The guidelines provide principles for assessing the equivalence of third-country confidentiality regimes against EU standards. They incorporate recent EBA assessments and extend their scope to confidentiality provisions under the MiCAR regulation. These guidelines do not address cooperation arrangements or participation in supervisory colleges.
This document is a guide published by the European Banking Authority (EBA) in December 2025, referenced EBA/GL/2025/05, concerning the amendment of the EBA/GL/2022/04 guidelines related to the equivalence of confidentiality regimes. It covers the assessment of confidentiality and professional secrecy regimes of third-country authorities to ensure their compliance with European standards. The scope includes legal frameworks under CRD, PSD2, AMLD, BRRD and MiCAR, and concerns several third-country authorities (Australia, China, Montenegro, Peru, Serbia, United Kingdom). The document is addressed to European competent authorities and is applicable from 4 May 2026 (p. 1-24).
The amended EBA guide aims to ensure that the confidentiality and professional secrecy regimes of third-country authorities are equivalent to European requirements, a prerequisite for sharing confidential information. This update notably incorporates the provisions of the MiCAR Regulation (2023/1114) relating to crypto-asset markets, clarifying definitions and the scope of application for competent authorities. Recent assessments confirm the equivalence of regimes applicable to AUSTRAC (Australia), NFRA (China), Central Bank of Montenegro, SBS (Peru), National Bank of Serbia, FCA and PRA (United Kingdom). These guidelines specify that equivalence concerns legal frameworks under CRD, PSD2, AMLD, BRRD and MiCAR, but do not address cooperation arrangements nor participation in supervisory colleges. No public consultation nor cost-benefit analysis was conducted, the impact being limited to inter-authority practices. Competent authorities must notify their compliance to the EBA before 4 May 2026, the effective date of the guidelines. This document is essential to ensure a harmonized framework for exchanging confidential information between the EU and third countries, strengthening international cooperation in financial supervision (p. 3-5, 9-11).
The EBA is mandated by Regulation (EU) No 1093/2010 and various sectoral directives (CRD, PSD2, AMLD, BRRD, MiCAR) to ensure that the confidentiality regimes of third-country authorities are equivalent to those of the EU before any exchange of confidential information. This requirement is a legal prerequisite for cooperation between European and foreign authorities. The amended guidelines incorporate recent assessments conducted by the EBA, notably under MiCAR, which introduces new confidentiality requirements for crypto-asset markets. The objective is to provide a clear and harmonized framework for assessing the equivalence of third-country regimes, thereby facilitating information exchange and cooperation. The guidelines do not cover cooperation modalities or participation in supervisory colleges. No public consultation nor cost-benefit analysis was conducted, as the amendments concern only inter-authority practices without direct impact on financial institutions (p. 4-7).
Regulatory framework and scope:
- The guidelines rely on Regulation (EU) No 1093/2010 and sectoral directives CRD, PSD2, AMLD, BRRD as well as on MiCAR Regulation (2023/1114).
- They concern the assessment of equivalence of confidentiality and professional secrecy regimes of third-country authorities, a prerequisite for sharing confidential information.
Assessment of third-country authorities:
- The EBA has confirmed the equivalence of regimes applicable to:
- AUSTRAC (Australia) under the AML Act 2006.
- NFRA (China), successor to the China Banking and Insurance Regulatory Commission, with a comprehensive set of laws and regulations (notably Administrative Rules on Professional Secrecy and Confidentiality, Civil Servant Law).
- Central Bank of Montenegro, with specific legal provisions (Central Bank Law, Law on Credit Institutions, AML Law).
- SBS (Peru), with a detailed legal framework covering confidentiality and sanctions (Law 26702, Law 27806).
- National Bank of Serbia, with several updated laws on banks, anti-money laundering and confidentiality.
- FCA and PRA (United Kingdom), with provisions derived from the Financial Services and Markets Act 2000 and the Banking Act 2009.
- These assessments focus on four key principles: notion of confidential information, professional secrecy obligation, use of confidential information, restrictions on disclosure.
Integration of MiCAR:
- The guidelines extend their scope to the provisions of Article 100 of MiCAR, specifying that MiCAR definitions apply.
- They specify that equivalence assessments must be taken into account within the framework of Articles 107 and 24 of MiCAR.
Obligations of competent authorities:
- Authorities must integrate these guidelines into their practices, notably by adapting their legal frameworks and supervisory processes.
- They must notify the EBA of their compliance or non-compliance before 4 May 2026.
- In the absence of notification, they will be considered non-compliant.
Limits and exclusions:
- The guidelines do not address cooperation arrangements or participation in supervisory colleges.
- No direct impact on financial institutions, which justifies the absence of public consultation and cost-benefit analysis.
Consultation and publication:
- The Banking Stakeholder Group (BSG) was consulted in writing on 26 November 2025 and made no comments.
- The guidelines will be translated into the official EU languages and published on the EBA website (p. 2-24).
Findings:
- The confidentiality and professional secrecy regimes of the assessed third-country authorities (Australia, China, Montenegro, Peru, Serbia, United Kingdom) are deemed equivalent to European requirements under CRD, PSD2, AMLD, BRRD and MiCAR.
- The assessments are based on detailed analysis of legal and regulatory frameworks, covering the definition of confidential information, secrecy obligations, use and disclosure of information.
- The guidelines now explicitly incorporate MiCAR provisions, notably Article 100.
Assumptions:
- Equivalence is assessed based on available legal and regulatory texts and practices declared by third-country authorities.
- European competent authorities will apply these guidelines in their assessments and decisions.
Interpretations:
- The integration of MiCAR reflects the evolution of the European regulatory framework, notably regarding crypto-asset markets.
- The absence of public consultation and cost-benefit analysis is justified by the technical and inter-authority nature of the subject.
Uncertainties:
- The guidelines do not cover practical cooperation modalities nor participation in colleges, which remain to be addressed separately.
- Future evolution of third-country legal frameworks may require new assessments.
- The real impact on international cooperation will depend on effective implementation by competent authorities (p. 3-7, 9-24).
The EBA concludes that the confidentiality and professional secrecy regimes of the listed third-country authorities are equivalent to European requirements, thus enabling secure sharing of confidential information under CRD, PSD2, AMLD, BRRD and MiCAR legislations. The amended guidelines incorporate MiCAR provisions, clarifying definitions and scope of application. They recommend that European competent authorities adopt these guidelines by adapting their practices and legal frameworks. Authorities must notify their compliance to the EBA before 4 May 2026, the effective date. The document specifies that these guidelines do not address cooperation arrangements nor participation in supervisory colleges, which fall under other instruments. Finally, publication and translation into all official EU languages will allow wide dissemination and harmonized application (p. 3-5, 9-11, 24).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.