Regulatory Glossary
Key terminology defined across Dutch, European, and national regulatory frameworks. Every entry cites its official source, supervisory context, and related legal framework, with links to deeper guidance.
Terms starting with A
Aanbeveling 2003/361/EG
Published inCyberbeveiligingswetRecommendation 2003/361/EC
Aanbeveling 2003/361/EG van de Commissie van 6 mei 2003 betreffende de definitie van kleine, middelgrote en micro-ondernemingen (PbEU 2003, L 124).
Aanbieder van beheerde beveiligingsdiensten
Published inCyberbeveiligingswetManaged security services provider
Een aanbieder van beheerde diensten die bijstand biedt of verleent voor activiteiten die verband houden met risicobeheer op het gebied van cyberbeveiliging.
Aanbieder van beheerde diensten
Published inCyberbeveiligingswetManaged service provider
Een entiteit die diensten verleent die verband houden met de installatie, het beheer, de exploitatie of het onderhoud van ICT-producten, -netwerken, -infrastructuur, -toepassingen of andere netwerk- en informatiesystemen, via bijstand of actieve administratie bij de klant ter plaatse of op afstand.
Aanbieder van een cryptodienst
Published inWwftCrypto-asset service provider
Natuurlijke persoon of rechtspersoon die beroeps- of bedrijfsmatig een cryptodienst als bedoeld in artikel 3, eerste lid, punt 16, van de verordening markten in cryptoactiva verleent.
Aanbieder van een onlinemarktplaats
Published inCyberbeveiligingswetProvider of an online marketplace
Een aanbieder van een onlinemarktplaats als bedoeld in artikel 2, onder n, van Richtlijn 2005/29/EG betreffende oneerlijke handelspraktijken.
Aanbieder van een onlinezoekmachine
Published inCyberbeveiligingswetProvider of an online search engine
Een aanbieder van een onlinezoekmachine als bedoeld in artikel 2, punt 5, van Verordening (EU) 2019/1150 van het Europees Parlement en de Raad van 20 juni 2019 ter bevordering van billijkheid en transparantie voor zakelijke gebruikers van online-tussenhandelsdiensten (PbEU 2019, L 186).
Aanbieder van een platform voor socialenetwerkdiensten
Published inCyberbeveiligingswetProvider of a social networking services platform
Een platform dat eindgebruikers in staat stelt met elkaar in contact te komen, informatie te delen, informatie te ontdekken en met elkaar te communiceren via meerdere apparaten, met name via chats, posts, video’s en aanbevelingen.
Aanbieder van een register voor topleveldomeinnamen (TLD-nameregister)
Published inCyberbeveiligingswetTop-level domain name registry
Een entiteit waaraan een specifiek topleveldomein is gedelegeerd en die verantwoordelijk is voor het beheer daarvan, waaronder de registratie van domeinnamen en de technische werking, ongeacht of die handelingen zijn uitbesteed.
Actively exploited vulnerability
Published inCRAA vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without permission of the system owner.
Admission to trading
Published inMiCAThe admission of crypto-assets to trading on a trading platform for crypto-assets in accordance with the rules of that platform.
Advanced electronic seal
Published ineIDAS2An electronic seal which meets the requirements set out in Article 36.
Advanced electronic signature
Published ineIDAS2An electronic signature which meets the requirements set out in Article 26.
AI literacy
Published inEU AI ActSkills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause.
AI Office
Published inEU AI ActThe Commission’s function of contributing to the implementation, monitoring and supervision of AI systems and general-purpose AI models, and AI governance, provided for in Commission Decision of 24 January 2024; references in this Regulation to the AI Office shall be construed as references to the Commission.
AI regulatory sandbox
Published inEU AI ActA controlled framework set up by a competent authority which offers providers or prospective providers of AI systems the possibility to develop, train, validate and test, where appropriate in real world conditions, an innovative AI system, pursuant to a sandbox plan for a limited time under regulatory supervision.
AI system
Published inEU AI ActA machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
Anonymous crypto-asset account
Published inAMLRAn account, including a register or wallet, which is opened, held or managed by a crypto-asset service provider for an individual customer, and which does not allow the identification of the customer, or the customer’s verification in accordance with this Regulation.
Anti-Money Laundering Authority (AMLA)
Published inAMLRAMLA · Anti-Money Laundering Authority
The Authority for Anti-Money Laundering and Countering the Financing of Terrorism established by Regulation (EU) 2024/1620.
Asset-referenced token
Published inMiCAA type of crypto-asset that is not an electronic money token and that purports to maintain a stable value by referencing another value or right or a combination thereof, including one or more official currencies.
Attribute
Published ineIDAS2A feature, characteristic, quality or right of a natural or legal person or of an entity.
Auditfunctie
Published inWwftAudit function
Een onafhankelijke functie binnen een instelling die belast is met het onderzoeken en evalueren van de toereikendheid en doeltreffendheid van de beleidslijnen, procedures en maatregelen die zijn getroffen ter naleving van deze wet.
Authentic source
Published ineIDAS2A repository or system, held under the responsibility of a public body or private entity, that contains and provides attributes about a natural or legal person and that is considered to be a primary source of that information or which is recognised as authentic in accordance with Union or national law, including administrative practice.
Authentication
Published ineIDAS2An electronic process that enables the confirmation of the electronic identification of a natural or legal person, or the confirmation of the origin and integrity of data in electronic form.
Authorised representative (CRA)
Published inCRAA natural or legal person established within the Union who has received a written mandate from a manufacturer to act on its behalf in relation to specified tasks. The EU AI Act defines the same term differently.
Authorised representative (EU AI Act)
Published inEU AI ActA natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to, respectively, perform and carry out on its behalf the obligations and procedures established by this Regulation. The Cyber Resilience Act defines the same term differently.
Terms starting with B
Basic information
Published inAMLRInformation on a legal entity referred to in Article 62(1) and on an express trust or similar legal arrangement referred to in Article 67(1).
Belangrijke entiteit
Published inCyberbeveiligingswetImportant entity
Een belangrijke entiteit als bedoeld in artikel 3, tweede lid, van de NIS2-richtlijn en bedoeld in de artikelen 12 en 13 van deze wet.
Bemiddelaar in levensverzekeringen
Published inWwftLife insurance intermediary
Bemiddelaar als bedoeld in artikel 1:1 van de Wet op het financieel toezicht die bemiddelt in levensverzekeringen als bedoeld in artikel 1:1 van die wet.
Beneficial owner
Published inAMLRAny natural person who ultimately owns or controls a legal entity or an express trust or similar legal arrangement, or on whose behalf a transaction or activity is being conducted, as determined in accordance with Section 1 of Chapter IV.
Beveiliging van netwerk- en informatiesystemen
Published inCyberbeveiligingswetSecurity of network and information systems
Het vermogen van netwerk- en informatiesystemen om, op een bepaald betrouwbaarheidsniveau, weerstand te bieden aan gebeurtenissen die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die via deze netwerk- en informatiesystemen worden aangeboden of toegankelijk zijn, kunnen aantasten.
Beveiligingsscan
Published inCyberbeveiligingswetSecurity scan
Technisch onderzoek van netwerk- en informatiesystemen om inzicht te krijgen in kwetsbaarheden en risico's van deze systemen.
Bevoegde autoriteit
Published inCyberbeveiligingswetCompetent authority
De bevoegde autoriteit, bedoeld in artikel 8, eerste lid, van de NIS2-richtlijn en bedoeld in artikel 15 van deze wet.
Bevoegde autoriteit van een andere lidstaat van de Europese Unie
Published inCyberbeveiligingswetCompetent authority of another Member State of the European Union
Een bevoegde autoriteit van een andere lidstaat van de Europese Unie als bedoeld in artikel 8, eerste lid, van de NIS2-richtlijn en die als zodanig is aangewezen in het nationale recht van die andere lidstaat.
Bijna-incident
Published inCyberbeveiligingswetNear miss
Een gebeurtenis die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die via netwerk- en informatiesystemen worden aangeboden of toegankelijk zijn, had kunnen aantasten, maar waarvan de verwezenlijking met succes is voorkomen of die zich niet heeft verwezenlijkt.
Biometric categorisation system
Published inEU AI ActAn AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, unless it is ancillary to another commercial service and strictly necessary for objective technical reasons.
Biometric data
Published inEU AI ActPersonal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data.
Biometric identification
Published inEU AI ActThe automated recognition of physical, physiological and behavioural human features for the purpose of establishing the identity of a natural person by comparing biometric data of that person to biometric data of individuals stored in a database.
Biometric verification
Published inEU AI ActThe automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data.
Body governed by public law
Published ineIDAS2A body defined in point (4) of Article 2(1) of Directive 2014/24/EU.
Buitenlandse financiële onderneming
Published inWwftForeign financial undertaking
Financiële onderneming als bedoeld in onderdeel a van de definitie van financiële onderneming met een zetel in een andere lidstaat of een derde land.
Buitenlandse trustprovider
Published inWwftForeign trust service provider
Natuurlijke persoon, rechtspersoon of vennootschap die zijn woonplaats, zetel of hoofdkantoor heeft in een andere lidstaat of een derde-land en die beroeps- of bedrijfsmatig diensten verleent als bedoeld in artikel 1, onderdeel a, onderdelen 1° tot en met 5°, van de Wet toezicht trustkantoren 2018.
Bureau
Published inWwftFinancial Supervision Office
Bureau financieel toezicht, bedoeld in artikel 110 van de Wet op het notarisambt.
Business relationship
Published inAMLRA business, professional or commercial relationship between an obliged entity and a customer, connected with the obliged entity's professional activities, that is expected at the time contact is established to have an element of duration.
Terms starting with C
CE marking (CRA)
Published inCRAA marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing. The EU AI Act defines the same term differently.
CE marking (EU AI Act)
Published inEU AI ActA marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing. The Cyber Resilience Act defines the same term differently.
Centraal contactpunt
Published inCyberbeveiligingswetCentral point of contact
Het centrale contactpunt, bedoeld in artikel 8, derde lid, van de NIS2-richtlijn en bedoeld in artikel 14 van deze wet.
Centraal contactpunt van een andere lidstaat van de Europese Unie
Published inCyberbeveiligingswetCentral point of contact of another Member State of the European Union
Een centraal contactpunt van een andere lidstaat van de Europese Unie als bedoeld in artikel 8, derde lid, van de NIS2-richtlijn en dat als zodanig is aangewezen in het nationale recht van die andere lidstaat.
Certificate for electronic seal
Published ineIDAS2An electronic attestation which links electronic seal validation data to a legal person and confirms the name of that person.
Certificate for electronic signature
Published ineIDAS2An electronic attestation which links electronic signature validation data to a natural person and confirms at least the name or the pseudonym of that person.
Certificate for website authentication
Published ineIDAS2An attestation through which it is possible to authenticate a website and links the website to the natural or legal person to whom the certificate is issued.
Cliënt
Published inWwftClient
Natuurlijke persoon of rechtspersoon met wie een zakelijke relatie wordt aangegaan of die een transactie laat uitvoeren.
Close links
Published inMiCAClose links as defined in Article 4(1), point (35), of Directive 2014/65/EU.
Cloudcomputingdienst
Published inCyberbeveiligingswetCloud computing service
Een digitale dienst die administratie op aanvraag en brede toegang op afstand tot een schaalbare en elastische pool van deelbare computerbronnen mogelijk maakt, ook wanneer die bronnen over verschillende locaties verspreid zijn.
Common specification
Published inEU AI ActA set of technical specifications as defined in Article 2, point (4) of Regulation (EU) No 1025/2012 providing solutions for complying with certain requirements established under this Regulation.
Competent authority (DORA)
Published inDORAThe national or European regulatory body designated under sectoral legislation or DORA to supervise compliance by financial entities. MiCA defines the same term differently.
Competent authority (MiCA)
Published inMiCAOne or more competent authorities designated by a Member State in accordance with Article 93 of Regulation (EU) 2023/1114; the European Central Bank (ECB) when acting in accordance with Council Regulation (EU) No 1024/2013; or the national competent authority appointed under sectoral legislation where applicable. DORA defines the same term differently.
Component
Published inCRASoftware or hardware intended for integration into an electronic information system.
Concentration risk
Published inDORAOperational and systemic exposure arising from dependence on a single ICT third-party service provider or a small group of non-substitutable providers.
Conformity assessment (CRA)
Published inCRAThe process of verifying whether the essential cybersecurity requirements set out in Annex I have been fulfilled. The EU AI Act defines the same term differently.
Conformity assessment (EU AI Act)
Published inEU AI ActThe process of demonstrating whether the requirements set out in Chapter III, Section 2 relating to a high-risk AI system have been fulfilled. The Cyber Resilience Act defines the same term differently.
Conformity assessment body
Published ineIDAS2A conformity assessment body as defined in Article 2, point 13, of Regulation (EC) No 765/2008, which is accredited in accordance with that Regulation as competent to carry out conformity assessment of a qualified trust service provider and the qualified trust services it provides, or as competent to carry out certification of European Digital Identity Wallets or electronic identification means.
Conformity assessment body (CRA)
Published inCRAA conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008. The EU AI Act defines the same term differently.
Conformity assessment body (EU AI Act)
Published inEU AI ActA body that performs third-party conformity assessment activities, including testing, certification and inspection. The Cyber Resilience Act defines the same term differently.
Consensus mechanism
Published inMiCAThe rules and procedures by which an agreement is reached, among DLT network nodes, that a transaction is validated.
Consumer
Published inCRAA natural person who acts for purposes which are outside that person's trade, business, craft or profession.
Coördinator met het oog op een gecoördineerde bekendmaking van kwetsbaarheden
Published inCyberbeveiligingswetCoordinator for the purposes of coordinated vulnerability disclosure
De coördinator met het oog op een gecoördineerde bekendmaking van kwetsbaarheden, bedoeld in artikel 12, eerste lid, van de NIS2-richtlijn en bedoeld in artikel 17 van deze wet.
Correspondent relationship
Published inAMLRThe provision of banking services by one credit institution as correspondent to another as respondent, and comparable service relationships between credit institutions, financial institutions or crypto-asset service providers. The AMLR sets this out in two limbs, reproduced below.
Correspondentrelatie
Published inWwftCorrespondent relationship
Het verlenen van bankdiensten door een bank aan een andere bank, de respondent, en vergelijkbare dienstverlening tussen kredietinstellingen en financiële instellingen onderling. De Wwft omschrijft dit in twee onderdelen, hieronder integraal weergegeven.
Creator of a seal
Published ineIDAS2A legal person that creates an electronic seal.
Credit institution (AMLR)
Published inAMLRA credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013. MiCA defines the same term differently.
Credit institution (MiCA)
Published inMiCAA credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 and authorised under Directive 2013/36/EU. The AMLR defines the same term differently.
Criminal property
Published inAMLRAssets as defined in Article 2, point (2), of Directive (EU) 2018/1673.
Critical ICT third-party service provider
Published inDORAAn ICT third-party provider designated as systemically critical by European Supervisory Authorities (ESAs) based on cross-border reliance, substitutability, and systemic relevance.
Critical infrastructure
Published inEU AI ActCritical infrastructure as defined in Article 2, point (4), of Directive (EU) 2022/2557.
Critical or important function
Published inDORACritical · important function
An operational function whose disruption would materially impair a financial entity's financial performance, operational continuity, regulatory compliance, or core business operations.
Crowdfunding intermediary
Published inAMLRAn undertaking other than a crowdfunding service provider whose business consists of matching or facilitating the matching, through an online platform, of business project owners seeking funding with investors or lenders who provide funding, or of connecting consumers seeking credit with lenders.
Crowdfunding service provider
Published inAMLRA crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503.
Crypto-asset
Published inMiCAAMLRA digital representation of a value or of a right that is able to be transferred and stored electronically, using distributed ledger technology or similar technology. The AMLR defines the same term differently.
Crypto-asset service
Published inMiCAAny of the services and activities relating to any crypto-asset listed in points (16) to (25) of Article 3(1) of Regulation (EU) 2023/1114.
Crypto-asset service provider (AMLR)
Published inAMLRA crypto-asset service provider as defined in Article 3(1), point (15), of Regulation (EU) 2023/1114, where performing one or more crypto-asset services as defined in Article 3(1), point (16), of that Regulation, with the exception of the provision of advice on crypto-assets as referred to in Article 3(1), point (16)(h), of that Regulation. MiCA defines the same term differently.
Crypto-asset service provider (MiCA)
Published inMiCAA legal person or other undertaking whose occupation or business is the provision of one or more crypto-asset services to clients on a professional basis, and that is allowed to provide crypto-asset services in accordance with Article 59 of Regulation (EU) 2023/1114. The AMLR defines the same term differently.
Crypto-asset white paper
Published inMiCAA document that contains mandatory information disclosures relating to the offer to the public of crypto-assets or to the admission of crypto-assets to trading.
CSIRT
Published inCyberbeveiligingswetEen Computer security incident response team, bedoeld in artikel 10 van de NIS2-richtlijn en bedoeld in artikel 16 van deze wet.
CSIRT designated as coordinator
Published inCRAA CSIRT designated as coordinator pursuant to Article 12(1) of Directive (EU) 2022/2555.
CSIRT van een andere lidstaat van de Europese Unie
Published inCyberbeveiligingswetCSIRT of another Member State of the European Union
Een CSIRT van een andere lidstaat van de Europese Unie als bedoeld in artikel 10 van de NIS2-richtlijn en dat als zodanig is aangewezen in het nationale recht van die andere lidstaat.
CSIRT-netwerk
Published inCyberbeveiligingswetCSIRT network
Het netwerk van CSIRT’s, genoemd in artikel 15 van de NIS2-richtlijn.
Cultural goods
Published inAMLRCultural goods as defined in Article 2, point (1), of Regulation (EU) 2019/880 of the European Parliament and of the Council.
Cyber threat (CRA)
Published inCRAA cyber threat as defined in Article 2, point (8), of Regulation (EU) 2019/881. DORA defines the same term differently.
Cyber threat (DORA)
Published inDORAA potential circumstance, event, or action capable of damaging, disrupting, or otherwise adversely affecting network and information systems, users, or other individuals. The Cyber Resilience Act defines the same term differently.
Cyberbeveiliging
Published inCyberbeveiligingswetCybersecurity
De activiteiten die nodig zijn om netwerk- en informatiesystemen, de gebruikers van dergelijke systemen, en andere personen die getroffen worden door cyberdreigingen, te beschermen.
Cybercrisisbeheerautoriteit
Published inCyberbeveiligingswetCyber crisis management authority
De autoriteit voor cybercrisisbeheer, bedoeld in artikel 9, eerste lid, van de NIS2-richtlijn en bedoeld in artikel 18 van deze wet.
Cyberdreiging
Published inCyberbeveiligingswetCyber threat
Elke potentiële omstandigheid, gebeurtenis of actie die netwerk- en informatiesystemen, de gebruikers van dergelijke systemen en andere personen kan schaden, verstoren of op andere wijze negatief kan beïnvloeden.
Cybersecurity
Published inCRACybersecurity as defined in Article 2, point (1), of Regulation (EU) 2019/881.
Cybersecurity risk
Published inCRAThe potential for loss or disruption caused by an incident and is to be expressed as a combination of the magnitude of such loss or disruption and the likelihood of occurrence of the incident.
Terms starting with D
Data record
Published ineIDAS2Electronic data recorded with related meta-data supporting the processing of the data.
Datacentrumdienst
Published inCyberbeveiligingswetData centre service
Een dienst die structuren of groepen van structuren omvat die bestemd zijn voor de gecentraliseerde accommodatie, de interconnectie en de exploitatie van IT en netwerkapparatuur die diensten op het gebied van gegevensopslag, -verwerking en -transport aanbiedt, samen met alle faciliteiten en infrastructuren voor energiedistributie en omgevingscontrole.
Deep fake
Published inEU AI ActAI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
Deployer
Published inEU AI ActA natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.
Services for exchanging between virtual currencies and fiat currencies
Het beroeps- of bedrijfsmatig aanbieden van diensten voor het omwisselen van virtuele valuta tegen fiduciaire valuta of omgekeerd met gebruikmaking van eigen vermogen.
Digital operational resilience
Published inDORAThe ability of a financial entity to build, assure, and review its operational integrity and reliability by ensuring, either directly or indirectly via third-party ICT services, the full range of ICT-related capabilities needed to safeguard the security of network and information systems.
Digitale dienst
Published inCyberbeveiligingswetDigital service
Elke dienst van de informatiemaatschappij, dat wil zeggen elke dienst die gewoonlijk tegen vergoeding, langs elektronische weg, op afstand en op individueel verzoek van een afnemer van diensten wordt verricht zoals bedoeld in artikel 1, eerste lid, onderdeel b, van Richtlijn (EU) 2015/1535.
Distributed ledger
Published inMiCAAn information repository that keeps records of transactions and that is shared across, and synchronised between, a set of DLT network nodes using a consensus mechanism.
Distributed ledger technology (DLT)
Published inMiCADLT · Distributed ledger technology
A technology that enables the operation and use of distributed ledgers.
Distributor (CRA)
Published inCRAA natural or legal person in the supply chain, other than the manufacturer or the importer, that makes a product with digital elements available on the Union market without affecting its properties. The EU AI Act defines the same term differently.
Distributor (EU AI Act)
Published inEU AI ActA natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the Union market without affecting its properties. The Cyber Resilience Act defines the same term differently.
DNS-dienstverlener
Published inCyberbeveiligingswetDNS service provider
Een entiteit die voorziet in: a. publiek beschikbare recursieve domeinnaamresolutiediensten voor interneteindgebruikers; of b. gezaghebbende domeinnaamresolutiediensten voor gebruik door derden, met uitzondering van root-naamservers.
Domeinnaamsysteem (DNS)
Published inCyberbeveiligingswetDomain Name System (DNS)
Een hiërarchisch gedistribueerd naamgevingssysteem dat het mogelijk maakt internetdiensten en -bronnen te identificeren, waardoor eindgebruikersapparaten in staat worden gesteld routing- en connectiviteitsdiensten op het internet te gebruiken om die diensten en bronnen te bereiken.
Downstream provider
Published inEU AI ActA provider of an AI system, including a general-purpose AI system, which integrates an AI model, regardless of whether the AI model is provided by themselves and vertically integrated or provided by another entity based on contractual relations.
Terms starting with E
Economic operator
Published inCRAThe manufacturer, the authorised representative, the importer, the distributor, or other natural or legal person who is subject to obligations in relation to the manufacture of products with digital elements or to the making available of products with digital elements on the market in accordance with this Regulation.
Electronic archiving
Published ineIDAS2A service ensuring the receipt, storage, retrieval and deletion of electronic documents in order to guarantee their durability and legibility as well as to preserve their integrity, confidentiality and proof of origin throughout the preservation period.
Electronic attestation of attributes
Published ineIDAS2An attestation in electronic form that allows the authentication of attributes.
Electronic attestation of attributes issued by or on behalf of a public body responsible for an authentic source
Published ineIDAS2Electronic attestation of attributes issued by · on behalf of a public body responsible for an authentic source
An electronic attestation of attributes issued by a public body that is responsible for an authentic source or by a public body designated by the Member State to issue such attestations of attributes on behalf of the public bodies responsible for authentic sources in accordance with Article 45f and Annex VII.
Electronic document
Published ineIDAS2Any content stored in electronic form, in particular text or sound, visual or audiovisual recording.
Electronic identification
Published ineIDAS2The process of using person identification data in electronic form representing either a natural or legal person, or a natural person representing a legal person.
Electronic identification means
Published ineIDAS2A material and/or immaterial unit, including European Digital Identity Wallets, containing person identification data and which is used to authenticate for an online or offline service.
Electronic identification scheme
Published ineIDAS2A system for electronic identification under which electronic identification means are issued to natural or legal persons or to natural persons representing natural or legal persons.
Electronic information system
Published inCRAA system, including electrical or electronic equipment, capable of processing, storing or transmitting digital data.
Electronic ledger
Published ineIDAS2A sequence of electronic data records, which ensures the integrity of those records and the accuracy of the chronological ordering of those records.
Electronic money token (e-money token)
Published inMiCAe-money token · Electronic money token
A type of crypto-asset that purports to maintain a stable value by referencing the value of one official currency.
Electronic registered delivery service
Published ineIDAS2A service that makes it possible to transmit data between third parties by electronic means and provides evidence of the handling of the transmitted data, including proof of sending and receiving the data, and that protects transmitted data against the risk of loss, theft, damage or any unauthorised alterations.
Electronic seal
Published ineIDAS2Data in electronic form, which is attached to or logically associated with other data in electronic form to ensure the origin and integrity of that data.
Electronic seal creation data
Published ineIDAS2Unique data which is used by the creator of the electronic seal to create an electronic seal.
Electronic seal creation device
Published ineIDAS2Configured software or hardware used to create an electronic seal.
Electronic signature
Published ineIDAS2Data in electronic form which is attached to or logically associated with other data in electronic form and which is used by the signatory to sign.
Electronic signature creation data
Published ineIDAS2Unique data which is used by the signatory to create an electronic signature.
Electronic signature creation device
Published ineIDAS2Configured software or hardware used to create an electronic signature.
Electronic time stamp
Published ineIDAS2Data in electronic form which binds other data in electronic form to a particular time establishing evidence that the latter data existed at that time.
Elektronisch communicatienetwerk
Published inCyberbeveiligingswetElectronic communications network
Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.
Elektronische communicatiedienst
Published inCyberbeveiligingswetElectronic communications service
Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.
Emotion recognition system
Published inEU AI ActAn AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data.
End-point
Published inCRAAny device that is connected to a network and serves as an entry point to that network.
Enisa
Published inCyberbeveiligingswetHet Agentschap van de Europese Unie voor cyberbeveiliging, opgericht bij Verordening (EU) 2019/881.
Entiteit
Published inCyberbeveiligingswetEntity
Een natuurlijke persoon of rechtspersoon die is opgericht en erkend krachtens het nationale recht van de plaats van vestiging, die onder eigen naam rechten kan uitoefenen en aan verplichtingen kan worden onderworpen.
Entiteit die domeinnaamregistratiediensten verleent
Published inCyberbeveiligingswetEntity providing domain name registration services
Een registrar of een agent die namens registrars optreedt, zoals een verlener van privacy- of proxyregistratiediensten of een wederverkoper.
Essentiële entiteit
Published inCyberbeveiligingswetEssential entity
Een essentiële entiteit als bedoeld in artikel 3, eerste lid, van de NIS2-richtlijn en bedoeld in de artikelen 8 tot en met 11 van deze wet.
European Digital Identity Wallet
Published ineIDAS2An electronic identification means which allows the user to securely store, manage and validate person identification data and electronic attestations of attributes, in order to provide them to relying parties and other users of European Digital Identity Wallets, and to sign by means of qualified electronic signatures or to seal by means of qualified electronic seals.
European Digital Identity Wallet Trust Mark
Published ineIDAS2A verifiable, simple and recognisable indication that a European Digital Identity Wallet has been issued in accordance with this Regulation.
European standard
Published inCRAA European standard as defined in Article 2, point (1)(b), of Regulation (EU) No 1025/2012.
Exchange of crypto-assets for funds
Published inMiCAThe conclusion of purchase or sale contracts concerning crypto-assets with clients for funds by using proprietary capital.
Exchange of crypto-assets for other crypto-assets
Published inMiCAThe conclusion of purchase or sale contracts concerning crypto-assets with clients for other crypto-assets by using proprietary capital.
Execution of orders for crypto-assets on behalf of clients
Published inMiCAThe conclusion of agreements to buy or to sell one or more crypto-assets or to subscribe for one or more crypto-assets on behalf of clients and includes the conclusion of contracts to sell crypto-assets at the moment of their offer to the public or admission to trading.
Exploitable vulnerability
Published inCRAA vulnerability that has the potential to be effectively used by an adversary under practical operational conditions.
Terms starting with F
Family members
Published inAMLRIn relation to a politically exposed person: the spouse or equivalent registered partner, children and their spouses or equivalent partners, and the parents.
Financial entity
Published inDORARegulated financial institutions covered under DORA's scope, including credit institutions, payment institutions, investment firms, crypto-asset service providers, central securities depositories, insurance and reinsurance undertakings, and trade repositories.
Financial institution
Published inAMLRAn undertaking other than a credit institution or investment firm that carries out listed banking activities, including bureaux de change, together with insurance undertakings in respect of life and investment-related business and the further categories the AMLR lists. The full definition is reproduced below.
Financial instrument
Published inMiCAFinancial instruments as defined in Article 4(1), point (15), of Directive 2014/65/EU.
Financial Intelligence Unit (FIU)
Published inAMLRFIU · Financial Intelligence Unit
The central national unit established in each Member State for the purpose of receiving and analysing reports on suspicious transactions and other information relevant to money laundering, predicate offences or terrorist financing, and for disseminating the results of that analysis.
Financiële onderneming
Published inWwftFinancial undertaking
Een reeks in de Wet op het financieel toezicht omschreven ondernemingen, waaronder banken, beleggingsondernemingen, betaaldienstverleners, elektronischgeldinstellingen, levensverzekeraars en aanbieders van een cryptodienst, plus Nederlandse bijkantoren daarvan. De volledige opsomming staat hieronder.
Financieren van terrorisme
Published inWwftTerrorist financing
Het plegen van een misdrijf als bedoeld in artikel 421 van het Wetboek van Strafrecht, of van een misdrijf als bedoeld in de artikelen 83 of 140a van dat wetboek voor zover begaan met een terroristisch oogmerk.
Floating-point operation (FLOP)
Published inEU AI ActFLOP · Floating-point operation
Any mathematical operation or assignment involving floating-point numbers, which are a subset of the real numbers typically represented on computers by an integer of fixed precision scaled by an integer exponent of a fixed base.
Football agent
Published inAMLRA natural person who provides intermediation services for football players or clubs in relation to employment contracts or the transfer of players between football clubs.
Free and open-source software
Published inCRASoftware the source code of which is openly shared and which is made available under a free and open-source licence which provides for all rights to make it freely accessible, usable, modifiable and redistributable.
Funds
Published inMiCAAMLRFunds as defined in Article 4, point (25), of Directive (EU) 2015/2366. MiCA and the AMLR use identical wording.
Terms starting with G
Gambling services
Published inAMLRA service which involves wagering a stake with monetary value in games of chance, including those with an element of skill such as lotteries, casino games, poker games and betting transactions that are provided at a physical location, or by any means at a distance, across electronic media or any other technology for facilitating communication, and at the individual request of a recipient of services.
Gekwalificeerde verlener van vertrouwensdiensten
Published inCyberbeveiligingswetQualified trust service provider
Een verlener van vertrouwensdiensten die een of meer gekwalificeerde vertrouwensdiensten verleent en aan wie door het toezichthoudend orgaan de gekwalificeerde status is toegekend zoals vastgelegd in Verordening (EU) nr. 910/2014.
Gekwalificeerde vertrouwensdienst
Published inCyberbeveiligingswetQualified trust service
Een vertrouwensdienst die voldoet aan de toepasselijke eisen zoals vastgelegd in Verordening (EU) nr. 910/2014.
Geldovermaking
Published inWwftMoney remittance
Transactie die door of via een betaaldienstverlener voor rekening van een betaler wordt verricht met het oogmerk middelen ter beschikking te stellen aan een begunstigde, ongeacht of de betaler en de begunstigde dezelfde persoon zijn.
General-purpose AI model
Published inEU AI ActAn AI model that, in the Act's own words, “displays significant generality” and can competently perform many distinct tasks, and that can be integrated into a variety of downstream systems or applications. Models used only for research, development or prototyping before being placed on the market are excluded.
General-purpose AI system
Published inEU AI ActAn AI system which is based on a general-purpose AI model, that has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems.
Groep
Published inWwftGroup
Een groep als bedoeld in artikel 2:24b van het Burgerlijk Wetboek.
Grootschalig cyberbeveiligingsincident
Published inCyberbeveiligingswetLarge-scale cybersecurity incident
Een incident dat een dermate grote verstoring veroorzaakt dat het de capaciteit van een lidstaat om erop te reageren te boven gaat, of dat aanzienlijke gevolgen heeft voor ten minste twee lidstaten.
Terms starting with H
Hardware
Published inCRAA physical electronic information system, or parts thereof capable of processing, storing or transmitting digital data.
Harmonised standard
Published inEU AI ActCRAA harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012. The EU AI Act and the Cyber Resilience Act word it differently, and every definition is given below.
High-impact capabilities
Published inEU AI ActCapabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models.
High-net-worth individual
Published inAMLRA natural person whose total net assets amount to at least EUR 50 000 000, excluding that individual’s primary residence.
High-value goods
Published inAMLRThe goods listed in Annex IV.
Home Member State
Published inMiCAThe Member State whose authority is the primary one for an offeror, a person seeking admission to trading, an issuer or a crypto-asset service provider. MiCA sets it out in six limbs, one per situation, reproduced below.
Hoofdvestiging
Published inCyberbeveiligingswetMain establishment
De plaats waar de beslissingen in verband met de maatregelen voor het beheer van cyberbeveiligingsrisico’s hoofdzakelijk worden genomen binnen de Europese Unie.
Host Member State
Published inMiCAThe Member State where an offeror or person seeking admission to trading has made an offer to the public of crypto-assets or is seeking admission to trading on a trading platform for crypto-assets, or where a crypto-asset service provider provides crypto-asset services, when different from the home Member State.
Terms starting with I
ICT assets
Published inDORASoftware, hardware, digital infrastructure, or data components within an entity’s digital architecture that hold operational value.
ICT intra-group service provider
Published inDORAAn entity within a financial group that provides ICT services primarily or exclusively to financial entities in the same group.
ICT risk
Published inDORAAny reasonably identifiable operational circumstance related to the use of network and information systems that can compromise system security, cause hardware or software failures, lead to data loss or corruption, or impair the performance of financial services.
ICT services
Published inDORADigital and data services provided via ICT systems to one or more internal or external users on an ongoing basis (including hardware-as-a-service, cloud computing, and data storage).
ICT third-party service provider
Published inDORAAn undertaking that provides digital and data services on an ongoing basis to financial entities through contractual arrangements (e.g., cloud platforms, data analytics, software development, data center operations).
ICT-dienst
Published inCyberbeveiligingswetICT service
Een dienst die volledig of hoofdzakelijk bestaat in de verzending, opslag, opvraging of verwerking van gegevens door middel van netwerk- en informatiesystemen.
ICT-proces
Published inCyberbeveiligingswetICT process
Een reeks activiteiten die worden uitgevoerd om een ICT-product of -dienst te ontwerpen, te ontwikkelen, te leveren of te onderhouden.
ICT-product
Published inCyberbeveiligingswetICT product
Een element of groep elementen van een netwerk- of informatiesysteem.
Identificeren
Published inWwftIdentify
Opgave van de identiteit laten doen.
Importer (CRA)
Published inCRAA natural or legal person established in the Union who places on the market a product with digital elements that bears the name or trademark of a natural or legal person established outside the Union. The EU AI Act defines the same term differently.
Importer (EU AI Act)
Published inEU AI ActA natural or legal person located or established in the Union that places on the market an AI system that bears the name or trademark of a natural or legal person established in a third country. The Cyber Resilience Act defines the same term differently.
Incident (CRA)
Published inCRAAn incident as defined in Article 6, point (6), of Directive (EU) 2022/2555. The Cyberbeveiligingswet defines the same term differently.
Incident (Cyberbeveiligingswet)
Published inCyberbeveiligingswetEen gebeurtenis die de beschikbaarheid, authenticiteit, integriteit of vertrouwelijkheid van opgeslagen, verzonden of verwerkte gegevens of van de diensten die via netwerk- en informatiesystemen worden aangeboden of toegankelijk zijn, aantast. De Cyber Resilience Act hanteert een andere definitie.
An incident that negatively affects or is capable of negatively affecting the ability of a product with digital elements to protect the availability, authenticity, integrity or confidentiality of data or functions.
Incidentafhandeling
Published inCyberbeveiligingswetIncident handling
Alle handelingen en procedures die gericht zijn op het voorkomen, opsporen, analyseren en indammen van of het reageren op en herstellen van een incident.
Indirect connection
Published inCRAA connection to a device or network, which does not take place directly but rather as part of a larger system that is directly connectable to such device or network.
Information system
Published inDORAA system consisting of network and information infrastructure, software, computer hardware, and related data processing/storage devices.
Information-sharing arrangement
Published inDORAA voluntary agreement between financial entities and trusted partners to exchange cyber threat intelligence, indicators of compromise (IoCs), and defense techniques.
Informed consent
Published inEU AI ActA subject’s freely given, specific, unambiguous and voluntary expression of his or her willingness to participate in a particular testing in real world conditions, after having been informed of all aspects of the testing that are relevant to the subject’s decision to participate.
Input data
Published inEU AI ActData provided to or directly acquired by an AI system on the basis of which the system produces an output.
Instant credit transfer
Published inIPRA credit transfer which is executed immediately, 24 hours a day and on any calendar day.
Instelling
Published inWwftInstitution
Een instelling als bedoeld in artikel 1a.
Institution
Published inIPRFor the purposes of the Instant Payments Regulation, an institution under Directive 98/26/EC as amended: credit institutions, investment firms, public authorities and publicly guaranteed undertakings, and the further categories listed in the definition reproduced below.
Instructions for use
Published inEU AI ActThe information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use.
Intended purpose (CRA)
Published inCRAThe use for which a product with digital elements is intended by the manufacturer, including the specific context and conditions of use, as specified in the information supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation. The EU AI Act defines the same term differently.
Intended purpose (EU AI Act)
Published inEU AI ActThe use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation. The Cyber Resilience Act defines the same term differently.
International standard
Published inCRAAn international standard as defined in Article 2, point (1)(a), of Regulation (EU) No 1025/2012.
Internetknooppunt
Published inCyberbeveiligingswetInternet exchange point
Een netwerkfaciliteit die de interconnectie van meer dan twee onafhankelijke netwerken mogelijk maakt, hoofdzakelijk om de uitwisseling van internetverkeer te vergemakkelijken, zonder dat verkeer via een derde autonoom systeem hoeft te passeren.
Investment firm
Published inMiCAAn investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU.
Terms starting with J
Joint Examination Team
Published inDORAA multidisciplinary team of examiners established by the Lead Overseer to coordinate and execute oversight activities and on-site inspections for critical ICT third-party providers.
Terms starting with K
Kredietinstelling
Published inWwftCredit institution
Een kredietinstelling als bedoeld in artikel 1:1 van de Wet op het financieel toezicht.
Kritieke entiteit
Published inCyberbeveiligingswetCritical entity
Een entiteit die als zodanig is aangewezen op grond van de Wet weerbaarheid kritieke entiteiten.
Kwetsbaarheid
Published inCyberbeveiligingswetVulnerability
Een zwakheid, vatbaarheid of tekortkoming van ICT-producten of ICT-diensten die door een cyberdreiging kan worden uitgebuit.
Terms starting with L
Law enforcement
Published inEU AI ActActivities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.
Law enforcement authority
Published inEU AI ActA public authority competent for preventing, investigating, detecting or prosecuting criminal offences or executing criminal penalties, including safeguarding against threats to public security. It also covers any other body entrusted by Member State law with those public powers.
Lead Overseer
Published inDORAThe European Supervisory Authority (EBA, ESMA, or EIOPA) designated to conduct direct regulatory oversight of a designated critical ICT third-party service provider.
Legal arrangement
Published inAMLRAn express trust or other arrangement having a similar structure or function, including fiducie and certain types of Treuhand and fideicomiso.
Legal entity
Published inAMLRAny entity, other than a natural person, that can establish a legal relationship with other entities or natural persons, or be a subject of rights and obligations, including companies, partnerships and associations.
Legal Entity Identifier or LEI
Published inIPRLegal Entity Identifier · LEI
A unique alphanumeric reference code based on the ISO 17442 standard assigned to a legal entity.
Lidstaat
Published inWwftMember State
Een lidstaat van de Europese Unie alsmede een staat, niet zijnde een lidstaat van de Europese Unie, die partij is bij de Overeenkomst betreffende de Europese Economische Ruimte.
Linked transactions
Published inAMLRTwo or more transactions with either a single or multiple sources and destinations, which are carried out within a given period, where there are reasonable grounds to believe that they are conducted as part of a single transaction or are connected, or where they involve the same parties.
Logical connection
Published inCRAA virtual representation of a data connection implemented through a software interface.
Terms starting with M
Making available on the market (CRA)
Published inCRAThe supply of a product with digital elements for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. The EU AI Act defines the same term differently.
Making available on the market (EU AI Act)
Published inEU AI ActThe supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge. The Cyber Resilience Act defines the same term differently.
Management body (AMLR)
Published inAMLRA body of an obliged entity, appointed in accordance with national law, which is empowered to set the entity’s strategy, objectives and overall direction, and which oversees and monitors management decision-making, and includes the persons who effectively direct the business of the entity. MiCA defines the same term differently.
Management body (MiCA)
Published inMiCAThe body or bodies of an issuer, of an offeror or person seeking admission to trading, or of a crypto-asset service provider, which are appointed in accordance with national law, which are empowered to set the entity’s strategy, objectives and overall direction, and which oversee and monitor management decision-making, and include the persons who effectively direct the business of the entity. The AMLR defines the same term differently.
Management body in its supervisory function
Published inAMLRThe management body acting in its role of overseeing and monitoring management decision-making.
Manufacturer
Published inCRAA natural or legal person who develops or manufactures products with digital elements or has products with digital elements designed, developed or manufactured, and markets them under its name or trademark, whether for payment, monetisation or free of charge.
Market surveillance authority (CRA)
Published inCRAA market surveillance authority as defined in Article 3, point (4), of Regulation (EU) 2019/1020. The EU AI Act defines the same term differently.
Market surveillance authority (EU AI Act)
Published inEU AI ActThe national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020. The Cyber Resilience Act defines the same term differently.
Matching
Published ineIDAS2The process of establishing a link between the person identification data or person identification means of a user and an existing account belonging to the same user.
Meldpunt
Published inWwftFinancial Intelligence Unit (FIU)
De Financiële inlichtingen-eenheid, bedoeld in artikel 12, eerste lid.
Respectively, microenterprises, small enterprises and medium-sized enterprises as defined in the Annex to Recommendation 2003/361/EC.
Money laundering
Published inAMLRThe conduct as referred to in Article 3, paragraphs 1 and 5, of Directive (EU) 2018/1673.
Terms starting with N
Name of the payee
Published inIPRIn respect of a natural person, the name and surname and, in respect of a legal person, the commercial or legal name.
National competent authority
Published inEU AI ActA notifying authority or a market surveillance authority; as regards AI systems put into service or used by Union institutions, agencies, offices and bodies, references to national competent authorities or market surveillance authorities in this Regulation shall be construed as references to the European Data Protection Supervisor.
Nationale cyberbeveiligingsstrategie
Published inCyberbeveiligingswetNational cybersecurity strategy
Een samenhangend kader van een lidstaat dat strategische doelstellingen en prioriteiten op het gebied van cyberbeveiliging en het bestuur om die te bereiken in die lidstaat biedt.
Near miss
Published inCRAA near miss as defined in Article 6, point (5), of Directive (EU) 2022/2555.
Netwerk voor de levering van inhoud
Published inCyberbeveiligingswetContent delivery network
Een netwerk van geografisch verspreide servers met het oog op een hoge beschikbaarheid, toegankelijkheid of snelle levering van digitale inhoud en diensten aan internetgebruikers ten behoeve van aanbieders van inhoud en diensten.
Netwerk- en informatiesysteem
Published inCyberbeveiligingswetNetwork and information system
Een elektronisch communicatienetwerk, een apparaat of groep verbonden apparaten die digitale gegevens automatisch verwerken, of de digitale gegevens die daarmee worden opgeslagen, verwerkt, opgehaald of verzonden. De drie onderdelen staan hieronder.
Niet-gouvernementele organisatie
Published inWwftNon-governmental organisation
Een rechtspersoon of maatschap zonder winstoogmerk die zich richt op het algemeen maatschappelijk belang of ideële doeleinden.
NIS2-richtlijn
Published inCyberbeveiligingswetNIS2 Directive
Richtlijn (EU) 2022/2555 van het Europees Parlement en de Raad van 14 december 2022 betreffende maatregelen voor een hoog gezamenlijk niveau van cyberbeveiliging in de Unie, tot wijziging van Verordening (EU) nr. 910/2014 en Richtlijn (EU) 2018/1972 en tot intrekking van Richtlijn (EU) 2016/1148 (PbEU 2022, L 333).
Nominee director
Published inAMLRA natural person who acts as a director of a legal entity and complies with instructions given by another person, or is acting on behalf of another person, where that fact is not disclosed in the national company register.
Non-fungible token
Published inAMLRA crypto-asset that is unique and not fungible with other crypto-assets, including digital art and collectibles.
Non-personal data
Published inEU AI ActData other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679.
Norm
Published inCyberbeveiligingswetStandard
Een door een erkende normalisatie-instelling vastgestelde technische specificatie waarvan de naleving niet verplicht is, onderverdeeld in internationale, Europese, geharmoniseerde en nationale normen. De volledige omschrijving staat hieronder.
Notified body (CRA)
Published inCRAA conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation. The EU AI Act defines the same term differently.
Notified body (EU AI Act)
Published inEU AI ActA conformity assessment body notified in accordance with this Regulation and other relevant Union harmonisation legislation. The Cyber Resilience Act defines the same term differently.
Notifying authority
Published inEU AI ActCRAThe national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring. The EU AI Act and the Cyber Resilience Act use identical wording.
Terms starting with O
Obliged entity
Published inAMLRA natural or legal person listed in Article 3(1) that is not exempted in accordance with Article 4, 5, 6 or 7.
Offer to the public
Published inMiCAA communication to persons in any form, and by any means, presenting sufficient information on the terms of the offer and the crypto-assets to be offered so as to enable an investor to decide whether to purchase those crypto-assets.
Offeror
Published inMiCAA natural or legal person, or other undertaking, or the issuer, who offers crypto-assets to the public.
Offline
Published ineIDAS2In relation to the use of European Digital Identity Wallets, an interaction between a user and a third party at a physical location using close proximity technologies, whereby the wallet is not required to access remote systems via electronic communications networks for the purpose of the interaction.
Onderzoeksorganisatie
Published inCyberbeveiligingswetResearch organisation
Een entiteit die als primair doel heeft toegepast onderzoek of experimentele ontwikkeling te verrichten met het oog op de exploitatie van de resultaten van dat onderzoek voor commerciële doeleinden, maar met uitzondering van onderwijsinstellingen.
Ongebruikelijke transactie
Published inWwftUnusual transaction
Een transactie die op grond van de indicatoren, vastgesteld krachtens artikel 15, eerste lid, als ongebruikelijk is aan te merken.
Online interface
Published inMiCAAny software, including a website, part of a website or an application, that is operated by or on behalf of an offeror or crypto-asset service provider, and which serves to give clients access to the crypto-asset services of that provider or to the crypto-assets of that offeror.
Onze Minister
Published inCyberbeveiligingswetMinister of Justice and Security
Onze Minister van Justitie en Veiligheid.
Open-source software steward
Published inCRAA legal person, other than a manufacturer, that has the purpose or objective of systematically providing support on a sustained basis for the development of specific products with digital elements, qualifying as free and open-source software and intended for commercial activities, and that ensures the viability of those products.
Openbaar elektronisch communicatienetwerk
Published inCyberbeveiligingswetPublic electronic communications network
Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.
Openbare elektronische communicatiedienst
Published inCyberbeveiligingswetPublicly available electronic communications service
Hetgeen hieronder wordt verstaan in artikel 1.1 van de Telecommunicatiewet.
Operation of a trading platform for crypto-assets
Published inMiCAThe management of one or more multilateral systems, which bring together or facilitate the bringing together of multiple third-party buying and selling interests in crypto-assets, in the system and in accordance with its rules, in a way that results in a contract, either by exchanging crypto-assets for funds or by the exchange of crypto-assets for other crypto-assets.
Operator
Published inEU AI ActA provider, product manufacturer, deployer, authorised representative, importer or distributor.
Overheidsinstantie
Published inCyberbeveiligingswetPublic administration entity
Een in Nederland als zodanig erkende entiteit, met uitzondering van de rechterlijke macht, het parlement en de centrale bank, die voldoet aan de criteria van algemeen belang, rechtspersoonlijkheid en overheidsfinanciering of -toezicht die hieronder zijn opgenomen.
Terms starting with P
Partnership for information sharing in the AML/CFT area
Published inAMLRA mechanism that allows for the sharing and processing of information between obliged entities and, where applicable, public authorities for the purposes of the prevention and detection of money laundering, predicate offences and terrorist financing.
Pay-to-play service
Published inAMLRAn online gaming service that is accessible only upon the payment of a fee and is free from any elements of chance and wagers with monetary value.
Payment initiation channel
Published inIPRAny method, device or procedure through which payers can place payment orders with their PSP for a credit transfer, including online banking, a mobile banking application, an automated teller machine, or in any other way on the premises of the PSP.
Payment initiation service provider
Published inIPRA payment initiation service provider as defined in Article 4, point (18), of Directive (EU) 2015/2366 of the European Parliament and of the Council.
Payment service provider
Published inAMLRA payment service provider as defined in Article 4, point (11), of Directive (EU) 2015/2366.
Performance of an AI system
Published inEU AI ActThe ability of an AI system to achieve its intended purpose.
Person identification data
Published ineIDAS2A set of data, issued in accordance with Union or national law, enabling the identity of a natural or legal person, or of a natural person representing a natural or legal person, to be established.
Person seeking admission to trading
Published inMiCAA natural or legal person who applies for the admission of crypto-assets to trading on a trading platform for crypto-assets.
Personal data
Published inEU AI ActCRAeIDAS2Personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679. The EU AI Act and eIDAS 2 word it differently, and every definition is given below.
Persons known to be close associates
Published inAMLRNatural persons known to share beneficial ownership of a legal entity or arrangement, or other close business relations, with a politically exposed person, and persons holding sole beneficial ownership of an entity set up for a PEP's de facto benefit.
Persoonsgegevens
Published inCyberbeveiligingswetPersonal data
Persoonsgegevens als bedoeld in artikel 4, punt 1, van Verordening (EU) 2016/679.
Physical connection
Published inCRAA connection between electronic information systems or components implemented using physical means, including through electrical, optical or mechanical interfaces, wires or radio waves.
Placing of crypto-assets
Published inMiCAThe marketing, on behalf of or for the account of the offeror or a person seeking admission to trading, of crypto-assets to purchasers.
Placing on the market (CRA)
Published inCRAThe first making available of a product with digital elements on the Union market. The EU AI Act defines the same term differently.
Placing on the market (EU AI Act)
Published inEU AI ActThe first making available of an AI system or a general-purpose AI model on the Union market. The Cyber Resilience Act defines the same term differently.
Politically exposed person (PEP)
Published inAMLRPEP · Politically exposed person
A natural person who is or has been entrusted with prominent public functions. The AMLR lists the functions that qualify at Member State, Union and international level, and that list is reproduced below.
Politiek prominent persoon
Published inWwftPolitically exposed person (PEP)
Natuurlijke persoon die een prominente openbare functie bekleedt of heeft bekleed, met uitzondering van middelgrote of lagere functionarissen, alsmede de directe familieleden of naaste geassocieerden van deze personen.
Post-market monitoring system
Published inEU AI ActAll activities carried out by providers of AI systems to collect and review experience gained from the use of AI systems they place on the market or put into service for the purpose of identifying any need to immediately apply any necessary corrective or preventive actions.
Post-remote biometric identification system
Published inEU AI ActA remote biometric identification system other than a ‘real-time’ remote biometric identification system.
Precious metals and stones
Published inAMLRMetals and stones listed in Annex IV.
Predicate offence
Published inAMLRAny criminal activity as defined in Article 2, point (1), of Directive (EU) 2018/1673.
Product
Published ineIDAS2Hardware or software, or relevant components of hardware or software, which are intended to be used for the provision of electronic identification and trust services.
Product with digital elements
Published inCRAA software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately.
Professional football club
Published inAMLRAny legal entity that owns or manages a professional football team which participates in the national football league at the highest level, and where players are formally contracted and compensated for their services.
Profiling
Published inEU AI ActProfiling as defined in Article 4, point (4), of Regulation (EU) 2016/679.
Provider
Published inEU AI ActA natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model or where an AI system or a general-purpose AI model is developed and places it on the market or puts the AI system into service under its own name or trademark, whether for payment or free of charge.
Providing advice on crypto-assets
Published inMiCAOffering, giving or agreeing to give personalised recommendations to a client, either at the client’s request or on the initiative of the crypto-asset service provider providing the advice, in respect of one or more transactions relating to crypto-assets, or the use of crypto-asset services.
The safekeeping or controlling, on behalf of clients, of crypto-assets or of the means of access to such crypto-assets, where applicable in the form of private cryptographic keys.
Providing portfolio management on crypto-assets
Published inMiCAManaging portfolios in accordance with mandates given by clients on a discretionary client-by-client basis where such portfolios include one or more crypto-assets.
Providing services of transfer, on behalf of a natural or legal person, of crypto-assets from one distributed ledger address or account to another.
Public sector body
Published ineIDAS2A state, regional or local authority, a body governed by public law or an association formed by one or several such authorities or one or several such bodies governed by public law, or a private entity mandated by at least one of those authorities, bodies or associations to provide public services, when acting under such a mandate.
Publicly accessible space
Published inEU AI ActAny publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of whether certain conditions for access apply, and regardless of the potential capacity restrictions.
Putting into service
Published inEU AI ActThe supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose.
Terms starting with Q
Qualified certificate for electronic seal
Published ineIDAS2A certificate for an electronic seal, that is issued by a qualified trust service provider and meets the requirements laid down in Annex III.
Qualified certificate for electronic signature
Published ineIDAS2A certificate for electronic signatures, that is issued by a qualified trust service provider and meets the requirements laid down in Annex I.
Qualified certificate for website authentication
Published ineIDAS2A certificate for website authentication, which is issued by a qualified trust service provider and meets the requirements laid down in Annex IVa.
Qualified electronic archiving service
Published ineIDAS2An electronic archiving service which meets the requirements laid down in Article 45j.
Qualified electronic attestation of attributes
Published ineIDAS2An electronic attestation of attributes, which is issued by a qualified trust service provider and meets the requirements laid down in Annex VII.
Qualified electronic ledger
Published ineIDAS2An electronic ledger which meets the requirements laid down in Article 45l.
Qualified electronic registered delivery service
Published ineIDAS2An electronic registered delivery service which meets the requirements laid down in Article 44.
Qualified electronic seal
Published ineIDAS2An advanced electronic seal, which is created by a qualified electronic seal creation device, and that is based on a qualified certificate for electronic seal.
Qualified electronic seal creation device
Published ineIDAS2An electronic seal creation device that meets the requirements laid down in Annex IV.
Qualified electronic signature
Published ineIDAS2An advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures.
Qualified electronic signature creation device
Published ineIDAS2An electronic signature creation device that meets the requirements laid down in Annex II.
Qualified electronic time stamp
Published ineIDAS2An electronic time stamp which meets the requirements laid down in Article 42.
Qualified investors
Published inMiCAQualified investors as defined in Article 2, point (e), of Regulation (EU) 2017/1129.
Qualified trust service
Published ineIDAS2A trust service that meets the applicable requirements laid down in this Regulation.
Qualified trust service provider
Published ineIDAS2A trust service provider who provides one or more qualified trust services and is granted the qualified status by the supervisory body.
Qualifying holding
Published inMiCAA direct or indirect holding of 10% or more of the capital or voting rights in a crypto-asset service provider or an issuer of an asset-referenced token, or a holding making it possible to exercise significant influence over its management.
Terms starting with R
Real-time remote biometric identification system
Published inEU AI ActA remote biometric identification system whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay, and comprises not only instant identification, but also limited short delays in order to avoid circumvention.
Real-world testing plan
Published inEU AI ActA document that describes the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real world conditions.
Reasonably foreseeable misuse (CRA)
Published inCRAThe use of a product with digital elements in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems. The EU AI Act defines the same term differently.
Reasonably foreseeable misuse (EU AI Act)
Published inEU AI ActThe use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems. The Cyber Resilience Act defines the same term differently.
Reasonably foreseeable use
Published inCRAUse that is not necessarily the intended purpose supplied by the manufacturer in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation, but which is likely to result from reasonably foreseeable human behaviour or technical operations or interactions.
Recall
Published inCRARecall as defined in Article 3, point (22), of Regulation (EU) 2019/1020.
Recall of an AI system
Published inEU AI ActAny measure aimed at achieving the return to the provider or taking out of service or disabling the use of an AI system made available to deployers.
The reception from a person of an order to purchase or sell one or more crypto-assets or to subscribe for one or more crypto-assets and the transmission of that order to a third party for execution.
Relying party
Published ineIDAS2A natural or legal person that relies upon an electronic identification, European Digital Identity Wallets or other electronic identification means, or a trust service.
Remote biometric identification system
Published inEU AI ActAn AI system for the purpose of identifying natural persons, without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database.
Remote data processing
Published inCRAData processing at a distance for which the software is designed and developed by the manufacturer, or under the responsibility of the manufacturer, and the absence of which would prevent the product with digital elements from performing one of its functions.
Remote qualified electronic seal creation device
Published ineIDAS2A qualified electronic seal creation device that is managed by a qualified trust service provider in accordance with Article 39a on behalf of a seal creator.
Remote qualified electronic signature creation device
Published ineIDAS2A qualified electronic signature creation device that is managed by a qualified trust service provider in accordance with Article 29a on behalf of a signatory.
Representant
Published inCyberbeveiligingswetRepresentative
Een in de Europese Unie gevestigde natuurlijke persoon of rechtspersoon die uitdrukkelijk is aangewezen om op te treden namens een niet in de Unie gevestigde aanbieder van digitale diensten. De volledige opsomming van diensten staat hieronder.
Reserve of assets
Published inMiCAThe basket of reserve assets securing the claims against the issuer.
Retail holder
Published inMiCAA natural person who is acting for purposes which are outside that person’s trade, business, craft or profession.
Retail payment system
Published inIPRA payment system the main purpose of which is to process, clear or settle credit transfers or direct debits which are primarily of small amount, and that is not a large-value payment system.
Richtlijn
Published inWwftDirective
Richtlijn (EU) 2015/849 van het Europees Parlement en de Raad van 20 mei 2015 inzake de voorkoming van het gebruik van het financiële stelsel voor het witwassen van geld of terrorismefinanciering (PbEU 2015, L 141).
Richtlijn (EU) 2015/1535
Published inCyberbeveiligingswetDirective (EU) 2015/1535
Richtlijn (EU) 2015/1535 van het Europees Parlement en de Raad van 9 september 2015 betreffende een informatieprocedure op het gebied van technische voorschriften en regels betreffende de diensten van de informatiemaatschappij (PbEU 2015, L 241).
Richtlijn (EU) 2018/1972
Published inCyberbeveiligingswetDirective (EU) 2018/1972
Richtlijn (EU) 2018/1972 van het Europees Parlement en de Raad van 11 december 2018 tot vaststelling van het Europees wetboek voor elektronische communicatie (PbEU 2018, L 321).
Risico
Published inCyberbeveiligingswetRisk
Het potentieel voor verlies of verstoring veroorzaakt door een incident, uitgedrukt als een combinatie van de omvang van een dergelijk verlies of een dergelijke verstoring en de waarschijnlijkheid dat het incident zich voordoet.
Risk
Published inEU AI ActThe combination of the probability of an occurrence of harm and the severity of that harm.
Terms starting with S
Safety component
Published inEU AI ActA component of a product or of an AI system which fulfils a safety function for that product or AI system, or the failure or malfunctioning of which endangers the health and safety of persons or property.
Sand box plan
Published inEU AI ActA document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for the activities carried out within the sandbox.
Self-hosted address
Published inAMLRA self-hosted address as defined in Article 3, point (20), of Regulation (EU) 2023/1113.
Self-regulatory body
Published inAMLRA body that represents members of professions referred to in Article 3(1), points (3)(a), (b) and (f), or that has a role in regulating them, in performing certain supervisory or monitoring functions and in ensuring the enforcement of the rules that apply to them.
Senior management
Published inAMLRAn officer or employee with sufficient knowledge of the obliged entity’s money laundering and terrorist financing risk exposure and sufficient seniority to take decisions affecting its risk exposure, which need not, in all cases, be a member of the management body.
Sensitive operational data
Published inEU AI ActOperational data related to activities of prevention, detection, investigation, or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings.
Serious incident
Published inEU AI ActAn incident or malfunctioning of an AI system that directly or indirectly leads to any of the following: (a) the death of a person, or serious harm to a person’s health; (b) a serious and irreversible disruption of the management or operation of critical infrastructure; (c) the infringement of obligations under Union law intended to protect fundamental rights; (d) serious harm to property or the environment.
Shell bank (AMLR)
Published inAMLRA credit institution or financial institution, or an institution that carries out activities equivalent to those carried out by credit institutions and financial institutions, incorporated in a jurisdiction in which it has no physical presence, involving meaningful mind and management, and which is unaffiliated with a regulated financial group. The Wwft carries a parallel definition in Dutch.
Shell bank (Wwft)
Published inWwftEen kredietinstelling of financiële instelling, of een instelling die soortgelijke activiteiten uitoefent, die is opgericht in een rechtsgebied waarin zij geen fysieke aanwezigheid heeft die betekenisvolle leiding en beheer inhoudt, en die niet is aangesloten bij een gereglementeerde financiële groep. De AMLR bevat een gelijkluidende definitie in het Engels.
Shell crypto-asset service provider
Published inAMLRAn entity incorporated in a jurisdiction in which it has no physical presence, involving meaningful mind and management, and which is unaffiliated with a regulated financial group.
Signatory
Published ineIDAS2A natural person who creates an electronic signature.
Significant cyber threat
Published inDORAA cyber threat that could plausibly result in a major ICT-related incident based on technical capabilities, intent of malicious actors, or system vulnerabilities.
Significant cybersecurity risk
Published inCRAA cybersecurity risk which, based on its technical characteristics, can be assumed to have a high likelihood of an incident that could lead to a severe negative impact, including by causing considerable material or non-material loss or disruption.
Significant incident
Published inCyberbeveiligingswetEen incident als bedoeld in artikel 25, tweede lid.
Significante cyberdreiging
Published inCyberbeveiligingswetSignificant cyber threat
Een cyberdreiging waarvan op basis van de technische kenmerken ervan mag worden aangenomen dat zij ernstige gevolgen kan hebben voor de netwerk- en informatiesystemen van een entiteit of de gebruikers van de diensten van de entiteit door aanzienlijke materiële of immateriële schade te veroorzaken.
Software
Published inCRAThe part of an electronic information system which consists of computer code.
Software bill of materials
Published inCRAA formal record containing details and supply chain relationships of components included in the software elements of a product with digital elements.
Special categories of personal data
Published inEU AI ActThe categories of personal data referred to in Article 9(1) of Regulation (EU) 2016/679, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725.
Staat
Published inWwftState
Een soevereine staat of een autonoom gebiedsdeel daarvan.
Strong user authentication
Published ineIDAS2An authentication based on the use of at least two authentication factors from different categories of either knowledge, possession or inherence, that are independent, and designed to protect the confidentiality of the authentication data.
Subject for the purpose of real world testing
Published inEU AI ActA natural person who participates in testing in real world conditions.
Substantial modification (CRA)
Published inCRAA change to the product with digital elements following its placing on the market, which affects the compliance of the product with digital elements with the essential cybersecurity requirements set out in Part I of Annex I or which results in a modification to the intended purpose for which the product with digital elements has been assessed. The EU AI Act defines the same term differently.
Substantial modification (EU AI Act)
Published inEU AI ActA change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or modification of the intended purpose for which the AI system has been assessed. The Cyber Resilience Act defines the same term differently.
Supervisory authority
Published inAMLRThe national public body officially empowered to supervise the compliance of obliged entities with the requirements of this Regulation and Regulation (EU) 2024/1620, or an equivalent body.
Support period
Published inCRAThe period during which a manufacturer is required to ensure that vulnerabilities of a product with digital elements are handled effectively and in accordance with the essential cybersecurity requirements set out in Part II of Annex I.
Systemic risk
Published inEU AI ActA risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain.
Terms starting with T
Targeted financial restrictive measure
Published inIPRAn asset freeze imposed on a person, body or entity or a prohibition on making funds or economic resources available to a person, body or entity, or for its benefit, either directly or indirectly, pursuant to restrictive measures adopted in accordance with Article 215 TFEU.
Targeted financial sanctions
Published inAMLRBoth asset freezing and prohibitions to make funds or other assets available, directly or indirectly, for the benefit of designated persons and entities pursuant to Council Decisions adopted on the basis of Article 29 of the Treaty on European Union and Council Regulations adopted on the basis of Article 215 of the Treaty on the Functioning of the European Union.
Technische specificatie
Published inCyberbeveiligingswetTechnical specification
Een document waarin de technische vereisten worden voorgeschreven waaraan een product, proces, dienst of systeem moet voldoen.
Terrorist financing
Published inAMLRThe provision or collection of funds, by any means, directly or indirectly, with the intention that they be used or in the knowledge that they are to be used, in full or in part, in order to carry out any of the offences within the meaning of Articles 3 to 10 of Directive (EU) 2017/541.
Testing data
Published inEU AI ActData used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service.
Testing in real world conditions
Published inEU AI ActThe temporary testing of an AI system for its intended purpose outside a laboratory or simulated environment, to gather reliable data and verify conformity. The AI Act states that such testing is not placing on the market or putting into service, provided the conditions in Chapter V are met.
Third country
Published inAMLRAny country, territory or jurisdiction outside the European Union.
Threat-led penetration testing (TLPT)
Published inDORATLPT · Threat-led penetration testing
A controlled testing framework that mimics the tactics, techniques, and procedures (TTPs) of real-life threat actors to assess and test the resilience of critical live production systems.
Toezichthouder
Published inWwftSupervisor
Een toezichthouder als bedoeld in artikel 24.
Training data
Published inEU AI ActData used for training an AI system through fitting its learnable parameters.
Transactie
Published inWwftTransaction
Een handeling of samenstel van handelingen van of ten behoeve van een cliënt waarvan de instelling ten behoeve van haar dienstverlening aan die cliënt heeft kennisgenomen.
Trust or company service provider
Published inAMLRTrust · company service provider
Any natural or legal person that by way of business provides company formation, directorship or partnership services, a registered office or correspondence address, trust or fiduciary services, or a nominee shareholder for another person. The full list is reproduced below.
Trust service
Published ineIDAS2An electronic service normally provided for remuneration, covering the creation, verification and validation of electronic signatures, seals, time stamps, registered delivery services and attestations of attributes, certificates for website authentication, their preservation, and the recording of electronic data. The full list is reproduced below.
Trust service provider
Published ineIDAS2A natural or a legal person who provides one or more trust services either as a qualified or as a non-qualified trust service provider.
Trustkantoor
Published inWwftTrust office
Trustkantoor als bedoeld in artikel 1, eerste lid, van de Wet toezicht trustkantoren 2018.
Terms starting with U
Uiteindelijk belanghebbende
Published inWwftBeneficial owner
Natuurlijke persoon die de uiteindelijke eigenaar is van of zeggenschap heeft over een cliënt, dan wel de natuurlijke persoon voor wiens rekening een transactie of activiteit wordt verricht.
Union harmonisation legislation
Published inCRAUnion legislation listed in Annex I to Regulation (EU) 2019/1020 and any other Union legislation harmonising the conditions for the marketing of products to which that Regulation applies.
User
Published ineIDAS2A natural or legal person, or a natural person representing a natural or legal person, that uses European Digital Identity Wallets or trust services provided in accordance with this Regulation.
Utility token
Published inMiCAA type of crypto-asset which is only intended to provide access to a good or a service supplied by its issuer.
Terms starting with V
Validation
Published ineIDAS2The process of verifying and confirming that an electronic signature, an electronic seal, person identification data, an electronic attestation of attributes, an electronic time stamp, an electronic registered delivery service, an electronic ledger, a qualified certificate for website authentication or a European Digital Identity Wallet is valid.
Validation data (eIDAS2)
Published ineIDAS2Data that is used to validate an electronic signature, an electronic seal, electronic time stamps, electronic registered delivery services, electronic attestations of attributes, European Digital Identity Wallets, qualified certificates for website authentication or an electronic ledger. The EU AI Act defines the same term differently.
Validation data (EU AI Act)
Published inEU AI ActData used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting. eIDAS 2 defines the same term differently.
Validation dataset
Published inEU AI ActA separate dataset or part of the training dataset, either as a fixed or variable split.
Verifiëren
Published inWwftVerify
Vaststellen dat de opgegeven identiteit overeenkomt met de werkelijke identiteit.
Verlener van vertrouwensdiensten
Published inCyberbeveiligingswetTrust service provider
Een natuurlijke persoon of rechtspersoon die een of meer vertrouwensdiensten verleent als een gekwalificeerde of als een niet-gekwalificeerde verlener van vertrouwensdiensten.
Verordening (EG) nr. 300/2008
Published inCyberbeveiligingswetRegulation (EC) No 300/2008
Verordening (EG) nr. 300/2008 van het Europees Parlement en de Raad van 11 maart 2008 inzake gemeenschappelijke regels op het gebied van de beveiliging van de burgerluchtvaart en tot intrekking van Verordening (EG) nr. 2320/2002 (PbEU 2008, L 97).
Verordening (EU) 2016/679
Published inCyberbeveiligingswetRegulation (EU) 2016/679
Verordening (EU) 2016/679 van het Europees Parlement en de Raad van 27 april 2016 betreffende de bescherming van natuurlijke personen in verband met de verwerking van persoonsgegevens en betreffende het vrije verkeer van die gegevens en tot intrekking van Richtlijn 95/46/EG (algemene verordening gegevensbescherming) (PbEU 2016, L 119).
Verordening (EU) 2018/1139
Published inCyberbeveiligingswetRegulation (EU) 2018/1139
Verordening (EU) 2018/1139 van het Europees Parlement en de Raad van 4 juli 2018 inzake gemeenschappelijke regels op het gebied van burgerluchtvaart en tot oprichting van een Agentschap van de Europese Unie voor de veiligheid van de luchtvaart (PbEU 2018, L 212).
Verordening (EU) 2019/881
Published inCyberbeveiligingswetRegulation (EU) 2019/881
Verordening (EU) 2019/881 van het Europees Parlement en de Raad van 17 april 2019 inzake ENISA (het Agentschap van de Europese Unie voor cyberbeveiliging) en inzake de certificering van de cyberbeveiliging van informatie- en communicatietechnologie en tot intrekking van Verordening (EU) nr. 526/2013 (de cyberbeveiligingsverordening) (PbEU 2019, L 151).
Verordening (EU) 2022/2554
Published inCyberbeveiligingswetRegulation (EU) 2022/2554
Verordening (EU) 2022/2554 van het Europees Parlement en de Raad van 14 december 2022 betreffende digitale operationele weerbaarheid voor de financiële sector (PbEU 2022, L 333).
Verordening (EU) nr. 910/2014
Published inCyberbeveiligingswetRegulation (EU) No 910/2014
Verordening (EU) nr. 910/2014 van het Europees Parlement en de Raad van 23 juli 2014 betreffende elektronische identificatie en vertrouwensdiensten voor elektronische transacties in de interne markt en tot intrekking van Richtlijn 1999/93/EG (PbEU 2014, L 257).
Verordening (EU) nr. 1025/2012
Published inCyberbeveiligingswetRegulation (EU) No 1025/2012
Verordening (EU) nr. 1025/2012 van het Europees Parlement en de Raad van 25 oktober 2012 betreffende Europese normalisatie (PbEU 2012, L 316).
Verordening betreffende bij geldovermakingen en overdrachten van cryptoactiva te voegen informatie
Published inWwftRegulation on information accompanying transfers of funds and certain crypto-assets
Verordening (EU) 2023/1113 van het Europees Parlement en de Raad van 31 mei 2023 betreffende bij geldovermakingen en overdrachten van bepaalde cryptoactiva te voegen informatie en tot wijziging van Richtlijn (EU) 2015/849 (PbEU 2023, L 156).
Verordening markten in cryptoactiva
Published inWwftMarkets in Crypto-Assets Regulation
Verordening (EU) 2023/1114 van het Europees Parlement en de Raad van 31 mei 2023 betreffende markten in cryptoactiva en tot wijziging van de Verordeningen (EU) nr. 1093/2010 en (EU) nr. 1095/2010 en de Richtlijnen 2013/36/EU en (EU) 2019/1937 (PbEU 2023, L 150).
Vertrouwensdienst
Published inCyberbeveiligingswetTrust service
Een elektronische dienst die gewoonlijk tegen vergoeding wordt verricht, waaronder het aanmaken, verifiëren en valideren van elektronische handtekeningen, zegels, tijdstempels en attesteringen, en het valideren van certificaten. De volledige opsomming staat hieronder.
Virtuele valuta
Published inWwftVirtual currency
Een digitale weergave van waarde die niet door een centrale bank of overheid wordt uitgegeven of gegarandeerd, niet noodzakelijk aan een wettelijk vastgestelde valuta is gekoppeld en niet de juridische status van valuta of geld heeft, maar door natuurlijke of rechtspersonen als ruilmiddel wordt aanvaard en die elektronisch kan worden overgedragen, opgeslagen en verhandeld.
Vulnerability (CRA)
Published inCRAA weakness, susceptibility or flaw of a product with digital elements that can be exploited by a cyber threat. DORA defines the same term differently.
Vulnerability (DORA)
Published inDORAA flaw, weakness, or design error in an ICT asset or system that can be leveraged or exploited by a cyber threat. The Cyber Resilience Act defines the same term differently.
Terms starting with W
Wealth management services
Published inAMLRThe provision of banking, investment, fiduciary, estate planning or tax advisory services, in an integrated or personalised manner, to high-net-worth individuals.
Widespread infringement
Published inEU AI ActAn act or omission contrary to Union law protecting individuals that harms, or is likely to harm, the collective interests of individuals in at least two Member States. The AI Act sets this out in two limbs, both reproduced below.
Withdrawal
Published inCRAWithdrawal as defined in Article 3, point (23), of Regulation (EU) 2019/1020.
Withdrawal of an AI system
Published inEU AI ActAny measure aimed at preventing an AI system in the supply chain being made available on the market.
Witwassen
Published inWwftMoney laundering
Het plegen van een misdrijf als bedoeld in de artikelen 420bis, 420quater of 420sexies van het Wetboek van Strafrecht.
Terms starting with Z
Zakelijke relatie
Published inWwftBusiness relationship
Een zakelijke, professionele of commerciële relatie tussen een instelling en een cliënt die verband houdt met de beroeps- of bedrijfsactiviteiten van die instelling en waarvan op het tijdstip dat het contact wordt gelegd, wordt verwacht dat deze enige tijd zal duren.
Not sure which of these apply to you?
Applicability is a fact about your organisation, not a reading exercise. We derive the set from how your firm is actually built, and show the reasoning.