Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
AML Information Sharing Under GDPR: What Art. 75 Means for Your ProgramRegulatory Bodies
5 min readFor Compliance Officers

AML Information Sharing Under GDPR: What Art. 75 Means for Your Program

Scope - What This Guide Covers

This guide focuses on aligning anti-money laundering (AML) obligations with data protection requirements under Art. 75 of the AML Regulation, effective 10 July 2027. It provides practical frameworks for building information-sharing partnerships that meet both financial crime prevention and General Data Protection Regulation (GDPR) standards.

This guide is intended for compliance officers, Money Laundering Reporting Officers, and privacy teams at financial institutions, obliged entities under AML rules, and their supervisory authorities. If you're designing partnerships for cross-entity information sharing, this is your reference.

Key Concepts and Definitions

Art. 75 Information Sharing: Allows entities subject to AML rules to exchange information with each other and public authorities to detect and prevent money laundering and terrorist financing, with data protection safeguards.

Obliged Entities: Organizations covered by AML regulations, including financial institutions, credit institutions, trust and company service providers, and certain professional services.

Financial Intelligence Units (FIUs): National authorities responsible for receiving, analyzing, and disseminating financial intelligence to combat money laundering and terrorist financing.

Data Protection Authority (DPA): Independent public authority supervising GDPR compliance through investigation and enforcement powers.

Partnership Framework: A structured arrangement between obliged entities or between entities and authorities that defines information-sharing parameters, data protection measures, and operational boundaries.

Requirements Breakdown

Legal Basis for Processing

When sharing information under Art. 75, you're processing personal data. Your legal basis is crucial:

  • Compliance with legal obligation (GDPR Art. 6(1)(c)) applies when sharing is mandatory under AML rules.
  • Legitimate interests (Art. 6(1)(f)) may apply for voluntary information sharing, but you must document your balancing test.
  • For special category data, consider Art. 9(2)(f) (legal claims) or Art. 9(2)(g) (substantial public interest).

Document your legal basis assessment before your first information exchange. Your DPA will ask for it.

Data Minimisation Requirements

Art. 75 doesn't override GDPR Art. 5(1)(c). Share only what's necessary for the specific financial crime risk you're addressing. If investigating a suspicious wire transfer pattern, share transaction metadata and counterparty details, not the customer's entire account history.

Transparency Obligations

GDPR Art. 13 and 14 require you to inform data subjects about processing activities. Your privacy notice must explain:

  • That you may share information with other obliged entities or authorities for AML purposes.
  • The categories of recipients (name FIUs specifically; describe partner entity types generally).
  • Retention periods for shared information.
  • Data subject rights and their limitations under Art. 23.

Don't wait until 2027 to update your notices. Draft language now and test it with your DPA if you're uncertain.

Cross-Border Transfers

If your information-sharing partnership involves entities in different jurisdictions, you're making cross-border transfers. Within the EU, you're fine. Outside the EU, you need:

  • An adequacy decision for the destination country, or
  • Standard Contractual Clauses with supplementary measures, or
  • Binding Corporate Rules if sharing within a corporate group.

FIU-to-FIU exchanges often rely on specific legal frameworks, but your entity-to-entity partnerships need standard transfer mechanisms.

Implementation Guidance

Building Your Partnership Framework

Start with a written agreement that defines:

Scope boundaries: Specify which financial crime typologies trigger information sharing. "Money laundering" is too broad; "trade-based money laundering involving invoice manipulation in commodity trades" provides clarity.

Data categories: List the personal data elements you'll exchange. Include data fields, not just categories. Your partner needs to know whether "customer information" means name and account number or includes beneficial ownership structures.

Access controls: Define who at each entity can access shared information. Specify roles, not individuals. "Senior AML analysts with completed training" works; "whoever needs it" doesn't.

Retention and deletion: Align your retention periods with both AML record-keeping requirements and Data Minimisation principles. If AML rules require five-year retention but the shared data is no longer relevant after two years, delete it at two years.

Incident response: Define notification timelines and responsibilities before an incident forces you to improvise.

Technical Safeguards

Implement these baseline controls:

  • Encryption in transit and at rest: Use TLS 1.3 or higher for transmission; AES-256 for storage.
  • Access logging: Record every access to shared information with user identity, timestamp, and purpose.
  • Segregation: Store information received through Art. 75 partnerships separately from your standard customer database.
  • Automated retention enforcement: Configure your systems to purge data when retention periods expire.

Operational Procedures

Create a request workflow that documents:

  1. The financial crime indicator that triggered the information need.
  2. The specific data elements requested and their necessity.
  3. The approving authority (typically your MLRO or deputy).
  4. The recipient entity and receiving individual.
  5. The response provided and its date.

This documentation proves your Data Minimisation compliance and helps you respond to Data Subject Access Requests about information sharing.

Common Pitfalls

Treating Art. 75 as a general data-sharing authorization: Art. 75 is purpose-limited. You can't use it to share customer data for credit risk assessment, fraud prevention unrelated to AML, or business development. The purpose is financial crime detection and prevention.

Assuming FATF Recommendations override GDPR: The FATF Recommendations require effective information sharing, but they don't exempt you from data protection law. You must satisfy both frameworks simultaneously.

Neglecting data subject rights: Art. 75 doesn't eliminate rights of access, rectification, or erasure. It may allow you to restrict these rights under Art. 23 when exercising them would prejudice an investigation, but you must assess each request individually.

Sharing without documenting necessity: Your DPA won't accept "we thought it might be useful" as justification. Document the specific risk or investigation that made each information exchange necessary.

Ignoring the Joint Guidelines development process: The EDPB and AMLA are holding stakeholder events in 2024 and launching a public consultation in early 2027. Participate. The final guidelines will reflect industry input, and you'll want your operational challenges addressed.

Quick Reference Table

Requirement Key Action Deadline/Timing
Legal basis assessment Document Art. 6 and Art. 9 grounds for each partnership type Before first information exchange
Privacy notice update Add Art. 75 sharing to transparency disclosures Before 10 July 2027
Partnership agreements Draft written frameworks with partners Q1-Q2 2027
Technical controls Implement encryption, access logging, segregation Before operational launch
Cross-border transfer mechanisms Establish SCCs or other valid mechanisms for non-EU partners Before sharing with non-EU entities
Staff training Train AML and privacy teams on dual compliance requirements Q2 2027
Data retention policies Align AML and GDPR retention rules in documented policy Q1 2027
Incident response procedures Define breach notification process for shared data Before operational launch
DSAR procedures Create workflow for handling access requests about shared data Q2 2027
Stakeholder engagement Participate in EDPB/AMLA consultation When announced (early 2027)

The Joint Guidelines won't write your compliance program for you, but they'll clarify the boundaries. Until then, build your frameworks on the principles above, document your necessity assessments rigorously, and engage with the consultation process when it opens. Your early preparation determines whether July 2027 is a compliance deadline or an operational advantage.

Promotional banner for the Penetration Report Template Kit

You Might Also Like