-making, Data Protection Impact Assessments, and the need for effective redress mechanisms with human intervention. Third-party solutions like Yoti’s AI-powered selfie age checks promise stronger GDPR compliance, but platform commitments remain vague and unverified.
An Australia-style ban on under-16s using social media would be blunt yet effective, sending a clear message and giving parents stronger backing against early smartphone use. Currently, 84% of 12-year-olds are on social media and 94% own smartphones. Drawing on the legal drinking age analogy, the proposal urges enforceable age limits backed by age-verification technology, replacing ineffective self-regulation with a cross-party regulatory framework. While workarounds are possible, stronger laws could reinforce Ireland’s digital consent age and prioritise youth welfare.
Swiss bank Julius Baer was ordered by FINMA to pay €4.3M after failing to detect or act on suspicious transactions for high-risk clients between 2009 and 2019, including accounts linked to Russian and Indian nationals – marking a “serious violation” of AML obligations. The bank must forfeit SFr3M in illicit gains plus SFr1.3M in costs, intensifying pressure to overhaul compliance under new leadership.
A Google study reveals quantum computers could break RSA encryption with 20x fewer quantum resources than previously estimated, and elliptic curve cryptography (used by Bitcoin) is similarly vulnerable to Shor’s algorithm. Although such quantum machines aren’t yet available, the findings underscore the urgency of deploying NIST’s post-quantum cryptography standards to safeguard digital assets before the threat materialises.
The European Commission has opened a public consultation until 10 June 2025 on draft Digital Services Act guidelines requiring platforms likely used by minors to adopt a privacy-by-design default, including age-assurance measures, private-by-default children’s accounts, safer recommender systems, and block/mute controls to curb cyberbullying and harmful content. Developed through stakeholder workshops including children via Better Internet for Kids (BIK+), platform providers, and experts following a risk-based approach, these measures (excluding micro and small enterprises) aim to tailor protections to each service’s risk profile. In parallel, the Commission is building an EU privacy-preserving age-verification app by summer 2025, ahead of the EU Digital Identity Wallet rollout in late 2026.
Stay compliant, stay secure, and have a great week!