The EDPB and AMLA are drafting Joint Guidelines on sharing information for financial crime prevention without violating data protection laws. Your organization has until 10 July 2027 to establish the necessary operational framework. This is not theoretical: Article 75 of the AML Regulation creates a new legal pathway for companies and professionals covered by anti-money laundering rules to exchange personal data with each other and with public authorities. If you're involved in customer due diligence, transaction monitoring, or suspicious activity reporting, you need a compliance structure ready by that date.
The problem
Your AML team needs to share customer data with financial intelligence units, other obliged entities, and potentially law enforcement. Your privacy team must ensure every transfer meets Article 6 lawful basis requirements, respects purpose limitation under Article 5(1)(b), and implements appropriate technical and organizational measures under Article 32. Without clear procedures, you'll face two outcomes: over-cautious teams blocking legitimate information sharing, or under-governed processes exposing you to enforcement actions.
The Joint Guidelines won't arrive as finished regulation. The EDPB and AMLA are holding a stakeholder event later this year, followed by a public consultation in the first half of 2027. You're building your framework while the regulatory guidance is still taking shape.
What you need before starting
Legal clarity on scope
Identify which of your business units are "obliged entities" under the AML Regulation. This determines who can use the Article 75 information sharing pathway. Your retail banking division likely qualifies; your marketing analytics team does not.
Cross-functional authority
Designate a senior owner who reports to both your chief compliance officer and your data protection officer. Information sharing for financial crime sits at the intersection of two regulatory regimes, and you can't delegate decisions to either team in isolation.
Inventory of current sharing practices
Document every existing channel where you share customer data for AML purposes: what data moves, to whom, under which lawful basis, and with what safeguards. You're not starting from zero; you're formalizing and expanding what you already do.
Technical capability for granular access control
You'll need systems that can enforce purpose-specific access restrictions. A fraud analyst authorized to review transaction patterns for money laundering detection shouldn't automatically have access to the same data for marketing segmentation.
Step-by-step implementation
1. Map your information sharing partnerships
Create a register of every entity you'll share personal data with under Article 75. For each partnership, document:
- The partner's identity and AML obligations
- The categories of personal data you'll exchange
- The specific financial crime risks the partnership addresses
- Whether the partner is another obliged entity, a financial intelligence unit, or a competent authority
This register becomes your Article 30 processing record for AML information sharing. Update it whenever you add a new partnership or expand an existing one.
2. Draft partnership-specific data sharing agreements
For each partnership in your register, write an agreement that specifies:
- The lawful basis you're relying on (likely Article 6(1)(c) for compliance with a legal obligation, or Article 6(1)(e) for performance of a task carried out in the public interest)
- Data retention periods aligned to both AML record-keeping requirements and Article 5(1)(e) storage limitation
- Technical measures for secure transmission (encryption standards, access authentication, audit logging)
- Incident response procedures if either party experiences a personal data breach
- Deletion or return protocols when the partnership ends
If you're sharing special category data (for example, data revealing political opinions or trade union membership relevant to politically exposed person screening), you need an Article 9(2) condition as well. Article 9(2)(g) permits processing necessary for substantial public interest, but you must document how the processing meets that threshold.
3. Build transparency into your privacy notices
Update your customer-facing transparency obligations to describe AML information sharing. Your privacy notice should explain:
- That you share personal data with other financial institutions, FIUs, and authorities to detect and prevent money laundering and terrorist financing
- The lawful basis for this sharing (Article 75 of the AML Regulation, implemented via Article 6(1)(c) or (e) of GDPR)
- The categories of recipients
- That this sharing is mandatory for regulatory compliance, so customers cannot object under Article 21
Don't bury this in generic "we may share your data with third parties" language. Be specific about the AML context.
4. Implement purpose limitation controls
Configure your data access systems so that AML-related personal data is tagged with purpose metadata. When an analyst queries customer transaction history for money laundering detection, the system should log that purpose and restrict any attempt to use the same data for incompatible purposes like credit scoring or marketing.
If your current systems can't enforce purpose-based access control, you'll need to build it or procure it. Manual policy enforcement won't scale when you're sharing data across multiple partnerships.
5. Train your AML and compliance teams
Schedule joint training sessions that cover:
- How to determine whether a proposed information exchange falls within Article 75 scope
- When to escalate sharing requests that involve special category data or cross-border transfers to non-EU recipients
- How to document the necessity and proportionality of each sharing decision
- What to do if a customer submits a DSAR that includes data you've shared with partners
Your AML investigators need to understand data minimization; your privacy team needs to understand suspicious transaction reporting. Neither can operate in isolation.
Validation
Test data flow end-to-end
Select a representative partnership and conduct a controlled test: share a sample dataset, verify the partner receives only the specified data categories, confirm your audit logs capture the transfer, and validate that your systems enforce the agreed retention period.
Audit against Article 5 principles
Review your implementation against each GDPR principle:
- Lawfulness, fairness, transparency: Can you demonstrate a clear lawful basis and adequate notice?
- Purpose limitation: Are you preventing incompatible uses?
- Data minimization: Are you sharing only the fields necessary for the specific financial crime risk?
- Accuracy: Do you have processes to correct errors in shared data?
- Storage limitation: Are retention periods documented and enforced?
- Integrity and confidentiality: Are your technical measures appropriate for the risk?
Engage with the consultation process
When the EDPB and AMLA launch their public consultation in the first half of 2027, submit feedback based on your implementation experience. If your operational framework reveals ambiguities or conflicts between AML obligations and data protection requirements, document them and share them. The guidelines will be stronger if they reflect real-world compliance challenges.
Maintenance and ongoing tasks
Quarterly partnership review
Every quarter, audit your information sharing register. Confirm each partnership is still active, review the volume and categories of data shared, and assess whether any partnerships should be terminated or modified.
Monitor supervisory authority guidance
Watch for case law and guidance from your supervisory authority on how they interpret Article 75 in practice. If a supervisory authority issues an opinion on a similar information sharing arrangement, adapt your framework accordingly.
Update as Joint Guidelines evolve
The EDPB and AMLA will refine their Joint Guidelines based on consultation feedback. When the final version publishes, compare it to your current framework and identify gaps. You may need to revise data sharing agreements, update privacy notices, or add new technical controls.
Annual training refresh
AML regulations and data protection requirements both evolve. Schedule annual refresher training for everyone involved in information sharing, covering regulatory updates and lessons learned from your own operational experience.
You're not waiting for perfect clarity. You're building a framework that can adapt as the Joint Guidelines take shape, and you're doing it with enough lead time that July 2027 isn't a crisis deadline.



