29 July 2026
EC ¦ Report on the Implementation of Directive (EU) 2019/1153 Laying Down Rules Facilitating the Use of Financial and Other Information
EU financial intelligence rules deliver faster access to bank data, but operational gaps remain
The European Union’s framework for financial intelligence is entering a more demanding phase. Directive (EU) 2019/1153 has substantially improved how law enforcement authorities access bank account information and obtain financial intelligence for the prevention, detection, investigation and prosecution of serious crime.
Its practical importance lies in the connection it creates between financial intelligence units (FIUs), law enforcement authorities, asset recovery offices, Europol and national bank account registries. That connection supports the financial investigation of money laundering, terrorist financing and the predicate offences that generate criminal proceeds, including drug trafficking, organised crime, corruption, fraud, migrant smuggling and cybercrime.
The framework is not limited to identifying suspicious transactions. Its wider purpose is to help authorities follow money through accounts, uncover financial links between suspects, identify hidden assets and support freezing and confiscation measures.
Twenty-six Member States are bound by the directive. Denmark is not covered. Although implementation has been broadly successful, national rules do not always fully reflect the directive’s detailed requirements. The remaining issues concern both operational effectiveness and safeguards for personal data.
Direct access to centralised bank account registries
A central feature of the directive is the requirement for Member States to give designated competent authorities direct and immediate access to centralised bank account registries. Access must be available when necessary for preventing, detecting, investigating or prosecuting serious criminal offences, or for supporting a criminal investigation.
Asset recovery offices must be among the authorities able to use these registries. This is particularly significant because early identification of accounts can determine whether criminal assets are located and secured before they are transferred, concealed or dissipated.
The registries generally allow authorities to establish whether a person or entity holds bank or payment accounts and where those accounts are located. They do not necessarily provide the complete transaction history. That distinction matters: account identification is often the first step, while transaction records, beneficial ownership information and other financial data are needed to reconstruct the movement and use of criminal proceeds.
Member States have generally provided the required access. However, several have not fully transposed the safeguards governing registry use. These include requirements that designated staff maintain high standards of confidentiality and data protection, demonstrate integrity and appropriate skills, and use systems protected by high technological standards.
Several countries apply these requirements in practice even where their legislation does not state them clearly. That may reduce immediate operational risk, but it creates uncertainty about accountability, legal certainty and the consistency of safeguards across the Union.
Logging and oversight need closer attention
The directive requires operators of centralised bank account registries to keep detailed records of searches and access. The records must identify the case, the date and time of the query, the data used to initiate it, the result identifier, the authority involved and the official who carried out the search.
Data protection officers must regularly review the logs. They must also be available to the national supervisory authority, and the records must be erased five years after creation.
All Member States maintain access logs, but compliance is not uniform. In two cases, the authority conducting the search, rather than the registry operator, keeps the records. Elsewhere, national rules do not guarantee that every required item is recorded or apply a retention period that differs from the five-year requirement.
These details are not administrative technicalities. Financial intelligence systems provide access to highly sensitive information, and logging is central to detecting misuse, unauthorised searches and disproportionate access. The directive’s logging requirements are more specific than the general safeguards under the Law Enforcement Directive, particularly concerning regular review, result identifiers and mandatory retention periods.
FIU cooperation remains central to money-laundering investigations
The directive requires FIUs to provide designated competent authorities, upon request and on a case-by-case basis, with financial information already in their possession or with financial analyses they have produced.
This information may include material received from banks and other obliged entities through suspicious transaction reporting, information obtained from foreign FIUs and intelligence developed through the FIU’s own analytical work. It can help law enforcement connect suspicious financial activity to a predicate offence, identify wider criminal networks or establish the financial dimension of an investigation.
FIUs retain control over dissemination. They may refuse requests where disclosure could harm an ongoing investigation or analysis, would be disproportionate to the legitimate interests of a person or entity, or would not be relevant to the request. A refusal must be explained, and use for purposes beyond those originally approved requires the FIU’s prior consent.
All Member States have created a legal basis for FIU responses to requests from designated authorities. Some gaps remain, however. In certain countries, general cooperation provisions are used instead of rules specifically reflecting the directive. Other national systems refer only to terrorism financing, money laundering and related predicate offences rather than the broader category of serious crime covered by the directive. In at least one Member State, the FIU cannot respond to requests from every designated authority, but only to judicial authorities.
The newer anti-money-laundering framework provides more detailed rules in several areas. It confirms FIU autonomy, supports direct or indirect access to law enforcement information and expands the range of authorities that may request information. It also introduces more explicit obligations concerning timely responses and feedback.
These developments strengthen the system, but overlapping provisions may create uncertainty for national authorities. The relationship between the directive and the newer anti-money-laundering rules will need to be managed carefully to avoid inconsistent procedures.
Cross-border exchanges do not yet match criminal mobility
The directive allows competent authorities in one Member State to exchange financial information or financial analyses obtained from their FIU with counterparts in another Member State. The information must be used for the purpose for which it was requested or supplied. Further use or onward disclosure requires the prior consent of the FIU that provided it.
Member States have generally implemented this mechanism. Some national provisions, however, do not expressly state the requirements of purpose limitation and prior consent. Those principles are also addressed in the newer anti-money-laundering rules, which may reduce the practical impact of some gaps but do not eliminate the need for clear national implementation.
A broader structural problem concerns the absence of specific time limits in the directive for cross-border exchanges between FIUs and competent authorities. By comparison, the EU rules governing general law enforcement information exchanges contain organisational requirements, single points of contact and defined response periods.
Financial information is often shared as part of a wider package of investigative leads. Treating financial intelligence under a separate and slower process can create friction, even though the financial trail may be the most time-sensitive aspect of the investigation. Criminal funds can cross several jurisdictions within minutes, while formal cooperation procedures may take considerably longer.
Europol’s experience illustrates both the value and the limitations of the system. During 2023 and 2024, Europol made more than 160 requests for bank account and financial information and received responses in approximately 75% of cases. The information helped identify previously unknown suspects, reveal connections, map criminal financial circuits and support the freezing and recovery of illicit assets.
However, the average response delay was around 50 days. That delay can undermine investigations involving rapidly transferable funds, especially in cases involving online fraud, cybercrime, drug trafficking and migrant smuggling.
The private sector remains a critical source of evidence
Law enforcement authorities continue to face obstacles when seeking financial information from banks, payment institutions, virtual asset service providers and other obliged entities.
A recurring challenge is the volume and diversity of financial data. Authorities have called for common formats, improved analytical technology and secure systems that automate the submission and receipt of requests. Without such tools, investigators may receive relevant data but lack the capacity to process it quickly enough to identify patterns, links and asset movements.
Access during the early investigative stage is another major issue. In many Member States, law enforcement cannot request information directly from obliged entities before formal criminal proceedings begin. More than two thirds of the law enforcement authorities consulted supported the possibility of direct exchanges with obliged entities at an early stage, mainly to improve speed.
There is an important counterargument. Maintaining the FIU as an intermediary can protect the confidentiality of investigations and prevent premature disclosure of law enforcement interest. The appropriate balance may therefore depend on the type of information requested, the seriousness of the suspected conduct, the stage of the investigation and the need for judicial authorisation.
Cross-border access is particularly difficult. Where direct access to obliged entities is unavailable, authorities may need to use the European Investigation Order. Recognition can take up to 30 days, while funds can be moved across borders almost instantly. That mismatch is especially problematic where investigators are attempting to preserve proceeds before they reach additional accounts, crypto-asset platforms or third-country service providers.
Crypto-assets expose weaknesses in third-country cooperation
Virtual assets have become a recurring feature of financial crime investigations. Cryptocurrencies may be used in cybercrime, ransomware, drug trafficking, migrant smuggling, fraud and money laundering. Blockchain records can provide valuable investigative leads, but obtaining customer and account information from service providers remains difficult.
Several Member States have reported limited or no responses from virtual asset service providers established in third countries that offer services to customers in the Union. This creates a significant enforcement gap. A transaction may be visible on a public blockchain, while the identity, location and financial profile of the person controlling the relevant wallet remain inaccessible.
The effectiveness of the EU framework will therefore depend not only on domestic rules, but also on cooperation with foreign service providers, foreign authorities and platforms operating across jurisdictions. The wider application of anti-money-laundering obligations to the crypto-asset sector should improve the position, but practical enforcement will remain essential.
Public-private partnerships can improve intelligence quality
Several Member States have developed public-private partnerships involving obliged entities, FIUs and competent authorities. These partnerships can allow financial institutions and public authorities to share information on typologies, trends and, in some cases, operational cases within a controlled legal and security framework.
Where operational cooperation is permitted, financial institutions can provide targeted intelligence while authorities can share information about emerging threats and investigative priorities. This can help identify laundering methods, detect networks and disrupt criminal activity before assets are fully integrated into the legitimate economy.
In many countries, cooperation remains limited to general typologies and trends. The more effective models permit the exchange of operational information in defined circumstances, supported by clear safeguards, confidentiality rules and governance arrangements.
Such partnerships do not replace formal investigative powers or judicial cooperation. They can, however, reduce the delay associated with sequential requests and improve the quality of information supplied to investigators.
Data protection safeguards remain uneven
The directive contains specific safeguards for the processing of personal data, including sensitive data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or biometric characteristics, and information concerning a person’s sex life or sexual orientation.
Sensitive data must be processed with appropriate safeguards and by authorised staff who have received specific training, under the guidance of the data protection officer. Some Member States have not fully reflected these requirements in national law.
This issue illustrates a wider problem. The directive operates alongside general data protection rules for law enforcement, the newer anti-money-laundering legislation, asset recovery rules and general law enforcement information-exchange provisions. Where comparable information is processed under different instruments, authorities may face different obligations for authorisation, training, logging, retention and onward use.
The system must protect personal data without making financial investigations impracticable. Clearer alignment between overlapping instruments could help authorities understand which safeguards apply and reduce unnecessary administrative duplication.
Record-keeping creates a substantial administrative burden
For each exchange of information, Member States must ensure that records contain the names and contact details of the requesting organisation and officer, the national case reference, the subject matter of the request and the measures taken in response. Records must be retained for five years and made available to the national supervisory authority upon request.
Several implementation problems have been identified. Some national laws do not expressly require record-keeping even where records are maintained in practice. Other systems record only certain categories of exchange, such as requests made by an FIU, rather than covering all exchanges within the directive’s scope.
The scale of the obligation is considerable. It covers exchanges involving 26 FIUs and approximately 200 designated competent authorities, many of which include numerous divisions and departments.
The administrative burden should be assessed alongside existing electronic case-management systems. Modern systems may already record much of the relevant information, particularly where financial data is exchanged together with other investigative material. Better integration could preserve auditability while reducing duplicate data entry and reporting requirements.
Extending the definition of financial information remains premature
The directive defines financial information broadly as any type of information or data, such as data on financial assets, movements of funds or financial business relationships, already held by an FIU.
The question under review is whether the definition should also cover information held by public authorities or obliged entities that is available to an FIU without coercive measures under national law.
The evidence points to genuine operational problems. Authorities need better tools for processing large datasets, faster access to information held by private entities, improved cross-border procedures and more consistent access to crypto-asset information. These problems could support future legislative action.
At the same time, the legal landscape has changed significantly since the directive was adopted. The new anti-money-laundering package, the EU Anti-Money Laundering Authority and the asset recovery and confiscation rules are still being implemented or brought into operation. Their effects on access to financial information, financial investigations and asset recovery cannot yet be fully assessed.
It is therefore too early to conclude that expanding the definition of financial information would be necessary and proportionate. The priority should be to implement the existing reforms, measure their practical results and determine whether the remaining obstacles arise from a lack of legal powers, inadequate technology, insufficient resources or slow cooperation procedures.
Common transaction formats are an immediate priority
A practical improvement expected in 2026 is an implementing act requiring financial entities to provide transaction records in a common format across the Union. This responds to a long-standing law enforcement concern.
Standardisation could improve the speed and reliability of financial analysis, make it easier to compare data from multiple institutions and jurisdictions, and support the use of automated tools to identify suspicious flows. It could also reduce the cost of converting incompatible datasets during investigations.
Common formats will not, by themselves, solve problems involving legal access, third-country providers or the interpretation of complex transactions. They should nevertheless make existing powers more usable and help investigators move from raw records to actionable intelligence more efficiently.
The next phase should focus on implementation and integration
Directive 2019/1153 has strengthened the EU’s ability to connect bank account information, FIU intelligence and law enforcement investigations. It has improved early account identification, supported asset tracing and increased Europol’s access to financial information.
The main weaknesses are less about the absence of a basic legal framework than about uneven implementation and operational speed. These include incomplete national provisions on confidentiality and technical security, inconsistent logging, unclear interaction between legal instruments, limited early-stage access to obliged entities, inadequate data-processing capacity and slow cross-border responses.
The next phase should therefore focus on making the existing framework work consistently in practice. That means completing national implementation, aligning overlapping rules, improving secure information systems, strengthening FIU and law enforcement cooperation, supporting responsible public-private partnerships and reducing delays in cross-border financial investigations.
A further expansion of the definition of financial information may eventually be justified. For the moment, the stronger case is for testing the full effect of the reforms already adopted before adding another layer of legal obligations.
Dive deeper
- EUR-Lex ¦ REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL on the implementation of Directive (EU) 2019/1153 laying down rules facilitating the use of financial and other information for the prevention, detection, investigation or prosecution of certain criminal offences, and repealing Council Decision 2000/642/JHA, including the assessment of the need for, and proportionality of, extending the definition of financial information ¦ Link