Under the Central Bank of Ireland’s Consumer Protection Code, a regulated entity must retain details of individual transactions for six years after the date on which the particular transaction is discontinued or completed. A regulated entity must retain all other records for six years from the date on which the regulated entity ceased to provide any product or service to the consumer concerned.
The six-year requirement is a minimum retention period required by Central Bank regulation, not a maximum retention period. How regulated entities deal with retention of records after the period has elapsed may be impacted by other regulatory requirements such as the General Data Protection Regulation, anti-money laundering considerations and banks' internal policies.