Machine translations by Deepl

Privacy First is calling for a ban on automated risk profiling by banks

Comments submitted during the consultation organised by the European Anti-Money Laundering Authority (AMLA) on the ongoing screening of customers by banks and other businesses 

Privacy First took part in the consultation which was organised by the European Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA) on draft guidelines concerning the ongoing monitoring of customers by organisations subject to statutory anti-money laundering obligations (‘OEs’). The draft guidelines provide information on how, in AMLA’s view, OEs should organise the ongoing monitoring of customers. Privacy First has many fundamental objections to this.

Privacy First has fundamental objections to the proposed draft guidelines:

  1. Compliance with these draft guidelines effectively leads to the preventative and ongoing monitoring (surveillance) of citizens’ behaviour, with far-reaching consequences for their daily lives;
  2. Regulations on anti-money laundering (AML) and counter-terrorist financing (CFT) are always full of references to the ‘risk-based approach’, but to date there is no clarity as to what this actually entails; The AMLA’s draft guidelines do not provide sufficient guidance;
  3. In its draft guidelines, AMLA pays no attention whatsoever to the position of individuals (the ‘stakeholders’) or to the clients of OEs;
  4. the draft guidelines do not address the prevention of the harmful effects of the AML/CFT system;
  5. The draft guidelines contain incorrect assumptions about digital risk-profiling techniques and wrongly fail to prohibit the use of automated means of detecting crime (automated risk profiling).

General context

Under European legislation on anti-money laundering and counter-terrorist financing (‘AML/CFT’), businesses are required to fulfil public duties in the fight against crime. The EU’s AML/CFT system is based on banks and has been extended to a large group of other businesses, a significant proportion of which are SMEs. The effectiveness of involving this large group of businesses in the fight against crime under European legislation – whilst they lack the necessary expertise in this area – has never been demonstrated.

Our objections are explained in more detail below:

A financial surveillance state is emerging

Firstly, AMLA’s compliance with these draft guidelines effectively results in the preventative and ongoing monitoring of citizens’ behaviour, with far-reaching consequences for their daily lives. Efforts to detect money laundering and crime in general have now reached such a point that every law-abiding citizen is monitored by the state – via private bodies (notably banks) – at every turn in their lives. Privacy First is deeply concerned that AMLA fails to recognise that the creation of an infinite number of vague legal grounds, which constitute exceptions to the principles of fundamental rights and circumvent privacy rules, renders these fundamental rights a mere illusion. The application of these draft guidelines leads to a surveillance state that fails to respect fundamental rights as enshrined, amongst other things, in European legislation such as the European Charter and the GDPR. Privacy First notes that, although compliance with these rights is professed in words, the reality on the ground is very different.

The risk-based approach is not being implemented

Secondly, Privacy First notes that all legislative texts relating to anti-money laundering measures and the fight against crime are always peppered with the term ‘risk-based approach’, but that there has been no clarity to date as to what this actually entails. Nor does the AMLA explain in these guidelines what a risk-based approach entails. The usual response that ‘risk-based’ means ‘focusing on the greatest risks’ is too vague to be applied in practice. Privacy First calls on AMLA to give this concept real substance. Our proposal: to genuinely ease the supervisory requirements for low-risk customers and to focus on high-risk groups, taking into account the capabilities of the large group of organisations that fall within the SME sector. In such a system, AMLA would only need to define what is meant by ‘high-risk customers’. Given that most citizens abide by the law, this group should not represent a large percentage. The approach proposed by Privacy First would be proportionate and risk-based, and would also be in line with the way in which the government and the Public Prosecution Service themselves investigate and prosecute offences.

A lack of consideration for those affected and OE’s (other) customers

Thirdly, it is striking that the draft pays no attention whatsoever to the position of natural persons (data subjects) and to the clients of OEs, who must also be informed of the monitoring activities and must be able to assess whether OEs are complying with their obligations, including not requesting more data than is necessary (data minimisation).

Failure to prevent the harmful consequences of the AML/CFT system

In its response to the consultation, Privacy First calls on AMLA not only to focus on combating crime, but also to take responsibility for the harmful social consequences of the privatisation of crime-fighting. Privacy First urges AMLA to help prevent abuse and the emergence of a society governed by financial surveillance. Privacy First draws AMLA’s attention to the serious abuses that have taken place in the Netherlands and which have led to fundamental criticism from, amongst others, the Netherlands Institute for Human Rights, the Dutch Data Protection Authority, the Netherlands Court of Audit and the Advisory Division of the Council of State.

Misconceptions about automated risk profiling: digital risk profiling and digital monitoring must be stopped immediately

Furthermore, Privacy First points out that the AMLA places too much reliance on the use of digital tools (such as AI) by financial institutions to determine whether a customer may be involved in criminal activity. We draw attention to key reports published on digital risk profiling, which show that digital systems are flawed and lead to discrimination and exclusion. These include, amongst others, this report by Amnesty International, published in the message ‘Risk-profiling systems used to identify potential offenders are contrary to international law and must be banned’. See also the advice from the Dutch State Commission against Discrimination and Racism, which calls on the government to stop using data-driven profiling to detect fraud and crime.

Privacy First believes that the current landscape of digital risk profiling, whether carried out by public authorities or by OEs, is not yet sufficiently mature, and that the AMLA should make it clear in the draft guidelines that the use of digital tools for risk assessment and monitoring is not permitted.

The future of AML/CFT

Privacy First calls on AMLA to take responsibility for the impact of AML/CFT regulations on citizens’ fundamental rights and to adopt a critical and independent stance, which should include a ban on automated risk profiling.

Privacy First has a large number of other comments and proposals, which can be found in our full response to the consultation, as set out HERE It can be downloaded from our website (PDF).