lexiara

Recital 148

AMLR

(148) Compliance with the requirements of this Regulation is subject to checks by supervisors. Where obliged entities exchange information in the framework of a partnership for information sharing, those checks should also include compliance with the conditions laid down in this Regulation for those exchanges of information. While supervisory checks should be risk-based, they should be performed in any event prior to the commencement of the activities of the partnership for information sharing. Partnerships for information sharing that involve the processing of personal data might result in a high risk to the rights and freedoms of natural persons. Therefore, a data protection impact assessment pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council (28) should be carried out prior to the start of the activities of the partnership. In the context of supervisory checks, supervisors should consult, where relevant, data protection authorities, which alone are competent for assessing the data protection impact assessment. The data protection provisions and all requirements concerning the confidentiality of information on suspicious transactions contained in this Regulation apply to information shared in the framework of a partnership. Consistent with Regulation (EU) 2016/679, Member States should be able to maintain or introduce more specific provisions to adapt the application of that Regulation to provide more specific requirements in relation to the processing of personal data exchanged in the framework of a partnership for information sharing.

· All articles ·

Source: EUR-Lex CELLAR · retrieved 2026-09-04 · Text as adopted (Official Journal); later amendments are not incorporated in this text.