15/05/2025 - Since 1 March 2025, the Data Processing by Collaborative Groups Act (WGS) has officially come into force. This law provides a legal basis for the exchange and processing of personal data within cooperative associations aimed at combating undermining crime and serious social problems. With this, the WGS finally creates a clear legal basis for the exchange of personal data between cooperative associations but also between public and private organisations.
What will change?
The WGS allows four designated cooperation organisations to exchange personal data for specified purposes. This applies to Care and Safety Houses (ZVHs), Regional Information and Expertise Centres (RIECs), the Financial Expertise Centre (FEC) and the Inbox Criminal and Unexplained Assets (iCOV). These partnerships have now been in existence for at least five years, are of a permanent nature and work together to address key societal issues. New partnerships can be added to the WGS through a so-called follow-up procedure.
The WGS provides general rules for designated partnerships. Thus the participants within a cooperative are obliged to exchange data with each other if requested and to the extent necessary for the purpose of the cooperative. Only when there are compelling reasons not to provide the data, the relevant participant can object. This may be the case, for example, when the provision of personal data frustrates a criminal investigation. In addition, the Data Processing by Collaborative Groups Decree (BGS) lays down further rules as an elaboration of the WGS. These contain specific provisions for each designated alliance that deal with the purpose of the alliance and exactly what data may be provided at what stage.
Safeguards
The processing of personal data within a partnership can have major consequences for the data subject, especially if the data subject is wrongly associated with undermining crime. However, this should be countered by strong safeguards for the protection of personal data. To a large extent, these safeguards are already embedded in existing legislation such as the General Data Protection Regulation (GDPR). These include the requirements of purpose limitation and necessity whereby data may only be processed for defined purposes and only if strictly necessary.
To complement this, the WGS and BGS also mandate a number of concrete safeguards. For example, new employees must undergo extensive screening and systems are only accessible to authorised employees. These systems must also have an adequate level of security. In addition, it is mandatory to log all processing operations so that it is clear which individuals have had access to the data, and all data must be deleted or anonymised from the partnership's systems no later than five years after the initial processing. Finally, it is mandatory for each designated partnership to establish a lawfulness advisory committee. This committee assesses the lawfulness of new processing operations and proposes changes to resolve illegalities.
Conclusion
The WGS seeks to strike a balance between effective cooperation within designated partnerships on the one hand and the protection of the rights and freedoms of data subjects on the other. Whether this goal is actually achieved will have to be demonstrated in practice in the coming period.
Want to know what the coming into force of the WGS means for your organisation? Considerati regularly provides customised training on this topic and helps organisations adapt their protocols, procedures and policies to the WGS. If you want to know more, please get in touch with us.
Would you like to learn how your organisation can meet the AI literacy requirements? Contact us for training or tailored advice.
Our services ContactRecente blogs
The right of access is one of the fundamental rights in the General Data Protection Regulation (GDPR). In this blog, we outline the main pitfalls from…