No results found
In accordance with Act LIII of 2017 on the Prevention and Combating of Money Laundering and the Financing of Terrorism (hereinafter referred to as "Anti-Money Laundering Act"), we are obliged to have up-to-date customer due diligence related data regarding our Clients.
As required by law, Deloitte is obligated to
Deloitte performs customer due diligence procedure regarding all Clients in accordance with the applicable law but reserves the right to implement additional customer due diligence measures as set forth in its relevant internal policies.
When does customer due diligence need to be performed?
In the course of customer due diligence procedure, the provision of data is voluntary, but in the absence of the relevant data provided, Deloitte is obliged to refuse cooperation with the client based on AML rules.
Additional documents may occasionally be required—our colleagues will inform you separately if any of the following are needed.
What should I consider when submitting the Declaration?
When filling out the declaration, please pay attention to the following:
Please note that Deloitte requests documents regarding the person(s) acting on behalf of the client (the storage of document copies is carried out in accordance with legal regulations).
In the case of Hungarian citizens
In the case of foreign nationals
Please be informed that, pursuant to the Anti-Money Laundering Act, Deloitte is obliged to make photocopies of the documents presented, for identity verification purposes.
Of data requested by Deloitte companies operating in Hungary for customer due diligence and client acceptance procedures
1. Customer due diligence
Act LIII of 2017 on the Prevention and Combating of Money Laundering and the Financing of Terrorism (hereinafter referred to as "Anti-Money Laundering Act") requires entities providing particular services — including also Deloitte entities operating in Hungary, i.e. Deloitte Advisory and Management Consulting Private Limited Company, Deloitte Auditing and Consulting Ltd., Deloitte CRS Ltd., Deloitte Legal Göndöcz and Partners Law Firm (hereinafter together referred to as "Deloitte") — to perform a background check of future clients in the manner set out by the Anti-Money Laundering Act (hereinafter referred to as "customer due diligence") prior to the execution of the respective contract.
Although data supply is voluntary for such customer due diligence, Deloitte is required by the Anti-Money Laundering Act to refuse cooperation with the prospective client if such data supply fails to take place (should the customer due diligence fail). The data processing is prescribed by law (GDPR 6.§ 1. (c)).
Client data are processed by Deloitte as data controller according to the provisions of the Anti-Money Laundering Act and shall be regularly updated and retained for 8 (eight) years from the termination of the business relationship.
As part of the customer due diligence process, ownership structures are identified and documented, risk assessment activities are performed, and identification forms and supporting information are collected from clients. In carrying out these activities, data and information obtained from publicly available sources, as well as information provided by the client, are used. In the frame of the customer due diligence the client, the natural person acting on behalf or in the name of the client (proxy, person authorized to proceed or representative), the owners identified in the ownership structure and the beneficial owners of the client shall be identified. Deloitte’s identification forms used in the customer due diligence procedure are in line with the relevant legal requirements, and they only contain the obligatory data scope, thus the obtaining of those data may not be omitted, if required.
The following personal data may be collected and processed (not all categories of data are relevant or applicable to every type of data subject):
- First and last name
- Permanent residence address
- Temporary residence address (if different form the above address)
- Date and place of birth
- Mother’s maiden name
- Citizen personal identity number, ID number assigned upon birth, national register number or other similar identity number
- Nationality or citizenship
- Type of ID document (identity card or passport) and number of the document
- Document issuance and expiry dates
- Document issuing state and authority
- Nature and extent of the ownership
- Politically Exposed Person status
- Information relating to funds and assets
Please be informed that according to Section 7 (8) of the Anti-Money Laundering Act Deloitte is obliged to prepare copies of the documents presented for the purposes of identification and verification of identity (except for the back of the official address card proving personal identification).
2. Client acceptance
In addition to the customer due diligence obligation imposed in respect of certain services under the Anti-Money Laundering Act, Deloitte is required to carry out client acceptance procedure in respect of each client in accordance with Deloitte group’s internal policies . Such client acceptance procedure is designed to identify and prevent money-laundering, also to perform an internal client acceptance in the case of services outside the scope of the Anti-Money Laundering Act (hereinafter referred to as "client acceptance").
Regarding client acceptance, steps required by internal policies, such as screenings, ownership structure preparation, tasks related to risk assessment are carried out. The client acceptance is based exclusively on data and information extracted from publicly available databases. Should personal data be involved during the client acceptance (such as first and last name, nationality or citizenship, nature and extent of the ownership, other publicly available information) the legal basis of the data processing is Deloitte's legitimate interest in completing the client acceptance and be in compliance with internal policies. Data subjects may be the owners identified in the ownership structure, ultimate beneficial owners, executives and statutory representatives of the client. Otherwise, the provisions of this privacy statement shall be applicable for the processing of such personal data (data controller, retention period, data security, data subject rights).
3. Data Recipients / categories of persons or entities having access to personal data processed
4. Data handover
According to Section 22 of the Anti-Money Laundering Act the service provider obliged by such Act shall be entitled to accept the result of the client due diligence of another service provider shall the conditions determined in the Act fulfil. If – in the course of a Deloitte's customer due diligence performed pursuant to the Anti-Money Laundering Act – the client has provided consent Deloitte may provide copies of the data and documents required to perform the customer due diligence to another Deloitte company contracting with the client in the future. If such handover is carried out based on the client's consent, Deloitte receiving the copies of the data and documents, will use them solely for client due diligence purposes as described in this notice
5. Data security
Deloitte ensures data protection, i.e. protects data from unauthorised access, modification, transfer, publication, deletion or destruction, incidental destruction or damage, as well as from becoming inaccessible pursuant to the provisions of the Regulation no 2016/679 of the European Parliament and the Council on General Data Protection Regulation (hereinafter referred to as “GDPR”). Deloitte CE is a holder of ISO 27001 certification – widely recognized global information standard.
6. Data subjects’ rights
Requests related to the exercise of data subjects’ rights shall be addressed to the respective Deloitte company (registered office: 1068 Budapest, Dózsa György út 84/C).
Rights of the data subjects concerning processing:
The data controller shall inform the data subject in writing of the execution of the data subject's request within 30 (thirty) days of its receipt. Data subjects may submit their requests, statements, comments or questions related to the processing of their data by post in a letter sent to the attention of the respective Deloitte to the address 1068 Budapest, Dózsa György út 84/C or by sending an e-mail message to the dataprivacyHU@deloittece.com e-mail address.
7. Application of data privacy provisions
The provisions of the Data Privacy Act apply only to (personal) data of natural persons; and thus are not applicable for the processing of corporate information. Corporate information and documentation recorded in and deleted from the commercial register are publicly available according to Act V of 2006 on Public Company Information, Company Registration and Winding-up Proceedings.
[1] Deloitte Central Europe (“Deloitte CE”) refers to the regional organization of entities organized under the umbrella of Deloitte Central Europe Holdings Limited, the member firm of DTTL. DTTL and each of its member firms are legally separate and independent entities.
Did you find this useful?
To tell us what you think, please update your settings to accept analytics and performance cookies.