Record-keeping under the Wwft: how long do you keep data?

In short

  • The Wwft requires you to record the documents and information from your customer due diligence and to keep them in an accessible way.
  • The period is five years after the end of the business relationship, or five years after the transaction was carried out.
  • You keep information about a report to FIU-Nederland for five years after the report or after the acknowledgement of receipt from FIU-Nederland.
  • When the period ends, you destroy the personal data immediately, unless another law requires longer retention.

The record-keeping obligation (bewaarplicht) is the duty under the Wwft to record the documents and information from your customer due diligence and keep them for five years. The period starts after the end of the business relationship, or after the transaction if there is no ongoing relationship. When it ends, you destroy the personal data. This allows supervisors and FIU-Nederland to establish later what you knew and what you did.

Record-keeping sounds like administration. In practice, it is the evidence that your customer due diligence was carried out properly. For a supervisor, what has not been recorded did not happen.

What do you keep?

The Wwft requires you to record the documents and information you used for customer due diligence. This applies to standard due diligence, simplified due diligence and enhanced due diligence. The law lists at least:

  • For natural persons: surname, first names, date of birth, address and place of residence of the client and of anyone acting on the client's behalf. Also the type, number, date and place of issue of the identity document. Instead of these details, you may keep a copy of the document used to verify the identity.
  • For UBOs: at least the surname and first names, and the information and documents you gathered to verify their identity. Read more in What is a UBO?
  • For companies and other legal entities: legal form, registered name, trade name, address, place of business and country of the registered office, the Chamber of Commerce (KvK) number and how you verified the identity. For the representatives, you record surname, first names and date of birth.
  • For trusts and similar arrangements: the purpose and nature of the arrangement and the law that governs it.

That is the statutory minimum. A good file contains more: your risk assessment, the results of PEP and sanctions screening, the research into the source of wealth and source of funds, and the acceptance decision. Also record who made that decision and why.

Information about reports

Have you reported an unusual transaction to FIU-Nederland? Then you separately record:

  1. the information needed to reconstruct the transaction;
  2. a copy of the report and the information you provided with it;
  3. the acknowledgement of receipt from FIU-Nederland.

You keep this information for five years after making the report or after receiving the acknowledgement from FIU-Nederland. Read more about reporting in Reporting obligation under the Wwft.

How long do you keep records?

The main rule is five years. The starting point depends on the situation:

  • Business relationship: five years after the relationship ends. As long as the client remains a client, the period does not run.
  • Occasional transaction: five years after the transaction was carried out.
  • Report: five years after the report or after the acknowledgement of receipt from FIU-Nederland.

Record for each client the date on which the relationship ended. Without that date, you do not know when the period expires.

Keeping records accessible

Keeping records is not enough. The information must be retrievable and accessible. The Wwft also requires you to have systems that allow you to respond without delay and in full to questions from FIU-Nederland and your supervisor. For example, whether you have a business relationship with a particular person, or had one in the preceding five years, and what the nature of that relationship is. These requests arrive through secure channels and are confidential.

In practice, this means:

  • one fixed location for each client file, not spread across mailboxes and network drives;
  • a recorded version of documents, so that it is clear later what you knew at which moment;
  • a search function on name, date of birth and KvK number, also for relationships that have ended.

Destroying data after the period

When the retention period ends, you destroy the personal data obtained under the Wwft immediately, unless another statutory provision requires longer retention. Keeping data longer just in case is therefore not allowed.

Two other privacy rules in the Wwft also apply:

  • you use the data only to prevent money laundering and terrorist financing, not for commercial purposes;
  • you inform the client in advance about the processing of personal data for Wwft purposes.

Set out in a retention policy which periods you apply, who is responsible for destruction and how you check this. Where periods from different laws overlap, such as the tax retention obligation, record which period applies to each type of data.

What happens if you do not keep records properly?

Missing or incomplete files are a breach of the Wwft. Even if the due diligence was done, you cannot prove it without records. The supervisor may, among other things, issue an instruction, impose an order subject to a penalty or impose an administrative fine. Read more in Wwft breaches: which sanctions do you face?

What changes with the AMLR?

From 10 July 2027 the European AMLR applies. The retention period remains five years. Some things do change:

  • the period also starts on the date on which you refuse to enter into a relationship or carry out a transaction;
  • you also keep your assessment of a potentially suspicious transaction, even if it does not lead to a report;
  • a competent authority may, case by case, require you to keep the information for longer, by up to five additional years;
  • after the period you delete the personal data, unless other legislation requires longer retention.

Read more about the new rules in AMLR 2027.

Frequently asked questions

How long must I keep Wwft data?

Five years after the end of the business relationship, or five years after the transaction if there is no ongoing relationship. For information about a report, the period runs from the report or from the acknowledgement of receipt from FIU-Nederland.

When does the period start for a long-standing client?

Only when the relationship ends. As long as someone is a client, you keep the file and keep it up to date. Once the relationship ends, the five-year period starts.

May I keep a copy of an identity document?

Yes. The Wwft allows you to keep a copy of the document used to verify the identity, even if it contains a personal identification number. You use that copy only for Wwft purposes.

May I keep data for longer than five years?

Only if another statutory provision requires it. The Wwft requires you to destroy personal data immediately after the period ends. Keeping data longer just in case is therefore not allowed.

What changes with the AMLR?

The period remains five years. What is new is that the period also starts when you refuse a relationship or transaction, and that a competent authority may require you, case by case, to keep data for up to five more years.

Files that stand up to inspection?

BlueMonks carries out your customer due diligence and delivers a complete, traceable file for each client, with experienced analysts and our own KYC platform. You stay in control of every decision.