Scope - What This Guide Covers
This guide focuses on aligning anti-money laundering (AML) obligations with data protection requirements under Art. 75 of the AML Regulation, effective 10 July 2027. It provides practical frameworks for building information-sharing partnerships that meet both financial crime prevention and General Data Protection Regulation (GDPR) standards.
This guide is intended for compliance officers, Money Laundering Reporting Officers, and privacy teams at financial institutions, obliged entities under AML rules, and their supervisory authorities. If you're designing partnerships for cross-entity information sharing, this is your reference.
Key Concepts and Definitions
Art. 75 Information Sharing: Allows entities subject to AML rules to exchange information with each other and public authorities to detect and prevent money laundering and terrorist financing, with data protection safeguards.
Obliged Entities: Organizations covered by AML regulations, including financial institutions, credit institutions, trust and company service providers, and certain professional services.
Financial Intelligence Units (FIUs): National authorities responsible for receiving, analyzing, and disseminating financial intelligence to combat money laundering and terrorist financing.
Data Protection Authority (DPA): Independent public authority supervising GDPR compliance through investigation and enforcement powers.
Partnership Framework: A structured arrangement between obliged entities or between entities and authorities that defines information-sharing parameters, data protection measures, and operational boundaries.
Requirements Breakdown
Legal Basis for Processing
When sharing information under Art. 75, you're processing personal data. Your legal basis is crucial:
- Compliance with legal obligation (GDPR Art. 6(1)(c)) applies when sharing is mandatory under AML rules.
- Legitimate interests (Art. 6(1)(f)) may apply for voluntary information sharing, but you must document your balancing test.
- For special category data, consider Art. 9(2)(f) (legal claims) or Art. 9(2)(g) (substantial public interest).
Document your legal basis assessment before your first information exchange. Your DPA will ask for it.
Data Minimisation Requirements
Art. 75 doesn't override GDPR Art. 5(1)(c). Share only what's necessary for the specific financial crime risk you're addressing. If investigating a suspicious wire transfer pattern, share transaction metadata and counterparty details, not the customer's entire account history.
Transparency Obligations
GDPR Art. 13 and 14 require you to inform data subjects about processing activities. Your privacy notice must explain:
- That you may share information with other obliged entities or authorities for AML purposes.
- The categories of recipients (name FIUs specifically; describe partner entity types generally).
- Retention periods for shared information.
- Data subject rights and their limitations under Art. 23.
Don't wait until 2027 to update your notices. Draft language now and test it with your DPA if you're uncertain.
Cross-Border Transfers
If your information-sharing partnership involves entities in different jurisdictions, you're making cross-border transfers. Within the EU, you're fine. Outside the EU, you need:
- An adequacy decision for the destination country, or
- Standard Contractual Clauses with supplementary measures, or
- Binding Corporate Rules if sharing within a corporate group.
FIU-to-FIU exchanges often rely on specific legal frameworks, but your entity-to-entity partnerships need standard transfer mechanisms.
Implementation Guidance
Building Your Partnership Framework
Start with a written agreement that defines:
Scope boundaries: Specify which financial crime typologies trigger information sharing. "Money laundering" is too broad; "trade-based money laundering involving invoice manipulation in commodity trades" provides clarity.
Data categories: List the personal data elements you'll exchange. Include data fields, not just categories. Your partner needs to know whether "customer information" means name and account number or includes beneficial ownership structures.
Access controls: Define who at each entity can access shared information. Specify roles, not individuals. "Senior AML analysts with completed training" works; "whoever needs it" doesn't.
Retention and deletion: Align your retention periods with both AML record-keeping requirements and Data Minimisation principles. If AML rules require five-year retention but the shared data is no longer relevant after two years, delete it at two years.
Incident response: Define notification timelines and responsibilities before an incident forces you to improvise.
Technical Safeguards
Implement these baseline controls:
- Encryption in transit and at rest: Use TLS 1.3 or higher for transmission; AES-256 for storage.
- Access logging: Record every access to shared information with user identity, timestamp, and purpose.
- Segregation: Store information received through Art. 75 partnerships separately from your standard customer database.
- Automated retention enforcement: Configure your systems to purge data when retention periods expire.
Operational Procedures
Create a request workflow that documents:
- The financial crime indicator that triggered the information need.
- The specific data elements requested and their necessity.
- The approving authority (typically your MLRO or deputy).
- The recipient entity and receiving individual.
- The response provided and its date.
This documentation proves your Data Minimisation compliance and helps you respond to Data Subject Access Requests about information sharing.
Common Pitfalls
Treating Art. 75 as a general data-sharing authorization: Art. 75 is purpose-limited. You can't use it to share customer data for credit risk assessment, fraud prevention unrelated to AML, or business development. The purpose is financial crime detection and prevention.
Assuming FATF Recommendations override GDPR: The FATF Recommendations require effective information sharing, but they don't exempt you from data protection law. You must satisfy both frameworks simultaneously.
Neglecting data subject rights: Art. 75 doesn't eliminate rights of access, rectification, or erasure. It may allow you to restrict these rights under Art. 23 when exercising them would prejudice an investigation, but you must assess each request individually.
Sharing without documenting necessity: Your DPA won't accept "we thought it might be useful" as justification. Document the specific risk or investigation that made each information exchange necessary.
Ignoring the Joint Guidelines development process: The EDPB and AMLA are holding stakeholder events in 2024 and launching a public consultation in early 2027. Participate. The final guidelines will reflect industry input, and you'll want your operational challenges addressed.
Quick Reference Table
| Requirement | Key Action | Deadline/Timing |
|---|---|---|
| Legal basis assessment | Document Art. 6 and Art. 9 grounds for each partnership type | Before first information exchange |
| Privacy notice update | Add Art. 75 sharing to transparency disclosures | Before 10 July 2027 |
| Partnership agreements | Draft written frameworks with partners | Q1-Q2 2027 |
| Technical controls | Implement encryption, access logging, segregation | Before operational launch |
| Cross-border transfer mechanisms | Establish SCCs or other valid mechanisms for non-EU partners | Before sharing with non-EU entities |
| Staff training | Train AML and privacy teams on dual compliance requirements | Q2 2027 |
| Data retention policies | Align AML and GDPR retention rules in documented policy | Q1 2027 |
| Incident response procedures | Define breach notification process for shared data | Before operational launch |
| DSAR procedures | Create workflow for handling access requests about shared data | Q2 2027 |
| Stakeholder engagement | Participate in EDPB/AMLA consultation | When announced (early 2027) |
The Joint Guidelines won't write your compliance program for you, but they'll clarify the boundaries. Until then, build your frameworks on the principles above, document your necessity assessments rigorously, and engage with the consultation process when it opens. Your early preparation determines whether July 2027 is a compliance deadline or an operational advantage.




