2026-06-12

Added · Updated

Guidance Note on Reconciliation of Data Protection and Anti-Money Laundering-Countering the Financing of Terrorism Obligations for NBFIs

The Non-Bank Financial Institutions Regulatory Authority (NBFIRA) issued this guidance to clarify how Non-Bank Financial Institutions (NBFIs) must reconcile their data protection obligations under the Data Protection Act (DPA) with their anti-money laundering and countering the financing of terrorism (AML/CFT) duties under the Financial Intelligence Act (FI Act). It mandates that the FI Act takes precedence in cases of conflict regarding financial crime combatting, and requires NBFIs to appoint Data Protection Officers, apply data minimization, ensure transparency, and adhere to a 20-year data retention period for AML/CFT records. NBFIs must develop comprehensive compliance programs that integrate both sets of obligations, implementing robust technical and organizational security measures while respecting data subject rights with specific exceptions for AML/CFT investigations.

Non-Bank Financial Institutions Regulatory Authority logo

Botswana

Non-Bank Financial Institutions Regulatory Authority

Click to view full text