Source: OJ L, 2024/2494, 25.9.2024

Current language: EN

Article 10 Restrictions and permissible uses of information


Summary What does Article 10 of the ITS on supervisory cooperation say?

This article establishes the confidentiality and use-limitation rules that govern the handling of requests for cooperation and exchange of information made under Article 96 of Regulation (EU) 2023/1114.

It sets out two clear obligations: one on the receiving body regarding non-disclosure, and one on the submitting body regarding the permitted use of any information it receives.

Together, these rules ensure that sensitive regulatory communications are protected and not repurposed beyond their intended scope.

Important points:

  • The receiving body shall not disclose the existence or content of a request unless the submitting body has given its express consent — and if consent cannot be given, the submitting body must withdraw or suspend its request.
  • The submitting body is restricted to using any received information solely for the performance of its duties, functions, or for compliance and enforcement purposes under Regulation (EU) 2023/1114.
  • Permitted enforcement use explicitly extends to initiating, conducting, or assisting in criminal, administrative, civil, or disciplinary proceedings arising from a breach of that Regulation.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. The receiving body shall not disclose the existence and content of a request for cooperation or exchange of information pursuant to Article 96 of Regulation (EU) 2023/1114unless the submitting body has given its express consent to such disclosure. Where such consent is not given and where it is not reasonably practicable to comply with the request without disclosing its existence or content, the submitting body shall withdraw or suspend its request until it is able to provide such consent to disclosure.

    1. The submitting body that received information within the scope of this Regulation shall use it solely for the performance of its duties and the exercise of its functions or for the purposes of securing compliance with or enforcement of Regulation (EU) 2023/1114, including initiating, conducting, or assisting in, criminal, administrative, civil or disciplinary proceedings resulting from a breach of that Regulation.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod