The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017

PART 4 U.K.Reliance and Record-keeping

RelianceU.K.

39.—(1) A relevant person may rely on a person who falls within paragraph (3) (“the third party”) to apply any of the customer due diligence measures required by regulation 28(2) to (6) and (10) [F1, or to carry out any of the measures required by regulation 30A,] but, notwithstanding the relevant person's reliance on the third party, the relevant person remains liable for any failure to apply such measures.

(2) When a relevant person relies on the third party to apply customer due diligence measures [F2or carry out any of the measures required by regulation 30A] under paragraph (1) it—

(a)must immediately obtain from the third party all the information needed to satisfy the requirements of regulation 28(2) to (6) and (10) [F3and regulation 30A] in relation to the customer, customer's beneficial owner, or any person acting on behalf of the customer;

(b)must enter into arrangements with the third party which—

(i)enable the relevant person to obtain from the third party immediately on request copies of any identification and verification data and any other relevant documentation on the identity of the customer, customer's beneficial owner, or any person acting on behalf of the customer;

(ii)require the third party to retain copies of the data and documents referred to in paragraph (i) for the period referred to in regulation 40.

(3) The persons within this paragraph are—

(a)another relevant person who is subject to these Regulations under regulation 8;

F4(b). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

(c)a person who carries on business in a third country who is—

(i)subject to requirements in relation to customer due diligence and record keeping which are equivalent to those laid down in the fourth money laundering directive; and

(ii)supervised for compliance with those requirements in a manner equivalent to section 2 of Chapter VI of the fourth money laundering directive;

(d)organisations whose members consist of persons within sub-paragraph (a)F5... or (c).

(4) A relevant person may not rely on a third party established in [F6a high-risk third country], and for these purposes “high-risk third country” has the meaning given in regulation 33(3).

(5) Paragraph (4) does not apply to a branch or majority owned subsidiary of an entity F7... if all the following conditions are met—

[F8(a)the entity is—

(i)a person who is subject to the requirements in these Regulations as a relevant person within the meaning of regulation 8 and who is supervised for compliance with them; or

(ii)subject to requirements in national legislation having an equivalent effect to those laid down in the fourth money laundering directive on an obliged entity (within the meaning of that directive) and supervised for compliance with those requirements in a manner equivalent to section 2 of Chapter VI of the fourth money laundering directive;]

[F9(b)the branch or subsidiary complies fully with procedures and policies established for the group under—

(i)regulation 20 of these Regulations, or

(ii)requirements in national legislation having an equivalent effect to those laid down Article 45 of the fourth money laundering directive.]

(6) A relevant person is to be treated by a supervisory authority as having complied with the requirements of paragraph (2) if—

(a)the relevant person is relying on information provided by a third party which is a member of the same group as the relevant person;

(b)that group applies customer due diligence measures, rules on record keeping and programmes against money laundering and terrorist financing in accordance with these Regulations, the fourth money laundering directive or rules having equivalent effect; and

(c)the effective implementation of the requirements referred to in sub-paragraph (b) is supervised at group level by—

(i)an authority of an EEA state F10... with responsibility for the functions provided for in the fourth money laundering directive; or

(ii)an equivalent authority of a third country.

(7) Nothing in this regulation prevents a relevant person applying customer due diligence measures [F11, or carrying out any of the measures required by regulation 30A,] by means of an agent or an outsourcing service provider provided that the arrangements between the relevant person and the agent or outsourcing service provider provide for the relevant person to remain liable for any failure to apply such measures.

(8) For the purposes of paragraph (7), an “outsourcing service provider” means a person who—

(a)performs a process, a service or an activity that would otherwise be undertaken by the relevant person, and

(b)is not an employee of the relevant person.

Textual Amendments

Record-keepingU.K.

40.—(1) Subject to paragraph (5), a relevant person must keep the records specified in paragraph (2) for at least the period specified in paragraph (3).

(2) The records are—

(a)a copy of any documents and information obtained by the relevant person to satisfy the customer due diligence requirements in regulations 28, 29 and 33 to 37 [F12and the requirements of regulation 30A];

(b)sufficient supporting records (consisting of the original documents or copies) in respect of a transaction (whether or not the transaction is an occasional transaction) which is the subject of customer due diligence measures or ongoing monitoring to enable the transaction to be reconstructed.

(3) Subject to paragraph (4), the period is five years beginning on the date on which the relevant person knows, or has reasonable grounds to believe—

(a)that the transaction is complete, for records relating to an occasional transaction; or

(b)that the business relationship has come to an end for records relating to—

(i)any transaction which occurs as part of a business relationship, or

(ii)customer due diligence measures taken in connection with that relationship.

(4) A relevant person is not required to keep the records referred to in paragraph (3)(b)(i) for more than 10 years.

(5) Once the period referred to in paragraph (3), or if applicable paragraph (4), has expired, the relevant person must delete any personal data obtained for the purposes of these Regulations unless—

(a)the relevant person is required to retain records containing personal data—

(i)by or under any enactment, or

(ii)for the purposes of any court proceedings;

(b)the data subject has given consent to the retention of that data; or

(c)the relevant person has reasonable grounds for believing that records containing the personal data need to be retained for the purpose of legal proceedings.

(6) A relevant person who is relied on by another person must keep the records specified in paragraph (2) for the period referred to in paragraph (3) or, if applicable, paragraph (4).

(7) A person referred to in regulation 39(3) (“A”) who is relied on by a relevant person (“B”) must, if requested by B within the period referred to in paragraph (3) or, if applicable, paragraph (4), immediately—

(a)make available to B any information about the customer, any person purporting to act on behalf of the customer and any beneficial owner of the customer, which A obtained when applying customer due diligence measures; and

(b)forward to B copies of any identification and verification data and other relevant documents on the identity of the customer, any person purporting to act on behalf of the customer and any beneficial owner of the customer, which A obtained when applying those measures.

(8) Paragraph (7) does not apply where a relevant person applies customer due diligence measures by means of an agent or an outsourcing service provider (within the meaning of regulation 39(8)).

(9) For the purposes of this regulation—

(a)B relies on A where B does so in accordance with regulation 39(1);

(b)copy” means a copy of the original document which would be admissible as evidence of the original document in court proceedings;

[F13(c)data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);

(d)personal data” has the same meaning as in Parts 5 to 7 of that Act (see section 3(2) and (14) of that Act).]

Data ProtectionU.K.

41.—(1) Any personal data obtained by relevant persons for the purposes of these Regulations may only be processed for the purposes of preventing [F14money laundering, terrorist financing or proliferation financing].

F15(2) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

(3) No other use may be made of personal data referred to in paragraph (1), unless—

(a)use of the data is permitted by or under an enactment other than these Regulations [F16or the [F17UK GDPR]]; or

(b)the relevant person has obtained the consent of the data subject to the proposed use of the data.

F18(4) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

F18(5) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

[F19(6) Before establishing a business relationship or entering into an occasional transaction with a new customer, as well as providing the customer with the information required under Article 13 of the [F20UK GDPR] (information to be provided where personal data are collected from the data subject), relevant persons must provide the customer with a statement that any personal data received from the customer will be processed only—

(a)for the purposes of preventing [F21money laundering, terrorist financing or proliferation financing], or

(b)as permitted under paragraph (3).

(7) In Article 6(1) of the [F22UK GDPR] (lawfulness of processing), the reference in point (e) to processing of personal data that is necessary for the performance of a task carried out in the public interest includes processing of personal data in accordance with these Regulations that is necessary for the prevention of [F23money laundering, terrorist financing or proliferation financing].

(8) In the case of sensitive processing of personal data for the purposes of the prevention of [F24money laundering, terrorist financing or proliferation financing], section 10 of, and Schedule 1 to, the Data Protection Act 2018 make provision about when the processing meets a requirement in Article 9(2) or 10 of the [F25UK GDPR] for authorisation under the law of the United Kingdom (see, for example, paragraphs 10, 11 and 12 of that Schedule).

(9) In this regulation—

data subject” has the same meaning as in the Data Protection Act 2018 (see section 3 of that Act);

personal data” and “processing” have the same meaning as in Parts 5 to 7 of that Act (see section 3(2), (4) and (14) of that Act);

sensitive processing” means the processing of personal data described in Article 9(1) or 10 of the [F26UK GDPR] (special categories of personal data and personal data relating to criminal convictions and offences etc).]

Textual Amendments