Singuard Home Blog Contact eTrader eTrader for Businesses eTrader for Traders Broker Broker CRM Live Demo Prop Firm Prop Firm CRM Live Demo
Licenses & Regulation

GDPR for Trading Firms: Client Data Done Legally.

A trading firm collects a passport scan, a utility bill, a bank statement, a full trade history and a record of every support conversation. That file is one of the more sensitive collections any small business holds, and European law treats it accordingly.

By July 10, 2026 7 min read

The General Data Protection Regulation gives supervisory authorities the power to fine up to 20 million euro or 4% of global annual turnover, whichever is higher, for the most serious infringements. Small firms rarely see numbers at that ceiling. What they do see, regularly, is a complaint from one annoyed client that turns into a questionnaire from a national authority, and then into three months of a director's time reconstructing where the data went. That is the real cost for a business with a dozen staff.

This article covers the parts that actually bite in a brokerage or prop firm. It is descriptive, not legal advice, and every firm needs its own counsel on the specifics.

The rules follow the client, not the company address

The first objection is always the same: we are licensed offshore, so this does not apply. It does. The territorial scope provisions catch any firm that offers services to individuals located in the European Union or monitors their behaviour there, regardless of where the company sits. Accepting Spanish clients on a Seychelles licence puts the Spanish clients' data inside the regulation. The financial regulator is a separate question from the data protection one, and the two do not travel together. The same logic applies to prop firms selling evaluations to European traders, which is one reason the wider regulatory position of prop firms is worth reading alongside this.

Firms in that position generally need a representative established in the Union, plus a privacy notice that names a real contact rather than a support inbox that nobody monitors.

One lawful basis per purpose, written down

Personal data may only be processed on one of six lawful bases, and the basis is chosen per purpose rather than per client. In a trading firm the mapping is usually straightforward once someone sits down and does it:

PurposeUsual lawful basisPractical consequence
Opening and running the trading accountPerformance of a contractConsent is not needed and cannot be withdrawn separately
Identity checks and transaction monitoringLegal obligationErasure requests do not override it
Fraud prevention and platform securityLegitimate interestsRequires a documented balancing assessment
Marketing emails to prospectsConsentMust be freely given, recorded, and withdrawable in one click
Analytics cookies on the websiteConsentNo pre-ticked boxes, no loading before the choice

The record of processing activities that sits behind that table is the document an authority asks for first. It lists the categories of data, who receives them, where they go and how long they are kept. Firms that have one answer a complaint in a week. Firms that do not spend a month writing it under pressure.

The retention conflict nobody wants to face

Data minimisation says keep as little as possible for as short as possible. Anti-money-laundering law says keep identification records and transaction records for years after the relationship ends, with several member states applying longer periods. These are not contradictory, but they require the firm to split its storage by purpose rather than dumping everything into one archive.

The workable pattern is a hard boundary between the regulated file and everything else. Identity documents, source of funds evidence and the transaction record sit in restricted storage, accessible to compliance staff and nobody else, with a deletion date calculated from the end of the relationship. Marketing history, support chat, session logs and behavioural analytics live elsewhere on much shorter clocks. When a client asks to be forgotten, the second set goes and the first set stays with an explanation. Building that separation into the KYC and onboarding flow from the start is far cheaper than retrofitting it.

The single most common finding in small trading firms is that everyone can see everything. Sales staff with access to passport scans and bank statements is a failure of the security principle whether or not anything is ever misused. Role based access is not a technical nicety, it is the control that makes the rest defensible.

Two clocks you cannot miss

A data subject access request must be answered within one month of receipt, extendable by two further months for complex cases if you tell the person within the first month. The response includes a copy of the personal data held, the purposes, the recipients and the retention periods. In practice the hard part is not the legal text, it is assembling the data from a CRM, a trading server, a ticketing system, an email platform and a payment provider inside thirty days. Firms that can export a full client file in one action from the CRM handle these calmly; the rest do it by hand every time.

The second clock is 72 hours. When the firm becomes aware of a personal data breach likely to create a risk to individuals, the supervisory authority must be notified within that window, and the affected individuals told directly if the risk is high. Seventy two hours includes weekends. That means the decision path has to exist before the incident: who declares it a breach, who drafts the notification, who signs it. A firm that discovers a support agent exported client records on a Friday evening has until Monday evening, and a bank holiday does not extend it.

Every vendor is your problem

Trading firms outsource heavily. The identity verification provider, the payment processor, the email platform, the cloud host and the outsourced support desk all touch personal data, and each of them needs a written processor agreement that fixes what they may do with it. Choosing a verification provider is a data protection decision as much as a conversion one: where are the documents stored, who reviews them, how long are images retained, and can they be deleted on request.

Transfers outside the European Economic Area need their own legal footing, either an adequacy decision covering the destination country or standard contractual clauses with a transfer assessment behind them. A support team in a country with no adequacy decision is a transfer. So is a backup replicated to a region you picked because it was cheaper. Encryption at rest reduces the harm of a breach; it does not by itself make an unlawful transfer lawful.

Where marketing quietly creates liability

The area where trading firms get complaints is acquisition. Buying a lead list means processing personal data that the individuals never gave you, on a consent you cannot evidence, for a purpose the original collector probably did not describe. When one of those people complains, the firm cannot produce the consent record, because there is none. Affiliates create the same exposure at one remove: if a partner drives sign-ups from harvested addresses, the firm receiving the data is answering for it.

The defensible version is unglamorous. Collect your own contacts, log the timestamp and the exact wording consented to, keep the unsubscribe working, and audit affiliates on how they source traffic. SINGUARD's Executive Directors, Alex Onta & Roman Onta, have watched more than one launch stall because a cheap list poisoned the sending domain and produced regulatory correspondence in the same month.

"Ask your team one question: if a client emailed today demanding every record you hold on them, how long would it take to produce it. If the answer is more than a day, you do not have a data protection problem yet, but you will."

— Roman Onta, Executive Director, SINGUARD

Key Takeaways

Frequently Asked Questions

Does GDPR apply to an offshore broker with EU clients?

The regulation follows the individual, not the company address. If a firm established outside the EU offers services to people in the EU or monitors their behaviour there, the territorial scope provisions bring that processing inside the rules. Holding a licence in another jurisdiction changes which financial regulator supervises the business; it does not remove the data protection obligations that attach to European clients.

A client asked us to delete everything. Must we?

Not where another law requires the records to be kept. Anti-money-laundering rules oblige firms to retain identification documents and transaction records for a defined period after the relationship ends, and the right to erasure yields to that legal obligation. The correct response is to delete what is held for marketing and analytics, keep the regulated file in restricted storage, and write to the client explaining which categories were removed and which were retained and why.

What counts as a reportable data breach?

Any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. If it is likely to result in a risk to the individuals affected, the supervisory authority must be notified without undue delay and within 72 hours of the firm becoming aware. A misdirected email containing client statements qualifies. So does a support agent exporting a client list to a personal device.

Your Own Trading Firm, Live in 24 Hours.

SINGUARD builds the technology behind brokers and prop firms: trading platform, CRM, client portal and payment rails, one bundle, one predictable price. Book a call and see it working, or keep reading the guides.

More in Licenses & Regulation