Skip to main content

Regulatory Glossary

Key terminology defined across Dutch, European, and national regulatory frameworks. Every entry cites its official source, supervisory context, and related legal framework, with links to deeper guidance.

Terms starting with A

  • Aanbeveling 2003/361/EG

    Published inCyberbeveiligingswet

    Recommendation 2003/361/EC

    Aanbeveling 2003/361/EG van de Commissie van 6 mei 2003 betreffende de definitie van kleine, middelgrote en micro-ondernemingen (PbEU 2003, L 124).

  • Aanbieder van beheerde beveiligingsdiensten

    Published inCyberbeveiligingswet

    Managed security services provider

    Een aanbieder van beheerde diensten die bijstand biedt of verleent voor activiteiten die verband houden met risicobeheer op het gebied van cyberbeveiliging.

  • Aanbieder van beheerde diensten

    Published inCyberbeveiligingswet

    Managed service provider

    Een entiteit die diensten verleent die verband houden met de installatie, het beheer, de exploitatie of het onderhoud van ICT-producten, -netwerken, -infrastructuur, -toepassingen of andere netwerk- en informatiesystemen, via bijstand of actieve administratie bij de klant ter plaatse of op afstand.

  • Crypto-asset service provider

    Natuurlijke persoon of rechtspersoon die beroeps- of bedrijfsmatig een cryptodienst als bedoeld in artikel 3, eerste lid, punt 16, van de verordening markten in cryptoactiva verleent.

  • Aanbieder van een onlinemarktplaats

    Published inCyberbeveiligingswet

    Provider of an online marketplace

    Een aanbieder van een onlinemarktplaats als bedoeld in artikel 2, onder n, van Richtlijn 2005/29/EG betreffende oneerlijke handelspraktijken.

  • Aanbieder van een onlinezoekmachine

    Published inCyberbeveiligingswet

    Provider of an online search engine

    Een aanbieder van een onlinezoekmachine als bedoeld in artikel 2, punt 5, van Verordening (EU) 2019/1150 van het Europees Parlement en de Raad van 20 juni 2019 ter bevordering van billijkheid en transparantie voor zakelijke gebruikers van online-tussenhandelsdiensten (PbEU 2019, L 186).

  • Provider of a social networking services platform

    Een platform dat eindgebruikers in staat stelt met elkaar in contact te komen, informatie te delen, informatie te ontdekken en met elkaar te communiceren via meerdere apparaten, met name via chats, posts, video’s en aanbevelingen.

  • Top-level domain name registry

    Een entiteit waaraan een specifiek topleveldomein is gedelegeerd en die verantwoordelijk is voor het beheer daarvan, waaronder de registratie van domeinnamen en de technische werking, ongeacht of die handelingen zijn uitbesteed.

  • A vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner.

  • Admission to trading

    Published inMiCA

    The admission of crypto-assets to trading on a trading platform for crypto-assets in accordance with the rules of that platform.

  • Advanced electronic seal

    Published ineIDAS2

    An electronic seal which meets the requirements set out in Article 36.

  • An electronic signature which meets the requirements set out in Article 26.

  • AI literacy

    Published inEU AI Act

    Skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause.

  • AI Office

    Published inEU AI Act

    The Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission.

  • AI regulatory sandbox

    Published inEU AI Act

    A controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision.

  • AI system

    Published inEU AI Act

    A machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.

  • An account, including a register or wallet, which is opened, held or managed by a crypto-asset service provider for an individual customer, and which does not allow the identification of the customer, or the customer’s verification in accordance with this Regulation.

  • AMLA · Anti-Money Laundering Authority

    The Authority for Anti-Money Laundering and Countering the Financing of Terrorism established by Regulation (EU) 2024/1620.

  • Asset-referenced token

    Published inMiCA

    A type of crypto-asset that is not an electronic money token and that purports to maintain a stable value by referencing another value or right or a combination thereof, including one or more official currencies.

  • Attribute

    Published ineIDAS2

    A feature, characteristic, quality or right of a natural or legal person or of an entity.

  • Auditfunctie

    Published inWwft

    Audit function

    Een onafhankelijke functie binnen een instelling die belast is met het onderzoeken en evalueren van de toereikendheid en doeltreffendheid van de beleidslijnen, procedures en maatregelen die zijn getroffen ter naleving van deze wet.

  • Authentic source

    Published ineIDAS2

    A repository or system, held under the responsibility of a public body or private entity, that contains and provides attributes about a natural or legal person and that is considered to be a primary source of that information or which is recognised as authentic in accordance with Union or national law, including administrative practice.

  • Authentication

    Published ineIDAS2

    An electronic process that enables the confirmation of the electronic identification of a natural or legal person, or the confirmation of the origin and integrity of data in electronic form.

  • A natural or legal person established within the Union who has received a written mandate from a manufacturer to act on its behalf in relation to specified tasks. The EU AI Act defines the same term differently.

  • A natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation. The Cyber Resilience Act defines the same term differently.

Terms starting with B

  • Basic information

    Published inAMLR

    Information on a legal entity referred to in Article 62(1) and on an express trust or similar legal arrangement referred to in Article 67(1).

  • Belangrijke entiteit

    Published inCyberbeveiligingswet

    Important entity

    Een belangrijke entiteit als bedoeld in artikel 3, tweede lid, van de NIS2-richtlijn en bedoeld in de artikelen 12 en 13 van deze wet.

  • Life insurance intermediary

    Bemiddelaar als bedoeld in artikel 1:1 van de Wet op het financieel toezicht die bemiddelt in levensverzekeringen als bedoeld in artikel 1:1 van die wet.

  • Beneficial owner

    Published inAMLR

    Any natural person who ultimately owns or controls a legal entity or an express trust or similar legal arrangement, or on whose behalf a transaction or activity is being conducted, as determined in accordance with Section 1 of Chapter IV.

  • Beveiliging van netwerk- en informatiesystemen

    Published inCyberbeveiligingswet

    Security of network and information systems

    Het vermogen van netwerk- en informatiesystemen om, op een bepaald betrouwbaarheidsniveau, weerstand te bieden aan gebeurtenissen die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die via deze netwerk- en informatiesystemen worden aangeboden of toegankelijk zijn, kunnen aantasten.

  • Beveiligingsscan

    Published inCyberbeveiligingswet

    Security scan

    Technisch onderzoek van netwerk- en informatiesystemen om inzicht te krijgen in kwetsbaarheden en risico's van deze systemen.

  • Bevoegde autoriteit

    Published inCyberbeveiligingswet

    Competent authority

    De bevoegde autoriteit, bedoeld in artikel 8, eerste lid, van de NIS2-richtlijn en bedoeld in artikel 15 van deze wet.

  • Competent authority of another Member State of the European Union

    Een bevoegde autoriteit van een andere lidstaat van de Europese Unie als bedoeld in artikel 8, eerste lid, van de NIS2-richtlijn en die als zodanig is aangewezen in het nationale recht van die andere lidstaat.

  • Bijna-incident

    Published inCyberbeveiligingswet

    Near miss

    Een gebeurtenis die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die via netwerk- en informatiesystemen worden aangeboden of toegankelijk zijn, had kunnen aantasten, maar waarvan de verwezenlijking met succes is voorkomen of die zich niet heeft verwezenlijkt.

  • Biometric categorisation system

    Published inEU AI Act

    An AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons.

  • Biometric data

    Published inEU AI Act

    Personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data.

  • Biometric identification

    Published inEU AI Act

    The automated recognition of physical, physiological and behavioural human features for the purpose of establishing the identity of a natural person by comparing biometric data of that person to biometric data of individuals stored in a database.

  • Biometric verification

    Published inEU AI Act

    The automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data.

  • Body governed by public law

    Published ineIDAS2

    A body defined in point (4) of Article 2(1) of Directive 2014/24/EU.

  • Foreign financial undertaking

    Financiële onderneming als bedoeld in onderdeel a van de definitie van financiële onderneming met een zetel in een andere lidstaat of een derde land.

  • Foreign trust service provider

    Natuurlijke persoon, rechtspersoon of vennootschap die zijn woonplaats, zetel of hoofdkantoor heeft in een andere lidstaat of een derde-land en die beroeps- of bedrijfsmatig diensten verleent als bedoeld in artikel 1, onderdeel a, onderdelen 1° tot en met 5°, van de Wet toezicht trustkantoren 2018.

  • Bureau

    Published inWwft

    Financial Supervision Office

    Bureau financieel toezicht, bedoeld in artikel 110 van de Wet op het notarisambt.

  • Business relationship

    Published inAMLR

    A business, professional or commercial relationship between an obliged entity and a customer, connected with the obliged entity's professional activities, that is expected at the time contact is established to have an element of duration.

Terms starting with C

  • CE marking (CRA)

    Published inCRA

    A marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing. The EU AI Act defines the same term differently.

  • CE marking (EU AI Act)

    Published inEU AI Act

    A marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing. The Cyber Resilience Act defines the same term differently.

  • Centraal contactpunt

    Published inCyberbeveiligingswet

    Central point of contact

    Het centrale contactpunt, bedoeld in artikel 8, derde lid, van de NIS2-richtlijn en bedoeld in artikel 14 van deze wet.

  • Central point of contact of another Member State of the European Union

    Een centraal contactpunt van een andere lidstaat van de Europese Unie als bedoeld in artikel 8, derde lid, van de NIS2-richtlijn en dat als zodanig is aangewezen in het nationale recht van die andere lidstaat.

  • An electronic attestation which links electronic seal validation data to a legal person and confirms the name of that person.

  • An electronic attestation which links electronic signature validation data to a natural person and confirms at least the name or the pseudonym of that person.

  • An attestation through which it is possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued.

  • Cliënt

    Published inWwft

    Client

    Natuurlijke persoon of rechtspersoon met wie een zakelijke relatie wordt aangegaan of die een transactie laat uitvoeren.

  • Cloudcomputingdienst

    Published inCyberbeveiligingswet

    Cloud computing service

    Een digitale dienst die administratie op aanvraag en brede toegang op afstand tot een schaalbare en elastische pool van deelbare computerbronnen mogelijk maakt, ook wanneer die bronnen over verschillende locaties verspreid zijn.

  • Common specification

    Published inEU AI Act

    A set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012 providing solutions for complying with certain requirements established under this Regulation.

  • The national or European regulatory body designated under sectoral legislation or DORA to supervise compliance by financial entities. MiCA defines the same term differently.

  • One or more competent authorities designated by a Member State in accordance with Article 93 of Regulation (EU) 2023/1114; the European Central Bank (ECB) when acting in accordance with Council Regulation (EU) No 1024/2013; or the national competent authority appointed under sectoral legislation where applicable. DORA defines the same term differently.

  • Component

    Published inCRA

    Software or hardware intended for integration into an electronic information system.

  • Concentration risk

    Published inDORA

    Operational and systemic exposure arising from dependence on a single ICT third-party service provider or a small group of non-substitutable providers.

  • The process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled. The EU AI Act defines the same term differently.

  • The process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled. The Cyber Resilience Act defines the same term differently.

  • Conformity assessment body

    Published ineIDAS2

    A conformity assessment body as defined in Article 2, point 13, of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust service provider and the qualified trust services it provides, or as competent to carry out certification of European Digital Identity Wallets or electronic identification means.

  • A conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008. The EU AI Act defines the same term differently.

  • A body that performs third-party conformity assessment activities, including testing, certification and inspection. The Cyber Resilience Act defines the same term differently.

  • Consensus mechanism

    Published inMiCA

    The rules and procedures by which an agreement is reached, among DLT network nodes, that a transaction is validated.

  • Consumer

    Published inCRA

    A natural person who acts for purposes which are outside that person's trade, business, craft or profession.

  • Coordinator for the purposes of coordinated vulnerability disclosure

    De coördinator met het oog op een gecoördineerde bekendmaking van kwetsbaarheden, bedoeld in artikel 12, eerste lid, van de NIS2-richtlijn en bedoeld in artikel 17 van deze wet.

  • The provision of banking services by one credit institution as correspondent to another as respondent, and comparable service relationships between credit institutions, financial institutions or crypto-asset service providers. The AMLR sets this out in two limbs, reproduced below.

  • Correspondentrelatie

    Published inWwft

    Correspondent relationship

    Het verlenen van bankdiensten door een bank aan een andere bank, de respondent, en vergelijkbare dienstverlening tussen kredietinstellingen en financiële instellingen onderling. De Wwft omschrijft dit in twee onderdelen, hieronder integraal weergegeven.

  • Creator of a seal

    Published ineIDAS2

    A legal person that creates an electronic seal.

  • A credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013. MiCA defines the same term differently.

  • A credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 and authorised under Directive 2013/36/EU. The AMLR defines the same term differently.

  • Criminal property

    Published inAMLR

    Assets as defined in Article 2, point (2), of Directive (EU) 2018/1673.

  • An ICT third-party provider designated as systemically critical by European Supervisory Authorities (ESAs) based on cross-border reliance, substitutability, and systemic relevance.

  • Critical infrastructure

    Published inEU AI Act

    Critical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557.

  • Critical · important function

    An operational function whose disruption would materially impair a financial entity's financial performance, operational continuity, regulatory compliance, or core business operations.

  • An undertaking other than a crowdfunding service provider whose business consists of matching or facilitating the matching, through an online platform, of business project owners seeking funding with investors or lenders who provide funding, or of connecting consumers seeking credit with lenders.

  • A crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503.

  • Crypto-asset

    Published inMiCAAMLR

    A digital representation of a value or of a right that is able to be transferred and stored electronically, using distributed ledger technology or similar technology. The AMLR defines the same term differently.

  • Crypto-asset service

    Published inMiCA

    Any of the services and activities relating to any crypto-asset listed in points (16) to (25) of Article 3(1) of Regulation (EU) 2023/1114.

  • A crypto-asset service provider as defined in Article 3(1), point (15), of Regulation (EU) 2023/1114, where performing one or more crypto-asset services as defined in Article 3(1), point (16), of that Regulation, with the exception of the provision of advice on crypto-assets as referred to in Article 3(1), point (16)(h), of that Regulation. MiCA defines the same term differently.

  • A legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis, and that is allowed to provide crypto-asset services in accordance with Article 59 of Regulation (EU) 2023/1114. The AMLR defines the same term differently.

  • Crypto-asset white paper

    Published inMiCA

    A document that contains mandatory information disclosures relating to the offer to the public of crypto-assets or to the admission of crypto-assets to trading.

  • CSIRT

    Published inCyberbeveiligingswet

    Een Computer security incident response team, bedoeld in artikel 10 van de NIS2-richtlijn en bedoeld in artikel 16 van deze wet.

  • A CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555.

  • CSIRT of another Member State of the European Union

    Een CSIRT van een andere lidstaat van de Europese Unie als bedoeld in artikel 10 van de NIS2-richtlijn en dat als zodanig is aangewezen in het nationale recht van die andere lidstaat.

  • CSIRT-netwerk

    Published inCyberbeveiligingswet

    CSIRT network

    Het netwerk van CSIRT’s, genoemd in artikel 15 van de NIS2-richtlijn.

  • Cultural goods

    Published inAMLR

    Cultural goods as defined in Article 2, point (1), of Regulation (EU) 2019/880 of the European Parliament and of the Council.

  • Cyber threat (CRA)

    Published inCRA

    A cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881. DORA defines the same term differently.

  • Cyber threat (DORA)

    Published inDORA

    A potential circumstance, event, or action capable of damaging, disrupting, or otherwise adversely affecting network and information systems, users, or other individuals. The Cyber Resilience Act defines the same term differently.

  • Cyberbeveiliging

    Published inCyberbeveiligingswet

    Cybersecurity

    De activiteiten die nodig zijn om netwerk- en informatiesystemen, de gebruikers van dergelijke systemen, en andere personen die getroffen worden door cyberdreigingen, te beschermen.

  • Cybercrisisbeheerautoriteit

    Published inCyberbeveiligingswet

    Cyber crisis management authority

    De autoriteit voor cybercrisisbeheer, bedoeld in artikel 9, eerste lid, van de NIS2-richtlijn en bedoeld in artikel 18 van deze wet.

  • Cyberdreiging

    Published inCyberbeveiligingswet

    Cyber threat

    Elke potentiële omstandigheid, gebeurtenis of actie die netwerk- en informatiesystemen, de gebruikers van dergelijke systemen en andere personen kan schaden, verstoren of op andere wijze negatief kan beïnvloeden.

  • Cybersecurity

    Published inCRA

    Cybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881.

  • Cybersecurity risk

    Published inCRA

    The potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident.

Terms starting with D

  • Data record

    Published ineIDAS2

    Electronic data recorded with related meta-data supporting the processing of the data.

  • Datacentrumdienst

    Published inCyberbeveiligingswet

    Data centre service

    Een dienst die structuren of groepen van structuren omvat die bestemd zijn voor de gecentraliseerde accommodatie, de interconnectie en de exploitatie van IT en netwerkapparatuur die diensten op het gebied van gegevensopslag, -verwerking en -transport aanbiedt, samen met alle faciliteiten en infrastructuren voor energiedistributie en omgevingscontrole.

  • Deep fake

    Published inEU AI Act

    AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

  • Deployer

    Published inEU AI Act

    A natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.

  • Services for exchanging between virtual currencies and fiat currencies

    Het beroeps- of bedrijfsmatig aanbieden van diensten voor het omwisselen van virtuele valuta tegen fiduciaire valuta of omgekeerd met gebruikmaking van eigen vermogen.

  • The ability of a financial entity to build, assure, and review its operational integrity and reliability by ensuring, either directly or indirectly via third-party ICT services, the full range of ICT-related capabilities needed to safeguard the security of network and information systems.

  • Digitale dienst

    Published inCyberbeveiligingswet

    Digital service

    Elke dienst van de informatiemaatschappij, dat wil zeggen elke dienst die gewoonlijk tegen vergoeding, langs elektronische weg, op afstand en op individueel verzoek van een afnemer van diensten wordt verricht zoals bedoeld in artikel 1, eerste lid, onderdeel b, van Richtlijn (EU) 2015/1535.

  • Distributed ledger

    Published inMiCA

    An information repository that keeps records of transactions and that is shared across, and synchronised between, a set of DLT network nodes using a consensus mechanism.

  • DLT · Distributed ledger technology

    A technology that enables the operation and use of distributed ledgers.

  • Distributor (CRA)

    Published inCRA

    A natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties. The EU AI Act defines the same term differently.

  • Distributor (EU AI Act)

    Published inEU AI Act

    A natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market without affecting its properties. The Cyber Resilience Act defines the same term differently.

  • DNS-dienstverlener

    Published inCyberbeveiligingswet

    DNS service provider

    Een entiteit die voorziet in: a. publiek beschikbare recursieve domeinnaamresolutiediensten voor interneteindgebruikers; of b. gezaghebbende domeinnaamresolutiediensten voor gebruik door derden, met uitzondering van root-naamservers.

  • Domeinnaamsysteem (DNS)

    Published inCyberbeveiligingswet

    Domain Name System (DNS)

    Een hiërarchisch gedistribueerd naamgevingssysteem dat het mogelijk maakt internetdiensten en -bronnen te identificeren, waardoor eindgebruikersapparaten in staat worden gesteld routing- en connectiviteitsdiensten op het internet te gebruiken om die diensten en bronnen te bereiken.

  • Downstream provider

    Published inEU AI Act

    A provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.

Terms starting with E

  • Economic operator

    Published inCRA

    The manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation.

  • Electronic archiving

    Published ineIDAS2

    A service ensuring the receipt, storage, retrieval and deletion of electronic documents in order to guarantee their durability and legibility as well as to preserve their integrity, confidentiality and proof of origin throughout the preservation period.

  • An attestation in electronic form that allows the authentication of attributes.

  • Electronic attestation of attributes issued by · on behalf of a public body responsible for an authentic source

    An electronic attestation of attributes issued by a public body that is responsible for an authentic source or by a public body designated by the Member State to issue such attestations of attributes on behalf of the public bodies responsible for authentic sources in accordance with Article 45f and Annex VII.

  • Electronic document

    Published ineIDAS2

    Any content stored in electronic form, in particular text or sound, visual or audiovisual recording.

  • Electronic identification

    Published ineIDAS2

    The process of using person identification data in electronic form representing either a natural or legal person, or a natural person representing a legal person.

  • A material and/or immaterial unit, including European Digital Identity Wallets, containing person identification data and which is used to authenticate for an online or offline service.

  • A system for electronic identification under which electronic identification means are issued to natural or legal persons or to natural persons representing natural or legal persons.

  • A system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data.

  • Electronic ledger

    Published ineIDAS2

    A sequence of electronic data records, which ensures the integrity of those records and the accuracy of the chronological ordering of those records.

  • e-money token · Electronic money token

    A type of crypto-asset that purports to maintain a stable value by referencing the value of one official currency.

  • A service that makes it possible to transmit data between third parties by electronic means and provides evidence of the handling of the transmitted data, including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, damage or any unauthorised alterations.

  • Electronic seal

    Published ineIDAS2

    Data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the origin and integrity of that data.

  • Unique data which is used by the creator of the electronic seal to create an electronic seal.

  • Configured software or hardware used to create an electronic seal.

  • Electronic signature

    Published ineIDAS2

    Data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.

  • Unique data which is used by the signatory to create an electronic signature.

  • Configured software or hardware used to create an electronic signature.

  • Electronic time stamp

    Published ineIDAS2

    Data in electronic form which binds other data in electronic form to a particular time establishing evidence that the latter data existed at that time.

  • Elektronisch communicatienetwerk

    Published inCyberbeveiligingswet

    Electronic communications network

    Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.

  • Elektronische communicatiedienst

    Published inCyberbeveiligingswet

    Electronic communications service

    Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.

  • Emotion recognition system

    Published inEU AI Act

    An AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data.

  • End-point

    Published inCRA

    Any device that is connected to a network and serves as an entry point to that network.

  • Enisa

    Published inCyberbeveiligingswet

    Het Agentschap van de Europese Unie voor cyberbeveiliging, opgericht bij Verordening (EU) 2019/881.

  • Entiteit

    Published inCyberbeveiligingswet

    Entity

    Een natuurlijke persoon of rechtspersoon die is opgericht en erkend krachtens het nationale recht van de plaats van vestiging, die onder eigen naam rechten kan uitoefenen en aan verplichtingen kan worden onderworpen.

  • Entity providing domain name registration services

    Een registrar of een agent die namens registrars optreedt, zoals een verlener van privacy- of proxyregistratiediensten of een wederverkoper.

  • Essentiële entiteit

    Published inCyberbeveiligingswet

    Essential entity

    Een essentiële entiteit als bedoeld in artikel 3, eerste lid, van de NIS2-richtlijn en bedoeld in de artikelen 8 tot en met 11 van deze wet.

  • An electronic identification means which allows the user to securely store, manage and validate person identification data and electronic attestations of attributes, in order to provide them to relying parties and other users of European Digital Identity Wallets, and to sign by means of qualified electronic signatures or to seal by means of qualified electronic seals.

  • A verifiable, simple and recognisable indication that a European Digital Identity Wallet has been issued in accordance with this Regulation.

  • European standard

    Published inCRA

    A European standard as defined in Article 2, point (1)(b), of Regulation (EU) No 1025/2012.

  • The conclusion of purchase or sale contracts concerning crypto-assets with clients for funds by using proprietary capital.

  • The conclusion of purchase or sale contracts concerning crypto-assets with clients for other crypto-assets by using proprietary capital.

  • The conclusion of agreements to buy or to sell one or more crypto-assets or to subscribe for one or more crypto-assets on behalf of clients and includes the conclusion of contracts to sell crypto-assets at the moment of their offer to the public or admission to trading.

  • A vulnerability that has the potential to be effectively used by an adversary under practical operational conditions.

Terms starting with F

  • Family members

    Published inAMLR

    In relation to a politically exposed person: the spouse or equivalent registered partner, children and their spouses or equivalent partners, and the parents.

  • Financial entity

    Published inDORA

    Regulated financial institutions covered under DORA's scope, including credit institutions, payment institutions, investment firms, crypto-asset service providers, central securities depositories, insurance and reinsurance undertakings, and trade repositories.

  • Financial institution

    Published inAMLR

    An undertaking other than a credit institution or investment firm that carries out listed banking activities, including bureaux de change, together with insurance undertakings in respect of life and investment-related business and the further categories the AMLR lists. The full definition is reproduced below.

  • Financial instrument

    Published inMiCA

    Financial instruments as defined in Article 4(1), point (15), of Directive 2014/65/EU.

  • FIU · Financial Intelligence Unit

    The central national unit established in each Member State for the purpose of receiving and analysing reports on suspicious transactions and other information relevant to money laundering, predicate offences or terrorist financing, and for disseminating the results of that analysis.

  • Financiële onderneming

    Published inWwft

    Financial undertaking

    Een reeks in de Wet op het financieel toezicht omschreven ondernemingen, waaronder banken, beleggingsondernemingen, betaaldienstverleners, elektronischgeldinstellingen, levensverzekeraars en aanbieders van een cryptodienst, plus Nederlandse bijkantoren daarvan. De volledige opsomming staat hieronder.

  • Terrorist financing

    Het plegen van een misdrijf als bedoeld in artikel 421 van het Wetboek van Strafrecht, of van een misdrijf als bedoeld in de artikelen 83 of 140a van dat wetboek voor zover begaan met een terroristisch oogmerk.

  • Floating-point operation (FLOP)

    Published inEU AI Act

    FLOP · Floating-point operation

    Any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base.

  • Football agent

    Published inAMLR

    A natural person who provides intermediation services for football players or clubs in relation to employment contracts or the transfer of players between football clubs.

  • Software the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable.

  • Funds

    Published inMiCAAMLR

    Funds as defined in Article 4, point (25), of Directive (EU) 2015/2366. MiCA and the AMLR use identical wording.

Terms starting with G

  • Gambling services

    Published inAMLR

    A service which involves wagering a stake with monetary value in games of chance, including those with an element of skill such as lotteries, casino games, poker games and betting transactions that are provided at a physical location, or by any means at a distance, across electronic media or any other technology for facilitating communication, and at the individual request of a recipient of services.

  • Gekwalificeerde verlener van vertrouwensdiensten

    Published inCyberbeveiligingswet

    Qualified trust service provider

    Een verlener van vertrouwensdiensten die een of meer gekwalificeerde vertrouwensdiensten verleent en aan wie door het toezichthoudend orgaan de gekwalificeerde status is toegekend zoals vastgelegd in Verordening (EU) nr. 910/2014.

  • Gekwalificeerde vertrouwensdienst

    Published inCyberbeveiligingswet

    Qualified trust service

    Een vertrouwensdienst die voldoet aan de toepasselijke eisen zoals vastgelegd in Verordening (EU) nr. 910/2014.

  • Geldovermaking

    Published inWwft

    Money remittance

    Transactie die door of via een betaaldienstverlener voor rekening van een betaler wordt verricht met het oogmerk middelen ter beschikking te stellen aan een begunstigde, ongeacht of de betaler en de begunstigde dezelfde persoon zijn.

  • General-purpose AI model

    Published inEU AI Act

    An AI model that, in the Act's own words, “displays significant generality” and can competently perform many distinct tasks, and that can be integrated into a variety of downstream systems or applications. Models used only for research, development or prototyping before being placed on the market are excluded.

  • General-purpose AI system

    Published inEU AI Act

    An AI system which is based on a general-purpose AI model, that has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems.

  • Groep

    Published inWwft

    Group

    Een groep als bedoeld in artikel 2:24b van het Burgerlijk Wetboek.

  • Grootschalig cyberbeveiligingsincident

    Published inCyberbeveiligingswet

    Large-scale cybersecurity incident

    Een incident dat een dermate grote verstoring veroorzaakt dat het de capaciteit van een lidstaat om erop te reageren te boven gaat, of dat aanzienlijke gevolgen heeft voor ten minste twee lidstaten.

Terms starting with H

  • Hardware

    Published inCRA

    A physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data.

  • Harmonised standard

    Published inEU AI ActCRA

    A harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012. The EU AI Act and the Cyber Resilience Act word it differently, and every definition is given below.

  • High-impact capabilities

    Published inEU AI Act

    Capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models.

  • A natural person whose total net assets amount to at least EUR 50 000 000, excluding that individual’s primary residence.

  • High-value goods

    Published inAMLR

    The goods listed in Annex IV.

  • Home Member State

    Published inMiCA

    The Member State whose authority is the primary one for an offeror, a person seeking admission to trading, an issuer or a crypto-asset service provider. MiCA sets it out in six limbs, one per situation, reproduced below.

  • Hoofdvestiging

    Published inCyberbeveiligingswet

    Main establishment

    De plaats waar de beslissingen in verband met de maatregelen voor het beheer van cyberbeveiligingsrisico’s hoofdzakelijk worden genomen binnen de Europese Unie.

  • Host Member State

    Published inMiCA

    The Member State where an offeror or person seeking admission to trading has made an offer to the public of crypto-assets or is seeking admission to trading on a trading platform for crypto-assets, or where a crypto-asset service provider provides crypto-asset services, when different from the home Member State.

Terms starting with I

  • ICT assets

    Published inDORA

    Software, hardware, digital infrastructure, or data components within an entity’s digital architecture that hold operational value.

  • An entity within a financial group that provides ICT services primarily or exclusively to financial entities in the same group.

  • ICT risk

    Published inDORA

    Any reasonably identifiable operational circumstance related to the use of network and information systems that can compromise system security, cause hardware or software failures, lead to data loss or corruption, or impair the performance of financial services.

  • ICT services

    Published inDORA

    Digital and data services provided via ICT systems to one or more internal or external users on an ongoing basis (including hardware-as-a-service, cloud computing, and data storage).

  • An undertaking that provides digital and data services on an ongoing basis to financial entities through contractual arrangements (e.g., cloud platforms, data analytics, software development, data center operations).

  • ICT-dienst

    Published inCyberbeveiligingswet

    ICT service

    Een dienst die volledig of hoofdzakelijk bestaat in de verzending, opslag, opvraging of verwerking van gegevens door middel van netwerk- en informatiesystemen.

  • ICT-proces

    Published inCyberbeveiligingswet

    ICT process

    Een reeks activiteiten die worden uitgevoerd om een ICT-product of -dienst te ontwerpen, te ontwikkelen, te leveren of te onderhouden.

  • ICT-product

    Published inCyberbeveiligingswet

    ICT product

    Een element of groep elementen van een netwerk- of informatiesysteem.

  • Identificeren

    Published inWwft

    Identify

    Opgave van de identiteit laten doen.

  • Importer (CRA)

    Published inCRA

    A natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union. The EU AI Act defines the same term differently.

  • Importer (EU AI Act)

    Published inEU AI Act

    A natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country. The Cyber Resilience Act defines the same term differently.

  • Incident (CRA)

    Published inCRA

    An incident as defined in Article 6, point (6), of Directive (EU) 2022/2555. The Cyberbeveiligingswet defines the same term differently.

  • Incident (Cyberbeveiligingswet)

    Published inCyberbeveiligingswet

    Een gebeurtenis die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die via netwerk- en informatiesystemen worden aangeboden of toegankelijk zijn, aantast. De Cyber Resilience Act hanteert een andere definitie.

  • An incident that negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functions.

  • Incidentafhandeling

    Published inCyberbeveiligingswet

    Incident handling

    Alle handelingen en procedures die gericht zijn op het voorkomen, opsporen, analyseren en indammen van of het reageren op en herstellen van een incident.

  • Indirect connection

    Published inCRA

    A connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network.

  • Information system

    Published inDORA

    A system consisting of network and information infrastructure, software, computer hardware, and related data processing/storage devices.

  • A voluntary agreement between financial entities and trusted partners to exchange cyber threat intelligence, indicators of compromise (IoCs), and defense techniques.

  • Input data

    Published inEU AI Act

    Data provided to or directly acquired by an AI system on the basis of which the system produces an output.

  • A credit transfer which is executed immediately, 24 hours a day and on any calendar day.

  • Instelling

    Published inWwft

    Institution

    Een instelling als bedoeld in artikel 1a.

  • Institution

    Published inIPR

    For the purposes of the Instant Payments Regulation, an institution under Directive 98/26/EC as amended: credit institutions, investment firms, public authorities and publicly guaranteed undertakings, and the further categories listed in the definition reproduced below.

  • Instructions for use

    Published inEU AI Act

    The information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use.

  • Intended purpose (CRA)

    Published inCRA

    The use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation. The EU AI Act defines the same term differently.

  • Intended purpose (EU AI Act)

    Published inEU AI Act

    The use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation. The Cyber Resilience Act defines the same term differently.

  • International standard

    Published inCRA

    An international standard as defined in Article 2, point (1)(a), of Regulation (EU) No 1025/2012.

  • Internetknooppunt

    Published inCyberbeveiligingswet

    Internet exchange point

    Een netwerkfaciliteit die de interconnectie van meer dan twee onafhankelijke netwerken mogelijk maakt, hoofdzakelijk om de uitwisseling van internetverkeer te vergemakkelijken, zonder dat verkeer via een derde autonoom systeem hoeft te passeren.

  • Investment firm

    Published inMiCA

    An investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU.

Terms starting with J

  • Joint Examination Team

    Published inDORA

    A multidisciplinary team of examiners established by the Lead Overseer to coordinate and execute oversight activities and on-site inspections for critical ICT third-party providers.

Terms starting with K

  • Kredietinstelling

    Published inWwft

    Credit institution

    Een kredietinstelling als bedoeld in artikel 1:1 van de Wet op het financieel toezicht.

  • Kritieke entiteit

    Published inCyberbeveiligingswet

    Critical entity

    Een entiteit die als zodanig is aangewezen op grond van de Wet weerbaarheid kritieke entiteiten.

  • Kwetsbaarheid

    Published inCyberbeveiligingswet

    Vulnerability

    Een zwakheid, vatbaarheid of tekortkoming van ICT-producten of ICT-diensten die door een cyberdreiging kan worden uitgebuit.

Terms starting with L

  • Law enforcement

    Published inEU AI Act

    Activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.

  • Law enforcement authority

    Published inEU AI Act

    A public authority competent for preventing, investigating, detecting or prosecuting criminal offences or executing criminal penalties, including safeguarding against threats to public security. It also covers any other body entrusted by Member State law with those public powers.

  • Lead Overseer

    Published inDORA

    The European Supervisory Authority (EBA, ESMA, or EIOPA) designated to conduct direct regulatory oversight of a designated critical ICT third-party service provider.

  • Lidstaat

    Published inWwft

    Member State

    Een lidstaat van de Europese Unie alsmede een staat, niet zijnde een lidstaat van de Europese Unie, die partij is bij de Overeenkomst betreffende de Europese Economische Ruimte.

  • Linked transactions

    Published inAMLR

    Two or more transactions with either a single or multiple sources and destinations, which are carried out within a given period, where there are reasonable grounds to believe that they are conducted as part of a single transaction or are connected, or where they involve the same parties.

  • Logical connection

    Published inCRA

    A virtual representation of a data connection implemented through a software interface.

Terms starting with M

  • The supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. The EU AI Act defines the same term differently.

  • The supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. The Cyber Resilience Act defines the same term differently.

  • Management body (AMLR)

    Published inAMLR

    A body of an obliged entity, appointed in accordance with national law, which is empowered to set the entity’s strategy, objectives and overall direction, and which oversees and monitors management decision-making, and includes the persons who effectively direct the business of the entity. MiCA defines the same term differently.

  • Management body (MiCA)

    Published inMiCA

    The body or bodies of an issuer, of an offeror or person seeking admission to trading, or of a crypto-asset service provider, which are appointed in accordance with national law, which are empowered to set the entity’s strategy, objectives and overall direction, and which oversee and monitor management decision-making, and include the persons who effectively direct the business of the entity. The AMLR defines the same term differently.

  • The management body acting in its role of overseeing and monitoring management decision-making.

  • Manufacturer

    Published inCRA

    A natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge.

  • A market surveillance authority as defined in Article 3, point (4), of Regulation (EU) 2019/1020. The EU AI Act defines the same term differently.

  • The national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020. The Cyber Resilience Act defines the same term differently.

  • Matching

    Published ineIDAS2

    The process of establishing a link between the person identification data or person identification means of a user and an existing account belonging to the same user.

  • Meldpunt

    Published inWwft

    Financial Intelligence Unit (FIU)

    De Financiële inlichtingen-eenheid, bedoeld in artikel 12, eerste lid.

  • Respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC.

  • Money laundering

    Published inAMLR

    The conduct as referred to in Article 3, paragraphs 1 and 5, of Directive (EU) 2018/1673.

Terms starting with N

  • Name of the payee

    Published inIPR

    In respect of a natural person, the name and surname and, in respect of a legal person, the commercial or legal name.

  • National competent authority

    Published inEU AI Act

    A notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor.

  • Nationale cyberbeveiligingsstrategie

    Published inCyberbeveiligingswet

    National cybersecurity strategy

    Een samenhangend kader van een lidstaat dat strategische doelstellingen en prioriteiten op het gebied van cyberbeveiliging en het bestuur om die te bereiken in die lidstaat biedt.

  • Near miss

    Published inCRA

    A near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555.

  • Netwerk voor de levering van inhoud

    Published inCyberbeveiligingswet

    Content delivery network

    Een netwerk van geografisch verspreide servers met het oog op een hoge beschikbaarheid, toegankelijkheid of snelle levering van digitale inhoud en diensten aan internetgebruikers ten behoeve van aanbieders van inhoud en diensten.

  • Netwerk- en informatiesysteem

    Published inCyberbeveiligingswet

    Network and information system

    Een elektronisch communicatienetwerk, een apparaat of groep verbonden apparaten die digitale gegevens automatisch verwerken, of de digitale gegevens die daarmee worden opgeslagen, verwerkt, opgehaald of verzonden. De drie onderdelen staan hieronder.

  • Non-governmental organisation

    Een rechtspersoon of maatschap zonder winstoogmerk die zich richt op het algemeen maatschappelijk belang of ideële doeleinden.

  • NIS2-richtlijn

    Published inCyberbeveiligingswet

    NIS2 Directive

    Richtlijn (EU) 2022/2555 van het Europees Parlement en de Raad van 14 december 2022 betreffende maatregelen voor een hoog gezamenlijk niveau van cyberbeveiliging in de Unie, tot wijziging van Verordening (EU) nr. 910/2014 en Richtlijn (EU) 2018/1972 en tot intrekking van Richtlijn (EU) 2016/1148 (PbEU 2022, L 333).

  • Nominee director

    Published inAMLR

    A natural person who acts as a director of a legal entity and complies with instructions given by another person, or is acting on behalf of another person, where that fact is not disclosed in the national company register.

  • Nominee shareholder

    Published inAMLR

    A natural person or legal entity that holds shares in a legal entity on behalf of another person, where that fact is not disclosed in the national company register.

  • Non-fungible token

    Published inAMLR

    A crypto-asset that is unique and not fungible with other crypto-assets, including digital art and collectibles.

  • Non-personal data

    Published inEU AI Act

    Data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679.

  • Norm

    Published inCyberbeveiligingswet

    Standard

    Een door een erkende normalisatie-instelling vastgestelde technische specificatie waarvan de naleving niet verplicht is, onderverdeeld in internationale, Europese, geharmoniseerde en nationale normen. De volledige omschrijving staat hieronder.

  • Notified body (CRA)

    Published inCRA

    A conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation. The EU AI Act defines the same term differently.

  • Notified body (EU AI Act)

    Published inEU AI Act

    A conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation. The Cyber Resilience Act defines the same term differently.

  • Notifying authority

    Published inEU AI ActCRA

    The national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. The EU AI Act and the Cyber Resilience Act use identical wording.

Terms starting with O

  • Obliged entity

    Published inAMLR

    A natural or legal person listed in Article 3(1) that is not exempted in accordance with Article 4, 5, 6 or 7.

  • Offer to the public

    Published inMiCA

    A communication to persons in any form, and by any means, presenting sufficient information on the terms of the offer and the crypto-assets to be offered so as to enable an investor to decide whether to purchase those crypto-assets.

  • Offeror

    Published inMiCA

    A natural or legal person, or other undertaking, or the issuer, who offers crypto-assets to the public.

  • Offline

    Published ineIDAS2

    In relation to the use of European Digital Identity Wallets, an interaction between a user and a third party at a physical location using close proximity technologies, whereby the wallet is not required to access remote systems via electronic communications networks for the purpose of the interaction.

  • Onderzoeksorganisatie

    Published inCyberbeveiligingswet

    Research organisation

    Een entiteit die als primair doel heeft toegepast onderzoek of experimentele ontwikkeling te verrichten met het oog op de exploitatie van de resultaten van dat onderzoek voor commerciële doeleinden, maar met uitzondering van onderwijsinstellingen.

  • Unusual transaction

    Een transactie die op grond van de indicatoren, vastgesteld krachtens artikel 15, eerste lid, als ongebruikelijk is aan te merken.

  • Online interface

    Published inMiCA

    Any software, including a website, part of a website or an application, that is operated by or on behalf of an offeror or crypto-asset service provider, and which serves to give clients access to the crypto-asset services of that provider or to the crypto-assets of that offeror.

  • Onze Minister

    Published inCyberbeveiligingswet

    Minister of Justice and Security

    Onze Minister van Justitie en Veiligheid.

  • A legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products.

  • Openbaar elektronisch communicatienetwerk

    Published inCyberbeveiligingswet

    Public electronic communications network

    Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.

  • Openbare elektronische communicatiedienst

    Published inCyberbeveiligingswet

    Publicly available electronic communications service

    Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.

  • The management of one or more multilateral systems, which bring together or facilitate the bringing together of multiple third-party buying and selling interests in crypto-assets, in the system and in accordance with its rules, in a way that results in a contract, either by exchanging crypto-assets for funds or by the exchange of crypto-assets for other crypto-assets.

  • Operator

    Published inEU AI Act

    A provider, product manufacturer, deployer, authorised representative, importer or distributor.

  • Overheidsinstantie

    Published inCyberbeveiligingswet

    Public administration entity

    Een in Nederland als zodanig erkende entiteit, met uitzondering van de rechterlijke macht, het parlement en de centrale bank, die voldoet aan de criteria van algemeen belang, rechtspersoonlijkheid en overheidsfinanciering of -toezicht die hieronder zijn opgenomen.

Terms starting with P

  • A mechanism that allows for the sharing and processing of information between obliged entities and, where applicable, public authorities for the purposes of the prevention and detection of money laundering, predicate offences and terrorist financing.

  • Pay-to-play service

    Published inAMLR

    An online gaming service that is accessible only upon the payment of a fee and is free from any elements of chance and wagers with monetary value.

  • Any method, device or procedure through which payers can place payment orders with their PSP for a credit transfer, including online banking, a mobile banking application, an automated teller machine, or in any other way on the premises of the PSP.

  • A payment initiation service provider as defined in Article 4, point (18), of Directive (EU) 2015/2366 of the European Parliament and of the Council.

  • Payment service provider

    Published inAMLR

    A payment service provider as defined in Article 4, point (11), of Directive (EU) 2015/2366.

  • Performance of an AI system

    Published inEU AI Act

    The ability of an AI system to achieve its intended purpose.

  • Person identification data

    Published ineIDAS2

    A set of data, issued in accordance with Union or national law, enabling the identity of a natural or legal person, or of a natural person representing a natural or legal person, to be established.

  • A natural or legal person who applies for the admission of crypto-assets to trading on a trading platform for crypto-assets.

  • Personal data

    Published inEU AI ActCRAeIDAS2

    Personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679. The EU AI Act and eIDAS 2 word it differently, and every definition is given below.

  • Natural persons known to share beneficial ownership of a legal entity or arrangement, or other close business relations, with a politically exposed person, and persons holding sole beneficial ownership of an entity set up for a PEP's de facto benefit.

  • Persoonsgegevens

    Published inCyberbeveiligingswet

    Personal data

    Persoonsgegevens als bedoeld in artikel 4, punt 1, van Verordening (EU) 2016/679.

  • Physical connection

    Published inCRA

    A connection between electronic information systems or components implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves.

  • Placing of crypto-assets

    Published inMiCA

    The marketing, on behalf of or for the account of the offeror or a person seeking admission to trading, of crypto-assets to purchasers.

  • The first making available of a product with digital elements on the Union market. The EU AI Act defines the same term differently.

  • The first making available of an AI system or a general-purpose AI model on the Union market. The Cyber Resilience Act defines the same term differently.

  • PEP · Politically exposed person

    A natural person who is or has been entrusted with prominent public functions. The AMLR lists the functions that qualify at Member State, Union and international level, and that list is reproduced below.

  • Politically exposed person (PEP)

    Natuurlijke persoon die een prominente openbare functie bekleedt of heeft bekleed, met uitzondering van middelgrote of lagere functionarissen, alsmede de directe familieleden of naaste geassocieerden van deze personen.

  • Post-market monitoring system

    Published inEU AI Act

    All activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions.

  • A remote biometric identification system other than a ‘real-time’ remote biometric identification system.

  • Metals and stones listed in Annex IV.

  • Predicate offence

    Published inAMLR

    Any criminal activity as defined in Article 2, point (1), of Directive (EU) 2018/1673.

  • Product

    Published ineIDAS2

    Hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of electronic identification and trust services.

  • A software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately.

  • Any legal entity that owns or manages a professional football team which participates in the national football league at the highest level, and where players are formally contracted and compensated for their services.

  • Profiling

    Published inEU AI Act

    Profiling as defined in Article 4, point (4), of Regulation (EU) 2016/679.

  • Provider

    Published inEU AI Act

    A natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or where an AI system or a general-purpose AI model is developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.

  • Offering, giving or agreeing to give personalised recommendations to a client, either at the client’s request or on the initiative of the crypto-asset service provider providing the advice, in respect of one or more transactions relating to crypto-assets, or the use of crypto-asset services.

  • The safekeeping or controlling, on behalf of clients, of crypto-assets or of the means of access to such crypto-assets, where applicable in the form of private cryptographic keys.

  • Managing portfolios in accordance with mandates given by clients on a discretionary client-by-client basis where such portfolios include one or more crypto-assets.

  • Providing services of transfer, on behalf of a natural or legal person, of crypto-assets from one distributed ledger address or account to another.

  • Public sector body

    Published ineIDAS2

    A state, regional or local authority, a body governed by public law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate.

  • Publicly accessible space

    Published inEU AI Act

    Any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access apply, and regardless of the potential capacity restrictions.

  • Putting into service

    Published inEU AI Act

    The supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose.

Terms starting with Q

  • A certificate for an electronic seal, that is issued by a qualified trust service provider and meets the requirements laid down in Annex III.

  • A certificate for electronic signatures, that is issued by a qualified trust service provider and meets the requirements laid down in Annex I.

  • A certificate for website authentication, which is issued by a qualified trust service provider and meets the requirements laid down in Annex IVa.

  • An electronic archiving service which meets the requirements laid down in Article 45j.

  • An electronic attestation of attributes, which is issued by a qualified trust service provider and meets the requirements laid down in Annex VII.

  • Qualified electronic ledger

    Published ineIDAS2

    An electronic ledger which meets the requirements laid down in Article 45l.

  • An electronic registered delivery service which meets the requirements laid down in Article 44.

  • Qualified electronic seal

    Published ineIDAS2

    An advanced electronic seal, which is created by a qualified electronic seal creation device, and that is based on a qualified certificate for electronic seal.

  • An electronic seal creation device that meets the requirements laid down in Annex IV.

  • An advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures.

  • An electronic signature creation device that meets the requirements laid down in Annex II.

  • An electronic time stamp which meets the requirements laid down in Article 42.

  • Qualified investors

    Published inMiCA

    Qualified investors as defined in Article 2, point (e), of Regulation (EU) 2017/1129.

  • Qualified trust service

    Published ineIDAS2

    A trust service that meets the applicable requirements laid down in this Regulation.

  • A trust service provider who provides one or more qualified trust services and is granted the qualified status by the supervisory body.

  • Qualifying holding

    Published inMiCA

    A direct or indirect holding of 10% or more of the capital or voting rights in a crypto-asset service provider or an issuer of an asset-referenced token, or a holding making it possible to exercise significant influence over its management.

Terms starting with R

  • A remote biometric identification system whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, and comprises not only instant identification, but also limited short delays in order to avoid circumvention.

  • Real-world testing plan

    Published inEU AI Act

    A document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real world conditions.

  • The use of a product with digital elements in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems. The EU AI Act defines the same term differently.

  • The use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems. The Cyber Resilience Act defines the same term differently.

  • Use that is not necessarily the intended purpose supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation, but which is likely to result from reasonably foreseeable human behaviour or technical operations or interactions.

  • Recall

    Published inCRA

    Recall as defined in Article 3, point (22), of Regulation (EU) 2019/1020.

  • Recall of an AI system

    Published inEU AI Act

    Any measure aimed at achieving the return to the provider or taking out of service or disabling the use of an AI system made available to deployers.

  • The reception from a person of an order to purchase or sell one or more crypto-assets or to subscribe for one or more crypto-assets and the transmission of that order to a third party for execution.

  • Relying party

    Published ineIDAS2

    A natural or legal person that relies upon an electronic identification, European Digital Identity Wallets or other electronic identification means, or a trust service.

  • An AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database.

  • Remote data processing

    Published inCRA

    Data processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions.

  • A qualified electronic seal creation device that is managed by a qualified trust service provider in accordance with Article 39a on behalf of a seal creator.

  • A qualified electronic signature creation device that is managed by a qualified trust service provider in accordance with Article 29a on behalf of a signatory.

  • Representant

    Published inCyberbeveiligingswet

    Representative

    Een in de Europese Unie gevestigde natuurlijke persoon of rechtspersoon die uitdrukkelijk is aangewezen om op te treden namens een niet in de Unie gevestigde aanbieder van digitale diensten. De volledige opsomming van diensten staat hieronder.

  • Reserve of assets

    Published inMiCA

    The basket of reserve assets securing the claims against the issuer.

  • Retail holder

    Published inMiCA

    A natural person who is acting for purposes which are outside that person’s trade, business, craft or profession.

  • Retail payment system

    Published inIPR

    A payment system the main purpose of which is to process, clear or settle credit transfers or direct debits which are primarily of small amount, and that is not a large-value payment system.

  • Richtlijn

    Published inWwft

    Directive

    Richtlijn (EU) 2015/849 van het Europees Parlement en de Raad van 20 mei 2015 inzake de voorkoming van het gebruik van het financiële stelsel voor het witwassen van geld of terrorismefinanciering (PbEU 2015, L 141).

  • Richtlijn (EU) 2015/1535

    Published inCyberbeveiligingswet

    Directive (EU) 2015/1535

    Richtlijn (EU) 2015/1535 van het Europees Parlement en de Raad van 9 september 2015 betreffende een informatieprocedure op het gebied van technische voorschriften en regels betreffende de diensten van de informatiemaatschappij (PbEU 2015, L 241).

  • Richtlijn (EU) 2018/1972

    Published inCyberbeveiligingswet

    Directive (EU) 2018/1972

    Richtlijn (EU) 2018/1972 van het Europees Parlement en de Raad van 11 december 2018 tot vaststelling van het Europees wetboek voor elektronische communicatie (PbEU 2018, L 321).

  • Risico

    Published inCyberbeveiligingswet

    Risk

    Het potentieel voor verlies of verstoring veroorzaakt door een incident, uitgedrukt als een combinatie van de omvang van een dergelijk verlies of een dergelijke verstoring en de waarschijnlijkheid dat het incident zich voordoet.

  • Risk

    Published inEU AI Act

    The combination of the probability of an occurrence of harm and the severity of that harm.

Terms starting with S

  • Safety component

    Published inEU AI Act

    A component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.

  • Sand box plan

    Published inEU AI Act

    A document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox.

  • Self-hosted address

    Published inAMLR

    A self-hosted address as defined in Article 3, point (20), of Regulation (EU) 2023/1113.

  • Self-regulatory body

    Published inAMLR

    A body that represents members of professions referred to in Article 3(1), points (3)(a), (b) and (f), or that has a role in regulating them, in performing certain supervisory or monitoring functions and in ensuring the enforcement of the rules that apply to them.

  • Senior management

    Published inAMLR

    An officer or employee with sufficient knowledge of the obliged entity’s money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting its risk exposure, which need not, in all cases, be a member of the management body.

  • Sensitive operational data

    Published inEU AI Act

    Operational data related to activities of prevention, detection, investigation, or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings.

  • Serious incident

    Published inEU AI Act

    An incident or malfunctioning of an AI system that directly or indirectly leads to any of the following: (a) the death of a person, or serious harm to a person’s health; (b) a serious and irreversible disruption of the management or operation of critical infrastructure; (c) the infringement of obligations under Union law intended to protect fundamental rights; (d) serious harm to property or the environment.

  • Shell bank (AMLR)

    Published inAMLR

    A credit institution or financial institution, or an institution that carries out activities equivalent to those carried out by credit institutions and financial institutions, incorporated in a jurisdiction in which it has no physical presence, involving meaningful mind and management, and which is unaffiliated with a regulated financial group. The Wwft carries a parallel definition in Dutch.

  • Shell bank (Wwft)

    Published inWwft

    Een kredietinstelling of financiële instelling, of een instelling die soortgelijke activiteiten uitoefent, die is opgericht in een rechtsgebied waarin zij geen fysieke aanwezigheid heeft die betekenisvolle leiding en beheer inhoudt, en die niet is aangesloten bij een gereglementeerde financiële groep. De AMLR bevat een gelijkluidende definitie in het Engels.

  • An entity incorporated in a jurisdiction in which it has no physical presence, involving meaningful mind and management, and which is unaffiliated with a regulated financial group.

  • Signatory

    Published ineIDAS2

    A natural person who creates an electronic signature.

  • Significant cyber threat

    Published inDORA

    A cyber threat that could plausibly result in a major ICT-related incident based on technical capabilities, intent of malicious actors, or system vulnerabilities.

  • A cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption.

  • Significant incident

    Published inCyberbeveiligingswet

    Een incident als bedoeld in artikel 25, tweede lid.

  • Significante cyberdreiging

    Published inCyberbeveiligingswet

    Significant cyber threat

    Een cyberdreiging waarvan op basis van de technische kenmerken ervan mag worden aangenomen dat zij ernstige gevolgen kan hebben voor de netwerk- en informatiesystemen van een entiteit of de gebruikers van de diensten van de entiteit door aanzienlijke materiële of immateriële schade te veroorzaken.

  • Software

    Published inCRA

    The part of an electronic information system which consists of computer code.

  • A formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements.

  • The categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725.

  • Staat

    Published inWwft

    State

    Een soevereine staat of een autonoom gebiedsdeel daarvan.

  • Strong user authentication

    Published ineIDAS2

    An authentication based on the use of at least two authentication factors from different categories of either knowledge, possession or inherence, that are independent, and designed to protect the confidentiality of the authentication data.

  • A natural person who participates in testing in real world conditions.

  • A change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed. The EU AI Act defines the same term differently.

  • A change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or modification of the intended purpose for which the AI system has been assessed. The Cyber Resilience Act defines the same term differently.

  • Supervisory authority

    Published inAMLR

    The national public body officially empowered to supervise the compliance of obliged entities with the requirements of this Regulation and Regulation (EU) 2024/1620, or an equivalent body.

  • Support period

    Published inCRA

    The period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.

  • Systemic risk

    Published inEU AI Act

    A risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain.

Terms starting with T

  • An asset freeze imposed on a person, body or entity or a prohibition on making funds or economic resources available to a person, body or entity, or for its benefit, either directly or indirectly, pursuant to restrictive measures adopted in accordance with Article 215 TFEU.

  • Both asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated persons and entities pursuant to Council Decisions adopted on the basis of Article 29 of the Treaty on European Union and Council Regulations adopted on the basis of Article 215 of the Treaty on the Functioning of the European Union.

  • Technische specificatie

    Published inCyberbeveiligingswet

    Technical specification

    Een document waarin de technische vereisten worden voorgeschreven waaraan een product, proces, dienst of systeem moet voldoen.

  • Terrorist financing

    Published inAMLR

    The provision or collection of funds, by any means, directly or indirectly, with the intention that they be used or in the knowledge that they are to be used, in full or in part, in order to carry out any of the offences within the meaning of Articles 3 to 10 of Directive (EU) 2017/541.

  • Testing data

    Published inEU AI Act

    Data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service.

  • The temporary testing of an AI system for its intended purpose outside a laboratory or simulated environment, to gather reliable data and verify conformity. The AI Act states that such testing is not placing on the market or putting into service, provided the conditions in Chapter V are met.

  • Third country

    Published inAMLR

    Any country, territory or jurisdiction outside the European Union.

  • TLPT · Threat-led penetration testing

    A controlled testing framework that mimics the tactics, techniques, and procedures (TTPs) of real-life threat actors to assess and test the resilience of critical live production systems.

  • Toezichthouder

    Published inWwft

    Supervisor

    Een toezichthouder als bedoeld in artikel 24.

  • Training data

    Published inEU AI Act

    Data used for training an AI system through fitting its learnable parameters.

  • Transactie

    Published inWwft

    Transaction

    Een handeling of samenstel van handelingen van of ten behoeve van een cliënt waarvan de instelling ten behoeve van haar dienstverlening aan die cliënt heeft kennisgenomen.

  • Trust · company service provider

    Any natural or legal person that by way of business provides company formation, directorship or partnership services, a registered office or correspondence address, trust or fiduciary services, or a nominee shareholder for another person. The full list is reproduced below.

  • Trust service

    Published ineIDAS2

    An electronic service normally provided for remuneration, covering the creation, verification and validation of electronic signatures, seals, time stamps, registered delivery services and attestations of attributes, certificates for website authentication, their preservation, and the recording of electronic data. The full list is reproduced below.

  • Trust service provider

    Published ineIDAS2

    A natural or a legal person who provides one or more trust services either as a qualified or as a non-qualified trust service provider.

  • Trustkantoor

    Published inWwft

    Trust office

    Trustkantoor als bedoeld in artikel 1, eerste lid, van de Wet toezicht trustkantoren 2018.

Terms starting with U

  • Beneficial owner

    Natuurlijke persoon die de uiteindelijke eigenaar is van of zeggenschap heeft over een cliënt, dan wel de natuurlijke persoon voor wiens rekening een transactie of activiteit wordt verricht.

  • Union legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies.

  • User

    Published ineIDAS2

    A natural or legal person, or a natural person representing a natural or legal person, that uses European Digital Identity Wallets or trust services provided in accordance with this Regulation.

  • Utility token

    Published inMiCA

    A type of crypto-asset which is only intended to provide access to a good or a service supplied by its issuer.

Terms starting with V

  • Validation

    Published ineIDAS2

    The process of verifying and confirming that an electronic signature, an electronic seal, person identification data, an electronic attestation of attributes, an electronic time stamp, an electronic registered delivery service, an electronic ledger, a qualified certificate for website authentication or a European Digital Identity Wallet is valid.

  • Validation data (eIDAS2)

    Published ineIDAS2

    Data that is used to validate an electronic signature, an electronic seal, electronic time stamps, electronic registered delivery services, electronic attestations of attributes, European Digital Identity Wallets, qualified certificates for website authentication or an electronic ledger. The EU AI Act defines the same term differently.

  • Validation data (EU AI Act)

    Published inEU AI Act

    Data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting. eIDAS 2 defines the same term differently.

  • Validation dataset

    Published inEU AI Act

    A separate dataset or part of the training dataset, either as a fixed or variable split.

  • Verifiëren

    Published inWwft

    Verify

    Vaststellen dat de opgegeven identiteit overeenkomt met de werkelijke identiteit.

  • Verlener van vertrouwensdiensten

    Published inCyberbeveiligingswet

    Trust service provider

    Een natuurlijke persoon of rechtspersoon die een of meer vertrouwensdiensten verleent als een gekwalificeerde of als een niet-gekwalificeerde verlener van vertrouwensdiensten.

  • Verordening (EG) nr. 300/2008

    Published inCyberbeveiligingswet

    Regulation (EC) No 300/2008

    Verordening (EG) nr. 300/2008 van het Europees Parlement en de Raad van 11 maart 2008 inzake gemeenschappelijke regels op het gebied van de beveiliging van de burgerluchtvaart en tot intrekking van Verordening (EG) nr. 2320/2002 (PbEU 2008, L 97).

  • Verordening (EU) 2016/679

    Published inCyberbeveiligingswet

    Regulation (EU) 2016/679

    Verordening (EU) 2016/679 van het Europees Parlement en de Raad van 27 april 2016 betreffende de bescherming van natuurlijke personen in verband met de verwerking van persoonsgegevens en betreffende het vrije verkeer van die gegevens en tot intrekking van Richtlijn 95/46/EG (algemene verordening gegevensbescherming) (PbEU 2016, L 119).

  • Verordening (EU) 2018/1139

    Published inCyberbeveiligingswet

    Regulation (EU) 2018/1139

    Verordening (EU) 2018/1139 van het Europees Parlement en de Raad van 4 juli 2018 inzake gemeenschappelijke regels op het gebied van burgerluchtvaart en tot oprichting van een Agentschap van de Europese Unie voor de veiligheid van de luchtvaart (PbEU 2018, L 212).

  • Verordening (EU) 2019/881

    Published inCyberbeveiligingswet

    Regulation (EU) 2019/881

    Verordening (EU) 2019/881 van het Europees Parlement en de Raad van 17 april 2019 inzake ENISA (het Agentschap van de Europese Unie voor cyberbeveiliging) en inzake de certificering van de cyberbeveiliging van informatie- en communicatietechnologie en tot intrekking van Verordening (EU) nr. 526/2013 (de cyberbeveiligingsverordening) (PbEU 2019, L 151).

  • Verordening (EU) 2022/2554

    Published inCyberbeveiligingswet

    Regulation (EU) 2022/2554

    Verordening (EU) 2022/2554 van het Europees Parlement en de Raad van 14 december 2022 betreffende digitale operationele weerbaarheid voor de financiële sector (PbEU 2022, L 333).

  • Verordening (EU) nr. 910/2014

    Published inCyberbeveiligingswet

    Regulation (EU) No 910/2014

    Verordening (EU) nr. 910/2014 van het Europees Parlement en de Raad van 23 juli 2014 betreffende elektronische identificatie en vertrouwensdiensten voor elektronische transacties in de interne markt en tot intrekking van Richtlijn 1999/93/EG (PbEU 2014, L 257).

  • Verordening (EU) nr. 1025/2012

    Published inCyberbeveiligingswet

    Regulation (EU) No 1025/2012

    Verordening (EU) nr. 1025/2012 van het Europees Parlement en de Raad van 25 oktober 2012 betreffende Europese normalisatie (PbEU 2012, L 316).

  • Regulation on information accompanying transfers of funds and certain crypto-assets

    Verordening (EU) 2023/1113 van het Europees Parlement en de Raad van 31 mei 2023 betreffende bij geldovermakingen en overdrachten van bepaalde cryptoactiva te voegen informatie en tot wijziging van Richtlijn (EU) 2015/849 (PbEU 2023, L 156).

  • Markets in Crypto-Assets Regulation

    Verordening (EU) 2023/1114 van het Europees Parlement en de Raad van 31 mei 2023 betreffende markten in cryptoactiva en tot wijziging van de Verordeningen (EU) nr. 1093/2010 en (EU) nr. 1095/2010 en de Richtlijnen 2013/36/EU en (EU) 2019/1937 (PbEU 2023, L 150).

  • Vertrouwensdienst

    Published inCyberbeveiligingswet

    Trust service

    Een elektronische dienst die gewoonlijk tegen vergoeding wordt verricht, waaronder het aanmaken, verifiëren en valideren van elektronische handtekeningen, zegels, tijdstempels en attesteringen, en het valideren van certificaten. De volledige opsomming staat hieronder.

  • Virtuele valuta

    Published inWwft

    Virtual currency

    Een digitale weergave van waarde die niet door een centrale bank of overheid wordt uitgegeven of gegarandeerd, niet noodzakelijk aan een wettelijk vastgestelde valuta is gekoppeld en niet de juridische status van valuta of geld heeft, maar door natuurlijke of rechtspersonen als ruilmiddel wordt aanvaard en die elektronisch kan worden overgedragen, opgeslagen en verhandeld.

  • Vulnerability (CRA)

    Published inCRA

    A weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat. DORA defines the same term differently.

  • Vulnerability (DORA)

    Published inDORA

    A flaw, weakness, or design error in an ICT asset or system that can be leveraged or exploited by a cyber threat. The Cyber Resilience Act defines the same term differently.

Terms starting with W

  • The provision of banking, investment, fiduciary, estate planning or tax advisory services, in an integrated or personalised manner, to high-net-worth individuals.

  • Widespread infringement

    Published inEU AI Act

    An act or omission contrary to Union law protecting individuals that harms, or is likely to harm, the collective interests of individuals in at least two Member States. The AI Act sets this out in two limbs, both reproduced below.

  • Withdrawal

    Published inCRA

    Withdrawal as defined in Article 3, point (23), of Regulation (EU) 2019/1020.

  • Withdrawal of an AI system

    Published inEU AI Act

    Any measure aimed at preventing an AI system in the supply chain being made available on the market.

  • Witwassen

    Published inWwft

    Money laundering

    Het plegen van een misdrijf als bedoeld in de artikelen 420bis, 420quater of 420sexies van het Wetboek van Strafrecht.

Terms starting with Z

  • Zakelijke relatie

    Published inWwft

    Business relationship

    Een zakelijke, professionele of commerciële relatie tussen een instelling en een cliënt die verband houdt met de beroeps- of bedrijfsactiviteiten van die instelling en waarvan op het tijdstip dat het contact wordt gelegd, wordt verwacht dat deze enige tijd zal duren.

Not sure which of these apply to you?

Applicability is a fact about your organisation, not a reading exercise. We derive the set from how your firm is actually built, and show the reasoning.