https://obsidianri.com/zh/blog/newsroom-nl-20260817-council-state-aml-implementation-bill
On August 17, 2026, the Dutch Council of State (Raad van State) published its advisory opinion on the Implementatiewet ter voorkoming van witwassen en terrorismefinanciering (Iwt), the bill that transposes the EU AML package into Dutch law by implementing Directive (EU) 2024/1640 (AMLD6) and giving effect to Regulation (EU) 2024/1624 (AMLR). Dated August 12, 2026, the advisory concludes the bill must be amended before it is filed with the Tweede Kamer, and urges the government to safeguard the risk-based approach, prevent discrimination, and close data-protection gaps as AMLA supervision and large-scale data sharing take effect.
The Iwt repeals the current Wet ter voorkoming van witwassen en het financieren van terrorisme (Wwft) and shifts the reporting threshold from "unusual" to "suspicious" transactions. With AMLR applying directly from July 10, 2027, Dutch gatekeepers, namely banks, notaries, accountants and the advocatuur, must redesign client due diligence and suspicious-activity reporting programs before that date.
What does the Council of State demand the government fix?
The Afdeling advisering flags three areas where the bill must be tightened: the risk-based approach, non-discrimination, and personal-data protection. On all three it asks the government to monitor execution and add an evaluation clause.
The Council recalls that the existing Wwft already mandates a risk-based approach that has "insufficiently got off the ground" in practice, citing a recent Algemene Rekenkamer audit. It calls new rules unlikely to fix execution on their own, and advises the government to spell out in the explanatory memorandum the preconditions needed to make risk-based supervision work, how they relate to sanctions, and to add a monitoring and evaluation provision.
On discrimination, the opinion notes citizens are sometimes refused payment accounts, excluding them from full participation in society. Although the AMLR prohibits discrimination, it is unclear who supervises compliance. The Council asks the government to clarify how supervisors, including the Autoriteit Persoonsgegevens and the College voor de Rechten van de Mens, which are not designated direct supervisors, can effectively oversee meldingsplichtige entiteiten such as banks and notarissen.
On data protection, the Council warns that large-scale sharing of personal data, including special categories, risks losing track of where confidential data sits and for what purpose it may be used. It flags two concrete defects requiring amendment: the legal regime governing FIU-Nederland's data processing is unclear, and the bill lacks an explicit legal basis for processing special-category and criminal-offence data.
Which gatekeepers and supervisors must act, and by when?
The Iwt binds private gatekeepers (meldingsplichtige entiteiten) under AMLR and public actors under AMLD6. The bill designates De Nederlandsche Bank, the Autoriteit Financiële Markten, the Dienst Financieel-Economische Integriteit, the Bureau Financieel Toezicht, the deken (bar dean) and the Kansspelautoriteit as supervisors. AMLA will directly supervise roughly 40 large financial enterprises and the national supervisors, issue binding technical standards, and impose fines and periodic penalty payments.
The hard deadline is July 10, 2027, when AMLR applies directly and the Wwft is repealed. The bill itself remains at the pre-parliamentary stage: after the Council of State advisory, the government must amend it, then file it with the Tweede Kamer for lower-chamber and Eerste Kamer passage, royal assent and Staatsblad publication, as tracked on the Wetgevingskalender WGK027204 page.
What should compliance leads do now?
The advisory is not a compliance deadline, but it signals the shape of the final statute. Compliance leads at Dutch gatekeepers should:
Map client due diligence and suspicious-activity reporting workflows to the new "suspicious" threshold, and review enhanced and simplified due-diligence risk triggers.
Audit profiling and automated decision-making for indirect discrimination, using the College voor de Rechten van de Mens assessment framework.
Verify the lawfulness of special-category and criminal-data processing against the bill's currently missing legal basis, and track the FIU-Nederland data-regime fix.
Brief the deken, NOvA/LOTA and the internal DPO on the supervisory redesign, and watch for the bill's Tweede Kamer filing.
Take advantage of this real-time watch
The Council of State has not blocked the Iwt, but it has set conditions: amend the bill on risk-based supervision, discrimination oversight and data protection before filing. Dutch gatekeepers and their supervisors now have a narrow window, closing on July 10, 2027, to redesign programs against rules still being finalised. Obsidian's per-jurisdiction monitoring surfaces each Council of State advisory, parliamentary filing and AMLA standard the moment it publishes.
Frequently asked questions
Does the Council of State advisory delay the AMLR application deadline?
No. Regulation (EU) 2024/1624 (AMLR) applies directly from July 10, 2027 regardless of the Iwt's parliamentary timetable. The advisory only requires amendments to the Dutch implementation bill before it is filed with the Tweede Kamer.
Which entities are the meldingsplichtige entiteiten covered by the Iwt?
Private gatekeepers under the AMLR, including banks, notaries, accountants and the advocatuur, plus other designated professionals. They must perform client due diligence, monitor transactions and report suspicious transactions to FIU-Nederland.
What data-protection defects must the government fix in the bill?
The Council of State identifies two: the legal regime for FIU-Nederland's data processing is unclear, and the bill lacks an explicit legal basis for processing special-category and criminal-offence data. Both require amendment before the bill is filed.
Who supervises the non-discrimination rules under the new AML regime?
This is currently unclear and is one of the points the Council of State wants clarified. The government must explain how supervisors, including the Autoriteit Persoonsgegevens and the College voor de Rechten van de Mens, can oversee compliance by banks, notarissen and other gatekeepers.