skip to main content
NL EN
FIU-the Netherlands

In meeting my obligations under the Money Laundering and Terrorist Financing (Prevention) Act (Wwft), do I have to take account of the GDPR?

The GDPR requires that any processing of personal data must occur on a valid basis, such as a legal basis. The Wwft is a valid legal basis of this kind. As an entity with an obligation to report, you process the personal data of customers, representatives, and ultimate beneficiaries, among others. This means that, within the framework of the Wwft, you are required to process personal data for the purpose of carrying out checks on your customers.

’Know Your Customer’ checks as required by the Wwft must be carried out in accordance with the provisions of Chapter 2 of the Wwft. Among other things, this means that the identity of the customer (e.g., a buyer) and, if applicable, of the ultimate beneficiary, must be established and recorded. On the basis of the Wwft, this data must be retained for five years after the transaction or the termination of the business relationship. The same holds for data relating to unusual transactions.

  • Based on the Money Laundering and Terrorist Financing (Prevention) Act (Wwft), reporting entities are under an obligation to report any unusual transaction, whether completed or intended. If you fail to do so, you are in breach of the Wwft. If, whether intentionally or unintentionally, you do not meet the obligation to report, you commit an economic crime that has certain consequences. Further information on failure to report an unusual transaction can be found on the page Obligation to report.

  • The GDPR requires that any processing of personal data must occur on a valid basis, such as a legal basis. The Wwft is a valid legal basis of this kind. As an entity with an obligation to report, you process the personal data of customers, representatives, and ultimate beneficiaries, among others. This means that, within the framework of the Wwft, you are required to process personal data for the purpose of carrying out checks on your customers.

    ’Know Your Customer’ checks as required by the Wwft must be carried out in accordance with the provisions of Chapter 2 of the Wwft. Among other things, this means that the identity of the customer (e.g., a buyer) and, if applicable, of the ultimate beneficiary, must be established and recorded. On the basis of the Wwft, this data must be retained for five years after the transaction or the termination of the business relationship. The same holds for data relating to unusual transactions.

  • Indicators of unusual transactions are listed in the 2018 Implementation Decree for the Money Laundering and Terrorist Financing (Prevention) Act (Wwft) (Uitvoeringsbesluit Wwft 2018 [in Dutch]). These indicators differ per reporting entity. The page on reporting groups gives an overview of the various indicators per reporting group. If in your view a transaction meets one or more of the indicators that apply to your reporting group, you must report that transaction to FIU-the Netherlands.

    If you have questions about how to interpret a given indicator, you can ask your Wwft supervisory authority. This page shows which supervisory authority is responsible for your reporting group. This division of roles is addressed in more detail in the FAQ “What is the role of the Wwft supervisory authorities in relation to FIU Netherlands?’’.

  1. Previous
  2. 1
  3. 2
  4. 3
  5. 4
  6. 5
  7. 6
  8. Next