Skip to content
EBA · EU-wide

Information-sharing partnerships — the AMLR gateway

Fintech Passport
August 20, 2026 · 4-min read
Information-sharing partnerships — the AMLR gateway

For the first time, EU AML law provides an express gateway for obliged entities to share information with each other — and it is narrower and more procedural than the phrase “information sharing” suggests. Article 75 of Regulation (EU) 2024/1624 permits members of partnerships for information sharing to share information among themselves where strictly necessary for complying with Chapter III and Article 69, and in accordance with fundamental rights and judicial procedural safeguards.

1. The permission, and its two qualifiers

Both qualifiers do work. “Strictly necessary” is a necessity test, not a relevance test: information that would be useful but is not necessary for the specified purposes falls outside the gateway. And the specified purposes are closed — Chapter III (customer due diligence) and Article 69 (reporting of suspicions). Sharing for commercial purposes, for general fraud prevention outside those provisions, or for credit assessment is not authorised by this article.

2. Notify the supervisor before you start

Article 75(2) sets a pre-activity gate. Obliged entities intending to participate must notify their respective supervisory authorities, which then verify that the partnership has mechanisms in place to ensure compliance with the article and that the required data protection impact assessment has been carried out.

StepWhoTiming
Notification of intention to participateEach participating obliged entity, to its own supervisorBefore participation
Verification of compliance mechanisms and of the DPIASupervisory authorities — where relevant in consultation with each other and with the authorities responsible for Regulation (EU) 2016/679Prior to the beginning of the activities of the partnership
Consultation of FIUsSupervisory authorities, where relevantAs part of that verification

The verification must take place prior to the beginning of the activities of the partnership — so this is a condition precedent, not a registration formality that can follow a pilot. And responsibility for compliance with requirements under Union or national law remains with the participants: supervisory verification of the mechanisms does not transfer accountability for what is actually shared.

3. Limits on the information itself

Article 75(3) limits what may be exchanged in the framework of a partnership. That limitation is the provision to read alongside any design work, because it constrains the data model rather than the governance — and a partnership whose technical architecture can carry more than the article permits will struggle to demonstrate that it does not.

The data protection dimension is structural rather than incidental. The article expressly contemplates consultation with the authorities responsible for verifying compliance with Regulation (EU) 2016/679, and conditions verification on a completed data protection impact assessment. In practice that makes the DPIA the first deliverable of any partnership project, not a late-stage compliance artefact.

4. What has to be retained

Participation creates its own retention duty. Article 77(1)(d) requires obliged entities participating in information-sharing partnerships to retain copies of the documents and information obtained in the framework of those partnerships, and records of all instances of information sharing.

“All instances” is the operative phrase, and it is an audit-trail requirement: the partnership’s technical layer needs to log each exchange in a form the participant itself can retain, produce and — under Article 78 — retrieve speedily. A shared platform that holds the log centrally, with no participant-side record, does not discharge a participant’s own Article 77 duty.

FAQ

Can we share information with another firm under this article?

Only within a partnership for information sharing, only where strictly necessary for Chapter III customer due diligence or Article 69 suspicion reporting, and only after the supervisory verification has taken place.

Do we need supervisory approval before joining?

You must notify your supervisory authority, and the verification of the partnership’s mechanisms and of its data protection impact assessment must take place before the partnership’s activities begin.

Who is responsible if something is shared that should not have been?

Responsibility for compliance with Union or national law requirements remains with the participants in the partnership.


Related: AML record retention · Reporting suspicions · Group-wide AML requirements

Related reads.