World-Check and Risk Intelligence Databases: GDPR Challenges and Recent Litigation
Risk intelligence databases have become an essential part of regulatory compliance.
Organisations rely on platforms such as LSEG World-Check, Dow Jones Risk & Compliance, LexisNexis World Compliance and Moody’s Grid Database to screen individuals and entities for anti-money laundering, sanctions and financial crime risks. Given the significant penalties for non-compliance, few organisations are willing to disregard an adverse flag, and most will not independently investigate the underlying information contained in any report.
As a result, these databases have become highly influential in determining whether an individual can participate in legal, financial and business transactions. An adverse entry can cause account refusals, enhanced due diligence, banking restrictions, de-banking and delays to financial transactions.
However, risk intelligence databases largely aggregate information from media reports, litigation records, sanctions lists and regulatory findings. Many risk intelligence database entries originate from adverse media reporting identified through screening and due diligence processes and individuals affected by inaccurate, outdated or misleading information may therefore face serious practical consequences, even where the underlying allegations are disputed or unreliable. Unsurprisingly, the inclusion of individuals on these databases is increasingly giving rise to complaints and legal challenges.
Two recent cases are particularly noteworthy.
A claim that almost broke new legal ground
World-Check, a risk intelligence database operated by Refinitiv (now part of the London Stock Exchange Group (LSEG)), was recently sued by Luka Lazarević and Petar Stojilković (children, who brought claims through their respective mothers). The claimants argued that their inclusion on the database as relatives of Politically Exposed Persons (PEPs) was unlawful under UK data protection law.
Their grandparents, Serbian politicians, were themselves listed as PEPs. PEPs are individuals with prominent public functions, such as heads of state, senior government officials and judges. Because such positions may carry an elevated risk of corruption, bribery and money laundering, organisations are generally required to apply enhanced due diligence when dealing with them.
The claimants claimed that their designation as relatives of PEPs breached Articles 5, 14, 15, 22 and 25 UK GDPR. They argued that it was unfair and disproportionate to create standalone risk profiles solely because of their grandparent’s designation as PEPs. The central issue was whether minors with no public role and no alleged involvement in political activity or financial crime should be subject to such profiling. They argued that this was contrary to the principles of fairness, accuracy and data minimisation.
The most novel aspect of the case concerned Article 22 UK General Data Protection Regulation, which restricts decisions based solely on automated processing, including profiling, where these decisions produce legal or similarly significant effects on individuals. Article 22 is designed to protect individuals from being denied banking services, subjected to enhanced due diligence, or otherwise adversely affected without genuine human review. Article 22 does not prohibit automatic profiling, but it does protect individuals from automated decision-making based on that profiling.
The proceedings settled confidentially on the eve of trial. As part of the settlement, Refinitiv agreed to delete the standalone profiles of the two claimants and two of their siblings. Although the children’s names may still be referenced within their grandparents’ profiles, they can no longer be identified or labelled their own right.
Part of a wider trend
In Ioannides v Refinitiv Limited, a separate claim also in respect of the World-Check database, the owner of an investment firm brought proceedings and alleged that inaccurate information wrongly associated her company with a sanctioned individual who was, in reality, only a minority shareholder in a parent entity. The Claimant sought erasure, rectification and damages under UK data protection law. Again, these proceedings settled confidentially before trial.
What this means for businesses and individuals
These cases highlight a growing willingness to apply privacy and data protection rights in the context of addressing compliance issues.
Given the significant impact that risk intelligence databases can have on an individual’s reputation, financial affairs and business activities, those impacted may feel they have little choice but to bring legal challenges to enforce their rights.
These cases send a positive signal that individuals subjected to inaccurate or damaging profiles within risk intelligence databases, can challenge their inclusion or categorisation together with the contents of reports.
In addition, many database entries originate from adverse media reporting. Individuals may also want to consider the ways in which media reporting has informed their profile and whether rights exist to challenge underlying publications.