Reputation · Financial Databases · GDPR
A single entry in a financial intelligence database can close every door: bank accounts, credit lines, business relationships, employment. The entry may be wrong. It may be years out of date. Most people do not know it exists until the damage is done.
The Databases
These are not government databases. They are commercial risk intelligence products — compiled from public sources, used by financial institutions worldwide to make decisions that can end careers and close accounts.
Originally created in 2000, WorldCheck is now owned by the London Stock Exchange Group through its Refinitiv subsidiary. It is the world's most widely used risk intelligence database — consulted by banks, law firms, insurers, regulators, and multinationals before entering any significant relationship.
WorldCompliance is the risk intelligence database of LexisNexis Risk Solutions, part of the RELX Group. It serves compliance teams performing KYC (Know Your Customer) and AML (Anti-Money Laundering) screening, drawing on public records, regulatory sources, and adverse media across hundreds of jurisdictions.
An entry in either database triggers the same institutional response: enhanced due diligence, account review, and often relationship termination — without any notification to the subject.
The Impact
Institutions do not disclose that they have run a WorldCheck or WorldCompliance check, and they are not required to explain that an adverse entry was the reason for a refusal. The consequences can cascade across every aspect of a person's financial and professional life — often for years.
Key Concept
A PEP is not a criminal designation. It is a risk category — a label applied by financial institutions to individuals who hold or have held prominent public functions, on the basis that their position creates a heightened risk of involvement in bribery or corruption. Being classified as a PEP triggers mandatory enhanced due diligence under anti-money laundering regulations worldwide.
PEP status does not expire automatically. Databases frequently retain PEP classifications for years — sometimes indefinitely — after an individual has left public office. The standard applied varies between databases, and the burden of demonstrating that status should be removed falls on the individual.
Your Rights
Financial crime databases process personal data. In the UK and EU, that means the GDPR applies — giving individuals a suite of rights they can exercise directly against the database operator. These rights exist independently of any legal proceedings and can be invoked by anyone whose data is held.
You are entitled to know whether a database holds data about you and to receive a copy of it. A Data Subject Access Request (DSAR) is the essential first step — you cannot challenge what you cannot see.
Where your data is inaccurate or incomplete, you have the right to have it corrected. This covers factual errors, outdated information, and misidentification — all common problems in financial crime databases.
Where data is no longer necessary, is being processed unlawfully, or where you have withdrawn consent, you have the right to demand deletion. This is the principal route to removal from WorldCheck and WorldCompliance.
You can object to the processing of your personal data where it is based on legitimate interests. The database operator must then demonstrate compelling legitimate grounds that override your interests — a high bar in many cases.
Our Services
Most people discover a database problem only after a refusal. By then, the entry may have already been shared with multiple institutions. Acting quickly and methodically — across all relevant databases and all relevant rights — is the only way to contain the damage.
We file formal access requests with WorldCheck (Refinitiv/LSEG) and WorldCompliance (LexisNexis Risk Solutions) on your behalf. Under the GDPR, operators must respond within one month. The DSAR produces the exact text of the entry held — the starting point for every challenge.
Database entries cite sources — news articles, court records, regulatory filings. We identify each source, assess its accuracy and currency, and determine the legal basis the operator is relying on for processing. Inaccurate or outdated sources are challenged directly. Where the legal basis is insufficient, we build the case for erasure on that ground.
We submit formal requests for erasure under Article 17 GDPR or rectification under Article 16, setting out in full the legal and factual basis for the challenge. Where a client has served a sentence, where charges were dropped, where an acquittal was entered, or where the data is simply wrong, these are powerful grounds. The operator has one month to respond.
Where erasure or rectification is refused, we file complaints with the relevant national data protection authority — the ICO in the UK, or the competent DPA in the EU. A DPA investigation into a database operator carries significant weight and often produces a result that a direct request alone could not achieve.
Where regulatory channels do not produce a result, we bring proceedings in the appropriate court to obtain a binding erasure order. In parallel, we identify and address all institutions that have already been provided with the adverse data, to contain the spread of erroneous information across the financial system.
Stradalex
Most clients come to us after a bank refusal or an unexplained loss of a business relationship. The first step is finding out exactly what the database holds — which our DSAR process produces within weeks. From there, the challenge strategy depends on what the entry says, what it is based on, and how long it has been there.
PEP status, adverse media entries, old convictions, dropped charges, and simple misidentification — all of these are grounds we have used successfully to secure erasure or correction. The database operators are not infallible, and the law gives individuals real tools to push back.