AMLR Information Sharing
We design AMLR-compliant processes for information sharing, data protection and record-keeping
Information Sharing, Data Protection and Record Retention under the AMLR
9 mins read • Legal Writer • ANTI–MONEY LAUNDERING • 22 June 2026
In last week’s article in this blog series, we reviewed reporting obligations and how obliged entities must act when suspicions of money laundering or terrorist financing arise. Reporting to the Financial Intelligence Unit is a central part of the AMLR. For obliged entities, however, the responsibility does not stop at identifying and reporting suspicious transactions. They must also be able to manage information sharing, personal data and documentation in a legally secure manner. This requires clear processes, appropriate technical solutions and, often, support from experienced AML specialists.
Articles 75–78 of the AMLR address how obliged entities may share information with each other, how personal data may be processed, how long records must be retained and how information must be made available quickly to competent authorities. The rules are detailed and impose high demands on both legal assessment and practical compliance.
Article 75 AMLR – Information-sharing partnerships
Article 75 provides clear regulation of so-called information-sharing partnerships. The provision means that obliged entities may, in certain situations, share information with each other where this is strictly necessary to fulfil their obligations under the AMLR.
The purpose of the provision is to enable information sharing between obliged entities, and in some cases also authorities, to uncover unlawful transactions. This may include, for example, transactions linked to predicate offences to money laundering, money laundering or terrorist financing.
At the same time, information sharing may involve significant risks to privacy, confidentiality and data protection. Information may only be shared where this is strictly necessary to fulfil obligations under Chapter Three on customer due diligence measures, Article 69 on reporting suspicions, and in accordance with fundamental rights.
Obliged entities that wish to participate in an information-sharing partnership must notify their supervisory authorities before the partnership begins. The supervisory authorities must verify that the partnership has sufficient procedures and mechanisms to ensure compliance and that a data protection impact assessment has been carried out. Each participating obliged entity remains independently responsible for compliance with the rules.
Article 75.3 contains an exhaustive list of the types of information that may be shared within a partnership, limited to the following information:
- Information on the identity of the customer and the beneficial owner.
- Information on the purpose and intended nature of the business relationship or transaction and, where applicable, information on the source of funds.
- Information on the customer’s transactions.
- Information on risk factors linked to the customer.
- The obliged entity’s own risk assessments of the customer.
- Information retained under the rules on record-keeping.
- Information on suspicions and suspicious transactions.
Only the information that is actually required for the purpose of the partnership may be disclosed. This means that information that is not necessary for that purpose may not be exchanged. For obliged entities, this requires clear internal guidelines on what information may be disclosed, to whom, in which situations and subject to which limitations.
Article 75 also contains several safeguards designed to reduce the risk of improper use of information. The procedure for exchanging information between obliged entities also entails an obligation to comply with certain conditions under Article 75.4. The list of conditions is extensive, but includes, among other things, requirements such as:
- All information exchanges must be documented.
- Technical and organisational security measures must be implemented.
- AI-generated information may only be shared where there is sufficient human oversight.
Obliged entities may not rely solely on information received from other participants in the partnership. If a business receives information from a partnership indicating that a customer is assessed as high risk, the business must conduct its own risk assessment before deciding, for example, to terminate the business relationship.
This condition is central from a legal certainty perspective. For example, a customer should not be denied access to basic financial services solely on the basis of information from a third party.
Article 75.5 further provides that information received by an obliged entity within a partnership must not be onwardly transmitted, for example where specific authorities request the information or where the information is provided to another obliged entity in connection with reliance on another obliged entity’s customer due diligence measures.
Obliged entities participating in information-sharing partnerships must also have internal guidelines and procedures in place before participation begins.
These guidelines must, among other things, describe and identify:
- What information may be shared and to what extent, and how access to information must be restricted.
- The roles and responsibilities within the partnership.
- The risk situations that may justify information sharing.
Supervisory authorities may also require an independent audit of how the partnership operates. This may be particularly relevant for larger banks and financial groups where the exchange of information is extensive.
Article 76 AMLR – Data protection and personal data processing
Article 76 addresses which personal data obliged entities may process as part of their AML work. The starting point is that the processing of special categories of personal data under the GDPR is normally prohibited. The AMLR, however, provides exceptions where this is strictly necessary to prevent money laundering and terrorist financing.
This means that obliged entities may, in certain cases, process special categories of personal data under Article 9 GDPR and data relating to criminal convictions and offences under Article 10 GDPR.
Article 76.2 AMLR sets out clear requirements for the processing of data falling within Article 9 GDPR to be permitted:
- Customers must be informed that such data may be processed.
- The data must be accurate and come from reliable sources.
- The processing of data must not result in biased or discriminatory decisions.
- A high level of security and confidentiality must be ensured.
For data relating to criminality under Article 10 GDPR, additional requirements apply beyond those set out in Article 76.2 AMLR:
- The personal data under Article 10 GDPR must concern predicate offences to money laundering, money laundering or terrorist financing.
- Obliged entities must have procedures enabling them to distinguish between suspicions, ongoing investigations, legal proceedings and convictions. The AMLR specifically highlights the presumption of innocence, the right to a fair trial and the right of defence.
An important provision in Article 76 is that personal data processed under the AMLR may only be used to prevent money laundering and terrorist financing. It is therefore prohibited to use information collected for AML purposes for commercial purposes, such as marketing, customer segmentation or sales analysis.
Article 76 also allows obliged entities to use automated processes, profiling and AI systems in their AML work. However, the Regulation sets clear requirements for how this may be done:
- Only data collected under the customer due diligence measures in the AMLR may be used.
- Decisions must be subject to meaningful human intervention.
- The customer must be able to obtain an explanation of the decision and must be able to appeal the decision.
This means that a business may not allow an AI system alone to determine that a customer should be denied an account, have their business relationship terminated or become subject to enhanced customer due diligence measures.
Article 77 AMLR – Record-keeping
Article 77 contains detailed rules on the documents and information that obliged entities must retain. The provision covers, among other things, the obligation to retain:
- Copies of customer due diligence documentation.
- Documentation of assessments of suspicions carried out under Article 69.2 AMLR.
- Copies of suspicious transaction reports.
- Documentation identifying transactions.
- Information from information-sharing partnerships under Article 75.
The AMLR further requires that these records must not be editable retrospectively.
Obliged entities may, in certain cases, choose to retain references to information instead of copies of the information itself. This exception to Article 77.1 is only permitted, however, where the information can be provided quickly to authorities and where safeguards are in place to prevent the information from being altered.
The starting point under Article 77.3 is that records must be retained for five years from the point at which the business relationship ends, the transaction is carried out, or a business relationship or transaction is refused. After these five years, the personal data must, as a general rule, be erased.
Competent authorities may, however, in individual cases require records to be retained for longer where this is necessary to prevent, detect, investigate or prosecute money laundering or terrorist financing. Any retention period extending beyond the ordinary period may be no longer than an additional five years.
For obliged entities, this means that clear routines are needed and that data must not be retained for longer than necessary. Incorrect retention may result in important information being unavailable during an authority review. At the same time, excessive retention may constitute a breach of the GDPR.
Article 78 AMLR – Rapid access to information
Article 78 requires obliged entities to be able to respond quickly and fully to requests from the Financial Intelligence Unit and other competent authorities.
Obliged entities must therefore have systems that make it possible to identify, among other things, whether a particular person is or has been a customer, as well as the type of business relationship that has existed and the nature of that relationship. Requests must be handled through secure channels and in a manner that ensures confidentiality.
This means that obliged entities need both technical solutions and internal routines for how requests are received, reviewed, documented and answered.
Practical implications for businesses
Articles 75–78 mean that AML work is becoming more integrated with data protection, information security and internal governance. Obliged entities must not only identify money laundering risks. They must also ensure that the right information is shared, that sensitive data is handled correctly and that documentation is available when authorities request it.
For many organisations, it will also be important to review existing systems for record-keeping, customer due diligence and regulatory reporting. At Morling Consulting, our legal consultants specialising in AML regulation help businesses across Europe design processes for information sharing, data protection and documentation. We also assist obliged entities with support from experienced AML specialists to align internal routines with the regulatory framework.
In last week’s article in this blog series, we reviewed reporting obligations and how obliged entities must act when suspicions of money laundering or terrorist financing arise. Reporting to the Financial Intelligence Unit is a central part of the AMLR. For obliged entities, however, the responsibility does not stop at identifying and reporting suspicious transactions. They must also be able to manage information sharing, personal data and documentation in a legally secure manner. This requires clear processes, appropriate technical solutions and, often, support from experienced AML specialists.
Articles 75–78 of the AMLR address how obliged entities may share information with each other, how personal data may be processed, how long records must be retained and how information must be made available quickly to competent authorities. The rules are detailed and impose high demands on both legal assessment and practical compliance.
Article 75 AMLR – Information-sharing partnerships
Article 75 provides clear regulation of so-called information-sharing partnerships. The provision means that obliged entities may, in certain situations, share information with each other where this is strictly necessary to fulfil their obligations under the AMLR.
The purpose of the provision is to enable information sharing between obliged entities, and in some cases also authorities, to uncover unlawful transactions. This may include, for example, transactions linked to predicate offences to money laundering, money laundering or terrorist financing.
At the same time, information sharing may involve significant risks to privacy, confidentiality and data protection. Information may only be shared where this is strictly necessary to fulfil obligations under Chapter Three on customer due diligence measures, Article 69 on reporting suspicions, and in accordance with fundamental rights.
Obliged entities that wish to participate in an information-sharing partnership must notify their supervisory authorities before the partnership begins. The supervisory authorities must verify that the partnership has sufficient procedures and mechanisms to ensure compliance and that a data protection impact assessment has been carried out. Each participating obliged entity remains independently responsible for compliance with the rules.
Article 75.3 contains an exhaustive list of the types of information that may be shared within a partnership, limited to the following information:
- Information on the identity of the customer and the beneficial owner.
- Information on the purpose and intended nature of the business relationship or transaction and, where applicable, information on the source of funds.
- Information on the customer’s transactions.
- Information on risk factors linked to the customer.
- The obliged entity’s own risk assessments of the customer.
- Information retained under the rules on record-keeping.
- Information on suspicions and suspicious transactions.
Only the information that is actually required for the purpose of the partnership may be disclosed. This means that information that is not necessary for that purpose may not be exchanged. For obliged entities, this requires clear internal guidelines on what information may be disclosed, to whom, in which situations and subject to which limitations.
Article 75 also contains several safeguards designed to reduce the risk of improper use of information. The procedure for exchanging information between obliged entities also entails an obligation to comply with certain conditions under Article 75.4. The list of conditions is extensive, but includes, among other things, requirements such as:
- All information exchanges must be documented.
- Technical and organisational security measures must be implemented.
- AI-generated information may only be shared where there is sufficient human oversight.
Obliged entities may not rely solely on information received from other participants in the partnership. If a business receives information from a partnership indicating that a customer is assessed as high risk, the business must conduct its own risk assessment before deciding, for example, to terminate the business relationship.
This condition is central from a legal certainty perspective. For example, a customer should not be denied access to basic financial services solely on the basis of information from a third party.
Article 75.5 further provides that information received by an obliged entity within a partnership must not be onwardly transmitted, for example where specific authorities request the information or where the information is provided to another obliged entity in connection with reliance on another obliged entity’s customer due diligence measures.
Obliged entities participating in information-sharing partnerships must also have internal guidelines and procedures in place before participation begins.
These guidelines must, among other things, describe and identify:
- What information may be shared and to what extent, and how access to information must be restricted.
- The roles and responsibilities within the partnership.
- The risk situations that may justify information sharing.
Supervisory authorities may also require an independent audit of how the partnership operates. This may be particularly relevant for larger banks and financial groups where the exchange of information is extensive.
Article 76 AMLR – Data protection and personal data processing
Article 76 addresses which personal data obliged entities may process as part of their AML work. The starting point is that the processing of special categories of personal data under the GDPR is normally prohibited. The AMLR, however, provides exceptions where this is strictly necessary to prevent money laundering and terrorist financing.
This means that obliged entities may, in certain cases, process special categories of personal data under Article 9 GDPR and data relating to criminal convictions and offences under Article 10 GDPR.
Article 76.2 AMLR sets out clear requirements for the processing of data falling within Article 9 GDPR to be permitted:
- Customers must be informed that such data may be processed.
- The data must be accurate and come from reliable sources.
- The processing of data must not result in biased or discriminatory decisions.
- A high level of security and confidentiality must be ensured.
For data relating to criminality under Article 10 GDPR, additional requirements apply beyond those set out in Article 76.2 AMLR:
- The personal data under Article 10 GDPR must concern predicate offences to money laundering, money laundering or terrorist financing.
- Obliged entities must have procedures enabling them to distinguish between suspicions, ongoing investigations, legal proceedings and convictions. The AMLR specifically highlights the presumption of innocence, the right to a fair trial and the right of defence.
An important provision in Article 76 is that personal data processed under the AMLR may only be used to prevent money laundering and terrorist financing. It is therefore prohibited to use information collected for AML purposes for commercial purposes, such as marketing, customer segmentation or sales analysis.
Article 76 also allows obliged entities to use automated processes, profiling and AI systems in their AML work. However, the Regulation sets clear requirements for how this may be done:
- Only data collected under the customer due diligence measures in the AMLR may be used.
- Decisions must be subject to meaningful human intervention.
- The customer must be able to obtain an explanation of the decision and must be able to appeal the decision.
This means that a business may not allow an AI system alone to determine that a customer should be denied an account, have their business relationship terminated or become subject to enhanced customer due diligence measures.
Article 77 AMLR – Record-keeping
Article 77 contains detailed rules on the documents and information that obliged entities must retain. The provision covers, among other things, the obligation to retain:
- Copies of customer due diligence documentation.
- Documentation of assessments of suspicions carried out under Article 69.2 AMLR.
- Copies of suspicious transaction reports.
- Documentation identifying transactions.
- Information from information-sharing partnerships under Article 75.
The AMLR further requires that these records must not be editable retrospectively.
Obliged entities may, in certain cases, choose to retain references to information instead of copies of the information itself. This exception to Article 77.1 is only permitted, however, where the information can be provided quickly to authorities and where safeguards are in place to prevent the information from being altered.
The starting point under Article 77.3 is that records must be retained for five years from the point at which the business relationship ends, the transaction is carried out, or a business relationship or transaction is refused. After these five years, the personal data must, as a general rule, be erased.
Competent authorities may, however, in individual cases require records to be retained for longer where this is necessary to prevent, detect, investigate or prosecute money laundering or terrorist financing. Any retention period extending beyond the ordinary period may be no longer than an additional five years.
For obliged entities, this means that clear routines are needed and that data must not be retained for longer than necessary. Incorrect retention may result in important information being unavailable during an authority review. At the same time, excessive retention may constitute a breach of the GDPR.
Article 78 AMLR – Rapid access to information
Article 78 requires obliged entities to be able to respond quickly and fully to requests from the Financial Intelligence Unit and other competent authorities.
Obliged entities must therefore have systems that make it possible to identify, among other things, whether a particular person is or has been a customer, as well as the type of business relationship that has existed and the nature of that relationship. Requests must be handled through secure channels and in a manner that ensures confidentiality.
This means that obliged entities need both technical solutions and internal routines for how requests are received, reviewed, documented and answered.
Practical implications for businesses
Articles 75–78 mean that AML work is becoming more integrated with data protection, information security and internal governance. Obliged entities must not only identify money laundering risks. They must also ensure that the right information is shared, that sensitive data is handled correctly and that documentation is available when authorities request it.
For many organisations, it will also be important to review existing systems for record-keeping, customer due diligence and regulatory reporting. At Morling Consulting, our legal consultants specialising in AML regulation help businesses across Europe design processes for information sharing, data protection and documentation. We also assist obliged entities with support from experienced AML specialists to align internal routines with the regulatory framework.
Related posts
9 July 2026
Money Laundering in Real Estate – Risks, Obligations and Practical Measures
7 July 2026
EU cooperation under the AMLR – final part on Articles 81–90
30 June 2026
Risk-mitigating measures against anonymous instruments and large cash payments – Articles 79–80 AMLR
Speak to an AML lawyer
Do you need to align your AMLR information-sharing and record-keeping processes? Contact us and we will assess your compliance framework
"*" indicates required fields