The Wwft tells you to collect data and keep it for five years. The GDPR tells you to collect as little as possible and delete it in time. That looks like a conflict, but it is not one: the Wwft is precisely the legal obligation the GDPR lets you rest the processing on, and the Wwft settles the sharpest edges itself. Below are the six points where the two meet, and what each means for your client file. Every article number links to the official legal text.
Every processing operation needs a basis. Here it is the legal obligation, not consent.
So do not put a consent checkbox on your due diligence. Consent can be withdrawn and a legal duty cannot, so that checkbox promises a choice that does not exist. You inform your client, you do not ask them.
Personal data you collect under the Wwft may only be processed to prevent money laundering and terrorist financing, and not further for commercial purposes.
Data collected for one purpose may not simply be reused for another.
What you gather for due diligence may not flow into your CRM, your newsletter or your commercial profiling. The Wwft says this in so many words, so here it is not only a GDPR principle but a Wwft breach as well.
The data subject must know who processes what, why and for how long.
This is the duty most often missed, because firms assume the privacy statement on the website covers it. The Wwft asks for active notice at a specific moment: before you start. One paragraph in your engagement letter is enough, as long as it says what you collect, why, and how long you keep it.
If you report an unusual transaction you are bound to secrecy towards everyone: about the report itself, about further information supplied, and about whether an investigation exists or is intended.
Everyone has the right to access the personal data processed about them.
The Wwft resolves this itself: art. 23(3) allows you to set the right of access aside, as far as that is necessary and proportionate for that secrecy. Mind the scope, because it is narrower than people assume. What is secret is the report. That you carry out due diligence you may say, and in fact must say. Only the report and the investigation stay inside.
Do not keep data longer than the purpose requires.
This is the mistake we meet most often: five years is read as a minimum, so firms keep things longer just in case. Art. 34a(3) orders you to destroy the data immediately once that term expires. Five years is therefore both the floor and the ceiling, and keeping it longer breaches both laws at once.
A sanctions hit and a news article are not the same thing
Data on criminal convictions and offences may only be processed where the law allows it.
A sanctions listing is an administrative measure, not a conviction. A news article about a criminal offence, however, is data of a criminal nature. So record the fact of the hit and the list it sits on, not a press archive about a person: you do not need the latter to demonstrate your duty. The Dutch exceptions for this category change on 1 September 2026, so check the current text.
Who is controller, and who is processor
You are the controller for due diligence: it is your legal duty, you decide whom you screen and what you do with the outcome. Software that carries it out for you is a processor, acting on your instructions. That distinction is not cosmetic: it decides who answers an access request (you), who signs a processing agreement (both of you) and whom a data subject turns to (you, not your supplier).
Our data processing agreement is ready to sign, and names our sub-processors and the country each one sits in.
How Cloudpliant handles this
Retention is configurable per firm and deletes automatically once the term expires, so the ceiling in art. 34a(3) is not manual work.
For adverse media we store the count and where it was found, never the body of the article: the fact of the hit demonstrates your duty, a press archive does not.
Every risk classification comes from a fixed rule matrix, not a language model, so you can show a supervisor exactly how an outcome was reached.
All production data sits in the EU, and every report records which list was consulted at which moment.
This page explains the legal text and is not legal advice. Every article number links to the official consolidated text so you can read it yourself. Last checked against the legal text on 20 August 2026.
Get started with Cloudpliant today
It's time to take control of your compliance. Cloudpliant provides one streamlined way to meet your WWFT, AML and KYC obligations, without the hassle.