Hoepman: “The amount of data available to law enforcement is staggering” so access to private communication is unnecessary

Jaap-Henk Hoepman in his article Good riddance to lawful hacking explains that there is no need for law enforcement to get access to private communications:

The amount of data available to law enforcement is staggering. Even if they can no longer listen in to our communications or read our messages, the metadata (who we are talking to, when, how often, and how much) is still available to them. Law enforcement can track our locations, either through data brokers that in turn get their data form the location based services we use on our phones, or by asking the mobile network operators for the current location of our phones. Camera surveillance is increasing, especially as more and more people attach video doorbells like Amazon’s Ring next to their front door, or by people wearing Meta’s AI glasses. Perhaps the only caveat is this: metadata is mostly circumstantial evidence, that does not necessarily prove without any doubt that someone was indeed involved in perpetrating a crime. Access to data (e.g. pictures or video footage) or messages may be needed to seal a case.

Hopefully, the European legislator will realise that encryption and other protective measures are essential for citizens to protect themselves against criminals and other unsavoury characters.

Geplaatst in English - posts in English on this blog, Europa, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce | Tags: , , , , , | Plaats een reactie

EDPS letter on transfers of personal data to the US

The European Data Protection Supervisor (EDPS) wrote a letter to the European Commission on the US Supreme Court judgment Trump v. Slaughter. The Supervisor aks the Commission to closely assess whether this development affects the adequacy decision underpinning the EU-US Data Privacy Framework.

The EDPS wrote:

The EDPB wishes to highlight that the existence and effective functioning of one or more independent supervisory authorities in the third country, with responsibility for ensuring and enforcing compliance with the data protection rules, is one of the key elements to be taken into account when assessing the adequacy of the level of protection in a third country according to Article 45(2)(b) of Regulation (EU) 2016/679. It is also considered one of the key elements to ensure that data subjects in the EEA are guaranteed an essentially equivalent level of data protection in practice, and to ensure cooperation with the supervisory authorities of the Member States.

The EDPB respectfully notes that the European Commission, in the adequacy decision underpinning the EU-US Data Privacy Framework (‘DPF’) [4] , explicitly refers to the independence of the US authorities, including the FTC and that its five Commissioners may only be removed by the President for inefficiency, neglect of duty, or malfeasance in office [5] . Given the potential consequences that the US Supreme Court’s judgment may have in the EEA and its considerable significance for the EDPB, the EDPB asks the European Commission to closely assess whether this development affects the functioning of Commission Implementing Decision EU 2023/1795 and would welcome relevant actions, including the continued sharing of information with the EDPB in a timely manner.

 

[4] Commission Implementing Decision EU 2023/1795, available at https://eur-lex.europa.eu/legalcontent/EN/TXT/PDF/?uri=CELEX:32023D1795

[5] Commission Implementing Decision EU 2023/1795, §58 – 60.

Geplaatst in Belastingrecht, English - posts in English on this blog, Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce | Tags: , , , , , | Plaats een reactie

In the US beneficial ownership reporting is limited to foreign entities and foreign beneficial owners

Although, as far as I am aware, the concepts behind ‘anti-money laundering’ and the ‘beneficial owner’ (‘BO’) originated in the US, that country does not implement the rules drawn up by the Financial Action Task Force (FATF). In the US, the rules on the registration of BOs were already quite different from those we have in the EU. The difference has recently become even greater, as now only foreign BOs belonging to foreign companies need to be registered.

The Financial Crimes Enforcement Network (FinCEN) of the US announced:

FinCEN Permanently Ends Beneficial Ownership Reporting Requirements for Millions of Small Business Owners

On this page the background of the decision is explained by FinCEN.

The reaction from organisations marketing BO-registration, like Transparency International and FACT Coalition, was predictable. Reuters quotes a representative of the FACT Coalition saying the new rule is “hand[ing] a major victory to U.S. adversaries, corrupt officials, fraudsters, and tax evaders who use our financial system to move and hide illicit wealth”. In this article the authors comment that a future administration could just as quickly reinstate BO reporting obligations for domestic companies and U.S. persons.

Geplaatst in Belastingrecht, English - posts in English on this blog, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Ubo-register | Tags: , , , | Plaats een reactie

Europese privacytoezichthouder bekritiseert voorstellen waar Europese misdaadbestrijdingsinstanties meer bevoegdheden krijgen

Na een succesvolle machtsgreep op het gebied van de geprivatiseerde misdaadbestrijding (bestrijding van ‘witwassen’ en ‘terrorismefinanciering’) is de EU nu druk bezig om de overige misdaadbestrijdingsbevoegdheden en -activiteiten te versterken.
Er zijn voorstellen gedaan tot wijziging van de Europese regels inzake gegevensbescherming inzake [a] de algemene misdaadbestrijding, [b] Europol en [c] Eurojust. Deze voorstellen zijn onderdeel van de ProtectEU strategie van de Europese Commissie.

EDPS advies
De Europese instantie die toezicht houdt op gegevensbescherming op Europees niveau, de European Data Protection Supervisor (EDPS), heeft adviezen uitgebracht over Europese voorstellen inzake de bevoegdheden van Europol en Eurojust. De titels van de persberichten luiden (machinevertaald):

  • Een samenhangend kader voor gegevensbescherming voor de instanties op het gebied van justitie en binnenlandse zaken van de EU vereist strenger toezicht en strengere handhaving [1].
  • De uitbreiding van de bevoegdheden van Europol mag niet ten koste gaan van een krachtige EU-gegevensbescherming [2].
  • Modernisering van Eurojust: een sterker mandaat vereist even sterke waarborgen voor gegevensbescherming [3].

Uit deze titels kan al worden afgeleid dat de EDPS zeer kritisch is over de voorstellen, nu waarborgen ter bescherming van burgers onvoldoende zijn.

 

Noten:

[1] A coherent data protection framework for EU Justice and Home Affairs agencies needs stronger supervision and enforcement. EDPS Opinion 17/2026 on the Proposal for a Regulation amending Regulation (EU) 2018/1725 on the protection of natural persons with regard to the processing of personal data by the EU institutions, bodies, offices and agencies
[2] Expanded Europol powers must not come at the expense of robust EU data protection. EDPS Opinion 17/2026 on the Proposal for a Regulation amending Regulation (EU) 2018/1725 on the protection of natural persons with regard to the processing of personal data by the EU institutions, bodies, offices and agencies
[3] Modernising Eurojust: a stronger mandate requires equally strong data protection safeguards. EDPS Opinion 19/2026 on the Proposal for the Regulation on the establishment of Eurojust and repealing Regulation (EU) 2018/1727.

Geplaatst in Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce, Strafrecht | Tags: , , , | Plaats een reactie

Are IP addresses personal data? | IP addresses in the draft guidelines by the AMLA

Privacy International (PI) published the article Are IP addresses personal data? In the article PI explains what an IP address is and informs the reader on the decisions of the Court of Justice of the European Union.

On the character of the IP address PI writes:

Every time you visit a website or use some other Internet service, you need to tell the other party where you connected from so they can send information back to you. That means giving out your IP address widely and frequently (including to those who place their content on other people’s websites, such as advertisers). As such, IP addresses can, in practice, be used to track and identify us in various ways. They are frequently used within the advertising industry to assist with targeted advertising. They can also be used to help with the geolocation tracking of individuals (even though the location of an IP address may not always match the device’s location). (…)

the UK’s data protection regulator, the Information Commissioner’s Office (ICO) describes IP addresses as ‘online identifiers’; a digital means of identifying an individual within information, which makes it ‘identifiable’ and therefore personal data. IP addresses are also considered to be an ‘online identifer’ within recital 30 of the GDPR which explicitly lists IP addresses as an example.

VPN-protection

The use of IP adresses by advertising companies like Google and Meta and by criminals to follow their targets, is a good reason to use a VPN. That is something that does not seem to be known by law enforcement agencies (LEAs). They want obliged entities (‘OEs’, companies with AML-duties, like banks) to use IP addresses to detect potential criminal activity.

An example of that is found in the draft rules by the Authority for Countering Money Laundering and Financing of Terrorism (AMLA) on ongoing monitoring by OEs [*], marking by me:

27. The following non-exhaustive list of events are provided as instances of what may trigger a review of customer information (…)
b) Behavioural, activity-based or transactional anomalies: unusual transaction patterns, inconsistent behaviour, frequent and unexplained changes of professional service providers, repeated or unusual changes in IP address or device location, where relevant, or any activity that deviates from the customer’s profile or from the expected purpose and intended nature of the business relationship. Obliged entities should consider AMLA’s guidelines pursuant to Article 69(5) AMLR on indicators of suspicious activity or behaviors.

Perhaps the AMLA and the LEAs need some extra training in the areas of cybersecurity and protection against tracking

 

 

[*] Page 27 of the consultation document. More information on the consultation: announcement, consultation page, consultation document, my article in Dutch.

Geplaatst in English - posts in English on this blog, Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce, Strafrecht | Tags: , , , , , , , , , , | Plaats een reactie

Advies Raad van State over implementatie Europese antiwitwasregels

De Afdeling advisering van de Raad van State heeft een interessant advies uitgebracht over het wetsvoorstel inzake implementatie van de Europese antiwitwasverordening en -richtlijn (onderdeel van het ‘AML Package’, het ‘antiwitwaspakket’). De verordening treedt medio volgend jaar in werking. Kern van de verordening is dat bedrijven overheidstaken op het gebied van misdaadbestrijding moeten uitvoeren. Een groot aantal bedrijven, van boekhouder tot bank, hebben dit soort taken.

Alertheid op grondrechten schendende elementen in de geprivatiseerde criminaliteitsbestrijding
De Afdeling constateert dat de nieuwe Europese regels weinig wetgevende ruimte voor de Nederlandse overheid laat, maar roept de regering desalniettemin op om alert te zijn op grondrechten schendende elementen in de regelgeving, respectievelijk de praktische uitvoering [*]:

De Afdeling advisering onderkent dat Nederland door deze centralisatie aanmerkelijk minder ruimte heeft om zelf regels te stellen. Toch mag van de regering ten aanzien van de toepassing van het AML-pakket een actieve houding worden verwacht om te zorgen voor een goed werkend systeem in Nederland. De Afdeling advisering benadrukt dat de regering in het bijzonder de vinger aan de pols moet houden bij de uitwerking van de risicogebaseerde benadering, het voorkomen van discriminatie en uitsluiting en de bescherming van persoonsgegevens, omdat deze aspecten in de huidige praktijk kwetsbaar zijn gebleken.

De nieuwe regels zullen enorme gevolgen hebben, zo meldt de Afdeling, al zijn de details nog niet bekend [*]:

Op dit moment is nog onzeker hoe deze aanpak er uit zal komen te zien, terwijl wel vaststaat dat de aanpak en in het bijzonder de grootschalige gegevensdeling tussen tal van publieke en private partijen, grote gevolgen zal hebben voor burgers, bedrijven en instellingen.

Democratische legitimiteit ontbreekt
Dat nog veel onbekend is, komt door de regelgevende bevoegdheden van de nieuwe Europese antiwitwasautoriteit, de Authority for Countering Money Laundering and Financing of Terrorism , ‘AMLA’. De Afdeling zet vraagtekens bij de democratische legitimiteit van de nadere regels (technische reguleringsnormen, richtsnoeren en aanbevelingen) die de AMLA tot stand  brengt [**]:

Ten tweede is er de instelling van de AMLA als toezichthouder én regelgever. Deze zal rechtstreeks toezicht houden op veertig grote financiële ondernemingen en op de nationale toezichthouders. De AMLA krijgt ruime toegang tot informatie en de bevoegdheid om administratieve maatregelen, geldboeten en dwangsommen op te leggen aan poortwachters. (zie noot 5) Ook wordt deze autoriteit verantwoordelijk voor het opstellen van technische normen, die bindend zijn na bekrachtiging door de Europese Commissie (hierna: Commissie). (zie noot 6) Voorts gaat de AMLA richtsnoeren en aanbevelingen uitbrengen voor toezichthouders, FIE’s en meldingsplichtige entiteiten. Deze zijn formeel niet bindend maar de geadresseerden moeten wel ‘alles in het werk stellen’ om deze in acht te nemen. (…)

De AMLA heeft op Europees niveau daarmee grote invloed op de betekenis en praktische uitvoering van het AML-pakket binnen de Nederlandse rechtsorde. In dit licht kunnen er vanuit het oogpunt van publieke verantwoording vragen gesteld worden over de democratische legitimiteit van de richtsnoeren en aanbevelingen die de AMLA uitbrengt. (…)

Wel rijst de vraag hoe precies en wie vooraf wordt geconsulteerd en hoe achteraf in brede zin publieke verantwoording wordt afgelegd. Dat is in dit kader van groot belang, gelet op de betekenis die de richtsnoeren en aanbevelingen van de AMLA in de praktijk zullen hebben voor uitleg en toepassing van het AML-pakket, niet alleen voor toezichthouders en de FIU, maar ook de meldingsplichtige entiteiten en burgers. De toelichting gaat nu nog niet in op de vraag hoe consultatie en verantwoording reële betekenis verkrijgen, zodat het daadwerkelijk voorwerp kan worden van publiek debat.

Wordt er geleerd van de fouten uit het verleden?
In het verleden zijn ernstige fouten gemaakt in de geprivatiseerde criminaliteitsbestrijding. De Afdeling merkt op dat de vernieuwde regels niet betekenen dat dezelfde fouten niet opnieuw gemaakt worden [*]:

Het is niet aannemelijk dat de nieuwe regelgeving als vanzelf tot een betere uitvoering zal leiden. Zij adviseert de regering om in de toelichting van het wetsvoorstel in te gaan op de vraag welke randvoorwaarden zij van belang acht om de risico-gebaseerde aanpak in de praktijk te borgen, en hoe deze zich verhouden tot de sanctiemogelijkheden. Mede in verband daarmee adviseert zij om de uitvoeringspraktijk te monitoren en een evaluatiebepaling op te nemen in het wetsvoorstel.

Daarbij moet de voorkomen van discriminatie en uitsluiting specifieke aandacht krijgen. In het advies maakt de Afdeling melding van de kritiek van het College voor de Rechten van de Mens en de Algemene Rekenkamer.

Mijn commentaar: AMLA laat in de consultatiedocumenten die de afgelopen tijd zijn uitgebracht zien dat zij voornemens is dezelfde fouten opnieuw te maken, zelfs op nog grotere schaal.

Riskante grootschalige verzamelingen van persoonsgegevens bij bedrijven en overheid
De Afdeling waarschuwt voor de grote maatschappelijke risico’s veroorzaakt door de grootschalige gegevensverwerking [*]:

De Afdeling advisering waarschuwt voor het risico dat op een zeker moment het overzicht verloren gaat waar zich welke (vertrouwelijke) gegevens bevinden, voor wie deze toegankelijk zijn en met welk doel deze nog mogen worden gebruikt.

Ik vraag me af of dit overzicht er op dit moment wel is.

Tot slot
De Afdeling maakt nog veel meer opmerkingen. Het zal me benieuwen wat de verantwoordelijke ministeries met dit advies gaan doen.

 

 

[*] Bron: de samenvatting.
[**] Bron: het complete advies.

Geplaatst in Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce, Strafrecht | Tags: , , , , , , , | Plaats een reactie

EFIPP – public-private partnership Europol with banks in the EU

In the EU based on the new rules on anti-money laundering (‘AML’) and countering terrorist financing, ‘CFT’ (the AML Package), many public-private partnerships (PPPs) with banks will be established.

One very important PPP is already there: EFIPP, the Europol Financial Intelligence Public-Private Partnership. The organisation has a website, where the activities are explained. According to the annual report of 2024 the members of this PPP in that year were:

32 Financial Institutions (FIs)
21 Financial Intelligence Units (FIUs)
17 Law Enforcement Agencies (LEAs)

Illustration: EFIPPP website. Click to enlarge

 

The Dutch Anti-Money Laundering Centre (AMLC), part of the Dutch Tax Authority, in 2020 in an article mentioned that AMLC is part of a steering group of EFIPPP (this still seems to be the case). According to this article two Dutch banks are member of EFIPPP: ABN Amro and ING Bank.

Geplaatst in English - posts in English on this blog, Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce | Tags: , , , , , , , , , , , , | Plaats een reactie

FIUs prepare for public-private partnerships (PPPs) with banks | AML, CFT

The world-wide organisation of FIU’s [1], the Egmont Group, in July this year published a statement on the use of public-private partnerships (PPPs) in combatting crime [2]:

Public Statement by the Egmont Group of Financial Intelligence Units – Advancing the Future of Public-Private Partnerships in Combating Money Laundering and Terrorist Financing

Attached to the statement are a report on PPPs (pdf) and a brochure on PPPs (pdf).

The report explains, in veiled terms, that the current system for detecting crime (‘anti-money laundering’, AML, and countering terrorist financing, ‘CFT’) has failed and that hopes are now pinned on analysing, in collaboration with the banks [3], the transactions and activities of every citizen and organisation in the countries participating in the Egmont Group.

The report is useful for the EU, at a time when public authorities are busy preparing AML/CFT-partnerships with banks to analyse transactions across the EU, based on the Payment Services Regulation (PSR), which is expected to come into force shortly, and on the Anti-Money Laundering Regulation (AMLR) (including Article 75) which will come into force in 2027.

 

Notes:

[1] FIUs, ‘Financial Intelligence Units’, are government bodies to which organisations with anti-crime responsibilities, such as banks, must report suspected criminal activity.
[2] By using the terms ‘money laundering’ and ‘terrorist financing’, the authorities suggest that the public responsibilities of businesses (‘obliged entities’, ‘OEs’) are limited; in reality, however, these terms cover all forms of crime that yield a financial gain – in other words, just about everything.
[3] As is customary, the publications obscure the fact that this is not about cooperation with ‘the private sector’, but actually about cooperation with banks. The role of other companies is irrelevant, e.g. because they have too little contact with their customers or are themselves too small.

 

Illustration from the PPPs brochure by the Egmont Group

Geplaatst in English - posts in English on this blog, Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce | Tags: , , , , , , , , , , | Plaats een reactie

AI bij de Raad van Europa

In diverse publicaties heeft de Raad van Europa aandacht besteed aan de gevolgen van het gebruik van artificial intelligence (‘AI’).
In januari dit jaar maakte de organisatie publicaties over rechtsbescherming tegen AI-discriminatie en richtlijnen voor mensenrechtentoezichthouders bekend. Lees het bericht Lacunes en beleidsmaatregelen inzake door AI en algoritmen veroorzaakte discriminatie in Europa [1] en de bijbehorende rapporten, beschikbaar in diverse talen:

De Raad van Europa heeft een Raamverdrag over artificiële intelligentie [4] uitgebracht, waarbij onder meer de EU partij is. Eerder bracht de Raad het ‘Verdrag 108+‘ [5] over gegevensbescherming tot stand. De Raad heeft een themapagina over AI.

 

Noten:

[1] Aankondiging: Gaps and policies in AI- and algorithm-driven discrimination in Europe.
[2] Legal protection against algorithmic discrimination in Europe: current frameworks and remaining gaps, naast Nederlands en Engels ook in enkele andere talen.
[3] European policy guidelines on AI and algorithm-driven discrimination for equality bodies and other national human rights structures, naast Nederlands en Engels ook in enkele andere talen.
[4] The Framework Convention on Artificial Intelligence, zie de speciale pagina. Er is een Nederlandse vertaling.
[5] Convention 108+ – Convention for the protection of individuals with regard to the processing of personal data.

Geplaatst in Europa, Financieel recht, onder meer Wft, Wtt, Fraude, witwasbestrijding, Wwft, Grondrechten, ICT, privacy, e-commerce | Tags: , , , | Plaats een reactie

De deurbellenziekte en de spionagesamenleving

Hoewel Nederlanders denken dat ze privacybewust zijn, is de werkelijkheid anders. Overal verschijnen deurbellen met spionagefunctionaliteit, ook op plaatsen waar je prima uit het raam kunt kijken om te kijken wie er voor de deur staat. Hoewel die spionagedeurbellen de openbare weg niet mogen filmen, gebeurt dat wel en ontbreekt bij de Autoriteit Persoonsgegevens handhavingscapaciteit.

In De Groene verscheen een mooi artikel van Tom Grosfeld (betaalmuur) over de spionagedeurbellen in Nederland, met als introductie:

Net als China rolt het Westen de infrastructuur voor massasurveillance onbeschaamd uit. Als burgers werken wij hier met onze slimme deurbel vrijwillig aan mee.

en met een verslag van wat er in buurtapps gebeurt:

Het is daarnaast bekend dat het installeren van een slimme deurbel geen woninginbraken voorkomt, maar hoogstens helpt bij het latere opsporen van de dader. Meer dan om veiligheid draait het dus om controle, om ‘zien wat er rondom je huis gebeurt’. Maar juist dit volledige zien, deze permanente zichtbaarheid, leidt tot angst en wantrouwen, tot alertheid en onrust, aangezien er telkens meldingen binnenkomen van potentieel verdachte personen of situaties.

En bovenal leidt het tot massasurveillance, waarbij willekeurige passanten niet alleen het risico lopen niet langer onbespied de straat over te kunnen, maar ook gestigmatiseerd of aan de digitale schandpaal genageld te worden. Om inzicht te krijgen in deze dynamiek hoeven we alleen maar een blik op onze buurtapps te werpen.

Bij die spionagedeurbellen blijft het niet want ook Nederlanders kopen de spionagebrillen van dat grote Amerikaanse advertentiebedrijf en rijden in auto’s volgeladen met spionageapparatuur.

Niemand weet waar de data heen gaat en wie er allemaal gezellig mee kunnen kijken in de straat van de spionagedeurbel.

Geplaatst in Grondrechten, ICT, privacy, e-commerce | Tags: , , , , , | Plaats een reactie