All news
EDPB / EDPS July 1, 2026 6 min

Anti-money laundering and privacy: the EDPB and AMLA write the sharing rules together

From 10 July 2027 obliged entities will be able to share information to fight financial crime. Article 75 of the AML Regulation allows it; the joint guidelines will say how to do it without breaching the GDPR

TL;DR for the DPO

If your clients include banks, financial intermediaries, accountants, notaries, lawyers, auditors or estate agents, they are all obliged entities under anti-money laundering rules. From 10 July 2027 they will be able to share information with each other and with authorities about suspicious cases. The rules for doing that without breaching the GDPR are being written now, and the consultation will land only months before the possibility becomes operational.

What was announced

On 1 July 2026, from Brussels and Frankfurt, the EDPB and AMLA - the European Anti-Money Laundering Authority, based in Frankfurt - announced they will work together on joint guidelines dedicated to partnerships for information sharing. The question they answer is stated plainly: how to share information to fight financial crime while protecting personal data.

The legal basis is Article 75 of the AML Regulation, which allows companies and professionals covered by anti-money laundering rules to share information with each other and with public authorities, within clear limits. That possibility will apply from 10 July 2027. A joint drafting team with members from both the EDPB and AMLA will lead the work.

The calendar, which is the useful part

  • Later in 2026: a joint EDPB-AMLA event to gather early views on the elements that would benefit from clarification.
  • First half of 2027: public consultation on the draft guidelines.
  • 10 July 2027: the Article 75 sharing possibility becomes applicable.

The dates leave little room

Only months will separate the end of the consultation from the date of application. Obliged entities will be building their processes while the final text is still fresh, and anyone waiting for the guidelines before starting to think about it will arrive late.

Why the problem is real

Because sharing anti-money laundering information is one of the most sensitive processing operations there is. It concerns people who are neither under investigation nor convicted: they have simply been judged suspicious by an internal analysis. The data travels between private parties, not only towards authorities. And by definition the data subject knows nothing about it, because AML confidentiality rules forbid telling them.

Together those three elements describe exactly the scenario the GDPR watches most closely: opaque processing, high impact on the individual, on data that can amount to an accusation. Without precise rules the risk is not theoretical: it is the formation of private lists of unwanted people, built on unverified suspicions that those on them cannot contest.

What a DPO can do now

There is nothing to apply today, but a lot to prepare. Three things are useful now and do not depend on the final text.

  • Check whether your clients are obliged entities: the population is wider than people assume and includes professions that do not consider themselves covered until somebody tells them.
  • In the record of processing, look at how the AML processing is described today: in most cases it stops at reporting to the financial intelligence unit and contemplates no horizontal sharing at all.
  • Diary the late-2026 event and the 2027 consultation: that is the material you will need to update impact assessments before 10 July, not after.

The point worth making to the client

That sharing is permitted by the AML Regulation does not automatically make it lawful under the GDPR: legal basis, minimisation, retention and security still have to be settled. The joint guidelines exist precisely because the two planes do not coincide, and the first to discover that in practice will be whoever moved without waiting for them.

Official source:EDPB — EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing (1 July 2026)

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

EDPB / EDPS
12-14gli articoli sotto esame

In 2026 every European authority is looking at the same thing: privacy notices

Each year the EDPB picks a topic and every national authority checks it together, in the same period, through questionnaires and inspections. For 2026 the topic is transparency: how controllers tell people what happens to their data. In scope are Article 13, where data comes from the data subject, and Article 14, where it comes from elsewhere. The Czech authority has already written the theme into its inspection plan.

Aug 10, 2026New 6 min
EDPB / EDPS
28 agotermine per candidarsi

Competition and data protection: the EDPB opens the table, and there is a deadline

After the DSA and before the DMA and the AI Act, the fourth piece of the European regulatory mosaic concerns the relationship between competition and data protection. This is not theoretical: it touches data as a market asset, mergers, and the position of those who process data because they dominate a market. The EDPB and the Commission are asking for input before they write, and this time the deadline is close.

Jul 30, 2026New 6 min
EDPB / EDPS
16-17luglio 2026

EDPB from Dublin: a legal basis is needed so authorities can share information across regulatory fields

The number and complexity of complaints are rising, partly because of increased use of AI, and authorities say openly that resources are not enough. The solutions on the table: joint operations, pooling resources between authorities, and the upcoming Procedural Regulation.

Jul 17, 2026New 6 min