In meeting my obligations under the Money Laundering and Terrorist Financing (Prevention) Act (Wwft), do I have to take account of the GDPR?
The GDPR requires that any processing of personal data must occur on a valid basis, such as a legal basis. The Wwft is a valid legal basis of this kind. As an entity with an obligation to report, you process the personal data of customers, representatives, and ultimate beneficiaries, among others. This means that, within the framework of the Wwft, you are required to process personal data for the purpose of carrying out checks on your customers.
’Know Your Customer’ checks as required by the Wwft must be carried out in accordance with the provisions of Chapter 2 of the Wwft. Among other things, this means that the identity of the customer (e.g., a buyer) and, if applicable, of the ultimate beneficiary, must be established and recorded. On the basis of the Wwft, this data must be retained for five years after the transaction or the termination of the business relationship. The same holds for data relating to unusual transactions.
-
Do you want to know whether FIU-the Netherlands has personal data about you and whether you can access it?
The answers to these questions can be found in articles of the General Data Protection Regulation, in the associated directives, and in the Police Data Act (Dutch acronym: Wpg) and Decree. But the bottom line is that you are not allowed to access this data with us. How is that?
All unusual transactions reported to us remain in our database for five years, as required by the Money Laundering and Terrorist Financing (Prevention) Act (Dutch acronym: Wwft). To give an impression of the size of this database, in 2022 we received over 1.8 million unusual transactions (UTRs). It is determined by law that the UTR-information we have, i.e. the unusual transactions and the associated personal data, fall under the classification State Secret – Secret, see Article 5 of the Government Information Security Decree – Special Information. Only authorized FIU employees have access to this information. Therefore, if a person asks us for access to his or her personal data, we are not allowed to provide it. After all, the information is state secret.
Unusual transactions are analyzed by FIU-the Netherlands to establish whether there are sufficient grounds to designate them suspicious. These transactions declared suspicious (STRs) may then be shared with the relevant intelligence, security and investigation services, such as the police and the fiscal intelligence and investigation service (Dutch acronym: FIOD). This is allowed since STRs are legally subject to the Wpg.
-
First of all, it is important that you observe confidentiality as set out in Article 23 of the Money Laundering and Terrorist Financing (Prevention) Act (Wwft). This Article prescribes what is possible and what is not. Secondly, it is important to preserve data. When you report an unusual transaction, you will receive a confirmation of receipt from FIU-the Netherlands, which is the proof that you have actually reported one or more transactions. You must keep this confirmation and all other important details of the unusual transaction(s) for five years. Further information can be found in Article 34 of the Wwft .
As explained on the webpage About FIU-the Netherlands, we analyze unusual transactions to assess whether there is sufficient ground to declare them suspicious. If a transaction is declared suspicious, you will be informed of this: the so-called dissemination notification. It is important that you do not jump to conclusions based on this notice. For more information see the frequently asked question ‘’ I have received a Dissemination Notification. What does this mean?’’
You will not be notified if we do not declare an unusual transaction suspicious. However, we do save all unusual transactions for five years as the legislation dictates. So we can still declare transactions suspicious at a later date. For example, due to new reports.
-
FIU-the Netherlands receives unusual transactions (UTRs) from the obliged entities which we then analyze in the context of money laundering, predicate offences and terrorism financing. These analyses are based on, among other things, our own database of UTRs, additional sources such as police information, and the requests we can do based on article 17 of the Dutch AML/CFT legislation. This way we assess whether there is sufficient ground to declare a, or a combination of, transaction(s) suspicious.
The suspicious transactions (STRs) are shared with the relevant intelligence, security, and law enforcement services. If desired, they can be used for analysis purposes and as start, steer and process information. It is important to note that a suspicious transaction is not equivalent to a suspicion as described in Article 27 of the Dutch Code of Criminal Procedure. However, FIU-the Netherlands has assessed that the information contained in the transaction may be important for the prevention and detection of crimes in order to safeguard the integrity of the financial system. The intelligence, security, and law enforcement services decide independently whether they want to/can use the STR.
If we declare a UTR suspicious, you will receive a message about this. The exception is if there are compelling reasons not to send this message, for example certain confidentially risksYou will receive the message that a reported transaction has been declared suspicious, the so-called dissemination notification, through our portal. It is important that you do not jump to conclusions based on this. This is because we are not allowed to share why a transaction has been declared suspicious and so the exact reason remains unknown to you. Our advice, therefore, is to see a declaration of suspicion as additional information. No more and no less. Based on your own information position and your risk appetite, you as gatekeeper decide what to do. An example could be to analyse the circumstances of the transaction in more detail or to additionally monitor them. This will increase your understanding of potential risks and thus leads to better decision making.