In a world where data leaks are increasingly common, families need to rethink their approach to privacy and treat it as an ongoing discipline to manage, rather than a fixed state to assume.
Over the past decade, the privacy that many families once took for granted has been steadily weakened. The Panama Papers (2016), the Paradise Papers (2017) and the Pandora Papers (2021) exposed ownership information on a global scale. More recently, we have seen data breaches at national tax authorities, cases of incorrect information being shared by financial institutions under the automatic exchange of information and ongoing attempts by hackers to obtain data to embarrass, blackmail or otherwise compromise the family. Most recently, Liechtenstein's Register of Beneficial Owners (VwbP) was attacked. These are not isolated incidents. For families, for whom privacy is a key asset - often the most prized one - it is now clear that privacy can no longer be assumed.
For families with legitimate privacy concerns — whether that’s personal security, protection from kidnapping or extortion, defense against predatory litigation, or a clear wish to keep their financial affairs out of the public eye— a leak is damaging and, crucially, permanent. Information cannot ever be “unleaked.”
At PwC, we see a deeper challenge beyond any single breach. It is that most families do not have a clear view of where their data actually sits, who can access it, or where the vulnerabilities lie. A compromised register – as we saw recently - is just one of many ways in which privacy can fail; and rarely the one families are watching most closely.
If your family holds sensitive ownership information through structures in any jurisdiction - which is now the reality for most families - this framework gives you a clear, practical way to understand your exposure and take control of how you manage it.
Start by mapping the landscape:
Which jurisdictions hold Ultimate Beneficial Owner (UBO) data on your family?
Which registers have been completed — corporate registries, trust registries, UBO registers, land registries, and tax-authority databases via automatic exchange?
What was provided to each source — names, addresses, passport copies, source-of-wealth narratives?
Which intermediaries hold your data (law firms, trust companies, banks, accountants, family offices) and to what storage standards?
What is held electronically versus in hard copy?
Before undertaking any technical deep dive, review the true online presence of each family member. Time and again, a family takes elaborate steps to protect identities, assets and locations, only for someone to post a photograph from the family yacht, instantly revealing ownership and location.
We often find that not everything shared was legally required. Families sometimes provide more detail than they need to, either to be helpful or to satisfy an over-cautious compliance officer. It is worth establishing:
Was the information legally mandated, or simply requested by an intermediary?
Where have you provided personal data beyond what the regulation required?
Have you consented to data-sharing that you could withdraw?
Going forward, adopt a clear principle: share the minimum required to comply and confirm what that minimum actually is, every time, before disclosing anything.
Different jurisdictions carry very different risk profiles. Consider:
Is the UBO register public, restricted, or non-public?
What is the jurisdiction's track record on data protection?
Is there a risk of regime change that could alter disclosure norms?
Is the jurisdiction under pressure to increase transparency as international standards evolve?
As a general rule: the more data held in one place, the more attractive a target it becomes.
Where structures use nominee directors, nominee shareholders or professional trustees, be clear about what each layer actually achieves:
Nominees are not effective against UBO registers, which look through to the ultimate beneficial owner.
Nominees may still serve a purpose in certain public-facing documents.
Does the structure make sense on every level — not only for asset protection and tax efficiency, but also for privacy?
Where GDPR applies (across the EU and the EEA, including Liechtenstein), data subjects generally have rights. These are not absolute and may be limited by statutory AML-register rules, but they remain a practical tool:
Right of access - confirm what data is held about you.
Right to rectification - correct inaccurate data.
Right to erasure - request deletion where data is no longer necessary for its original purpose.
Right to restriction of processing - limit how your data is used.
Right to object - object to processing in certain circumstances.
Families should consider exercising applicable rights actively and regularly, while recognising that statutory AML-register exemptions and limitations will apply. We do not see this right being actively and consistently exercised yet, but believe in future it will be.
Legal structure is only one dimension of privacy. In practice, operational security matters more:
What addresses are used for correspondence — personal residential addresses, or registered offices?
Is sensitive information discussed over email? (In our experience, this is the single biggest risk in most families.)
Where are documents stored, physically and digitally, and who has access?
Which individuals at your service providers can see your data, and what vetting, training and confidentiality obligations apply? Are they contractually obliged to notify you of a breach?
Assume that any data you have provided to a register, intermediary or institution could one day become public. Then ask:
If this information were published tomorrow, what would the consequences be?
Does disclosure of your identity, address or wealth create physical risk?
Could the information be used by adverse parties in existing or future disputes?
Is there anything that would be embarrassing or easily mischaracterised if reported in the press?
Would disclosure create issues within the family, for example, beneficiaries discovering the extent of family wealth?
For each identified risk, develop a response plan now, not after the next leak.
Privacy is a discipline. It calls for active, ongoing control over what data exists, where it sits, who can access it and what happens if those controls fail. Today, families need to treat their personal data with the same rigour they apply to their investments: actively managed, regularly reviewed, and ready to adapt as risks change.
Get in touch if you would like to discuss this further. At PwC, our multidisciplinary family office team can consider your position from every angle — legal, tax, regulatory and operational – to help you act with confidence.
Lisa Cornwell