Netherlands
4 regulators · 4 instruments · 6 obligations · 1 upcoming deadline
| Obligation | Timing | Regulator | Arises from | Source | Detail |
|---|---|---|---|---|---|
| Banking | |||||
| AML compliance programme and officer | Ongoing | FIU-NL | Money Laundering and Terrorist Financing (Prevention) Act | source | |
This is mandated by the Money Laundering and Terrorist Financing (Prevention) Act (Wwft). It calls for a rigorous, risk-based regulatory framework regulated by the relevant industry sectorial regulator, such as De Nederlandsche Bank (DNB), AFM, and the BFT. There is supposed to be an AML compliance program that will involve risk assessments of integrity (SIRA), rigorous customer due diligence that will identify the Ultimate Beneficial Owner (UBOs), as well as a transaction monitoring system. There will also be an independent Compliance Officer who has a mandate to make immediate reports on any unusual transaction reports (UTRs) to the FIU-Netherlands under a very strict "tipping-off" prohibition. |
|||||
| AML record retention | Retention period 5 years | FIU-NL | Money Laundering and Terrorist Financing (Prevention) Act | source | |
Under the Money Laundering and Terrorist Financing (Prevention) Act (Wwft), it is an absolute requirement for all gatekeepers in the Netherlands to maintain a full archive of their AML compliance information for a minimum of 5 years beginning from the moment when the business relationship ends or from the time of execution of a single transaction. In accordance with the Wwft legislation, this archive should include CDD information (verified documentation and UBO structure of the customers) in addition to the full transaction ledger and other compliance logs, as well as Unusual Transaction Reports sent to the FIU-Netherlands. Despite the fact that the Wwft legislation allows storing personal data in accordance with the GDPR, companies should be very careful about combining this provision with a 7-year corporate tax retention obligation in Dutch law by systematically deleting all hyper-specific CDD information once the AML 5-year term expires. |
|||||
| Customer due diligence (KYC/CDD) | At onboarding + ongoing | FIU-NL | Money Laundering and Terrorist Financing (Prevention) Act | source | |
The Wwft law states that the Dutch gatekeepers should follow a very rigorous Customer Due Diligence process that needs to be fully completed before the establishment of a business relationship or high-value transactions can take place. Working in three different regulatory tiers, companies need to carry out standard due diligence to prove client identification through reliable sources such as the KVK Chamber of Commerce, establish account purposes, and identify Ultimate Beneficial Owners who own more than 25%. In case Simplified Due Diligence (SDD) provides a streamlined approach to verification of low-risk entities such as publicly traded organizations, Enhanced Due Diligence (EDD) is mandatorily carried out based on complicated transactions, high-risk jurisdictions not belonging to the EU, and Politically Exposed Persons (PEPs), as the compliance department needs senior management approvals to fully verify the source of Wealth of their clients. With the strict "No KYC, No Business" rule in effect, failing to complete the mentioned process legally bars the gatekeeper from taking forward the relationship with clients and demands immediate closure of the process, along with mandatory FIU filing in the Netherlands. |
|||||
| Suspicious transaction reporting | Deadline Event-based | FIU-NL | Money Laundering and Terrorist Financing (Prevention) Act | source | |
In line with Wwft, Dutch gatekeepers have a legal duty to report any concluded or planned suspicious transactions to FIU-Netherlands using a stringent dual indicator system aimed at ensuring financial integrity. The compliance process should ensure that the program will automatically detect any transaction that falls under the Objective Indicators of Suspicious Activity, including transfers of money valued at €2,000 or more, or cash transactions above €10,000, while considering the contextual Subjective Indicators when there is a suspicious situation created by the non-credible or complicated conduct of the customer. Transactions flagged under the subjective indicator require clear descriptions of the transactions to avoid rejection in accordance with the stringent "tipping off" prohibition that bans alerting the customer. In addition, the FIU utilizes a strong postponement system that enables the freezing of specific transactions for 5 to 10 business days for urgent examination and absolves firms of civil liability claims resulting from the freeze. |
|||||
| Telecom & Tech | |||||
| Lawful basis, notice and data subject rights | Ongoing | AP | General Data Protection Regulation Implementation Act | source | |
Personal data processing for financial crime prevention within the Netherlands is subject to an extremely stringent overlap between GDPR, the Dutch GDPR Implementation Act (UAVG), and the Wwft, where, instead of consent from the customer to process their data, there is a statutory duty placed upon companies to obtain identity and transaction data. Even though organizations are mandated to provide proactive notifications to customers through an online Privacy Policy that their personal data is being processed under statute for AML, the absolute prohibition of tipping off in the Wwft makes it such that the company is not obliged to inform the customer that their particular transaction is under scrutiny or has been reported to the FIU. More specifically, Article 41 of the Dutch UAVG gives the gatekeepers the ability to override the usual rights of a data subject, such as the Right to Erasure and the Right of Access. |
|||||
| Personal data breach notification | Deadline Event-based | AP | General Data Protection Regulation Implementation Act | source | |
Data breach notification requirements under the General Data Protection Regulation (GDPR) and the Dutch General Data Protection Regulation Implementation Act (UAVG) require data controllers to inform the Dutch Data Protection Authority (AP) about the incident within 72 hours of the moment it was detected, except in cases where there are no grounds to believe that such an incident may affect the rights and freedoms of individuals. In case of data compromise involving potential identity theft or financial fraud, a similar notification should be made to the victims themselves without unnecessary delays, but the requirement can be waived if the data has been encrypted or neutralized immediately. Also, every company is obligated to keep an exhaustive log of all incidents that have happened to it, including details of the incident itself, its consequences, and actions taken to counteract it. Failure to observe those timelines and maintain records may result in significant administrative sanctions of up to €10 million or 2% of the company's total annual turnover. Now, such sanctions are automatically published by AP as open records, increasing reputational risks for corporations. |
|||||
| No obligations match these filters. | |||||