[eu]cite

Home› Anti-Money Laundering› GwG-EN

Section 29

Processing of Personal Data by the Financial Intelligence Unit

(1) The Financial Intelligence Unit may process personal data transmitted, collected or retrieved on the basis of this Act, insofar as this is necessary for the performance of its tasks.
(2) The Financial Intelligence Unit may match personal data it has stored for the performance of its tasks against other data, where this is permitted under this Act or under another Act.
(2a) The Financial Intelligence Unit may, when processing personal data under subsection (1) and when matching such personal data against other data under subsection (2), use automated data-analysis applications 1. for risk assessment under section 30(2), third sentence, 2. in operational analysis under section 28(1), third sentence, no. 2, and 3. in strategic analysis under section 28(1), third sentence, no. 8, of reports and other information under this Act. The following personal data may not be processed in automated data-analysis applications under the first sentence: 1. data originally collected by the Federal Intelligence Service, the Federal Office for the Protection of the Constitution, the Land authorities for the protection of the constitution, or the Military Counter-Intelligence Service; 2. data obtained by a measure under sections 100a, 100b, 100c, 100f, 100g, 100h, 100i, 100k(1), second sentence, sections 110a or 163f of the Code of Criminal Procedure, or from comparably serious interferences with informational self-determination; 3. biometric data. The following types of data may be processed by means of an automated data-analysis application: surname, first names, former names, other names, alias personal particulars, deviating spellings of names, name of the legal person, sex, date of birth, place of birth, state of birth, marital status, current and former nationalities, current and former addresses, the number of an identification document including the issuing public body, telecommunications connections owned or used, and electronic mail addresses, electronic addresses for new payment methods (wallet addresses), other particulars relevant to professional reachability, and data on the business relationship within the meaning of section 1(4) of a person with an obliged entity under section 2, in particular data on an account held with an obliged entity. Personal data from generally accessible sources may not be included, by automated means, in the processing of personal data in automated data-analysis applications.
(2b) The use of automated data-analysis applications under subsection (2a) may allow reports and other information held in the Financial Intelligence Unit's data holdings to be assessed and identified as to whether relevant indications exist that an asset is connected with money laundering, terrorist financing, or another criminal offence. For this purpose, relationships between persons, groups of persons, institutions, organisations, objects and items may be established, insignificant information and findings excluded, and incoming findings matched to known matters. For this purpose, the information to be provided by obliged entities when filing a report, and other information held in the Financial Intelligence Unit's data holdings, shall be matched, by automated means, against the parameters for risk assessment under section 30(2), second to eighth sentences, or against parameters for operational and strategic analysis, as to relationships and possible matches. Self-learning and automated systems capable of independently making assessments of the dangerousness of persons are not permitted.
(2c) The Financial Intelligence Unit may, for the performance of its tasks under this Act, collect and process information under section 28(1), third sentence, no. 2 and match it against other data.
(3) The Financial Intelligence Unit may process personal data held by it for training purposes or for statistical purposes, insofar as processing of anonymised data for those purposes is not possible.
(4) The Financial Intelligence Unit may process personal data held by it in order to prepare the use of automated data-analysis applications that it uses for the performance of its tasks under this Act.
(5) The Financial Intelligence Unit shall, by organisational and technical measures, ensure that data are processed only in accordance with their permitted legal use. In doing so, limitations on access to the automated data-analysis applications shall also be provided for.
(6) The Financial Intelligence Unit shall, through training, ensure that the personnel deployed are familiar with the applicable European and national data protection provisions.
(7) The Federal Commissioner for Data Protection and Freedom of Information shall carry out checks, at least every two years, of the data processing connected with the processing of personal data under subsection (1). These checks are without prejudice to the tasks referred to in section 14 of the Federal Data Protection Act.
(8) Where the Federal Commissioner for Data Protection and Freedom of Information has objected to breaches under section 16(2) of the Federal Data Protection Act, he or she may order appropriate measures where this is necessary to remedy a significant breach of data protection provisions.

←→ also move between sections