[eu]cite

Home› Banking & Credit Institutions› KWG (EN)

Section 24c

Automated retrieval of account information

(1) A credit institution must maintain a data system in which the following data must be stored without delay: 1. the number of an account subject to the duty of identity verification under section 154(2), first sentence, of the Fiscal Code, of a securities account, or of a safe-deposit box, and the day of opening and the day of closure or dissolution, 2. the first and last name, address, and, for natural persons, the date of birth, of the holder and of a person authorised to give instructions, and, in the cases of section 10(1), point 2, of the Anti-Money Laundering Act, the first and last name and, where collected, the address of a deviating beneficial owner within the meaning of section 3 of the Anti-Money Laundering Act. On every change to a particular under the first sentence, a new data record must be created without delay. The data must be deleted after ten years have elapsed following the closure of the account or securities account. In the case of the second sentence, the old data record must be deleted after three years have elapsed following the creation of the new data record. The credit institution must ensure that the Federal Institute can retrieve data from the data system under the first sentence at any time, by an automated procedure determined by the Federal Institute. It must ensure, by technical and organisational measures, that it does not become aware of retrievals.
(2) The Federal Institute may retrieve individual data from the data system under subsection (1), first sentence, insofar as this is necessary for it to perform its supervisory tasks under this Act or the Anti-Money Laundering Act, in particular with regard to unauthorised banking business or financial services or the abuse of institutions through money laundering, terrorist financing, or other criminal acts that may endanger the assets of institutions, and there is particular urgency in the individual case. The Financial Intelligence Unit may, equally, retrieve individual data from the data system under subsection (1), first sentence, to perform its tasks under the Anti-Money Laundering Act.
(3) The Federal Institute provides information from the data system under subsection (1), first sentence, on request, to: 1. the supervisory authorities under section 9(1), fifth sentence, point 2, insofar as this is necessary for them to perform their supervisory tasks under the conditions of subsection (2), 2. the authorities or courts responsible for providing international legal assistance in criminal matters and, in other respects, for the prosecution and punishment of criminal offences, insofar as this is necessary for them to perform their statutory tasks, 3. the national authority responsible for restrictions on capital and payment transactions under the Foreign Trade and Payments Act, insofar as this is necessary for it to perform tasks arising from the Foreign Trade and Payments Act or legal acts of the European Union in connection with restricting economic or financial relations, 4. the authorities responsible under section 13(1) and section 22(3), first sentence, of the Foreign Trade and Payments Act, insofar as this is necessary for them to perform their statutory tasks, 5. the Customs Criminal Investigation Office, insofar as this is necessary for it to perform its statutory tasks under section 4(2) and (3) of the Customs Investigation Service Act, and 6. the Central Office for Sanctions Enforcement, insofar as this is necessary for it to perform its statutory tasks. Account-retrieval requests to the Federal Institute must be transmitted electronically, using the officially prescribed data record, through the officially determined interfaces. The Federal Institute may permit exceptions to electronic transmission. The Federal Institute must retrieve the data stored in the data systems by an automated procedure and transmit them on to the requesting body. The Federal Institute examines the permissibility of the transmission only where there is particular cause to do so. Responsibility for the permissibility of the transmission lies with the requesting body. The Federal Institute may, for the purposes named in the first sentence, provide information from the data system under subsection (1), first sentence, to foreign bodies in accordance with the general data protection provisions. Section 9(1), sixth and seventh sentences, and (2), applies correspondingly. The provisions on international legal assistance in criminal matters remain unaffected.
(3a) The Federal Institute provides information from the data systems under subsection (1), first sentence, on request, to: 1. the domestic designated authorities within the meaning of Article 3(1) of Directive (EU) 2019/1153 of the European Parliament and of the Council of 20 June 2019 laying down rules facilitating the use of financial and other information for the prevention, detection, investigation or prosecution of certain criminal offences, and repealing Council Decision 2000/642/JHA, insofar as this is necessary for them to perform their statutory tasks in preventing or prosecuting serious criminal offences within the meaning of Annex I to Regulation (EU) 2016/794 of the European Parliament and of the Council of 11 May 2016 on the European Union Agency for Law Enforcement Cooperation (Europol) and replacing and repealing Council Decisions 2009/371/JHA, 2009/934/JHA, 2009/935/JHA, 2009/936/JHA and 2009/968/JHA (OJ L 135, 24.5.2016, p. 53), or to support a criminal investigation connected with a serious criminal offence; 2. the Federal Criminal Police Office, in its function as the national unit under section 1, point 1, of the Europol Act, for the purpose of onward transmission to Europol, insofar as this is necessary for Europol to perform its tasks under Article 4 of Regulation (EU) 2016/794, within the scope of Europol's competence in the individual case. The Federal Institute must retrieve the data by an automated procedure and transmit them directly on to the requesting body. Subsection (3), fourth and sixth sentences, applies correspondingly.
(4) The Federal Institute logs, for every retrieval: 1. the reference number, 2. the date and time of the retrieval, 3. the type of data used in carrying out the retrieval, 4. the unique identifier of the results, and 5. the person who carried out the retrieval. For every retrieval for the purpose of providing information on request under subsection (3), it also logs the requesting body and the requesting body's reference number. For a retrieval under subsection (3a) by a domestic designated authority within the meaning of Article 3(1) of Directive (EU) 2019/1153, it also logs the unique user identifier of the person who addressed the request to the Federal Institute and, where different, the user identifier of the person who receives the results transmitted on. The logs serve exclusively the purpose of monitoring data protection compliance and ensuring data security. They are reviewed regularly by the Federal Institute's data protection officer and made available on request to the Federal Commissioner for Data Protection and Freedom of Information. Logs under the first and second sentences must be kept protected against access for 18 months, and logs under the third sentence for five years. On expiry of the retention period, the logs must be deleted, unless they are required for ongoing review procedures. The Federal Institute ensures, by special training programmes, that the personnel deployed are familiar with the applicable provisions, including in particular European and national data protection provisions. The Federal Institute keeps statistics on the number and handling of requests under subsection (3a).
(5) The credit institution must, at its own expense and within its area of responsibility, take all precautions necessary, in accordance with the state of the art, for the automated retrieval while ensuring data protection and data security of the data under subsection (1), first sentence. This includes, in each case in accordance with the Federal Institute's specifications, the acquisition of the equipment necessary to ensure confidentiality and protection against unauthorised access, the setting up of a suitable telecommunications connection, and participation in the closed user system, as well as the ongoing provision of these precautions. The Federal Institute determines the state of the art, in consultation with the Federal Office for Information Security, by a procedure it determines.
(6) The Federal Institute must take measures corresponding to the state of the art to ensure data protection and data security, which in particular safeguard the confidentiality and integrity of the data under subsection (1), first sentence, on retrieval by the Federal Institute. The Federal Institute must take corresponding measures for the onward transmission of the data under subsections (3) and (3a); in the case of requests under subsection (3a), these measures must ensure that the requesting authorities restrict access to the retrieved and onward-transmitted data to individual persons and their unique user identifiers. The Federal Institute determines the state of the art, in consultation with the Federal Office for Information Security, by a procedure it determines.
(7) The Federal Ministry of Finance may, by statutory instrument, set out further provisions on the technical procedures for automated retrieval and onward transmission, on exceptions from the duty of transmission by automated procedure, and on the logging of retrievals and the statistics on requests. It may transfer this power by statutory instrument to the Federal Institute.
(8) Insofar as the Deutsche Bundesbank maintains accounts and securities accounts for third parties, it is deemed a credit institution for the purposes of subsections (1), (5), and (6).

←→ also move between sections