Esmé Bosma

Coördinator sectorteam Financiële Dienstverlening, Autoriteit Persoonsgegevens (Dutch DPA)

Pre-event interview

In the run-up to the Leaders in Finance Anti Money Laundering event on 1 October in Amsterdam, we spoke with Esmé Bosma, Coördinator sectorteam Financiële Dienstverlening, Autoriteit Persoonsgegevens (Dutch DPA). We discussed the balance between effective AML measures and the protection of privacy and personal data, with a focus on proportionality, responsible data sharing, and the careful use of technology and AI.

What is your focus in relation to financial institutions, data protection and AML?
Currently, I am coordinator of the financial sector at the Autoriteit Persoonsgegevens (the Dutch Data Protection Authority). We aim to ensure that organisations protect personal data in line with the General Data Protection Regulation (GDPR). Previously, I worked as a consultant and advised public and private parties on combating financial crime and environmental crime. Before that, I completed a PhD in Political Science for which I studied how banks counter terrorist financing at the human-technology interface in the Netherlands and the UK. I am intrinsically motivated to improve the global approach to tackling crime, whilst reducing the  adverse effects on law-abiding citizens and businesses such as the high privacy impact, de-risking, and financial exclusion. 

In our financial sector team, we focus on how financial institutions process and monitor financial data. Financial data are sensitive and can reveal a lot about a person, including their income, debts, purchasing behaviour, location, and relationships, as well as their religious beliefs or political affiliations. Because financial data can have a significant impact on people’s lives, it is important to supervise that data protection obligations and safeguards for human rights are in place.

In AML discussions, privacy is sometimes seen as a blocker. From the perspective of the Autoriteit Persoonsgegevens, is that a fair way to look at it?
I do not see privacy as a mere technical or compliance hurdle that should be completed by “ticking a box”. Privacy and data protection are fundamental human rights that should be at the heart of how financial institutions operate and relate to there customers. It is important to consider and protect the private lives of citizens, to ensure effective legal protection and safeguards in an increasingly digitized world, and to properly justify the potentially far-reaching impact of decisions based on financial data.

Of course, the processing of personal data could be blocked by the GDPR, for example when there is no legal basis, or when GDPR principles such as data minimisation or purpose limitation are insufficiently considered. GDPR principles are also represented in the AMLR, which stipulates for example that financial institutions are not allowed to gather data for KYC purposes and then use it for commercial purposes. Another example is that obliged entities may not use unreliable sources because of the data accuracy principle. The GDPR requires that data controllers take ownership and responsibility for data protection and they can be held accountable if they fail to do so.


Financial institutions have a legal responsibility to detect and prevent financial crime, while also protecting personal data. Where do you see the main tension between these responsibilities?
It is understandable that gatekeepers may sometimes find it challenging to balance their AML obligations with GDPR requirements, as both frameworks contain open norms that ask for careful consideration of concepts like the ‘risk-based approach’ and ‘proportionality’. But AML and data protection are two sides of the same coin that should balance out. The public interest of fighting financial crime and the fundamental right to data protection both protect innocent citizens – their safety and their privacy. 

This alignment is also acknowledged in the AMLR. The GDPR or the Law Enforcement Directive (LED) applies to all personal data processed in the context of fighting financial crime. Also, AMLA will closely collaborate with the European Data Protection Board (EDPB), especially when drafting guidelines and recommendations that have a significant impact on the protection of personal data. I think this collaboration is extremely valuable to strike the right balance. 


One of the central themes of the AML Event is balancing effectiveness with proportionality. What does proportionality mean from a data protection perspective in the AML context?
From a data protection angle, proportionality means that the infringement on privacy and personal data must be proportionate to the objective of the AML measure. The greater the impact on privacy, the stronger the justification must be that such processing is necessary and effective for achieving the AML objective.

Furthermore, practitioners should always consider whether an AML objective can be achieved through a measure that is less intrusive regarding the privacy of people. Also, extensive processing of personal data is harder to justify when its effectiveness cannot sufficiently be substantiated. This view aligns with the risk-based character of AML legislation, meaning that data should be gathered and processed only for specific purposes and based on concrete risks. 

Data sharing and cooperation are often mentioned as essential in the fight against financial crime. What safeguards are needed to make cooperation responsible and legally sound?
I believe that it is crucial to implement proper safeguards when sharing data and when collaborating to combat financial crime. Reports by RUSI and ECNL have called attention to misuse of FATF standards by authoritarian governments, who have mobilised them to restrict legitimate activity or target civil society. Public and private partners who aim to collaborate should therefore be aware of such risks and think about safeguards against mistakes and (un)intentional misuse. 

The EDPB and AMLA are currently developing Joint Guidelines for Article 75 of the AMLR, which creates a framework for setting up partnerships for information sharing to combat financial crime. We aim to clarify how information can be shared to fight financial crime while protecting personal data. 

Technology, data analytics and AI are becoming increasingly important in AML and financial crime prevention. What should institutions keep in mind when using these technologies from a data protection perspective?
I would recommend institutions to keep core GDPR principles in mind when exploring the uses of new technologies, such as fairness, purpose limitation and security. These principles, and other concepts such as adequate human oversight and privacy-by-design, require full integration with technology development to ensure responsible use. 

Moreover, the efficiency and effectiveness of technology ultimately rely on the underlying data and its quality. Sound data management is therefore key and should be in line with GDPR principles such as data accuracy and data minimisation. This forms the foundation for effective and efficient monitoring of AML/CFT risk during the whole customer lifecycle.Where relevant, for example when processing is likely to entail a high privacy risk, it is important to liase with your Data Protection Officer. 

Looking ahead to the AML Event on 1 October, what is one question or topic you hope will be discussed by banks, regulators, public authorities and other stakeholders?
I think we should be careful not to keep expanding the system on the assumption that it will become more effective, while its current effectiveness remains unclear. We should regularly step back to evaluate and improve the system but also be willing to accept risks and stop efforts that do not work or have significant negative consequences. 

Share

Uniting the financial sector by discussing pressing topics and enhancing cooperation. That’s what we love to do at Leaders in Finance. By listening, learning, and connecting with others, we accelerate the sharing of ideas, thus powering (upcoming) leaders and organizations to shape the future of financial services.

Each part of the Leaders in Finance Group – Podcasts, Events, Lunches, Academy – has its unique approach. Want to explore how we can benefit your organizational goals? We’re happy to meet and discuss opportunities.

We’d love to keep you informed on the next iterations of this event. Please enter your details below, and we’ll keep you posted!