TL;DR for the DPO
If your clients include banks, financial intermediaries, accountants, notaries, lawyers, auditors or estate agents, they are all obliged entities under anti-money laundering rules. From 10 July 2027 they will be able to share information with each other and with authorities about suspicious cases. The rules for doing that without breaching the GDPR are being written now, and the consultation will land only months before the possibility becomes operational.
What was announced
On 1 July 2026, from Brussels and Frankfurt, the EDPB and AMLA - the European Anti-Money Laundering Authority, based in Frankfurt - announced they will work together on joint guidelines dedicated to partnerships for information sharing. The question they answer is stated plainly: how to share information to fight financial crime while protecting personal data.
The legal basis is Article 75 of the AML Regulation, which allows companies and professionals covered by anti-money laundering rules to share information with each other and with public authorities, within clear limits. That possibility will apply from 10 July 2027. A joint drafting team with members from both the EDPB and AMLA will lead the work.
The calendar, which is the useful part
- Later in 2026: a joint EDPB-AMLA event to gather early views on the elements that would benefit from clarification.
- First half of 2027: public consultation on the draft guidelines.
- 10 July 2027: the Article 75 sharing possibility becomes applicable.
The dates leave little room
Only months will separate the end of the consultation from the date of application. Obliged entities will be building their processes while the final text is still fresh, and anyone waiting for the guidelines before starting to think about it will arrive late.
Why the problem is real
Because sharing anti-money laundering information is one of the most sensitive processing operations there is. It concerns people who are neither under investigation nor convicted: they have simply been judged suspicious by an internal analysis. The data travels between private parties, not only towards authorities. And by definition the data subject knows nothing about it, because AML confidentiality rules forbid telling them.
Together those three elements describe exactly the scenario the GDPR watches most closely: opaque processing, high impact on the individual, on data that can amount to an accusation. Without precise rules the risk is not theoretical: it is the formation of private lists of unwanted people, built on unverified suspicions that those on them cannot contest.
What a DPO can do now
There is nothing to apply today, but a lot to prepare. Three things are useful now and do not depend on the final text.
- Check whether your clients are obliged entities: the population is wider than people assume and includes professions that do not consider themselves covered until somebody tells them.
- In the record of processing, look at how the AML processing is described today: in most cases it stops at reporting to the financial intelligence unit and contemplates no horizontal sharing at all.
- Diary the late-2026 event and the 2027 consultation: that is the material you will need to update impact assessments before 10 July, not after.
The point worth making to the client
That sharing is permitted by the AML Regulation does not automatically make it lawful under the GDPR: legal basis, minimisation, retention and security still have to be settled. The joint guidelines exist precisely because the two planes do not coincide, and the first to discover that in practice will be whoever moved without waiting for them.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free