The Polish DPA (UODO) Opinion on CRBR Changes
A draft amendment to the Polish AML Act, tabled in March 2025, introduces a fundamental change to how the Central Register of Beneficial Owners (CRBR) works. It is a direct response to the judgment of the Court of Justice of the European Union of 22 November 2022 (joined cases C-37/20 and C-601/20), which held that full, unrestricted public access to the register was a disproportionate interference with the rights to privacy and data protection.
The Polish data protection authority (UODO), in its opinion of 30 April 2025, welcomed the intent to align the law with the CJEU ruling, but pointed to several issues that need to be clarified before the new model, based on a “legitimate interest” concept, can be considered compliant with the GDPR and the Polish Constitution.

From open access to conditional access
The draft moves away from open access towards a conditional system. Access is split into two main channels:
- Direct access (Article 68a): granted to a narrowly defined group such as law enforcement, the prosecution service, the special services, the National Revenue Administration and obliged institutions applying financial security measures. This channel is the least controversial from a data protection standpoint.
- Access based on legitimate interest (Article 68d): granted on request to anyone who demonstrates a “legitimate interest related to preventing or combating money laundering, terrorist financing or related offences”. This is the most widely debated change.
What UODO flags
The authority’s concerns centre on precision and safeguards:
- No legal definition of legitimate interest. Combined with a very broad catalogue of potential applicants, this creates a real risk of discretion and could keep access to sensitive personal data very wide, contrary to the reasoning of the CJEU.
- AML outsourcing providers. Article 68d(2)(14) explicitly lists “providers of AML products” as having a legitimate interest. UODO notes that their access is conditional and that products built on register data may only be supplied to obliged institutions or public authorities. Still, processing by commercial entities raises the risk of secondary use for marketing or commercial risk profiling, so precise contractual limits and effective audit mechanisms are essential.
- Data minimisation. The draft limits the data categories that can be disclosed, excluding full date of birth, exact address and the PESEL number. UODO assesses this positively as an implementation of the GDPR minimisation principle.
Recommendations
UODO does not question the need for change, but asks for a data protection impact assessment (DPIA), a narrower and precise definition of “legitimate interest”, explicit technical and organisational security standards for the new IT system, strong guarantees for external providers, and clear accountability and transparency for data controllers.
What it means for obliged institutions
The direction is clear: access to beneficial ownership data will be more structured and more closely tied to a documented AML purpose. Institutions should keep their due diligence evidence in order and rely on tools that can demonstrate a legitimate, AML-specific purpose for every lookup. Hyperflow supports that workflow with structured screening and monitoring.
UK perspective
The UK equivalent of the CRBR is the register of People with Significant Control maintained by Companies House, reinforced by the Register of Overseas Entities. The UK data protection authority is the Information Commissioner’s Office (ICO), which plays a role similar to UODO when the balance between transparency and privacy is debated.