Source: OJ L, 2024/1640, 19.6.2024

Current language: EN

Article 30 Protected channels of communication


Summary What does Article 30 of the Sixth anti-money laundering (AML 6) directive say?

This article establishes FIU.net, the dedicated system for secure information exchange between Financial Intelligence Units across Member States.

It sets out the governance and operational rules for the platform, placing AMLA in charge of its management.

The article connects directly to Articles 31 and 32, which govern the actual obligations and procedures for information exchange and joint analyses — FIU.net is the mandatory technical infrastructure through which those obligations must be fulfilled.

Important points:

  • FIU.net is managed by AMLA and must be used by FIUs to exchange information; in the event of a technical failure, alternative means ensuring a high level of data security and data protection must be used instead.
  • FIUs are able to use FIU.net to cross-match data on a hit/no-hit basis with data made available by other FIUs and Union bodies, offices and agencies.
  • AMLA has the power to suspend access to FIU.net for any FIU, third-country counterpart, or Union body where it believes such access would jeopardise the security and confidentiality of the system, including over concerns about an FIU's independence and autonomy.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. A system for the exchange of information between FIUs of Member States (FIU.net) shall be set up. FIU.net shall ensure the secure communication and exchange of information and shall be capable of producing a written record of all processing activities. FIU.net may also be used for communications with FIUs’ counterparts in third countries and with other authorities and with Union bodies, offices and agencies. FIU.net shall be managed by AMLA.

    2. FIU.net shall be used for the exchange of information between FIUs and AMLA for the purposes of joint analyses pursuant to Article 32 of this Directive and Article 40 of Regulation (EU) 2024/1620.

    1. Member States shall ensure that FIUs exchange information pursuant to Article 31 and 32 using FIU.net. In the event of a technical failure of FIU.net, the information shall be transmitted by any other appropriate means ensuring a high level of data security and data protection.

    2. Exchanges of information between FIUs and their counterparts in third countries that are not connected to FIU.net shall take place through protected channels of communication.

    1. Member States shall ensure that, in order to fulfil their tasks as laid down in this Directive, FIUs cooperate to the greatest extent possible in the application of state-of-the-art technologies in accordance with their national law.

    2. Member States shall also ensure that FIUs cooperate to the greatest extent possible in the application of solutions developed and managed by AMLA in accordance with Article 5(5), point (i), Article 45(1), point (d), and Article 47 of Regulation (EU) 2024/1620.

    1. Member States shall ensure that FIUs are able to use the functionalities of the FIU.net to cross-match, on a hit/no-hit basis, the data they make available on FIU.net, with the data made available on that system by other FIUs and Union bodies, offices and agencies insofar as such cross-matching falls within the respective mandates of those Union bodies, offices and agencies.

    1. AMLA may suspend the access of an FIU or counterpart in a third country or Union body, office or agency to FIU.net where it has grounds to believe that such access would jeopardise the implementation of this Chapter and the security and confidentiality of the information held by FIUs and exchanged through FIU.net, including where there are concerns in relation to an FIU’s independence and autonomy.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod