Sanctions AgentEU sanctions · Danish PEP

Privacy policy

How Sanctions Agent handles personal data

Last updated: 28 September 2026

1. Who is responsible for your data

Sanctions Agent is run by a private individual, not a company. The data controller is:

Niki Mench
Roskilde, Denmark
Email: hello@sanctionsagent.eu

No data protection officer has been appointed, as the law doesn't require one for a service of this size and kind. If the service is later run by a company, this policy will be updated to name it, and account holders will be emailed before the change takes effect.

2. Summary

  • We only process what is needed to run a screening service: your email address to sign in, and the details you submit to be checked.
  • Dates of birth, nationalities, addresses and ID numbers you submit are never stored. They are used in memory to calculate the result and then discarded.
  • We keep a short log of the names that are searched for, for 90 days, to find and fix matching errors and to detect misuse. It is encrypted, kept on an isolated system, and never shared or sold.
  • Accounts that haven't been used for 24 months are deleted automatically.
  • No advertising, no tracking, no analytics tools. The website sets no cookies.

3. Whose data we process

  • Users: people who sign in and run checks, usually on behalf of a business.
  • People who are searched for: the persons and companies whose names users check.
  • People who appear on the source lists: the EU sanctions list and the Danish PEP lists.
  • Website visitors.

4. What we process, why, and on what legal basis

4.1 Your account

DataYour email address; a normalised form of it, used to recognise addresses that deliver to the same inbox (for example name+tag@gmail.com); the date your account was created; the date it was last used; your plan.
PurposeLetting you sign in, providing the service you signed up for, and deleting accounts that are no longer used.
Legal basisPerformance of a contract with you, GDPR Art. 6(1)(b).

4.2 Signing in and keeping accounts secure

DataThe one-time login code (stored only as a one-way hash); sign-in and access tokens (stored only as hashes); your IP address and a hashed form of your email address, used to limit repeated login attempts; a temporary cookie during sign-in (section 11).
PurposeSending you a login code, keeping you signed in, and protecting accounts against password-guessing, email flooding and takeover.
Legal basisArt. 6(1)(b) (providing the sign-in you asked for), and our legitimate interest in the security of the service and its users, Art. 6(1)(f).

4.3 Running a check

When you screen a person or company, you decide whom to screen and why, so for that screening you are the controller and need your own legal basis (for most users, the customer due diligence duties in the Danish Anti-Money Laundering Act, hvidvaskloven, or equivalent rules). We use the details you submit only to calculate the result. Apart from the search log in section 4.4, nothing you submit is stored, and neither are the results we return.

If you use Sanctions Agent through an AI assistant such as Claude, we receive only the details the assistant sends in the check itself, not your conversation. Your use of the assistant is covered by its provider's own privacy policy.

4.4 The search log

DataThe name that was searched; which check was used (sanctions or PEP) and whether a person or company was specified; the number of hits and the highest match score; whether a date of birth, nationality, country, address or ID number was supplied (yes/no only, never the values); the account that ran the search; a pseudonymised identifier derived from the IP address (a keyed one-way hash, not the address itself); the time.
PurposeSee section 5.
Legal basisOur legitimate interests, Art. 6(1)(f).
RetentionDeleted automatically after 90 days.

4.5 Usage counting

DataThe number of checks per account per calendar month: a number, not what was searched.
PurposeApplying your plan's monthly limit (accounts whose email addresses deliver to the same inbox share one limit), and a record of use of the service over time.
Legal basisArt. 6(1)(b).
Retention24 months.

4.6 Technical logs

DataIP address, time, requested address (URL), response status and browser/client type.
PurposeOperating the service, diagnosing faults and detecting attacks.
Legal basisLegitimate interest in the security and operation of the service, Art. 6(1)(f).
Retention14 days.

4.7 The website

This website uses no cookies, no analytics, no tracking and no third-party content. The only data processed is the technical log in section 4.6.

5. Our legitimate interests in keeping a search log

We don't keep the search log to track users. We keep it because a screening service can't be run safely and responsibly without it:

  1. Making sure the checks actually work. A sanctions check that misses a real match fails silently: it returns "no hits", which looks exactly like a correct answer. Names reach us in endless variations: different spellings and transliterations of the same name, missing accents, reversed word order, Cyrillic script, company names with and without legal suffixes. The only reliable way to find the forms our matching doesn't handle is to review real searches that returned no or weak results, and fix the cause. Several matching errors in this service were found exactly this way. Accurate screening protects our users, and it serves the wider public interest in EU sanctions and anti-money-laundering rules working as intended.
  2. Preventing misuse, including misuse against the people being searched for. This service exists for businesses meeting their screening duties. It must not become a tool for looking people up out of curiosity, for harassment, or for collecting information about private individuals. The log lets us spot patterns that don't fit legitimate screening (large numbers of searches for apparently private individuals, bulk extraction of the lists, or an account behaving as if it has been taken over) and suspend the account. This is as much in the interest of the people being searched for as in ours.
  3. Keeping the service secure and available, for example by identifying automated abuse.
  4. Understanding overall use to plan capacity and the future of the service, including a possible paid plan. For this purpose only aggregated figures are used, such as the number of checks or the share of searches with hits, and never individual searches.

How we balance this against the interests of the people concerned. We have assessed that these interests are not overridden by the rights of the people being searched for, because of how the log is limited:

  • Minimal data: only the name is kept; never date of birth, nationality, address or ID number, and never the matched list entry itself.
  • Short retention: deleted automatically after 90 days.
  • Isolation: stored encrypted, in a separate system that can't be reached from the internet. The part of the service that answers checks can add entries but can't read them back.
  • Restricted use: only the operator can read the log. It is never sold, shared, used for marketing, combined with other sources, or used to build profiles of the people searched for.
  • Expected use: screening a name with a compliance tool is something a business's customers can reasonably expect.

You can object to this processing at any time (section 14). We will then stop, unless we have compelling legitimate grounds, for example an ongoing investigation into misuse of an account.

6. If someone searched for you

We receive the names of people being screened from our users, not from those people themselves. We have no contact details for them, so we can't inform each person individually (GDPR Art. 14(5)(b)); this policy is published instead. The business that screened you is responsible for its own screening and should have told you about it in its own privacy notice. We only hold the limited search-log entry described in section 4.4, for at most 90 days. You have the rights described in section 14. We will answer requests while respecting the rights of others, which may limit what we can say about who carried out a search.

7. The sanctions and PEP lists

To answer checks we keep copies of two public lists:

  • The EU consolidated list of financial sanctions, published by the European Commission.
  • The Danish PEP lists (Denmark, the Faroe Islands and Greenland), published by Finanstilsynet (the Danish Financial Supervisory Authority) under the Danish Anti-Money Laundering Act.

These lists contain personal data about the people named on them, and the authorities publish them so that businesses can carry out exactly this kind of screening. We process them on the basis of our legitimate interest, and that of our users, in meeting screening obligations (Art. 6(1)(f)). We refresh our copy daily, replace it completely at each update, and add nothing to it: someone removed from a list disappears from our copy at the next refresh. If you believe your entry on a list is wrong, the publishing authority can correct the source; you are also welcome to contact us.

A match is never a conclusion that someone is sanctioned or politically exposed. It is a candidate that the user must review.

8. Who we share data with

We don't sell data, and we don't share it with advertisers or data brokers. We use these service providers (data processors), under data processing agreements:

AhaSend B.V.
Willem Fenengastraat 16, 1096 BN Amsterdam, Netherlands
Chamber of Commerce no. 99533111
Your email address and login code, to deliver login emails. Hosted in the EU. We instruct AhaSend not to keep the content of the email at all, and to delete the delivery record (recipient, subject, delivery status) after 1 day. No open or click tracking.
HostingAll service data, encrypted where described above. Hosted in the EU

We only disclose data to public authorities when legally required to.

9. Transfers outside the EU/EEA

None. All personal data is processed within the EU/EEA, by us and by the service providers listed above.

10. How long we keep data

Account (email address, creation and last-used date)Until you ask us to delete it, and in any case deleted automatically 24 months after it was last used (last sign-in, check or renewed session)
Login code10 minutes (as a hash), deleted within the following hour
Access token / sign-in session1 hour / 90 days, deleted after expiry
Login rate-limit data (IP address, hashed email)24 hours
Monthly usage count24 months
Search log90 days
Technical logs14 days
Details submitted for a check (other than the name in the search log)Not stored

11. Cookies

The website sets no cookies. During sign-in, auth.sanctionsagent.eu sets one strictly necessary cookie (sa_flow) that keeps your sign-in steps together. It lasts at most 10 minutes and is deleted when sign-in completes. Because it is strictly necessary for a service you requested, it doesn't require consent.

12. Security

All connections use HTTPS. Login codes and tokens are stored only as one-way hashes. The account and search-log databases are encrypted and kept separate from the internet-facing part of the service, and each part of the service only has access to the data it needs.

13. Automated decisions

We don't make decisions about anyone based on automated processing. Match scores are an aid for the user's own review, and we advise users never to base a decision on a match without human review.

14. Your rights

Under the GDPR you have the right to:

  • access the data we hold about you;
  • have it corrected;
  • have it erased, including your account and the search-log entries linked to it, sooner than the automatic deletion described in section 10;
  • restrict its processing;
  • receive it in a portable format (for data processed on the basis of a contract);
  • object to processing based on legitimate interests (sections 4.2, 4.4, 4.6 and 7).

To use these rights, email hello@sanctionsagent.eu. If you have an account, write from the address you sign in with; otherwise we may ask for the information needed to find your data. We respond within one month.

You can also complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, dt@datatilsynet.dk, www.datatilsynet.dk.

15. Children

Sanctions Agent is a service for businesses and is not intended for children.

16. Changes to this policy

We will update this page when our processing changes. Material changes will be emailed to account holders before they take effect.