in force 2025-11-10
02010R1094-20250701 → 02010R1094-20251110
Amended by Regulation (EU) 2025/2088 32025R2088
Regulation (EU) 2025/2088 of the European Parliament and of the Council of 8 October 2025 amending Regulations (EU) No 1092/2010, (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010, (EU) No 806/2014, (EU) 2021/523 and (EU) 2024/1620 as regards certain reporting requirements in the fields of financial services and investment support (Text with EEA relevance)
detected 2026-09-04
8 provisions touched — 8 substantive, 0 date-only, 0 disputed · every change carries an explanation that passed its citation check
MODIFIED +639 −0 Art. 16a Opinions§
applies from: unchanged
Paragraph 1 now includes two additional subparagraphs stating that the Authority's opinions may, where appropriate, address the functioning of legislative acts in force, including the appropriateness of removing redundant or obsolete reporting and disclosure requirements in Union law or national transposing measures.
It also adds that, for opinions on legislative acts in force, the Authority may consult relevant stakeholders on that matter and take their input into account, and that the Commission may, after considering those opinions, submit a legislative proposal to the European Parliament and the Council where appropriate.
Paragraphs 2 and 3 of the article remain textually unchanged between the two versions.
Cited: Art. 16a, v2 · Art. 16a, v1
text before / after
02010R1094-20250701 → 02010R1094-20251110
Article 16a Opinions 1. The Authority may, upon a request from the European Parliament, from the Council or from the Commission, or on its own initiative, provide opinions to the European Parliament, to the Council and to the Commission on all issues related to its area of competence. In its opinions, the Authority may, where appropriate, address the functioning of legislative acts in force, including the appropriateness of removing any redundant or obsolete reporting and disclosure requirements in Union law or in measures of national law transposing Union law. To provide opinions on legislative acts in force, as referred to in the second subparagraph, the Authority may consult all relevant stakeholders specifically on that matter and take their input into account. The Commission may, after considering those opinions, where appropriate, submit to the European Parliament and to the Council a legislative proposal. 2. The request referred to in paragraph 1 may include a public consultation or a technical analysis. 3. With regard to the prudential assessment of mergers and acquisitions falling within the scope of Directive 2009/138/EC and which, according to that Directive, require consultation between competent authorities from two or more Member States, the Authority may, at the request of one of the competent authorities concerned, issue and publish an opinion on a prudential assessment, except in relation to the criteria set out in point (e) of Article 59(1) of Directive 2009/138/EC. The opinion shall be issued promptly and, in any event, before the end of the assessment period in accordance with Directive 2009/138/EC. 4. The Authority may, upon a request from the European Parliament, from the Council or from the Commission provide technical advice to the European Parliament, the Council and the Commission in the areas set out in the legislative acts referred to in Article 1(2).
MODIFIED +332 −12 Art. 29 Common supervisory culture§
applies from: unchanged
Point (d) of Article 29(1) now adds that proposed amendments to technical standards, guidelines and recommendations may include amendments addressing three specified matters.
These added matters, listed as new points (i) to (iii), cover removing redundant or obsolete reporting and disclosure requirements while minimising costs and preserving data usability and quality, ensuring proportionate and consistent reporting and disclosure requirements, and addressing regulatory gaps related to reporting and disclosure requirements.
The earlier version of point (d) contained no such list and ended after referring to proposing amendments where appropriate.
Cited: Art. 29, v2 · Art. 29, v1
text before / after
02010R1094-20250701 → 02010R1094-20251110
Article 29
Common supervisory culture
1. The Authority shall play an active role in building a common Union supervisory culture and consistent supervisory practices, as well as in ensuring uniform procedures and consistent approaches throughout the Union. The Authority shall carry out, at a minimum, the following activities:
(a) providing opinions to competent authorities;
(aa) establishing Union strategic supervisory priorities in accordance with Article 29a;
(ab) establishing coordination groups in accordance with Article 45b to promote supervisory convergence and identify best practices;
(b) promoting an effective bilateral and multilateral exchange of information between competent authorities, pertaining to all relevant issues, including cyber security and cyber-attacks, with full respect for the applicable confidentiality and data protection provisions provided for in the relevant Union legislative acts;
(c) contributing to developing high quality and uniform supervisory standards, including reporting standards, and international accounting standards in accordance with Article 1(3);
(d) reviewing the application of the relevant regulatory and implementing technical standards adopted by the Commission, and of the guidelines and recommendations issued by the Authority and proposing amendments where appropriate; appropriate, including amendments to:
(i) remove redundant or obsolete reporting and
disclosure requirements, and minimise costs while preserving data usability and quality;
(ii) ensure proportionate and consistent reporting and disclosure requirements; and
(iii) address regulatory gaps related to reporting and disclosure requirements;
(e) establishing sectoral and cross-sectoral training programmes, including with respect to technological innovation, different forms of cooperatives and mutuals, facilitating personnel exchanges and encouraging competent authorities to intensify the use of secondment schemes and other tools; and
(f) putting in place a monitoring system to assess material environmental, social and governance-related risks, taking into account the Paris Agreement to the United Nations Framework Convention on Climate Change.
2. The Authority may, as appropriate, develop new practical instruments and convergence tools to promote common supervisory approaches and practices.
For the purpose of establishing a common supervisory culture, the Authority shall develop and maintain an up-to-date Union supervisory handbook on the supervision of financial institutions in the Union, which duly takes into account the nature, scale and complexity of risks, business practices, business models and size of financial institutions and of markets. The Union supervisory handbook shall set out best practices and shall specify high- quality methodologies and processes.
The Authority shall, where appropriate, conduct open public consultations regarding the opinions referred to in point (a) of paragraph 1, tools and instruments referred to in this paragraph. It shall also, where appropriate, analyse the related potential costs and benefits. Such consultations and analyses shall be proportionate in relation to the scope, nature and impact of the opinions or tools and instruments. The Authority shall, where appropriate, also request advice from the relevant Stakeholder Group referred to in Article 37.
MODIFIED +240 −5 Art. 30 Peer reviews of competent authorities§
applies from: unchanged
Point (d) of Article 30(3) now ends with a semicolon rather than a full stop, and a new point (e) has been added covering an assessment of the effectiveness and degree of convergence of reporting and disclosure requirements adopted in application or implementation of Union law, while considering the specific characteristics of national financial legal frameworks.
The prior version's list of assessment items in Article 30(3) ended at point (d) without any equivalent provision on reporting and disclosure requirements.
Cited: Art. 30, v2 · Art. 30, v1
text before / after
02010R1094-20250701 → 02010R1094-20251110
Article 30
Peer reviews of competent authorities
1. The Authority shall periodically conduct peer reviews of some or all of the activities of competent authorities, to further strengthen consistency and effectiveness in supervisory outcomes. To that end, the Authority shall develop methods to allow for an objective assessment and comparison between the competent authorities reviewed. When planning and conducting peer reviews, existing information and evaluations already made with regard to the competent authority concerned, including any relevant information provided to the Authority in accordance with Article 35, and any relevant information from stakeholders shall be taken into account.
2. For the purposes of this Article, the Authority shall establish ad hoc peer review committees, which shall be composed of staff from the Authority and members of the competent authorities. The peer review committees shall be chaired by a member of the Authority’s staff. The Chairperson, after consulting the Management Board and following an open call for participation, shall propose the chair and the members of a peer review committee which shall be approved by the Board of Supervisors. The proposal shall be deemed to be approved unless, within 10 days of the Chairperson proposing it, the Board of Supervisors adopts a decision to reject it.
3. The peer review shall include an assessment of, but shall not be limited to:
(a) the adequacy of resources, the degree of independence, and governance arrangements of the competent authority, with particular regard to the effective application of the legislative acts referred to in Article 1(2) and the capacity to respond to market developments;
(b) the effectiveness and the degree of convergence reached in the application of Union law and in supervisory practice, including regulatory technical standards and implementing technical standards, guidelines and recommendations adopted pursuant to Articles 10 to 16, and the extent to which the supervisory practice achieves the objectives set out in Union law;
(c) the application of best practices developed by competent authorities whose adoption might be of benefit for other competent authorities;
(d) the effectiveness and the degree of convergence reached with regard to the enforcement of the provisions adopted in the implementation of Union law, including the administrative sanctions and other administrative measures imposed against persons responsible where those provisions have not been complied with. with;
(e) the effectiveness and the degree of convergence of reporting and disclosure requirements adopted in application or implementation of Union law, while considering the specific characteristics of national financial legal frameworks.
4. The Authority shall produce a report setting out the results of the peer review. That peer review report shall be prepared by the peer review committee and adopted by the Board of Supervisors in accordance with Article 44(4). When … 533 unchanged words … 45b. The peer review work plan shall constitute a separate part of the annual and multiannual working programme. It shall be made public. In case of urgency or unforeseen events, the Authority may decide to carry out additional peer reviews.
MODIFIED +120 −28 Art. 35 Collection of information§
applies from: unchanged
Paragraph 4 now directs the Authority, before requesting information, to take account of information collected by other authorities as defined in Article 35a(12), in addition to relevant existing statistics from the European Statistical System and the European System of Central Banks.
The wording describing the purpose of this consideration was also changed from avoiding duplication of reporting obligations to ensuring there is no duplication of reporting requirements.
Cited: Art. 35, v2 · Art. 35, v1
text before / after
02010R1094-20250701 → 02010R1094-20251110
Article 35
Collection of information
1. At the request of the Authority, the competent authorities of the Member States shall provide the Authority with all the necessary information to carry out the duties assigned to it by this Regulation, provided that they have legal access to the relevant information and that the request for information is necessary in relation to the nature of the duty in question.
2. The Authority may also request information to be provided at recurring intervals and in specified formats. Such requests shall, where possible, be made using common reporting formats.
3. Upon a duly justified request from a competent authority of a Member State, the Authority may provide any information that is necessary to enable the competent authority to carry out its duties, in accordance with the professional secrecy obligations laid down in sectoral legislation and in Article 70.
4. Before requesting information in accordance with this Article Article, and in order to avoid the ensure that there is no duplication of reporting obligations, requirements, the Authority shall take account of information collected by other authorities as defined in Article 35a(12) and any relevant existing statistics produced and disseminated by the European Statistical System and the European System of Central Banks.
5. Where information is not available or is not made available by the competent authorities in a timely fashion, the Authority may address a duly justified and reasoned request to other supervisory authorities, to the ministry responsible for finance where it has at its disposal prudential information, to the national central bank or to the statistical office of the Member State concerned.
6. Where information is not available or is not made available under paragraph 1 or 5 in a timely fashion, the Authority may address a duly justified and reasoned request directly to the relevant financial institutions. The reasoned request shall explain why the information concerning the respective individual financial institutions is necessary.
The Authority shall inform the relevant competent authorities of requests in accordance with this paragraph and with paragraph 5.
At the request of the Authority, the competent authorities shall assist the Authority in collecting the information.
7. The Authority may use confidential information received under this Article only for the purposes of carrying out the duties assigned to it by this Regulation.
INSERTED +11,006 −0 Art. 35a Exchange of information between authorities and with other entities§
applies from: unknown (an inserted provision states its own application date only in prose)
Article 35a is a wholly new provision setting out rules for the Authority to exchange information with other authorities and with financial institutions, including conditions for requesting and sharing data, professional secrecy and data protection obligations, exceptions to notification duties, memoranda of understanding, access for research and innovation purposes, and a reporting obligation to the Commission on legal obstacles to information exchange.
It also defines the terms other authorities and financial institution for purposes of this article and related provisions.
Cited: Art. 35a, v2
text before / after
inserted text (02010R1094-20251110)
Article 35a Exchange of information between authorities and with other entities 1. The Authority shall share, on a regular or case-by-case basis, information that it obtained from financial institutions or the other authorities when carrying out its duties and that stems from the application and implementation of Union law, with the other authorities upon request, provided that the requesting authority is entitled to obtain that information from financial institutions or the other authorities pursuant to Union law. 2. The Authority shall request information from any of the other authorities that have obtained that information, instead of requesting it directly from financial institutions, provided that the Authority is entitled to obtain that information pursuant to Union law. The first subparagraph shall be without prejudice to the powers of the Authority to obtain the requested information from financial institutions where the other authority is unable to share the information, where urgent action is needed or where obtaining the information directly from financial institutions is necessary for the performance of the Authority’s tasks pursuant to Union law. 3. A request to exchange information pursuant to paragraph 1 of this Article shall indicate the legal basis under Union law that entitles the requesting authority to obtain the information from financial institutions or the other authorities. The requesting authority and the Authority shall be subject to the obligations of professional secrecy and data protection laid down in Articles 70 and 71 and in sectoral legislation which apply to the sharing of information between the financial institution and the requesting authority and between the financial institution and the Authority. 4. Where the Authority exchanges information pursuant to paragraph 1, it shall, without undue delay, inform each authority from which it obtained the information or each financial institution, if the information was obtained from financial institutions directly, about the exchange. In the case of recurring or periodic exchanges of information, the Authority shall be obliged to inform the financial institution or the authority from which it obtained the information only once. 5. By way of derogation from paragraph 4, the Authority shall not be obliged to inform the authority or the financial institution, as applicable, about the exchange of information where either of the following conditions is met: (a) the information has been anonymised in such a manner that it no longer relates to any identified or identifiable natural person and that the financial institution or other legal entities are no longer identifiable; or (b) the information has been modified, aggregated or treated by any other method of disclosure control to protect confidential information, including trade secrets, and to protect personal data through appropriate technical and organisational measures in accordance with Regulations (EU) 2016/679 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj). and (EU) 2018/1725 Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ L 295, 21.11.2018, p. 39, ELI: http://data.europa.eu/eli/reg/2018/1725/oj). of the European Parliament and of the Council. 6. By way of derogation from paragraph 4, the Authority shall not inform the financial institution about the exchange of information if it determines, or is informed by the requesting authority, that doing so could compromise supervisory or resolution proceedings, actions or investigations. 7. Paragraphs 1 to 6 shall also apply to information that the Authority has received from a financial institution or the other authorities and upon which the Authority has subsequently performed quality checks or which the Authority has otherwise processed. 8. To facilitate exchanges of information as referred to in paragraphs 1 to 7, the Authority and the other authorities may enter into memoranda of understanding regarding the arrangements for such exchanges. The memoranda of understanding may also specify arrangements for the sharing of resources for the collection and processing of shared information. The Commission may, after consulting the Authority and the other authorities, develop guidance on the main elements of such memoranda of understanding. 9. Paragraphs 1 to 8 shall be without prejudice to the protection of intellectual property rights and shall not prevent or restrict the exchange of information between the Authority and the other authorities in accordance with other provisions of this Regulation or with other Union legislation. In the event of a conflict between this Article and other provisions of this Regulation or other Union legislation that govern the exchange of information between the Authority and the other authorities, such other provisions shall prevail. 10. The Authority and the competent authorities may, at their own discretion, grant access to information obtained when carrying out their duties for re-use by financial institutions, researchers and other entities that have a legitimate interest in that information for research and innovation purposes, provided that the Authority or the competent authority granting access has ensured that all of the following conditions have been complied with: (a) the necessary measures have been taken to anonymise the information, in a manner that prevents individual financial institutions, entities, data subjects and, where it is the Authority which grants access to the information, Member States from being identified; (b) the information has been modified, aggregated or treated by any other method of disclosure control to protect confidential information, including trade secrets or content covered by intellectual property rights. Information received from any authority shall be shared pursuant to the first subparagraph only with the consent of the authority that initially obtained that information. 11. By 11 November 2027 the Authority shall, in close cooperation with competent authorities, report to the Commission on all legal obstacles in sectoral legislation that prevent them, in any way, from exchanging information with the other authorities or with other entities. The report may also address non-material, obsolete, duplicative or otherwise irrelevant reporting requirements. It may also include suggestions for improving consistency between reporting requirements for financial and non-financial entities. The report shall be updated on a regular basis, where necessary. Taking into account the report referred to in the first subparagraph, the protection of intellectual property rights and the obligations of professional secrecy and data protection, the Commission shall, where appropriate, submit to the European Parliament and to the Council a legislative proposal to remove such legal obstacles in sectoral legislation, to foster the exchange of information between authorities and with other entities. 12. For the purposes of this Article, Article 35(4) and Article 70(3), other authorities means any of the following authorities: (a) the ESRB; (b) the European Supervisory Authority (European Banking Authority); (c) the European Supervisory Authority (European Securities and Markets Authority); (d) competent authorities, as defined in Article 4, point (2), of this Regulation; (e) competent authorities, as defined in Article 4, point (2), of Regulation (EU) No 1093/2010; (f) competent authorities, as defined in Article 4, point (3), of Regulation (EU) No 1095/2010; (g) the authorities composing the Single supervisory mechanism, as defined in Article 2, point (9), of Council Regulation (EU) No 1024/2013 Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions (OJ L 287, 29.10.2013, p. 63, ELI: http://data.europa.eu/eli/reg/2013/1024/oj).; (h) the Single Resolution Board (SRB), as established by Regulation (EU) No 806/2014 of the European Parliament and of the Council Regulation (EU) No 806/2014 of the European Parliament and of the Council of 15 July 2014 establishing uniform rules and a uniform procedure for the resolution of credit institutions and certain investment firms in the framework of a Single Resolution Mechanism and a Single Resolution Fund and amending Regulation (EU) No 1093/2010 (OJ L 225, 30.7.2014, p. 1, ELI: http://data.europa.eu/eli/reg/2014/806/oj).; (i) resolution authorities, such as those referred to in Article 3(3) of Directive 2014/59/EU of the European Parliament and of the Council Directive 2014/59/EU of the European Parliament and of the Council of 15 May 2014 establishing a framework for the recovery and resolution of credit institutions and investment firms and amending Council Directive 82/891/EEC, and Directives 2001/24/EC, 2002/47/EC, 2004/25/EC, 2005/56/EC, 2007/36/EC, 2011/35/EU, 2012/30/EU and 2013/36/EU, and Regulations (EU) No 1093/2010 and (EU) No 648/2012, of the European Parliament and of the Council (OJ L 173, 12.6.2014, p. 190, ELI: http://data.europa.eu/eli/dir/2014/59/oj).; (j) the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA), as established by Regulation (EU) 2024/1620 of the European Parliament and of the Council Regulation (EU) 2024/1620 of the European Parliament and of the Council of 31 May 2024 establishing the Authority for Anti-Money Laundering and Countering the Financing of Terrorism and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010 and (EU) No 1095/2010 (OJ L, 2024/1620, 19.6.2024, ELI: http://data.europa.eu/eli/reg/2024/1620/oj).; (k) financial supervisors, as defined in Article 2, second subparagraph, point (1), of Directive (EU) 2024/1640 of the European Parliament and of the Council Directive (EU) 2024/1640 of the European Parliament and of the Council of 31 May 2024 on the mechanisms to be put in place by Member States for the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, amending Directive (EU) 2019/1937, and amending and repealing Directive (EU) 2015/849 (OJ L, 2024/1640, 19.6.2024, ELI: http://data.europa.eu/eli/dir/2024/1640/oj).; For the purposes of this Article, financial institution means financial institution as defined in Article 2, point (a), of Regulation (EU) No 1092/2010.
INSERTED +1,627 −0 Art. 35b Integrated reporting system§
applies from: unknown (an inserted provision states its own application date only in prose)
This new Article 35b requires the ESAs, acting through the Joint Committee and in cooperation with the ESRB, ECB, AMLA, the SRB, competent authorities and other stakeholders, to prepare by 11 November 2030 a report exploring options for a cross-sectoral integrated reporting system, including a feasibility study and implementation roadmap covering a common data dictionary and a shared data space, with the Commission empowered to submit a related legislative proposal based on that report's findings.
The same new article also directs the ESAs, through the Joint Committee and with the same cooperating bodies and competent authorities, to promptly set up a permanent single contact point through which entities can flag duplicative, redundant or obsolete reporting and disclosure requirements.
Cited: Art. 35b, v2
text before / after
inserted text (02010R1094-20251110)
Article 35b Integrated reporting system 1. By 11 November 2030, the ESAs, through the Joint Committee and in close cooperation with the ESRB, the European Central Bank (ECB), AMLA, the SRB, the competent authorities and other relevant stakeholders, shall prepare a report presenting options to enhance the efficiency of supervisory data collection in the Union. Building on the sectoral work of the ESAs to integrate reporting, that report shall provide a feasibility study, including an assessment of impacts, costs and benefits, of a cross-sectoral integrated reporting system and, based on that feasibility study, present a roadmap for the implementation. The report referred to in the first subparagraph shall cover: (a) a common data dictionary, including a repository of reporting and disclosure requirements, ensuring consistency and clarity of reporting requirements and data standardisation; and (b) a data space for collecting and exchanging information. Taking into account the findings of the report referred to in the first subparagraph and following a thorough impact assessment, the Commission shall, where appropriate and necessary, submit to the European Parliament and to the Council a legislative proposal to ensure the financial, human and IT resources necessary for establishing the integrated reporting system. 2. The ESAs, through the Joint Committee and in close cooperation with the ESRB, the ECB, AMLA, the SRB and the competent authorities, shall promptly establish a permanent single contact point for entities to communicate duplicative, redundant or obsolete reporting and disclosure requirements.
MODIFIED +106 −5 Art. 54 Establishment§
applies from: unchanged
The list of matters on which the Joint Committee cooperates now includes a new item covering reporting and disclosure requirements and the collection of information from financial institutions, added after the existing reference to advice by the Committee established under Article 1(7).
The remainder of Article 54, including paragraphs 1, 2a, 3 and 4, is unchanged between the two versions.
Cited: Art. 54, v2 · Art. 54, v1
text before / after
02010R1094-20250701 → 02010R1094-20251110
Article 54
Establishment
1. The Joint Committee of the European Supervisory Authorities is hereby established.
2. The Joint Committee shall serve as a forum in which the Authority shall cooperate regularly and closely to ensure cross-sectoral consistency, while considering sectoral specificities, with the European Supervisory Authority (European Banking Authority) and the European Supervisory Authority (European Securities and Markets Authority), in particular regarding:
financial conglomerates and, where required by Union law, prudential consolidation,
accounting and auditing,
micro-prudential analyses of cross-sectoral developments, risks and vulnerabilities for financial stability,
retail investment products,
cybersecurity,
information and best practice exchange with the ESRB and the other ESAs,
retail financial services and consumer and investor protection issues,
advice by the Committee established in accordance with Article 1(7). 1(7),
reporting and disclosure requirements and the collection of information from financial institutions.
2a. The Joint Committee may assist the Commission in assessing the conditions and the technical specifications and procedures for ensuring secure and efficient inter-connection of the centralised automated mechanisms pursuant to the report referred in Article 32a(5) of Directive (EU) 2015/849 as well as in the effective interconnection of the national registers under that Directive.
3. The Joint Committee shall have a dedicated staff provided by the ESAs that shall act as a permanent secretariat. The Authority shall contribute adequate resources to administrative, infrastructure and operational expenses.
4. In the event that a financial institution reaches across different sectors, the Joint Committee shall resolve disagreements in accordance with Article 56.
MODIFIED +71 −4 Art. 70 Obligation of professional secrecy§
applies from: unchanged
Paragraph 3 now states that the exchange of information may occur not only with competent authorities but also with other authorities as defined in Article 35a(12), a reference not present before.
The paragraph also adds the words "of this Article" after the reference to paragraphs 1 and 2, and drops the word "other" before "Union legislation".
Cited: Art. 70, v2 · Art. 70, v1
text before / after
02010R1094-20250701 → 02010R1094-20251110
Article 70
Obligation of professional secrecy
1. Members of the Board of Supervisors, and all members of the staff of the Authority, including officials seconded by Member States on a temporary basis, and all other persons carrying out tasks for the Authority on a contractual basis, shall be subject to the requirements of professional secrecy pursuant to Article 339 TFEU and the relevant provisions in Union legislation, even after their duties have ceased.
2. Without prejudice to cases covered by criminal law, any confidential information received by persons referred to in paragraph 1 whilst performing their duties may not be divulged to any person or authority whatsoever, except in summary or aggregate form, such that individual financial institutions cannot be identified.
The obligation under paragraph 1 of this Article and the first subparagraph of this paragraph shall not prevent the Authority and the competent authorities from using the information for the enforcement of the legislative acts referred to in Article 1(2), and in particular for legal procedures for the adoption of decisions.
2a. The Management Board, and the Board of Supervisors shall ensure that individuals who provide any service, directly or indirectly, permanently or occasionally, relating to the tasks of the Authority, including officials and other persons authorised by the Management Board and the Board of Supervisors or appointed by the competent authorities for that purpose, are subject to the requirements of professional secrecy equivalent to those in paragraphs 1 and 2.
The same requirements for professional secrecy shall also apply to observers who attend the meetings of the Management Board, and the Board of Supervisors and who take part in the activities of the Authority.
3. Paragraphs 1 and 2 of this Article shall not prevent the Authority from exchanging information with competent authorities and with other authorities as defined in Article 35a(12) in accordance with this Regulation and with other Union legislation applicable to financial institutions.
That information shall be subject to the conditions of professional secrecy referred to in paragraphs 1 and 2. The Authority shall lay down in its internal rules of procedure the practical arrangements for implementing the confidentiality rules referred to in paragraphs 1 and 2.
4. The Authority shall apply Commission Decision (EU, Euratom) 2015/444
Commission Decision (EU, Euratom) 2015/444 of 13 March 2015 on the security rules for protecting EU classified information (OJ L 72, 17.3.2015, p. 53)..
The full entry, with the citation mapping v1 = 02010R1094-20250701, v2 = 02010R1094-20251110, is committed at eu/32010R1094/CHANGELOG.md.