Reputation · Financial Databases · GDPR

When your name becomes
a liability

A single entry in a financial intelligence database can close every door: bank accounts, credit lines, business relationships, employment. The entry may be wrong. It may be years out of date. Most people do not know it exists until the damage is done.

⛔ Bank accounts closed
⛔ Mortgage applications refused
⛔ Business relationships severed
⛔ Professional licences at risk
⛔ Counterparties alerted

The Databases

WorldCheck & WorldCompliance

These are not government databases. They are commercial risk intelligence products — compiled from public sources, used by financial institutions worldwide to make decisions that can end careers and close accounts.

LSEG · Refinitiv
WorldCheck

Originally created in 2000, WorldCheck is now owned by the London Stock Exchange Group through its Refinitiv subsidiary. It is the world's most widely used risk intelligence database — consulted by banks, law firms, insurers, regulators, and multinationals before entering any significant relationship.

10,000+
client institutions
170+
countries
3M+
profiles
PEPs Sanctions Adverse Media Enforcement Actions Criminal Records
LexisNexis Risk Solutions
WorldCompliance

WorldCompliance is the risk intelligence database of LexisNexis Risk Solutions, part of the RELX Group. It serves compliance teams performing KYC (Know Your Customer) and AML (Anti-Money Laundering) screening, drawing on public records, regulatory sources, and adverse media across hundreds of jurisdictions.

An entry in either database triggers the same institutional response: enhanced due diligence, account review, and often relationship termination — without any notification to the subject.

PEPs & Associates Sanctions Regulatory Actions Watchlists
How your data moves from database to decision
👤
YouOpen an account, apply for finance, or onboard as a client
KYC check
🏦
InstitutionQueries WorldCheck or WorldCompliance automatically
Match found
🗄️
DatabaseReturns profile — PEP, adverse media, or watchlist hit
Risk flag
🚫
RejectionAccount refused, closed, or frozen — no explanation given

The Impact

What a database entry actually does to you

Institutions do not disclose that they have run a WorldCheck or WorldCompliance check, and they are not required to explain that an adverse entry was the reason for a refusal. The consequences can cascade across every aspect of a person's financial and professional life — often for years.

🏦
Bank account closure
Existing accounts are closed with little notice. New accounts refused across multiple banks simultaneously — often due to shared data between institutions.
🏠
Mortgage & credit refused
Mortgage applications, personal loans, and credit facilities are declined. The underlying reason — a database flag — is rarely disclosed by the lender.
🤝
Business relationships severed
Corporate counterparties, investors, and suppliers run their own KYC checks. A flag triggers immediate relationship review — and often termination without explanation.
💼
Employment difficulties
Regulated employers in financial services, law, and government conduct background screening. A database hit can end a hiring process or trigger disciplinary action.
📜
Professional licensing
Regulatory bodies and licensing authorities use financial crime databases. Adverse entries can affect fitness and propriety assessments for directors, lawyers, and financial professionals.
👨‍👩‍👧
Family members affected
Databases record "close associates" and family members of listed individuals as PEP-adjacent. Spouses, children, and business partners can be flagged without any adverse finding against them personally.
The cascade — how one database entry spreads
DATABASE ENTRY WorldCheck / WorldCompliance Banks & Lenders Accounts closed/refused Employers & Regulators Fitness & propriety at risk Business Partners Relationships terminated Insurance & Finance Applications declined Family & Associates PEP-adjacent flags Investors & Counterparties KYC failures, exit

Key Concept

What is a Politically Exposed Person?

A PEP is not a criminal designation. It is a risk category — a label applied by financial institutions to individuals who hold or have held prominent public functions, on the basis that their position creates a heightened risk of involvement in bribery or corruption. Being classified as a PEP triggers mandatory enhanced due diligence under anti-money laundering regulations worldwide.

The three categories of PEP

Foreign PEPs
Individuals who hold or have held prominent public functions in a foreign country — including heads of state, heads of government, ministers, members of parliament, judges of supreme courts, senior military officers, and senior executives of state-owned enterprises.
Domestic PEPs
Individuals holding prominent public functions in the institution's own jurisdiction. The treatment of domestic PEPs varies by country, but the FATF recommendations require a risk-based approach in all cases.
International Organisation PEPs
Senior officials of international organisations — including UN agencies, the World Bank, the IMF, and regional development banks.
Family members & close associates
Spouses, children, parents, and siblings of PEPs are automatically treated as PEP-adjacent. So are individuals with close business, personal, or financial relationships with a PEP. These individuals may be flagged without any adverse finding of their own.

PEP status does not expire automatically. Databases frequently retain PEP classifications for years — sometimes indefinitely — after an individual has left public office. The standard applied varies between databases, and the burden of demonstrating that status should be removed falls on the individual.

PEP CLASSIFICATION PEP Public official Head of State / Government Minister Senior Judiciary / Military State-Owned Enterprise Exec Family & Associates Senior Political Party Official ⚠ PEP status persists after leaving office — sometimes indefinitely

Your Rights

The Right to Be Forgotten — and your other data rights

Financial crime databases process personal data. In the UK and EU, that means the GDPR applies — giving individuals a suite of rights they can exercise directly against the database operator. These rights exist independently of any legal proceedings and can be invoked by anyone whose data is held.

Article 15 GDPR

Right of Access

You are entitled to know whether a database holds data about you and to receive a copy of it. A Data Subject Access Request (DSAR) is the essential first step — you cannot challenge what you cannot see.

Article 16 GDPR

Right to Rectification

Where your data is inaccurate or incomplete, you have the right to have it corrected. This covers factual errors, outdated information, and misidentification — all common problems in financial crime databases.

Article 17 GDPR

Right to Erasure — The Right to Be Forgotten

Where data is no longer necessary, is being processed unlawfully, or where you have withdrawn consent, you have the right to demand deletion. This is the principal route to removal from WorldCheck and WorldCompliance.

Article 21 GDPR

Right to Object

You can object to the processing of your personal data where it is based on legitimate interests. The database operator must then demonstrate compelling legitimate grounds that override your interests — a high bar in many cases.

How the Right to Be Forgotten works in practice
01 Data Subject Access Request 02 Identify Source & Legal Basis 03 Formal Erasure / Rectification Request 04 DPA Complaint if refused Entry erased or corrected

Our Services

How Stradalex helps

Most people discover a database problem only after a refusal. By then, the entry may have already been shared with multiple institutions. Acting quickly and methodically — across all relevant databases and all relevant rights — is the only way to contain the damage.

1

Data Subject Access Request (DSAR)

We file formal access requests with WorldCheck (Refinitiv/LSEG) and WorldCompliance (LexisNexis Risk Solutions) on your behalf. Under the GDPR, operators must respond within one month. The DSAR produces the exact text of the entry held — the starting point for every challenge.

2

Source identification and legal analysis

Database entries cite sources — news articles, court records, regulatory filings. We identify each source, assess its accuracy and currency, and determine the legal basis the operator is relying on for processing. Inaccurate or outdated sources are challenged directly. Where the legal basis is insufficient, we build the case for erasure on that ground.

3

Formal erasure and rectification requests

We submit formal requests for erasure under Article 17 GDPR or rectification under Article 16, setting out in full the legal and factual basis for the challenge. Where a client has served a sentence, where charges were dropped, where an acquittal was entered, or where the data is simply wrong, these are powerful grounds. The operator has one month to respond.

4

Supervisory authority complaints

Where erasure or rectification is refused, we file complaints with the relevant national data protection authority — the ICO in the UK, or the competent DPA in the EU. A DPA investigation into a database operator carries significant weight and often produces a result that a direct request alone could not achieve.

5

Judicial proceedings

Where regulatory channels do not produce a result, we bring proceedings in the appropriate court to obtain a binding erasure order. In parallel, we identify and address all institutions that have already been provided with the adverse data, to contain the spread of erroneous information across the financial system.

Stradalex

Instruct us

Most clients come to us after a bank refusal or an unexplained loss of a business relationship. The first step is finding out exactly what the database holds — which our DSAR process produces within weeks. From there, the challenge strategy depends on what the entry says, what it is based on, and how long it has been there.

PEP status, adverse media entries, old convictions, dropped charges, and simple misidentification — all of these are grounds we have used successfully to secure erasure or correction. The database operators are not infallible, and the law gives individuals real tools to push back.