Source: OJ L, 2024/2545, 26.11.2024

Current language: EN

Article 11 Restrictions and permissible use of information


Summary What does Article 11 of the ITS on competent authority information exchange say?

This article governs the confidentiality obligations that apply when competent authorities exchange information and cooperate with one another.

It sits alongside the procedural articles governing requests and responses, adding an important layer of protection around how shared information is handled and disclosed.

The article covers three distinct confidentiality concerns: the requirement to flag sensitive information, the rules around disclosing the existence of a request, and the restrictions on how received information may ultimately be used.

Important points:

  • Both the requesting authority and the requested authority are required to include a confidentiality warning in all communications relating to requests for assistance or unsolicited information transfers.
  • The requested authority may only disclose the existence of a request to a third party after discussing the scope of that disclosure with, and obtaining the consent of, the requesting authority — failing which it must not act on the request.
  • Information received under Article 10 (unsolicited transmission) may only be used for securing compliance with or enforcement of Regulation (EU) 2023/1114, including related criminal, administrative, civil, or disciplinary proceedings.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The requesting authority and the requested authority shall include an appropriate confidentiality warning in any request for assistance, reply to a request for assistance or transmission of unsolicited information in accordance with the forms set out in the relevant Annex.

    1. Where, in order to execute the request, the requested authority is required to disclose the fact that the requesting authority has made a request, it shall disclose the request after having discussed the nature and extent of the disclosure required with the requesting authority and after having obtained the consent of that competent authority to such disclosure. Where the requesting authority does not provide its consent to the disclosure, the requested authority shall not act upon the request, and the requesting authority may withdraw or suspend its request until it is able to provide such consent to disclosure.

    1. Information received in accordance with Article 10 shall be used solely for the purposes of securing compliance with or enforcement of the provisions of Regulation (EU) 2023/1114, including initiating, conducting or assisting in criminal, administrative, civil or disciplinary proceedings resulting from a breach of the provisions of that Regulation.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod