← Luxembourg

Reminder of professional obligations – Law of 25 March 2020, as amended, establishing a central electronic data retrieval system related to payment ac

Published on 14 December 2023 Email this Share this on LinkedIn Share this on Facebook Communiqué Reminder of professional obligations – Law of 25 March 2020, as amended, establishing a central electronic data retrieval system related to payment accounts and bank accounts identified by IBAN and safe-deposit boxes held by credit institutions in Luxembourg (“Central System” or “CRBA”) To the professionals referred to under point

(6)of Article 1 of the Law of 25 March 2020 establishing a central electronic data retrieval system related to IBAN accounts and safe-deposit boxes, as amended Ladies and Gentlemen, This communiqué refers to the professional obligations laid down in the Law of 25 March 2020 establishing a central electronic data retrieval system related to payment accounts and bank accounts identified by IBAN and safe-deposit boxes held by credit institutions in Luxembourg, as amended (the “Law”). In accordance with Article 2 of the Law, the professionals are required to put in place a data file which allows the identification of any natural or legal person holding or controlling, within these professionals, payment accounts or bank accounts identified by IBAN, as defined under point
(15)of Article 2 of Regulation (EU) No 260/2012, or safe-deposit boxes (the “File”). In order to meet the objectives of the Law and of the CRBA and to ensure that the identification of any natural or legal person as mentioned above may be performed, the professionals must comply with the File structure and the details of the data that must be included when making the File available, in accordance with Article 2
(4)of the Law and as specified, in particular, in Circular CSSF 20/747 on the technical modalities relating to the application of the Law, as amended (the “Circular”). The CSSF draws the professionals’ attention to Annexes 1 and 2 of the Circular which describe the technical modalities that professionals must strictly follow and the structure of the File to be submitted to the CSSF. Complying with the structure and mandatory information is essential to ensure a proper transmission of the File data into the Central System, i.e. the CRBA. Thus, any non-compliance with the technical specifications set out in the above-mentioned Annexes has direct consequences as regards: the reliability of the CRBA which depends, like any central register, on the quality of the data entered into the CRBA; the accuracy of the data transmitted by the CSSF to the national authorities and self-regulatory bodies that have access to the CRBA in accordance with the terms laid down in the Law; and the accuracy of the data retrieved by the national authorities, among which the Financial Intelligence Unit, that have a direct, immediate and unfiltered access to the CRBA, in accordance with the provisions of the Law. Consequently, any inconsistency when making the File available may affect the objectives set by the Law, and, in particular, hinder the correct and full identification of the accounts and safe-deposit boxes by all the authorities and self-regulatory bodies that have access to the CRBA data within the scope of their respective missions. Deficiencies in the implementation of the File are thus not acceptable and must be addressed promptly. As manager of the CRBA, the CSSF continuously followed up with the professionals when the CRBA was set up, in particular by offering technical and legal assistance and by publishing (
  1. i)information in the form of “Questions & Answers”, (
  2. ii)communications via MFT and (iii) other specific publications whose purpose was to clarify and improve the structure of the File and its input into the CRBA. More specifically, in addition to the reminder above, the CSSF would like to draw the attention of the professionals, through this communiqué, to several examples of deficiencies identified by the CSSF and other users accessing the CRBA’s data and which will have to be taken into account by the professional when performing the review of their compliance with their obligations on this subject. Examples of deficiencies identified Among the deficiencies identified, the following examples should be mentioned: reversal of surname and name in the File fields, due to an erroneous understanding of the words “surname” and “name” in English, while Annex 2 of the Circular specifies “surname” as “nom – Familienname – last name” and “name” as “prénom – Name – first name”; erroneous understanding of the difference between legal name and name of a legal person (the Circular requests to provide the “legalName” as well as the “name”, the latter being defined as the “Usual business name”); missing mandatory information (i.e., empty fields) or input of non-relevant information in the fields “surname” or “name” (for example, use of spaces or single letters like A. instead of Alfred as first name); size of the File differing significantly from one day to the other, indicating a repeated problem of non-transmission of all daily data, unless a significant number of account closures could explain such variations; failure to comply with the correct date format (for example, month and day are reversed); where one person has several surnames/names, the professional did not correctly separate these surnames/names with a comma as set out in the Circular; errors identified in the roles of the persons indicated in the File, i.e. persons having been reported as account holders whereas they are only beneficial owners or representatives and vice versa; accounts reported as active accounts although already closed, etc. Among the main sources of errors leading to such deficiencies, the following may be mentioned: poor client data quality, i.a. incorrectly filled-in data not complying with the exact methodology set out in Annex 2 of the Circular; incomplete data due to missing information; incorrect data as not updated following a change in the data of the client, its beneficial owner and, where applicable, the representative of the account within the set deadlines; configuration not complying with the methodology set out in the Circular and its annexes; missing controls, notably by 2nd and 3rd lines of defence, of both the quality of client data and the files transmitted in relation to the CRBA. For example, missing assessment, by the internal control function, of the reconciliation between the data held by the professional and the data input into the File, or missing integration of the review of the professional’s compliance obligations resulting from the Law in the internal audit function’s work. 23 July 2020 - Updated on 23 July 2020 Circular CSSF 20/747 (version of 23.07.2020) Technical arrangements relating to the application of the Law of 25 March 2020 establishing a central electronic data retrieval system related to IBAN accounts and safe-deposit boxes held by credit institutions in Luxembourg (the “Law”) Link to the communiqué of… CSSF circular PDF (107.95Kb) PDF (108.19Kb) Main topic: Financial crime Relevant for Credit institutions E-money institutions Payment institutions Specialised PFS Circulaire CSSF 20/747 Modalités techniques relatives à l’application de la loi du 25 mars 2020 instituant un système électronique central de recherche de données concernant des comptes de paiement et des comptes bancaires identifiés par un numéro IBAN et des coffres-forts tenus par des établissements de crédit au Luxembourg (la « loi ») CIRCULAIRE CSSF 20/747 1/4 Circulaire CSSF 20/747 Concerne : Modalités techniques relatives à l’application de la loi du 25 mars 2020 instituant un système électronique central de recherche de données concernant des comptes de paiement et des comptes bancaires identifiés par un numéro IBAN et des coffresforts tenus par des établissements de crédit au Luxembourg (la « loi ») Luxembourg, le 23 juillet 2020 Mesdames, Messieurs, À tous les établissements de crédit et prestataires de de paiement au Luxembourg proposant des services La loi du 25 mars 2020 (« la loi ») institue un système électronique central de recherche de données concernant des comptes de paiement et des comptes bancaires identifiés par un numéro IBAN, ainsi que des coffres-forts tenus par des établissements de crédit au Luxembourg. services de tenue de comptes de La présente circulaire vise à apporter aux professionnels tels que définis à paiement l’article 1er point 6 de la loi, les précisions nécessaires en vue de la mise en place ou de comptes par un et l’opération dans leurs systèmes informatiques, de l’infrastructure technique sens du nécessaire afin de permettre le fonctionnement efficace, dans la relation entre règlement (UE) n° 260/2012 du la CSSF et le professionnel, du système électronique central de recherche de Parlement données mis en place et géré par la CSSF 1. bancaires numéro Conseil identifiés IBAN, au européen du 14 établissant des techniques et pour les et mars 2012 exigences commerciales virements et les euros et prélèvements en modifiant règlement le du (CE) L’objet de la présente circulaire consiste plus précisément à éclairer les professionnels en ce qui concerne les aspects techniques et informatiques du système électronique central de recherche de données afin qu’ils puissent aménager et adapter leurs systèmes en conformité avec les exigences techniques du système tel qu’il est mis en place par la CSSF. n° 924/2009, ainsi que tout Le système est basé sur la création et la mise à disposition pour la CSSF d’un établissement de crédit tenant fichier par chacun des professionnels, en ce qui concerne des comptes de des paiement 2, des comptes bancaires identifiés par un numéro IBAN et des coffres- coffres-forts au forts tenus par des établissements de crédit, excluant ainsi les comptes tenus Luxembourg pour des besoins internes ou techniques. La CSSF, en sa capacité de gestionnaire, accédera aux fichiers respectifs des professionnels par moyen d’une procédure sécurisée afin de pouvoir procéder à des recherches. Les annexes de la circulaire apportent des précisions sur la structure du fichier et le détail des données à y renseigner, la mise en place et la sauvegarde, la confidentialité et la sécurité dudit fichier. Et dont la mise en place est requise pour le 10 septembre 2020 au plus tard selon les exigences de l’article 67
(1)de la Directive (UE) 2015/849 telle que modifiée par la Directive (UE) 2018/
  1. 1 2 Voir également les Q&A de la CSSF du 3 juin 2020 portant sur la définition de comptes de paiement, sous le lien suivant : https://www.cssf.lu/wp-content/uploads/QA_payment_account_definition.pdf CIRCULAIRE CSSF 20/747 2/4 L’annexe 1 décrit les modalités techniques que les professionnels sont appelés à suivre strictement. L’annexe 2 décrit la structure du fichier de données attendu par la CSSF. La CSSF rappelle que les professionnels sont responsables de l’exactitude et du caractère complet des données qu’ils ont l’obligation de renseigner dans leurs fichiers auxquels la CSSF accède dans le cadre du système électronique central de recherche de données. Concernant les données que l’annexe 2 présente comme étant à inclure à titre « optionnel » dans le fichier mis à disposition de la CSSF, il est précisé qu’à partir du moment où les professionnels disposent de ces données dans leur système, ils ont l’obligation de les faire figurer dans les fichiers auxquels la CSSF accédera. Il convient de noter que l’obligation de mise en place du fichier de données concerne les comptes de paiement et les comptes bancaires identifiés par un numéro IBAN, au sens du règlement (UE) n° 260/2012, existants à la date d’entrée en vigueur de la loi du 25 mars 2020 et donc le 26 mars 2020, ou clôturés depuis cette date, ainsi que les comptes ouverts après cette date. Il est également à noter que ladite obligation concerne les coffres-forts en location en date du 26 mars 2020, ou clôturés depuis cette date, ainsi que les coffres-forts mis en location après cette date. Pour tout compte de paiement et compte bancaire identifié par un numéro IBAN, ainsi que tout coffre-fort clôturé après le 26 mars 2020, les durées de conservation de l’article 3, paragraphe 6, de la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme s’appliquent. Claude WAMPACH Directeur Marco ZWICK Directeur Françoise KAUTHEN Claude MARX Directeur Directeur général CIRCULAIRE CSSF 20/747 Jean-Pierre FABER Directeur 3/4 Commission de Surveillance du Secteur Financier 283, route d’Arlon L-2991 Luxembourg (+352) 26 25 1-1 direction@cssf.lu www.cssf.lu CIRCULAIRE CSSF 20/747 4/4 Circular CSSF 20/747 Technical modalities relating to the application of the Law of 25 March 2020 establishing a central electronic data retrieval system related to payment account and bank accounts identified by IBAN and safe-deposit boxes held by credit institutions in Luxembourg (the “Law”) CIRCULAR CSSF 20/747 1/4 In case of discrepancies between the French and the English text, the French text shall prevail. Circular CSSF 20/747 Re: Technical modalities relating to the application of the Law of 25 March 2020 establishing a central electronic data retrieval system related to payment account and bank accounts identified by IBAN and safe-deposit boxes held by credit institutions in Luxembourg (the “Law”) Ladies and Gentlemen, Luxembourg, 23 July 2020 The Law of 25 March 2020 (“the Law”) establishes a central electronic data To all credit institutions and retrieval system related to payment accounts and bank accounts identified by payment service providers in IBAN and safe-deposit boxes held by credit institutions in Luxembourg. Luxembourg offering payment account services or bank account services for accounts identified by IBAN, within the meaning of Regulation (EU) No 260/2012 of the European This circular aims at providing the professionals, as defined in point 6 of Article 1 of the Law, with the necessary details in view of setting up and implementing in their IT systems, the technical infrastructure required to allow the central electronic data retrieval system established and managed by the CSSF to operate efficiently between the CSSF and professionals
  2. Parliament and of the Council of The purpose of this circular is more precisely to provide the professionals with 14 March 2012 establishing an insight into the technical and IT related aspects of the central electronic data and business retrieval system in order to allow them to adapt their systems accordingly and credit assure conformity with the particular technical requirements of the system as technical requirements for transfers and direct debits in euro and amending Regulation (EC) No 924/2009, as well as to any credit institution holding safe-deposit boxes in Luxembourg established by the CSSF. The system is based on creating and making a file available to the CSSF by each of the professionals with regard to payment accounts 2, bank accounts identified by IBAN and safe-deposit boxes held by credit institutions, excluding thus accounts held for internal or technical purposes. The CSSF, in its capacity as manager of the central electronic data retrieval system, will access the respective files submitted by the professionals, by means of a secure procedure in order to be able to conduct researches. The circular’s annexes break down the structure of the file and data to be entered, and provide details on the creation, backup, confidentiality and security of said file. Annex 1 describes the technical modalities the professionals are required to strictly follow. The setup of such a system is required by 10 September 2020 at the latest in accordance with the requirements of Article 67
(1)of Directive (EU) 2015/849, as amended by Directive (EU) 2018/843. 1 2 Cf. also the CSSF Q&A of 3 June 2020 on payment account definition, under the following link: https://www.cssf.lu/wp-content/uploads/QA_payment_account_definition.pdf CIRCULAR CSSF 20/747 2/4 Annex 2 describes the structure of the data file to be submitted by the professionals to the CSSF. The CSSF reminds that professionals are responsible for the accuracy and completeness of the data they are required to enter in their files, which the CSSF accesses within the framework of the central electronic data retrieval system. As regards the data which, according to Annex 2, can be optionally registered within the file made available to the CSSF, it is noted that if professionals have these data in their system, they are required to reflect them in the files which the CSSF will access. It should be pointed out that the obligation to create a data file applies to payment accounts and bank accounts identified by IBAN, within the meaning of Regulation (EU) No 260/2012, which exist at the date of entry into force of the Law of 25 March 2020, i.e. on 26 March 2020, or which are closed since that date, as well as the accounts that were opened after that date. It should also be noted that this obligation concerns safe-deposit boxes leased on 26 March 2020, or closed since that date, as well as safe-deposit boxes leased out after that date. For all payment accounts and bank accounts identified by IBAN as well as all safe-deposit box closed after 26 March 2020, the retention periods laid down in Article 3
(6)of the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended, shall apply. Claude WAMPACH Director Marco ZWICK Director Françoise KAUTHEN Claude MARX Director Director General CIRCULAR CSSF 20/747 Jean-Pierre FABER Director 3/4 Commission de Surveillance du Secteur Financier 283, route d’Arlon L-2991 Luxembourg (+352) 26 25 1-1 direction@cssf.lu www.cssf.lu CIRCULAR CSSF 20/747 4/4

🔗 Vers la source officielle

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.