
Most firms keep client files long after the relationship ends. They treat it as the safe side of the line. Cyprus law does not see it that way.
Section 68 of L.188(I)/2007 sets two duties, not one. The first is to keep the file for five years. The second, which most people skip, is to delete the personal data when those five years are up. Keeping it longer is not the cautious default. It is something you have to justify.
The rule applies whether you are an accountant supervised by ICPAC or a lawyer supervised by the Bar Association. It is statutory, not supervisory. The text is Greek, no official English translation exists, and the renderings here are ours.
What goes in the file
Section 68(1) lists three categories of documents and information you must keep for five years:
1. A copy of everything you collected for customer due diligence — passport copies, identity verification, electronic identification data, anything you used to identify the client.
2. Transaction records — the evidence and supporting documents necessary to identify what was bought, sold, or transferred.
3. Correspondence — letters, emails, and other communications with the client and anyone else in the business relationship.
The clock starts when the relationship ends, or on the date of an occasional transaction — not on the date each document was created. A passport copy taken on day one of a relationship lasting eleven years stays on your shelf for sixteen years total. That is not an extension. That is the normal rule.
When the clock runs out
Section 68(1A) is the part that gets missed. When the five years are up, you delete the personal data, unless another law says otherwise. You may keep the documents and information for five more years, but only where further retention is reasonably justified to prevent, detect, or investigate money laundering or terrorist financing. Section 68(3) caps that extension at five additional years.
In plain terms: delete at five, unless another law requires you to keep. If you want to hold for longer, you need to be able to say why. "Just in case" is not a reason the law recognises.
There is a nuance worth noticing. The duty to delete targets personal data. The extension applies to documents and information. The law does not explain how those two interact when a file is partly one and partly the other. ICPAC's guidance on record keeping does not restate the deletion duty at all — it mentions deletion only as a limit on the client's right to erasure.
Who can ask for the file
Section 68(2) requires you to make all the section 68(1) documents available promptly and without delay to MOKAS (the financial intelligence unit) and to your supervisory authority. Two requesters, one standard: fast.
Section 68B adds a different kind of demand. It is not about a specific file. It requires systems to answer whether you have, or had in the last five years, a business relationship with a named person, and what type it was. That is a question about your entire client book.
Lawyers, auditors, accountants, and tax advisers get a partial exemption under section 69(e) — but only for information received while assessing a client's legal position or representing them in proceedings. Section 68 is not part of that exemption. The file-keeping duty applies in full.
What ICPAC adds
ICPAC's AML Directive, issued under section 59(4) of the same law, adds a fourth category the statute does not list: suspicious transaction reports and activity reports filed by staff, including the compliance officer's examination, findings, and any follow-up with MOKAS. Keep these for the same five years.
ICPAC also requires records to be visible, legible, and of sufficient quality to permit reconstruction of transactions — a higher bar than the statute sets. The Greek text of section 68(1)(b) asks for records necessary for the identification of transactions. Whether identification reaches reconstruction is a gap ICPAC has closed for its own members.
What FATF says
FATF's assessment methodology, aimed at countries and assessors rather than firms, adds two things section 68(1) does not carry: records should include the results of any analysis undertaken, and transaction records should be sufficient to permit reconstruction of individual transactions. The Cyprus statute asks for identification. The international standard asks for reconstruction. ICPAC has bridged that gap for its members.
Sanctions records
ICPAC's separate Sanctions Directive, issued under a different law, runs a parallel five-year record for sanctions screening work. Its minimum list is the one most screening set-ups never write down: what triggered the match, what checks followed, which regime applied, who was involved (including whoever decided a match was a false positive), what action was taken, and whether MOKAS was consulted.
Two extras outside section 68
Two more pieces of the file live elsewhere in the law. Where the beneficial owner is a senior managing official, section 61(1)(b) requires you to keep a record of the actions taken and any difficulties in verification. Section 61(2) requires you to demonstrate that the extent of your due diligence is proportionate to the risk. Neither is on the section 68 list. Both belong in the file.
The bottom line
The file you would hand an inspector is defined at both ends. Filling it is diligence. Emptying it, on the day the clock runs out, is the same duty.
Not legal advice. Verify against the primary source before acting.
FIRMCY screens names against all of the lists above — plus a worldwide PEP database and adverse media — with fuzzy matching and an audit-ready report for every check. New organisations get 100 free credits, no card required.
Start screening free Free PEP & sanctions check FATF high-risk countries Weekly AML briefing Live on Telegram ↗