Where the GDPR and the Wwft meet

The Wwft tells you to collect data and keep it for five years. The GDPR tells you to collect as little as possible and delete it in time. That looks like a conflict, but it is not one: the Wwft is precisely the legal obligation the GDPR lets you rest the processing on, and the Wwft settles the sharpest edges itself. Below are the six points where the two meet, and what each means for your client file. Every article number links to the official legal text.

What exactly is the GDPR?

GDPR stands for General Data Protection Regulation, and that is European law rather than a national one: Regulation (EU) 2016/679 opens in a new tab of 27 April 2016. The Dutch call the same regulation the AVG, short for Algemene verordening gegevensbescherming, and your Dutch clients will use that name. Because it is a regulation and not a directive, that text applies directly in every member state: the Netherlands did not rewrite it into an act of its own, it only added the Uitvoeringswet AVG opens in a new tab for the choices the regulation leaves to member states. Supervision sits with the Autoriteit Persoonsgegevens (UAVG art. 6 opens in a new tab), not with your Wwft supervisor or your professional tribunal.

The Wwft works the other way around: a Dutch act implementing European directives. From 10 July 2027 anti-money-laundering law moves to a regulation as well: the AMLR, that is Regulation (EU) 2024/1624 opens in a new tab, the European anti-money-laundering regulation. It will then apply directly across the EU exactly as the GDPR does. What changes then is on Wwft obligations.

The legal basis: do not ask for consent

Wwft · arts. 3 opens in a new tab and 5 opens in a new tab

Due diligence is mandatory before you enter a business relationship, and you may not start the relationship until it is complete.

GDPR · art. 6 opens in a new tab(1)(c)

Every processing operation needs a basis. Here it is the legal obligation, not consent.

So do not put a consent checkbox on your due diligence. Consent can be withdrawn and a legal duty cannot, so that checkbox promises a choice that does not exist. You inform your client, you do not ask them.

Purpose limitation: KYC data stays KYC data

Wwft · art. 34a opens in a new tab(1)

Personal data you collect under the Wwft may only be processed to prevent money laundering and terrorist financing, and not further for commercial purposes.

GDPR · art. 5 opens in a new tab(1)(b)

Data collected for one purpose may not simply be reused for another.

What you gather for due diligence may not flow into your CRM, your newsletter or your commercial profiling. The Wwft says this in so many words, so here it is not only a GDPR principle but a Wwft breach as well.

Inform them, and do it beforehand

Wwft · art. 34a opens in a new tab(2)

Before entering the relationship or carrying out an occasional transaction, you inform the client about the data processing the Wwft requires of you.

GDPR · arts. 13 opens in a new tab and 14 opens in a new tab

The data subject must know who processes what, why and for how long.

This is the duty most often missed, because firms assume the privacy statement on the website covers it. The Wwft asks for active notice at a specific moment: before you start. One paragraph in your engagement letter is enough, as long as it says what you collect, why, and how long you keep it.

Confidentiality against the right of access

Wwft · arts. 16 opens in a new tab and 23 opens in a new tab

If you report an unusual transaction you are bound to secrecy towards everyone: about the report itself, about further information supplied, and about whether an investigation exists or is intended.

GDPR · art. 15 opens in a new tab

Everyone has the right to access the personal data processed about them.

The Wwft resolves this itself: art. 23(3) allows you to set the right of access aside, as far as that is necessary and proportionate for that secrecy. Mind the scope, because it is narrower than people assume. What is secret is the report. That you carry out due diligence you may say, and in fact must say. Only the report and the investigation stay inside.

Five years is a ceiling too

Wwft · arts. 33 opens in a new tab(3) and 34 opens in a new tab(2)

Keep the due-diligence records five years after the business relationship ends or after the transaction, and a report five years after filing it.

GDPR · art. 5 opens in a new tab(1)(e)

Do not keep data longer than the purpose requires.

This is the mistake we meet most often: five years is read as a minimum, so firms keep things longer just in case. Art. 34a(3) orders you to destroy the data immediately once that term expires. Five years is therefore both the floor and the ceiling, and keeping it longer breaches both laws at once.

A sanctions hit and a news article are not the same thing

Wwft · art. 3 opens in a new tab(2)(d)

Ongoing monitoring means screening against sanctions lists, PEP lists and adverse media.

GDPR · art. 10 opens in a new tab · UAVG art. 33 opens in a new tab(2)

Data on criminal convictions and offences may only be processed where the law allows it.

A sanctions listing is an administrative measure, not a conviction. A news article about a criminal offence, however, is data of a criminal nature. So record the fact of the hit and the list it sits on, not a press archive about a person: you do not need the latter to demonstrate your duty. The Dutch exceptions for this category change on 1 September 2026, so check the current text.

Who is controller, and who is processor

You are the controller for due diligence: it is your legal duty, you decide whom you screen and what you do with the outcome. Software that carries it out for you is a processor, acting on your instructions. That distinction is not cosmetic: it decides who answers an access request (you), who signs a processing agreement (both of you) and whom a data subject turns to (you, not your supplier).

Our data processing agreement is ready to sign, and names our sub-processors and the country each one sits in.

How Cloudpliant handles this

  • Retention is configurable per firm and deletes automatically once the term expires, so the ceiling in art. 34a(3) is not manual work.
  • For adverse media we store the count and where it was found, never the body of the article: the fact of the hit demonstrates your duty, a press archive does not.
  • Every risk classification comes from a fixed rule matrix, not a language model, so you can show a supervisor exactly how an outcome was reached.
  • All production data sits in the EU, and every report records which list was consulted at which moment.

How every classification is produced is on the methodology page, and all the duties in one overview on Wwft obligations.

This page explains the legal text and is not legal advice. Every article number links to the official consolidated text so you can read it yourself. Last checked against the legal text on 20 August 2026.

Get started with Cloudpliant today

10 client files free, the whole product. Connect Exact Online, or add a client by hand.

No credit card needed. The demo takes 30 minutes, online, no obligation.