Back to Blog
    Regulatory Updates

    EDPB and AMLA to Develop Joint Guidelines on Information Sharing

    The EDPB and AMLA are developing Joint Guidelines to clarify how organizations can share information to combat financial crime while complying with the GDPR and the upcoming AML Regulation.

    PolicyForge Legal Team
    July 25, 2026
    8 min read
    gdpr
    amla
    edpb
    privacy policy
    data sharing
    Share:

    Fighting financial crime runs on shared information; data protection law runs on limiting it. Organizations in the EU's financial ecosystem have lived inside that contradiction for years. Now the two regulators on either side of it are writing a joint answer: the European Data Protection Board (EDPB) and the EU's new Anti-Money Laundering Authority (AMLA) announced they will develop Joint Guidelines on partnerships for information sharing — ahead of the new AML Regulation that applies from July 2027.

    TL;DR — Key Takeaways
  1. The EDPB and AMLA will jointly clarify how organizations can share information to combat financial crime without breaching the GDPR.
  2. The guidelines land ahead of the EU's new AML Regulation, which becomes applicable in July 2027 — giving affected firms a preparation runway.
  3. The core message: sharing data for anti-money-laundering (AML) purposes does not suspend GDPR duties — transparency, lawful basis, and minimization still apply.
  4. Practical impact: map your AML data flows now, document lawful bases, and prepare your privacy policy and data subject request process for the overlap.
  5. Key FactsDetails
    What happenedEDPB and AMLA committed to Joint Guidelines on partnerships for information sharing
    Who issued itEuropean Data Protection Board with the EU Anti-Money Laundering Authority
    RegulationsGDPR + upcoming EU AML Regulation (applies July 2027)
    AnnouncedJuly 1, 2026
    Impact levelMedium
    Most affectedBanks, fintechs, payment processors, crypto exchanges, AML screening vendors

    What Happened

    As reported in the EDPB's announcement, the EDPB and AMLA are developing Joint Guidelines focused on partnerships for information sharing in the fight against financial crime.

    Some context makes clear why this matters. The EU's 2024 anti-money-laundering package created a single AML rulebook — including a directly applicable AML Regulation — and a new supervisory authority, AMLA, to oversee it. The new regulation becomes applicable in July 2027. Information-sharing partnerships, where institutions pool intelligence about suspicious activity, are one of the package's more privacy-sensitive innovations: they work precisely by moving personal data between organizations that would otherwise never share it.

    Until now, firms structuring these partnerships had to guess how data protection authorities would view them. Joint guidance from both the data protection and AML supervisors is the EU's way of replacing that guesswork with a single set of expectations before the 2027 deadline arrives.

    Why a joint approach is unusual — and useful

    Historically, AML compliance teams and privacy teams have answered to different regulators giving different signals: financial supervisors pushing for more sharing and monitoring, data protection authorities warning against exactly that. A jointly authored document means one standard both sides have signed off on. For compliance officers, that converts an unresolvable tension into a checklist.

    Does This Affect You?

  6. Banks, credit unions, and investment firms with monitoring and suspicious-activity reporting obligations.
  7. Fintechs, payment processors, crypto-asset service providers, and digital wallets that must run AML programs while processing large volumes of consumer data.
  8. Information-sharing consortiums and utilities — any partnership formed to pool financial-crime intelligence between institutions.
  9. KYC, identity verification, and AML screening vendors that process personal data on behalf of financial institutions.
  10. Any EU-exposed business in the payments chain — if you process EU residents' personal data and share it for financial-crime prevention, these guidelines will describe your obligations.
  11. If none of these describe you but you handle financial data, treat this as a preview: the balancing framework the guidelines establish will shape how EU regulators view any purpose-driven data sharing.

    What This Means for Your Privacy Documentation

    Your privacy policy must disclose AML sharing — carefully

    GDPR transparency obligations don't pause for financial-crime prevention. If you share personal data through AML partnerships, your privacy policy needs to say so: the categories of data involved, the kinds of recipients, and the legal basis (typically compliance with a legal obligation, or legitimate interest for sharing that goes beyond strict legal mandates). The craft is in disclosing honestly without publishing a roadmap for evading your controls — a reason to draft this section deliberately rather than copy it from a template. A privacy policy generator built around your actual data flows gives you a defensible starting point to refine.

    Every sharing flow needs a documented lawful basis

    "We have to, for AML" is a conclusion, not documentation. Each flow of personal data into a partnership or to an authority should be tied to a specific lawful basis under Article 6 GDPR (and Article 9, where special-category data is involved), recorded in your records of processing. Where legitimate interest carries the weight, the balancing test must exist on paper. A structured review with a GDPR compliance tool is the efficient way to find flows that are running on assumption rather than analysis.

    Data subject rights get complicated — not optional

    Here is the genuinely hard part the Joint Guidelines are expected to address: individuals hold GDPR rights to access, rectify, and erase their data, but fulfilling those rights inside an AML context can tip off a suspect or compromise an investigation. EU law allows restrictions on data subject rights to safeguard the prevention and detection of crime — but restrictions must be applied case by case, justified, and documented. Blanket denials of access requests because "it's AML data" are exactly what data protection authorities sanction.

    Operationally, that means your data subject request workflow needs a branch for AML-adjacent data: who assesses whether an exemption applies, how the justification is recorded, and what the individual is told. A tracked DSAR intake process is the difference between a defensible restriction and an undocumented one.

    Action Checklist

  12. Read the announcement from the EDPB and assign someone to track the guidelines as they develop.
  13. Map your AML data flows. Document every flow of personal data to partners, consortiums, or authorities for financial-crime purposes: what data, to whom, under what mechanism.
  14. Attach lawful bases. Tie each flow to a documented Article 6 (and where relevant Article 9) basis, with balancing tests where legitimate interest is used.
  15. Audit your privacy policy for accurate, non-compromising disclosure of AML-related sharing.
  16. Check data minimization. Confirm each partnership receives only what the financial-crime purpose actually requires.
  17. Build the DSAR exemption branch. Define who decides, on what criteria, and how decisions are recorded when a request touches AML data.
  18. Calendar the runway. The AML Regulation applies from July 2027 — work backwards from that date for your compliance milestones.
  19. Frequently Asked Questions

    Does sharing data for AML purposes exempt us from the GDPR?

    No — this is the central misconception the Joint Guidelines exist to correct. AML obligations provide a lawful basis for necessary processing; they do not switch off transparency, minimization, security, or data subject rights. The two frameworks apply simultaneously.

    What is AMLA?

    The Anti-Money Laundering Authority is the EU's new supervisory body for anti-money-laundering and counter-terrorist-financing, created as part of the 2024 EU AML package that also produced the directly applicable AML Regulation taking effect in July 2027. The Joint Guidelines are one of its first major collaborations with the data protection side of EU regulation.

    Can we refuse a data subject access request because the data relates to an AML investigation?

    Sometimes — but never by default. EU law permits restricting rights where necessary to protect the prevention, investigation, and detection of crime, and each restriction must be assessed and documented individually. An unjustified blanket refusal is itself a GDPR violation.

    When should we start preparing?

    Now. The guidelines are being developed ahead of the AML Regulation's July 2027 application date precisely to give firms time. Data-flow mapping and lawful-basis documentation are slow, cross-functional work — they are cheaper to start early than to rush later.

    The Bottom Line

    The EDPB-AMLA collaboration is good news dressed as more regulation: it means the EU's privacy and financial-crime regulators intend to give one answer instead of two contradictory ones. The firms that benefit will be those whose documentation is ready to meet it — data flows mapped, lawful bases written down, policies telling the truth, and a rights process that can handle the hard cases. PolicyForge covers the documentation layer: privacy policies generated from your real practices, compliance monitoring that flags when rules like these move, and DSAR tooling for the requests that need careful handling.

    This article is for general information and is not legal advice.
    PLT

    PolicyForge Legal Team

    Our expert legal team combines decades of compliance experience with cutting-edge AI technology to deliver accurate, up-to-date legal guidance.

    GDPR Compliance
    Data Protection
    Privacy Law
    Business Regulations

    Related Posts

    Regulatory Updates

    EDPB Issues GDPR Guidelines on AI Web Scraping and Anonymisation

    The EDPB has adopted new guidelines on data anonymisation, web scraping for generative AI, and blockchain. Learn what this GDPR guidance means for your privacy compliance.

    7/25/20268 min read
    Regulatory Updates

    Canada OPC Issues PIPEDA Guidance for Financial Entities

    The Office of the Privacy Commissioner of Canada has published new guidance for financial reporting entities on submitting privacy codes of practice for regulatory review.

    7/25/20268 min read

    Ready to generate your legal policies?

    Create compliant privacy policies, terms of service, and more with AI assistance.