Showing posts with label due diligence. Show all posts
Showing posts with label due diligence. Show all posts

Wednesday, 31 January 2024

Would’ve, Could’ve, Should’ve: Preliminary Reflections on the EU’s New Corporate Sustainability Due Diligence Directive


 


Tara Van Ho, Senior Lecturer in Law, University of Essex

 

Photo credit: Infrogmation of New Orleans, via Wikimedia commons

 

The European Union’s Council and Parliament have agreed to a provisional text for a new directive that would require certain large corporations to undertake human rights and environmental due diligence.

 

I was reminiscing just the other day while having coffee all alone, and Lord, it took me away, back to a first-glance feeling during my first UN Forum. My hope was mixed with equal levels of scepticism about the likelihood that laws like this would be adopted let alone be effective. Over the past twelve years, the hopes and scepticism have been met in equal measure, but never more so than with this law.

 

While the final text is not yet public, a press release indicates the key expectations and components of the agreed text. MEP Axel Voss has posted the side-by-side comparator of the various drafts, including the new draft agreement. This draft confirms:

 

-          The directive will apply to large EU companies with a worldwide net turnover of €150million and 500+ employees;

-          It will eventually capture non-EU companies with €300 million net turnover generated in the EU and the Commission will publish a list of applicable non-EU companies the law;

-          Affected businesses will need to address actual and potential adverse human rights and environmental impacts in their “business chain of activities” which covers their own operations, their subsidiaries, and “the upstream business partners of the company and partially the downstream activities, such as distribution or recycling”;

-          The financial sector is (temporarily?) excluded pending a review and “a sufficient impact assessment;

-          There is a specific list of human rights and environmental protections that businesses will be expected to respect and address, and a list of obligations the breach of which will constitute “an adverse human rights impact”;

-          That list excludes from application certain ILO core conventions because not all EU member states have ratified them; 

-          Large companies will have an obligation of means to develop and implement an effective plan to mitigate their impact on climate change;

-          Those who are negatively affected (including civil society or trade unions) can bring claims for civil liability within a five-year period; and

-          At times, as a matter of last resort, businesses may need to end their business relationships where negative impacts cannot be prevented or ended.

 

This law represents progress for many in the world. If implemented in good faith, it could provide better access to remedies for victims who are negatively impacted by business operations. It should also lead to the adoption of better and greater preventative measures, avoiding the need for remediation in the first place.

 

It is the first mandatory human rights due diligence legislation to address climate change, not just environmental damage. It anticipates civil liability for businesses that breach their responsibilities. It suggests compliance with the law as a criterion for public procurement, placing the power of Member States’ purses beyond the law. The recognition that at times business relationships will need to be terminated to ensure compliance is significant and can help fill in gaps the negotiation has otherwise left unaddressed, like the issue of conflict-affected and high-risk areas (which I’ll return to later in the post).

 

I’d like to express my appreciation to the NGOs and Parliamentarians who have gotten us to this point: it is clear from the Council’s approach during negotiations that if you would’ve blinked then they would’ve looked away at the first chance. I particularly appreciate those who fought for the inclusion of international humanitarian law and specific language on conflict-affected and high-risk areas. This was needed and I was shocked by early rumours that the draft agreement excluded this issue. I’m happy those were wrong.

 

The long-awaited human rights requirements are intended to implement the 2011 United Nations Guiding Principles on Business and Human Rights (UNGPs). I remember it all too well how the EU celebrated the adoption of the UNGPs and how, together with the US and other capital-exporting states, promoted the UNGPs as the standard for businesses when addressing human rights. The EU long opposed proposals for an international treaty on business responsibility for human rights because they felt that it was unnecessary in light of the UNGPs’ existence and could distract states from implementing the UNGPs.

 

Only recently, and only because Parliament required it, the EU has joined the negotiations with all the enthusiasm of a 6-year-old child called to dinner when they’re playing with their dinosaurs (meaning: none). The new directive evidences strong disconnects from the EU’s demand that the UNGPs lead is pretty and what the EU advocates for in the binding treaty and what the directive now requires for reasons I set out below.

 

In this post, I provide a list of things the EU would’ve, could’ve, and should’ve done had the Council been as serious as Parliament about implementing the UNGPs. The would’ves apply to an ideal application of the UNGPs: applying to all businesses and with a more robust and comprehensive understanding of human rights. The could’ves represent those areas in need of greater development: consulting with rightsholders abroad; and clarifying that contractual clauses are not enough. Finally, the “should’ve” is applying the law to the financial and arms sectors, a bare minimum expectation under the UNGPs, the exclusion of which should embarrass Council members for decades to come (I would have said generations but that felt a tad bit dramatic).

 

Would’ve: Applied to all businesses

 

First, the UNGPs are explicit that the responsibility to respect human rights applies to all businesses at all times including small and medium-sized enterprises (SMEs). In the Geneva treaty negotiations the EU has always walked a very thin line, insisting that the treaty, like the UNGPs, should apply to all businesses, not just transnational corporations. The initial Parliamentary proposal for a directive would’ve (largely) continued this approach and complied with the UNGPs. Yet, it was clear from the Commission’s proposal and the Council’s response that we were never going to get a UNGP-compliant directive. The Directive will now only apply to large companies (and not in the financial sector, an issue I’ll return to). The press release does not indicate an intention to expand the scope of the Directive in the future.

 

Including SMEs is admittedly difficult. In the transnational context, large European companies have long forced SMEs in places like Bangladesh and Pakistan to absorb the cost of social auditing processes while insisting on contracts that limit the legal liability of European buyers and parents. This often leads to corrupt practices for certifications or in redirecting revenue for the certification away from protections or living wages for employees. That would defeat the purpose of the law.

 

EU SMEs, on the other hand, often already have a language of human rights, practices that facilitate due diligence, and networks that can support their efforts to develop in this area. A graduated expansion coupled with clauses aimed at protecting SMEs from the abusive practices we’ve seen elsewhere could’ve provided an important example of how SMEs can be included in mandatory human rights due diligence legislation. It also would’ve strengthened the EU’s position in the Geneva-based negotiations.

 

Instead, whenever the EU pushes for an expansion of the treaty, I hope states like Pakistan and Bangladesh point out the hypocrisy.

 

Would’ve: Taken a broader approach to human and labour rights

 

The UNGPs also call for businesses to account for all human rights. In Principle 12, it states that businesses should account for, “at a minimum,” the International Bill of Human Rights (the Universal Declaration of Human Rights, the International Covenant on Civil and Political Rights, and the International Covenant on Economic, Social and Cultural Rights) and the ILO Core Conventions. Where relevant, businesses need to rely on other standards as well.

 

The EU’s press release suggests that the directive will only invoke treaties that are universally ratified by EU member states. That would mean most of the major UN treaties are addressed but there are some disturbing omissions, including the International Convention on the Protection of All Migrant Workers and of their Families and the ILO Core Conventions. Those are rather significant omissions given issues of modern slavery in EU food supplies, and more broadly problems with the treatment of migrant workers throughout EU corporate supply chains.

 

The list also prioritises EU commitments over relevant obligations where the law has extraterritorial impacts. There should have been a recognition that at times the Inter-American and African systems on human rights can be applicable. This recognition is important as the Inter-American and African systems have produced stronger jurisprudence on various issues, including indigenous rights and community rights than Europe (significantly stronger in the Inter-American system) while the Inter-American system also produces more progressive jurisprudence on the definition and nature of reparations, and the direct responsibility of businesses. While the African system has more limited jurisprudence, its jurisprudence on land rights and community rights is similarly more advanced than the European system’s.

 

Sometimes, I miss who I used to be when I could naively believe the absence of reference to the other human rights systems was an oversight, but I fear this strengthens the case for the laws as a form of neo-coloniality by suggesting a hierarchy of rights and systems that centres European expectations in legislation that is supposed to reflect broader standards.

 

Could’ve: Undertaken Direct Consultations with Foreign Rightsholders

 

The failure to recognise the relevance of Inter-American and African jurisprudence reflects a broader procedural failure by the Commission to consult foreign rightsholders who will be affected the law. I cannot do greater justice to this criticism than Caroline Omari Lichuma has done already in her TWAIL critique of European human rights due diligence laws.

 

While my experience suggests that many victims groups and rightsholders want mandatory laws, what they want in those mandatory laws matters just as much as the desire for a law. They had a right not just to voice their support for (or criticism of) the law but to make substantive demands for the law itself. What would the additional demands of rightsholders look like? Well, sometimes you just don't know the answer ‘til someone's on their knees and asks you for a particular legislative proposal, but a very recent study suggests that consultation might have led to different approaches to remediation, particularly for climate-related harms.

 

I often find that memories feel like weapons. In this field, we have often seen European businesses and states undertake “new” initiatives they claim are for the benefit of others without actually talking to the “others.” For example, studies suggest “social auditing” and certification schemes do not deliver on the promises European companies and social initiatives claim. This is unsurprising. Writing in the U.S., the founding father of critical race theory, Derek Bell, has explained that many “anti-racist” developments really represent interest convergence of White and Black leaders. As such, the concessions are less radical or responsive than what racialised communities would seek themselves. These additional demands, however, are often dismissed or ignored. When Dr Lichuma provided an overview of her critique at the 2022 UN Forum on Business and Human Rights, one European delegate infamously responded that Europe’s position wasn’t a matter of imperialism but of “leadership.” Real leadership, however, would reflect the results of consultations with rights-holders not just the political interests and concessions of European leaders.

 

Could’ve: Clarified that Contractual Clauses are not Enough

 

Recital 34, para 43 in the table contains an extensive discussion of the kinds of measures companies can take to comply with their human rights responsibilities. One of those is the development of contractual clauses with business partners. I worry that I've seen this film before and I didn't like the ending.

 

I’ve now mentioned twice that social auditing is a sham. There will be exceptions to this rule and I can point people to a few of my favourite exceptions, but let me reiterate what existing research indicates: social auditing is generally ineffective and often detrimental for rights-holders, providing a veneer of respectability for disrespectful practices.

 

Increasingly, it is clear that this is equally true of index listings meant to advise institutional investors on their human rights risks. Last year, the US advisory company Morningstar adopted rules aimed at exempting Israel that so fundamentally misunderstand the UNGPs that it renders all its human rights reporting questionable (short story: Morningstar concluded Israel isn’t a conflict-affected area…). More recently, index provider MSCI accepted audits from Xinjiang, China, as evidence that the car company Volkswagen was seriously addressing the issue of Uyghur forced labour. No company can adequately address the issue of Uyghur forced labour when operating in Xinjiang and (again, I cannot emphasise this enough) it is irresponsible to rely on a social audit in this context. Because these indexes set their own rules, and have no professional board standards, I can’t actually accuse them of professional malfeasance but these responses are shockingly inept.

 

Human rights due diligence is not supposed to be the same as an audit, but often businesses looking for a quick and dirty misdirection will use social audits and contractual clauses as a substitution for due diligence. I fear that if contractual clauses are allowed, due diligence will start to look more and more like social auditing and indexing and less like the robust and circular mechanism of assessment, responsiveness, and reparations than it is supposed to be.  

 

The directive could and should clarify that while contractual clauses can be important they cannot transfer legal liability. 

 

Should’ve: Applied to the Financial and Arms Sectors

 

At Recital 18, para 27, and  Recital 19, para 28, we find an effective exemption from the law for the arms and financial sectors, respectively. In Recital 19, the CSDDD excludes “downstream business partners” from the scope of due diligence obligations. I knew this was true from the press release, but seeing the blatant language was surreal. I’m laughin', but the joke's not funny at all.

 

I’m going to set aside the arms sector for now (because I’m working on a lot regarding that sector right now), but the exemption for the financial sector is gross (gross being a legal term of art, just ask anyone…). The draft agreement says that “as regards regulated financial undertakings, only the upstream but not the downstream part of their chain of activities is covered by this Directive.” In other words: the bank is not responsible for breaches caused by its financing of another’s activities no matter how much the bank should have known how its financing would be used for human rights violations.

 

Out of every group you’re concerned with protecting, out of every business and industry, it is the banks you the Council thinks can’t do due diligence?

 

Really?

 

The banks that kept looted Nazi material from their rightful Jewish owners for decades?

 

The banks that repeatedly financed South Africa’s apartheid regime, saving it when it was on the brink of collapsing?

 

The banks accused of facilitating money laundering for drug lords and terrorists?

 

The ones who facilitate tax evasion? 

 

The banks that finance dam projects in indigenous lands with such disregard for human rights that many of their logos should just be “Hi, it’s me, I’m the problem. It’s me.”

 

The banks that know how to do extensive due diligence on operational impacts when it’s in their financial interests?

 

Those banks? That’s who needs protecting with this law?

 

You cannot be serious about human rights if you are not serious about tackling the responsibility of the financial sector. When it comes to the Council members who betrayed the rights-holders with this clause, I got a list of names and yours is in red, underlined, France and Austria. France was the first to indicate resistance to the application to the financial sector, but it is Austria’s recent pressure on Ukraine, in which it leveraged international assistance for the war on the removal of Austrian Raiffiesen Bank from the list of international sponsors of war, that is perhaps the worst development in this area. People need to know this, so they know where to put pressure moving forward.

 

It appears there will be an “impact assessment” to determine if the law should apply to this industry, but that will be too little and far too late.

 

It’s also wholly unnecessary.

 

There is nothing particularly special about banks or the financial industry that makes human rights due diligence hard. They just don’t want to pay for it to be done properly. That’s not surprising. No company wants to pay for it. Disney once complained about reporting requirements before we even had any human rights due diligence laws because they didn’t way to cut into CEO bonuses or shareholder profits. The desire to not spend money on human rights due diligence is not an adequate reason for allowing those complicit in the Nazi genocide or South African apartheid or Russia’s unlawful war of aggression in Ukraine to continue to evade human rights responsibilities. If anything, their focus on profits and finances over people is exactly why this law is needed.

 

Concluding note

 

So that’s it: my would’ves, could’ves, should’ve for the EU. At times, the CSDDD provides me with hope about the direction of travel for this field, but in other areas it represents a crisis of my faith.

 

 

 

PS, Taylor Swift’s birthday was on the same day as the final trilogue. As a fun Easter Egg hunt for my fellow Swifties, I’ve sprinkled her lyrics throughout this post (13 times, obviously). I’ll send a friendship bracelet to the first Swiftie who emails me a list of all the hidden gems. Please use the subject line “T-Swift Easter Egg Hunt” in your email. My email address can be found on my Essex profile.

Monday, 30 May 2016

Money laundering, customer due diligence and data protection: the CJEU's judgment in Safe Interenvios




Marcin Kotula, Legal Officer at the European Commission

The views expressed are purely those of the author and may not in any circumstances be regarded as stating an official position of the European Commission

Background

The recent judgment of the CJEU in the case of Safe Interenvios was triggered by a preliminary reference from the Provincial Court in Barcelona (Audiencia Provincial). The Court in Barcelona submitted to the CJEU a number of questions related to the interpretation of the third Anti-Money Laundering Directive 2005/60/EC (AML Directive, since replaced by the fourth money laundering Directive, discussed here).

In the case in question, Safe, a company which falls under the definition of a "financial institution" within the meaning of the AML Directive and of a "payment institution" within the meaning of the Payment Services Directive 2007/64 (PSD) has been transferring the funds of its customers abroad through the accounts it held with 3 banks, BBVA, Sabadell and Liberbank. The transfers were to be carried out by agents who were accordingly authorised by Safe and verified by the Bank of Spain (Banco de EspaƱa). After discovering irregularities regarding Safe's agents the banks, acting under Spanish Law 10/2010 on the prevention of money laundering and terrorist financing[1] which transposes the AML Directive in Spain requested various information from Safe. When Safe did not provide them with the requested information the banks closed its accounts. Before closing Safe's account BBVA informed SEPBLAC[2] that Safe might be involved in money laundering activities.

Safe challenged the closure of its accounts before the Commercial Court in Barcelona (Juzgado de lo Mercantil) arguing that the banks have also been transferring funds abroad and that insofar they have been competing with Safe on the same market. In consequence, according to Safe, the closure of accounts was an act of unfair competition. Safe argued further that the information requested by the banks which related to Safe's customers as well as to the origin and destination of the funds could not have been provided without breaching the data protection legislation.

Safe's challenge was largely unsuccessful as the Commercial Court in Barcelona did not find a specific infringement of competition law by none of the banks. It concluded that BBVA closed Safe's account on the basis of checks which showed that nearly a quarter of transactions were not carried out by agents authorised by Safe and verified by the Bank of Spain. As for the closure of accounts by Sabadell and Liberbank, the court in Barcelona partly ruled in Safe's favour concluding that these two banks failed to properly set out the reasons for their closures.

Subsequently Safe, Sabadell and Liberbank appealed against that judgment to the Provincial Court in Barcelona which submitted the preliminary questions to the CJEU. 

The CJEU was asked, first, whether customer due diligence measures, laid down in the AML Directive to respond to the risks of money laundering and terrorist financing, could be applied by a credit institution (in the case at hand, a bank) to a financial/payment institution such as Safe, given that financial/payment institutions are already subject to supervision by competent authorities under the PSD and the AML Directive. The CJEU was then additionally asked what type of customer due diligence measures (standard, simplified or enhanced) could be applied in such a scenario and which circumstances could trigger the application of those measures. Finally, the national court asked if the measures and the provision of certain information requested by the banks from Safe are in line with EU competition law (Safe claimed that the banks compete with it on the payment services market) and with EU data protection law (according to Safe, the banks requested the identification data of its customers and of the recipients of the funds which Safe transferred).

The AML Directive sets out the legal framework for measures aimed at preventing and combatting money laundering and terrorist financing. Its provisions are to a great extent inspired by the recommendations of the Financial Action Task Force (FATF), the main international body in the area of combatting money laundering and terrorist financing.  Article 3 of the AML Directive defines which institutions and professions are to apply the anti-money laundering measures. The list in Article 3 includes credit institutions such as banks and financial institutions such as Safe. Chapter II of the AML Directive, which deals with customer due diligence, distinguishes between 3 types of such diligence, i.e. simplified, standard and enhanced.

As far as standard due diligence is concerned, Articles 7 and 8 of the AML Directive describe in which circumstances due diligence should be applied and what measures this might involve. The latter provision underlines that the extent the due diligence measures can be determined on a risk-sensitive basis depending on the type of customer, business relationship, product or transaction.

Article 9 of the AML Directive specifies the checks that need to be undertaken before the establishment of a business relationship or the carrying-out of a transaction. It also indicates when a business relationship must be terminated or a transaction cannot be carried out.

Article 11 sets out the simplified customer due diligence measures which inter alia apply in situations where the customers are credit institutions or financial institutions. Such customers are already covered by the scope of Article 2 of the AML Directive and need to apply due diligence measures towards their own customers. Enhanced customer due diligence is dealt with in Article 13.

Pursuant to Article 37 of the AML Directive the compliance with the requirements of the Directive by the institutions and persons that need to apply it is supervised by competent authorities. Credit institutions and payment institutions are also covered by the PSD.

Payment institutions get authorised to provide payment services by competent authorities designated by the Member States. These authorities are also empowered to supervise the compliance with the requirements that are applicable to payment service providers.

The CJEU's analysis

The CJEU first dealt with the question if financial institutions such as Safe can be the addressees of standard or enhanced customer due diligence measures despite the derogation in Article 11 of the AML Directive which foresees the application of simplified due diligence measures towards financial institutions.

The Court underlined that Article 11 of the AML Directive does not derogate from Article 7(c) under which standard customer diligence measures must be applied when there is a suspicion of money laundering or terrorist financing. Thus, a national provision which authorises the application of standard due diligence measures vis-Ć -vis financial institutions in such circumstances of suspicion is compatible with the Directive.

In a similar vein, Article 11 of the AML Directive does not derogate from Article 13 thereof. The latter requires enhanced customer due diligence measures to be applied in situations where the risk of money laundering or terrorist financing is higher. Paragraphs (2) to (4) of Article 13 contain a non-exhaustive list of such situations which by their nature present a higher risk. Whilst this list does not include the transfer of funds abroad the Member States have a margin of discretion in applying a risk-based approach and identifying other situations which are, by their nature, associated with a greater risk of money laundering or terrorist financing. In the case at hand, the transfer of funds abroad was included by the Spanish legislator in Law 10/2010 (Article 11) as one of the higher-risk situations which trigger enhanced customer due diligence.

The CJEU then dealt with Article 9 of Spanish Law 10/2010 which on the one hand allows the non-application of standard customer due diligence towards financial institutions but on the other hand empowers the Minister of Economic Affairs and Finance to exclude the application of simplified due diligence towards certain customers. On this point, the CJEU noted that the AML Directive only lays down the minimum level of EU harmonisation with Article 5 of the Directive envisaging the possibility of adopting or retaining in force stricter provisions in the EU Member States. This conclusion was supported by an earlier CJEU judgment in Jyske Bank Gibraltar. The stricter provisions which can apply in the Member States need to serve the purpose of strengthening the fight against money laundering and terrorist financing. They may thus also relate to additional situations which, according to the Member State, present a risk of money laundering or terrorist financing  even if the AML Directive does not prescribe any type of customer due diligence for those situations.

The second group of questions before the CJEU related to the extent of powers which credit institutions may exercise in the context of customer due diligence and to the relation between those powers and the powers of the supervisory authorities under Article 37 of the AML Directive and under Article 21 of the PSD. Here, the Court noted that an institution covered by the AML Directive cannot establish a business relationship or carry out a transaction through its account or must terminate an existing business relationship when it is unable to obtain the various items of information that are defined  in Article 8 of the Directive. These items include the verification of the customer's and the beneficial owner's identity (in the latter case pursuant to a risk-based approach) as well as the information on the purpose and intended nature of the business relationship. The inability of the institution to obtain these types of information might be due to the customers' refusal to cooperate (as in the case at hand) or to other factors.

The CJEU went on to identify the limitations that need to be applied when taking a measure such as the termination of a business relationship or the refusal to carry out a transaction through the bank account. The measure must be proportionate to the risk of money laundering or terrorist financing and thus cannot be taken in the absence of sufficient information which point out to that risk.

The Court then stated that the powers exercised in the context of customer due diligence and the supervisory powers of the competent authorities under the AML Directive and the PSD are rather to be seen as separate and complementary. In consequence, a credit institution may take account of the due diligence measures which its customer had to apply towards its own customers but the extent of the credit institution's due diligence measures in such a scenario must be appropriate to the risk of money laundering and terrorist financing. In addition, a credit institution must in that case neither compromise the supervisory tasks of the competent institutions under the PSD nor replace those supervisory authorities.

Next, the CJEU spelled out the conditions in which the national legislation can authorise or require standard or enhanced customer due diligence measures towards a financial institution. The CJEU's reply to the first group of questions indicated already that such measures can be applied vis-Ć -vis financial institutions pursuant to Article 13 of the AML Directive (enhanced due diligence) and Article 5 (stricter provisions). In this part of the judgment however the Court examined how the Member States (when prescribing such measures) or the credit institutions (when authorised by the Member State to apply such measures) can exercise the powers under Article 5 and 13.

The CJEU started by recalling its case-law on the freedom to provide services and on the permissible restrictions of that freedom (Art. 56 TFEU). It reminded that in Jyske Bank Gibraltar the prevention of and fight against money laundering and terrorist financing was recognised as a legitimate public interest objective which could justify a barrier to the freedom to provide services. It then turned to the question if Article 11 of Spanish Law 10/2010 which identifies the transfer of money abroad as a situation which always presents a higher risk of money laundering and terrorist financing (and in consequence triggers enhanced customer due diligence) is appropriate for attaining this legitimate public interest objective. In that regard, the Court stressed that both the national legislator (when prescribing standard or enhanced due diligence measures towards a financial institution) and the credit institutions (when authorised by the Member State to apply such measures) must carry out a complete risk assessment prior to deciding on the measures to take. Such measures must furthermore be proportionate to the risk so identified. The final element of this part of the CJEU's judgment was thus dedicated to the proportionality of Article 11 of Spanish Law 10/2010. Here, the Court concluded that the restriction of the freedom to provide services laid down in Article 11 would be proportionate if no less restrictive means were available and if the restriction was compatible with the fundamental rights and freedoms under the Treaties and the Charter e.g. with the right to protection of personal data (Article 8 of the Charter) and with the principle of free competition. Whilst, in principle, leaving the protection of personal data aspects for the last part of the judgment the Court found that a less restrictive measure was available in this case. In the case at hand the Spanish legislator generally presumed that all transfers of money abroad present a higher risk of money laundering and terrorist financing whereas it could have provided a possibility of rebutting that presumption in individual cases which objectively do not present such a risk.

The last group of preliminary questions put before the CJEU focussed on the compatibility of the enhanced due diligence measures with the EU data protection law, as set out in the Data Protection Directive (Directive 95/46). The Provincial Court in Barcelona asked if Safe can be obliged to provide the banks with the identification data of its customers and in particular those from whom the transferred funds originated as well as with the identification data of the recipients of the funds. In the reply to the previous group of questions the CJEU has already indicated that the due diligence measures taken pursuant to Articles 5 and 13 of the AML Directive need to be compatible with Article 8 of the Charter, i.e. with the right to the protection of personal data. The reply to the last group of questions could have thus elaborated on this statement and clarified which personal data of the customers and recipients can be validly requested by credit institutions. However, in the case at hand BBVA denied that it requested the identification data of Safe's customers and of the recipients of the funds. It merely requested the identification data of Safe's agents who used BBVA's accounts. Moreover, the CJEU found the last group of questions not to be sufficiently precise because they only referred generally to the Data Protection Directive without specifying any of its provisions which could be relevant in this context. The part of the preliminary questions which related to the Data Protection Directive was therefore considered inadmissible.  

Comments

The replies of the CJEU to the preliminary questions point out in the direction of giving a certain degree of flexibility to the national legislators and to the institutions and persons which apply customer due diligence measures. On the other hand, the measures prescribed or authorised by the national authorities and the measures applied in individual cases by banks and other institutions and persons covered by the AML Directive need to be preceded by comprehensive risk assessments. Those risk assessments should lead to the definition of measures which are appropriate to the identified level of risk. The measures can vary depending on the type of customer, business relationship, product or transaction.

This kind of well-balanced approach seems in line with the objectives of the AML Directive and with the CJEU's case-law which recognised preventing and combatting money laundering and terrorist financing as an overriding reason in the public interest.

The CJEU added a further safeguard at the later stages of the judgment: the proportionality of the customer due diligence measures depends not only on the results of the risk assessment but also on their compliance with the fundamental rights and freedoms and general principles of law. The Court specifically mentions the principle of free competition and the right to the protection of personal data enshrined in Article 8 of the Charter.

In Safe the CJEU did not however provide any specific indications on the issue which personal data can be requested from the customer in the context of due diligence measures and in which circumstances. This was so because the last group of preliminary questions was based on facts which were disputed in the proceedings and eventually this last group was declared inadmissible by the Court.

The AML Directive does not really address the matter how the measures it designs relate to the protection of personal data. In fact, there is only one point in the text of the Directive which touches upon that issue. It is Recital 33 which refers to the applicability of national data protection laws and of the international transfers rules of the Data Protection Directive in the context of the transmission of information to the Financial Intelligence Units (FIUs) and the disclosure of information about such a transmission.

On the other hand, the new fourth Anti-Money Laundering Directive 2015/849 is much more outspoken in this respect. Its Chapter V implicitly states that Article 7(e) of the Data Protection Directive constitutes the legal basis for processing personal data for the purpose of the prevention of money laundering and terrorist financing by recognising, in Article 43, that such processing is a matter of public interest. The same Chapter deals also with the issue of the information that needs to be provided to the customer before establishing a business relationship or carrying out an occasional transaction. Finally, it lays down more precise indications with regard to the transmission of information to FIUs and to the disclosure of that fact to the customers. According to Article 41(4) this issue should be regulated in national laws which must strike the balance between the access of the customer to the personal data and the interests of the proper functioning of the anti-money laundering procedures and investigations.

The provisions on the different kinds of customer due diligence are also more precise in the new Directive. There is no longer a derogation from standard due diligence for financial institutions. The Directive is now accompanied by three annexes. The first of these annexes contains a non-exhaustive list of risk variables that shall be taken into account when determining the extent of customer due diligence measures. The second annex includes a non-exhaustive list of factors which point out to a potentially lower risk of money laundering and terrorist financing, i.e. the degree of risk that might trigger the application of simplified customer due diligence. Finally, the third annex is a non-exhaustive list of factors suggesting a higher degree of risk which requires the application of enhanced customer due diligence. Generally speaking, the factors included in the three annexes relate to types of customers, geographic areas, and particular products, services, transactions or delivery channels. In addition, Articles 17 and 18 of Directive 2015/849 envisage guidelines on the risk factors and the measures to be taken in situations of simplified customer due diligence and enhanced customer due diligence respectively. Such guidelines shall be issued by ESAs, i.e. the European Supervisory Authorities (EBA, EIOPA and ESMA) by 26 June 2017.

Photo credit: gfintegrity.org



[1] Ley 10/2010 de prevención del blanqueo de capitales y de la financiación del terrorismo.
[2] The Executive Service of the Commission for the Prevention of Money Laundering and Financial Crime of the Bank of Spain - Servicio Ejecutivo de la Comisión de Prevención de Blanqueo de Capitales e Infracciones Monetarias del Banco de España.