Skip to main content
Knowledge HubScenario LabAboutTry the tool
Knowledge HubAML ProgrammeFinancial Crime Information Sharing: Can I Tell Another Bank?
Framework

Financial Crime Information Sharing:
Can I tell another bank?

A confidentiality shield is not a data protection basis, and neither one touches the tipping-off offence. Choose the route first, then decide what you can say.

Written by Pratik Zanke

UKEvidence reviewed 4 October 202652 min read2 worked scenarios, 4 outcomes
Jurisdiction
United Kingdom
Audience
Financial-crime, fraud, AML, MLRO, privacy and operational-risk practitioners at banks and other AML-regulated firms
Evidence reviewed
4 October 2026
Change sensitivity
High. The sharing gateway and the data protection basis are both recent, and two ICO pages relied on for operational controls are under review

The question, and what this framework will not decide

Another bank has emailed. It wants to know about a person who used to bank with you, and it says the request is about fraud. The statute gives you some protection. Does it give you enough to answer?

This framework answers one question. Before a firm tells another firm anything about a customer in connection with suspected economic crime, which route governs the disclosure, what does that route protect, and what does it leave exposed? It is written for UK practitioners who receive, make and approve these requests. It is a practitioner framework, not legal advice, and a live disclosure needs a legal view from the firm's own advisers.

It separates three questions that are usually asked as one. Does the law shield the firm from a claim for breach of confidence or civil liability? Does the firm have a lawful basis, and where it applies a condition, for the data protection side? And does the disclosure risk an offence of tipping off? A route can answer the first and leave the other two untouched.

Choose the route first. Then ask what the route protects, and what it does not.

Intelligence questionBefore a firm tells another firm anything about a customer in connection with suspected economic crime, which route governs the disclosure, what does that route protect and what does it leave exposed?
Evidence stateStatute text and regulator guidance are relied on as read on the evidence date, and the sources section lists each one. The eight-step sequence, the four outcome labels and the scenario conclusions are FinCrimeRadar assessments. The scenario facts are synthetic.
Decision objectWhether information may be shared with another firm, through which route, for what purpose, with what data and controls, and how the recipient may use it.
UncertaintyWhether a disclosure fits a route often turns on facts this guide cannot know: who the customer is to the recipient, whether a suspicious activity report has been made, and what the disclosure would reveal. Two ICO pages used for operational controls are marked as under review. Some government guidance wording is out of date.
What would change the assessmentAn amendment to sections 188 to 193 of the Economic Crime and Corporate Transparency Act, regulations prescribing further circumstances, the ICO replacing its under-review pages, or different facts such as a SAR, a law-enforcement request or a recipient outside the regulated sector.
Practitioner outcomeAfter this guide you should be able to tell a confidentiality shield from a data protection basis, choose the right sharing route, see when SAR or tipping-off concerns change the answer, and record a proportionate decision.

How evidence is labelled

  • Established What a named statute, regulator or government publication says, as read on the evidence date.
  • FinCrimeRadar assessment Our analysis of how the sources apply to the facts, and our recommended action.
  • Unknown A fact or point the sources do not settle.

Out of scope: reporting to the NCA through a SAR, sharing with law enforcement, sharing outside the UK, group-internal sharing, sanctions information and the Terrorism Act equivalents except where named. No live lookup or case tool is part of this guide.

Three questions, not one

Most mistakes in this area come from letting the answer to one question stand in for the other two.

1 Confidentiality and civil liability

Does the law stop the firm being sued for breach of an obligation of confidence, or for civil liability to the customer, because it told another firm something? Sections 188 and 189 of the Economic Crime and Corporate Transparency Act 2023 (ECCTA) answer that question for the disclosures they cover, and only where their conditions are met [1]. Section 339ZF of the Proceeds of Crime Act 2002 (POCA) provides that a good-faith disclosure made under the joint disclosure route does not breach an obligation of confidence or any other restriction on disclosure [12].

2 Data protection

Does the firm have an Article 6 lawful basis, a condition under Schedule 1 to the Data Protection Act 2018 where the data is criminal offence data, and compliance with the other principles? ECCTA says in terms that nothing in section 188 or 189 authorises a disclosure that would contravene the data protection legislation, or prevents civil liability arising under it [1]. The government guidance says private bodies do not need statutory authority to share information, but need a lawful basis under the UK GDPR when sharing personal data [4].

3 Tipping off

Could the disclosure reveal that a suspicious activity report has been made, or that an investigation is contemplated, in a way likely to prejudice that investigation? Section 333A of POCA creates the regulated-sector offence and sections 333B to 333D set out the exceptions [11]. The protections in ECCTA sections 188 and 189 are expressed as protection from breach of confidence and civil liability, and the government guidance tells firms that sharing after a SAR must not breach the tipping-off or prejudicing-investigation provisions [1] [4].

Source Established

ECCTA sections 188(2) and 189(2) protect against breach of an obligation of confidence and civil liability to the customer. Sections 188(11) and 189(10) provide that nothing in them authorises a disclosure that would contravene the data protection legislation, or prevents civil liability arising under it. [1] The government guidance calls the measures voluntary and says the protections apply to UK-based sharing and not to sharing outside the UK. [4]

Application FinCrimeRadar assessment

A route can settle the first question and leave the second and third open. We call this the shield problem. Treat ECCTA eligibility as an answer to question 1 only. It is not permission to ignore confidentiality duties outside the route, the UK GDPR, legal privilege, SAR duties or the tipping-off offence. It is also not a joint disclosure report, which is a separate POCA route.

Action FinCrimeRadar assessment

Write the three answers separately in the decision record, each with its own source. If one cannot be answered, the disclosure is not ready. Escalate it to the people who own that question, usually the MLRO for question 3 and privacy for question 2.

The Shield Swap

A confidentiality shield is traded for a data protection basis.

Risk
ECCTA eligibility is treated as permission to share.
Signal
The record cites sections 188 or 189 and says nothing about the lawful basis or the Schedule 1 condition.
Response
Answer the three questions separately and cite a source for each.

Five routes, and what each one covers

Name the route before anything is sent. Each row below states what the sources say about one route. The last column is our reading of what is left exposed.

Five sharing routes: who and what each covers, what triggers it, what it protects and what it leaves open
RouteWho and what it coversWhat triggers itWhat it protectsWhat it leaves open
ECCTA direct sharing (section 188)Businesses in the regulated sector sharing information about a customer or former customer directly with another such business. The Explanatory Notes and the government guidance read the provision as covering AML-regulated firms, and the Secretary of State can prescribe more. [1] [3] [4]Either the request condition or the warning condition, and the sender is satisfied the disclosure will or may assist the recipient's relevant actions. [1]No breach of an obligation of confidence and no civil liability to the customer for the sender. The recipient's use for its relevant actions does not breach confidence. [1]Data protection, the privileged disclosure exclusion, and tipping off. The route is voluntary and UK based. [1] [4]
ECCTA indirect sharing (section 189)Sharing through an intermediary by deposit-taking bodies, electronic money institutions, payment institutions, cryptoasset exchange providers and custodian wallet providers, and by certain legal, accountancy, audit, tax and insolvency firms above a revenue threshold. [1]The sender has decided to terminate, refuse or restrict because of economic crime concerns, the UK GDPR applies, and the sender and the intermediary have an agreement that the data will only be handled where the UK GDPR applies. [1]No breach of confidence and no civil liability for the sender's disclosure or the intermediary's qualifying onward disclosure. The eventual recipient's use for its relevant actions does not breach an obligation of confidence. [1]The government guidance says this route relies on the sender's decision in section 189(1)(c) and not on the request condition. Data protection, privilege and tipping off remain open. [1] [4]
POCA joint disclosure route (section 339ZB)Regulated-sector relevant undertakings sharing information with one another, linked to a suspicion that a person is engaged in money laundering. [12] [13]A request from an NCA authorised officer or from the recipient, a required notification made to the NCA before the disclosure, and the sender being satisfied the disclosure will or may assist in determining a matter connected with the suspicion. [12]A relevant disclosure made in good faith does not breach an obligation of confidence or other restriction. Section 333D(1) gives no tipping-off offence for a disclosure made in good faith by virtue of section 339ZB. A joint disclosure report can satisfy the required disclosure duties within set limits. [12] [11]The route is tied to money laundering suspicion, not economic crime generally. Data protection remains open, and information obtained from a UK law enforcement agency cannot be included without that agency's consent. [12]
Tipping-off exceptions (sections 333B to 333D)Disclosures within an undertaking or group, certain disclosures between credit institutions, financial institutions or professional advisers, and the other permitted disclosures in section 333D. [11]The conditions of the particular exception. For section 333C these include a link to a client, transaction or service both firms share, a purpose of only preventing an offence under Part 7 of POCA, and equivalent duties of professional confidentiality and data protection. [11]Each section provides that a person does not commit the offence in section 333A in the circumstances it describes. [11]The sections do not themselves address breach of confidence, civil liability or data protection. Those questions need their own answer. [11]
Ordinary sharing outside these protectionsAny firm sharing personal data with another organisation on its own footing. [4]A UK GDPR lawful basis, a Schedule 1 condition where the data is criminal offence data, and a position on the duty of confidence. [4] [9]Nothing beyond what the general law already gives. The government guidance says private bodies do not need statutory authority to share, and records the concern about confidentiality and civil liability that ECCTA addresses. [4]Confidentiality and civil liability exposure, data protection and tipping off all stay open, so the firm carries the full analysis. [4]

Source Established

The government guidance uses the term Super SAR for the joint disclosure report produced under POCA section 339ZB, and it says firms sharing after a SAR must not breach the provisions on tipping off or prejudicing investigations. [4] ECCTA section 189(3) lists the businesses covered for indirect sharing and ties the professional-services entries to a UK revenue band. [1]

Application FinCrimeRadar assessment

ECCTA sharing is not a Super SAR. A section 188 or 189 disclosure creates no joint report and, on the text we read, does not discharge a SAR duty. The routes can also sit together: the same facts may fit ECCTA for confidentiality and need the POCA route for the SAR boundary.

Action FinCrimeRadar assessment

Record which route you are relying on and why the sender, recipient and customer sit inside it. If none fits, say so and take the ordinary route with the full analysis, or do not share.

The eight-step sequence

Work the steps in order. Each ends with a recorded answer, and a missing answer at any step stops the disclosure.

The sequence is our own decision structure. The sources are cited step by step, and each step keeps what the authority says apart from how we apply it and what we recommend.

1 Purpose

What precise economic-crime decision would the sharing assist?

Source Established

ECCTA section 191 defines the relevant actions the sharing must serve: determining, to prevent, detect or investigate economic crime, whether and how to apply customer due diligence to a customer or proposed customer, carrying out those measures, and deciding whether to terminate, decline, restrict or refuse a transaction for such a customer. The warning condition in section 188(5) requires the sender to have decided on safeguarding action because of economic crime concerns. [1] The government guidance says disclosure for purposes other than those in ECCTA gets no protection, and that sharing personal data for commercial purposes could lead to ICO enforcement. [4]

Application FinCrimeRadar assessment

A purpose is a decision someone will take, stated in one sentence. Helping with fraud is not a purpose. If the decision cannot be named, necessity cannot be tested at step 4 and the relevant action cannot be identified at step 3.

Action FinCrimeRadar assessment

Write the purpose sentence into the record before drafting any content. Send a request back to the requester if it does not state one.

2 Route

Is this ECCTA direct sharing, ECCTA indirect sharing, POCA section 339ZB sharing, a permitted post-SAR disclosure, or ordinary sharing outside those protections?

Source Established

The routes and their conditions are set out in the table above. Economic crime for ECCTA sections 188 to 191 means a listed offence in Schedule 11, an attempt, conspiracy or related offence, or conduct that would be one if done in the UK. [1] Schedule 11 lists, among others, fraud under section 1 of the Fraud Act 2006, the money laundering offences in sections 327 to 329 of POCA, and the tipping-off offence in section 333A. [2]

Application FinCrimeRadar assessment

Choose the narrowest route that fits and name what it leaves open. Whether suspected conduct maps to a listed offence is a question for the file. Section 339ZB asks for a suspicion of money laundering, which is narrower than economic crime and needs its own basis in the facts.

Action FinCrimeRadar assessment

Record the route. If two routes apply, record both and say which of the three questions each one answers.

3 Scope

Are the sender, recipient, customer and proposed use within the chosen route?

Source Established

For direct sharing, both firms must carry on business to which section 188(3) applies, the information must relate to a customer or former customer of the sender, the request or warning condition must be met, the sender must be satisfied the disclosure will or may assist the recipient's relevant actions, and the disclosure must not be a privileged disclosure. [1] Relevant actions concern a customer or proposed customer of the person carrying them out. [1] The government guidance says the measures are domestic, and that it is the firm's own responsibility to verify that the other firm is legitimate. [4]

Application FinCrimeRadar assessment

Two points are easy to miss. First, is the person your customer or former customer? Second, is the recipient's relevant action about its own customer or proposed customer? On the text we read, a bank asking about someone who is not its customer may not be able to point to a relevant action, so test it and do not assume it.

Action FinCrimeRadar assessment

Check each element against the section text and record the result. Verify the requester through a contact you sourced yourself, not through the details in the request.

4 Data protection

What is the Article 6 basis, and are necessity, purpose compatibility, minimisation, accuracy, security and transparency documented?

Source Established

Section 70 of the Data (Use and Access) Act 2025 added Article 6(1)(ea), processing necessary for a recognised legitimate interest, and provides that this applies only if a condition in Annex 1 is met. Annex 1 paragraph 5 covers processing necessary for detecting, investigating or preventing crime, or apprehending or prosecuting offenders. [5] Section 70 and Schedule 4 came into force on 5 February 2026. [6] The ICO says the crime condition covers sharing for crime-related purposes, including scams, fraud and money laundering, that the firm must decide whether the use is necessary, and that recognised legitimate interest is a lawful basis and not an exemption. It adds that the firm must tell people it relies on this basis and which condition, that people can object, and that statutory crime reporting is more likely to rest on legal obligation. [7]

Application FinCrimeRadar assessment

The crime condition is open to a private firm sharing for a crime-related purpose, and it removes the balancing test. It does not remove necessity, proportionality, purpose limitation, minimisation, accuracy, security or transparency. It is not automatic permission to share. The recipient needs its own basis for its own use. The government guidance sentence that these provisions will come into force in 2026 is out of date, and we rely on the commencement instrument instead. [4]

Action FinCrimeRadar assessment

Record the basis and why the sharing is necessary for the stated purpose, list what is excluded, and check that the privacy information and the right to object are covered. The ICO's scams page, which is under review, still supports a data protection impact assessment for routine sharing, a data sharing agreement where sharing is not ad hoc, and secure handling. [10]

The Full File

The whole case file goes out because the route fits.

Risk
More personal data is shared than the stated decision needs.
Signal
Third-party names and allegation labels appear in a disclosure whose purpose does not need them.
Response
Build the minimum set from the stated purpose and leave out the rest.

5 Protected data

Are allegations or suspicions criminal offence data, and which Schedule 1 condition and policy document apply?

Source Established

The ICO says criminal offence data includes suspicion or allegations of criminal activity, and that a private firm without official authority needs a condition in Schedule 1 to the Data Protection Act 2018. [7] [10] Paragraph 10 applies where processing is necessary for the prevention, investigation or detection of an unlawful act and must be carried out without consent so as not to prejudice that purpose. The substantial public interest limb is removed for criminal offence data by paragraph 36. [8] Paragraph 10(2) removes the appropriate policy document requirement where processing consists of disclosure to a competent authority or is carried out in preparation for such disclosure. Paragraph 14 covers disclosures as a member of, or under arrangements made by, an anti-fraud organisation. Paragraph 15 covers a disclosure in good faith under POCA section 339ZB. [8] The ICO's conditions page, which is under review, records that paragraphs 10, 14 and 15 all need an appropriate policy document, except for paragraph 10 disclosure to the relevant authorities or preparation for such disclosure. [9] A policy document must explain how the Article 5 principles are met and the retention and erasure policy, and the record of processing must name the condition. [8]

Application FinCrimeRadar assessment

On these facts, the bank-to-bank disclosure is for Bank B's account decision and is not itself a disclosure to a competent authority or processing in preparation for one, so the paragraph 10(2) exception does not apply. For an ECCTA request the likely condition is paragraph 10. For a section 339ZB disclosure it is paragraph 15, and for sharing through an anti-fraud organisation it is paragraph 14. If special category data is also involved, the substantial public interest requirement stays for that data. The firm decides which condition fits and records why.

Action FinCrimeRadar assessment

Name the condition, confirm the policy document exists and covers this processing, and add the condition to the processing record. Share the allegation only if the purpose needs it. A factual identifier is often enough without the label.

6 SAR boundary

Has a SAR been made or an investigation contemplated, and could the disclosure reveal it or prejudice an investigation?

Source Established

Section 333A of POCA is an offence where a person discloses that a disclosure under Part 7 has been made to a constable, an HMRC officer, a nominated officer or an NCA officer, the disclosure is likely to prejudice any investigation that might follow, and the information came in the course of regulated sector business. It is also an offence to disclose that an investigation into a Part 7 offence is contemplated or under way, where that is likely to prejudice it. [11] Section 333C permits certain disclosures between credit institutions or between financial institutions only where the disclosure relates to a client, transaction or service both share, is for the purpose only of preventing an offence under Part 7, and meets the recipient location and equivalent confidentiality and data protection conditions. [11] Section 333D includes disclosure for the detection, investigation or prosecution of a criminal offence, and disclosure in good faith under section 339ZB. [11] The government guidance says firms that share after submitting a SAR must make sure they do not breach the provisions on tipping off or prejudicing investigations. [4]

Application FinCrimeRadar assessment

The offence is about what the disclosure reveals, namely the SAR or the contemplated investigation, and its likely effect. It is not about every fact held on the customer. Many requests can be answered without any reference to a SAR. Where the honest answer would reveal or imply one, ECCTA eligibility does not resolve the problem, because the ECCTA protections are expressed as protection from breach of confidence and civil liability.

Action FinCrimeRadar assessment

Ask the nominated officer whether a SAR exists or an investigation is contemplated for this customer before anything is sent. Draft so that nothing reveals or implies either. If that is not possible, use an exception or another route that fits, or escalate and do not share yet.

The Silent SAR

A reply says more about reporting than it should.

Risk
A reply reveals or implies that a SAR exists or that an investigation is contemplated.
Signal
A refusal explains itself by reference to reporting, or the nominated officer has not seen the draft.
Response
The nominated officer approves any reply, and it is drafted so that nothing reveals or implies a SAR.

7 Recipient use

How may the recipient use what it receives?

Source Established

Under section 188(7) the recipient's use of the disclosed information for its relevant actions does not breach an obligation of confidence. [1] The government guidance advises strict handling conditions, says the measures are not designed to give sectors additional powers to exclude customers inappropriately, and says they should assist risk-based decision making. It also advises receiving firms to make clear that they are the right entity to complain to. [4]

Application FinCrimeRadar assessment

Received intelligence is an input to the recipient's own assessment. It is not proof of wrongdoing and it is not an instruction to exit. The recipient owns the decision, the evidence behind it and any complaint about it.

Action FinCrimeRadar assessment

The sender states handling conditions with the disclosure: purpose, no onward disclosure, corroborate before acting, and a contact for corrections. The recipient records what it checked independently and does not rely on the sender's information as its only reason.

The Borrowed Verdict

Another firm's information becomes this firm's conclusion.

Risk
Received intelligence is treated as proof and used as an automatic exit instruction.
Signal
The recipient's file cites only the sender's information as its reason.
Response
Record the independent checks, corroborate before acting and keep the complaint route open.

8 Record

What must the record show?

Source Established

The government guidance encourages sending and receiving firms to keep an audit trail of all information shared and to record key decision points, which helps firms and the Financial Ombudsman Service with complaints and redress. [4] Schedule 1 requires a policy document and a record of processing that names the condition relied on. [8] For a section 339ZB request the NCA's procedure asks the requesting firm to obtain a reference number and to include it in any SAR submitted as a result. [14]

Application FinCrimeRadar assessment

The record is what lets the firm show a customer, the Ombudsman or the ICO why it shared what it shared. It should be one document completed before sending, not reconstructed afterwards.

Action FinCrimeRadar assessment

Capture the request, the purpose, the route, the data shared and the data withheld, the approvals, the handling restrictions, the retention period, the decision and the complaint or correction route.

The Missing Minutes

The decision cannot be reconstructed afterwards.

Risk
The firm cannot show why it shared what it shared.
Signal
The request, route, data shared and approvals sit in different inboxes.
Response
Complete one decision record before sending.

Four outcomes

Every request ends in one of four recorded outcomes. These are FinCrimeRadar labels, not legal categories.

  • Share under the identified route. The route conditions are met, the data protection and SAR boundary answers are recorded, and nothing beyond the ordinary record is needed.
  • Share after specified controls. The route fits, but named controls must be in place first, such as verifying the requester, minimising the data, confirming the policy document and agreeing handling conditions.
  • Escalate and do not share yet. An answer to the data protection or SAR boundary question is missing, or a SAR or investigation may be in play. The MLRO and privacy decide the next step.
  • Do not share under this route. A route condition is not met, for example the recipient is outside the regulated sector, the person is not within the route, or the purpose is not economic crime. Consider whether another route fits, or do not share.
Worked scenario 1 · Direct request

The request about a former customer

Another bank asks why you closed an account. The route may fit. The data still needs its own answer.

Composite scenario for teaching. It does not describe a real firm, customer or case.

  • You lead financial crime at Bank A, a UK bank carrying on business in the regulated sector. Six weeks ago Bank A closed a personal account after concerns about fraud, so the account holder is a former customer.
  • The fraud team at Bank B, also a UK bank, emails you. It says a customer who opened an account there five weeks ago has received three payments from different people that it suspects are authorised push payment scam payments, 14,500 GBP in total.
  • Bank B names the person, says it believes they were previously a customer of Bank A, and asks for the reason for the closure and any fraud concerns Bank A holds, so that it can decide whether to restrict or close the account.
  • Bank A's file holds the closure reason code and date, two reports from victims of other banks that name the account, device and address overlaps with two other accounts, the names of the two victims, and a note summarising an alleged mule role.
  • Bank A has not submitted a SAR about this person. The email comes from a named analyst at a bank email domain. There is no data sharing agreement between the banks. Bank A has an appropriate policy document for its crime-prevention processing, which has not been checked against this kind of disclosure.
What is the most defensible decision for Bank A?

How each option grades

Not supported by the evidence A. Send the full case file. ECCTA gives Bank A protection from breach of confidence and civil liability, so nothing more is needed.

Source

ECCTA sections 188(2) and 188(11) protect against breach of confidence and civil liability to the customer, and say nothing in the section requires or authorises a disclosure that would contravene the data protection legislation. [1] The ICO says recognised legitimate interest is a lawful basis and not an exemption, and that the firm must decide whether using the information is necessary. [7] The government guidance says the information must be accurate, adequate, relevant and limited to what is necessary. [4]

Application

The file holds the personal data of two other victims and an allegation label that Bank B's decision does not need. ECCTA answers the confidence and civil liability question. It does not answer the data protection question, and sending the whole file fails necessity and minimisation.

Action

Do not send the file. Build the minimum set from the purpose Bank B has stated, and leave out what that decision does not need.

Best supported by the evidence B. Verify the request through a contact Bank A sources itself, confirm that the section 188 conditions are met, then share a minimised set tied to Bank B's stated decision. Withhold the victims' names and unrelated material, record the basis, the Schedule 1 condition and the policy document, and attach handling conditions.

Source

The request condition in ECCTA section 188(4) is met where the disclosure responds to a request from the other firm, and that firm has reason to believe the sender holds information about the customer that will or may assist its relevant actions. Relevant actions include deciding whether to terminate a relationship with a customer. [1] Annex 1 paragraph 5 of the UK GDPR, the crime condition, covers processing necessary for detecting, investigating or preventing crime. [5] The ICO says suspicion or allegations of criminal activity are criminal offence data and need a Schedule 1 condition. [7] Schedule 1 paragraph 10 applies to processing necessary for the prevention, investigation or detection of an unlawful act. On these facts, the proposed disclosure is not to a competent authority or preparation for such disclosure, so an appropriate policy document is required. [8] [9]

Application

The route fits on these facts. Bank B's customer is the subject of the decision, the person is Bank A's former customer, and the request states the decision. Question 2 is still answered separately: the recognised legitimate interest basis, the paragraph 10 condition and the policy document must be recorded, and the disclosure must be limited to facts that bear on Bank B's decision. On the stated facts, no SAR has been made and no contemplated or current investigation has been identified. The nominated officer should confirm both points before disclosure.

Action

Verify the requester, check each section 188 element, share the closure date, the category of concern and the corroborating facts that bear on it, and leave out the victims' names. Attach handling conditions: purpose only, corroborate before acting, and a contact for corrections. Record the decision as share after specified controls.

Not supported by the evidence C. Decline. Without a statute that compels disclosure, a bank should not tell another bank anything about a customer.

Source

The government guidance says the measures are voluntary and were introduced to give firms clarity and comfort to share relevant customer information to prevent, detect or investigate economic crime. It also says private bodies do not need statutory authority to share information, though they need a lawful basis for personal data. [4]

Application

Voluntary means Bank A may decline, not that it must. Neither ECCTA nor the guidance requires a refusal, and a blanket rule skips the route that was built for this request. Declining is a defensible outcome where a condition fails, and it is not a defensible default when the conditions are met.

Action

Decide on the conditions. If one fails, record which and why, and treat that as the outcome. Do not record a blanket policy as the reason.

Contains a true point, stops short D. Hold everything until a full data sharing agreement and a data protection impact assessment are signed off, even though this is a one-off request.

Source

The ICO's scams page, which is under review, says an impact assessment is a legal requirement where processing is likely to result in high risk, and good practice for routine sharing and major projects. It says a data sharing agreement is good practice, particularly where sharing is not ad hoc or one-off. [10]

Application

An agreement and an assessment are sound for recurring sharing. A single request does not have to wait for a bilateral agreement, but the firm should assess whether the risk is high and record why it did or did not carry out a full assessment. Holding everything can also delay a request whose purpose may be time-sensitive.

Action

Carry out a short, proportionate assessment now and record the conclusion, share the minimised set if the conditions are met, and propose an agreement if requests between the two banks are likely to recur.

Decision Record

Facts
Former customer of Bank A, now a customer of Bank B. The request names the person and states Bank B's decision. No SAR has been made. The file holds third-party victim data and an allegation note. There is no data sharing agreement, and the policy document has not been checked against this disclosure.
Assumptions
The requester is who it says it is. The named person is the same individual. The nominated officer confirms no SAR exists and no investigation is contemplated. The closure was decided because of economic crime concerns.
Indicators
A closure for fraud concerns, two victim reports naming the account, and device and address overlaps with two other accounts.
Mitigants
Verification of the requester, a minimised data set, handling conditions, a correction contact and a check that the policy document covers the disclosure.
Decision
Share after specified controls.
Rationale
The section 188 conditions are met on the facts, the data protection and SAR boundary questions are answered separately, and the disclosure is limited to what Bank B's stated decision needs.

What Would Change My Decision?

Towards escalating or not sharing: the person is not, and was not, a customer of Bank A. The requester cannot be verified, or the request does not state a decision. Bank B is not carrying on business in the regulated sector. The nominated officer says a SAR exists or an investigation is contemplated. The policy document does not cover the processing.

Towards sharing more: Bank B shows that a further fact bears directly on its stated decision, and the same conditions and minimisation test are met for that fact.

Worked scenario 2 · Post-SAR counterfactual

The same request, after a SAR

Nothing about the request has changed. One fact in your own file has, and it moves the decision to a different question.

Counterfactual: change one fact FinCrimeRadar assessment

The fact changed. Bank A has now submitted a SAR about the same person. Every operational fact from scenario 1 is kept.

What follows. ECCTA eligibility is unchanged, so question 1 has the same answer. The decision now turns on question 3. Eligibility under sections 188 and 189 does not by itself resolve whether a disclosure would reveal or imply the SAR, or prejudice an investigation, because those protections are expressed as protection from breach of confidence and civil liability.

Composite scenario for teaching. It does not describe a real firm, customer or case.

  • All of the facts in scenario 1 apply. Bank B's request names the former customer, states that it needs the closure reason and any fraud concerns to decide whether to restrict or close the account, and does not mention a SAR.
  • Four weeks ago Bank A's nominated officer submitted a SAR about the person, and the NCA acknowledged it. The SAR reference is in the case file.
  • The nominated officer cannot say whether any investigation is contemplated or under way.
  • The person was a client of Bank A and is a client of Bank B. Both are credit institutions in the United Kingdom.
  • Some of the information in the file came from a report supplied by a police force.
What is the most defensible decision for Bank A now?

How each option grades

Not supported by the evidence A. Share the same minimised set as in scenario 1. ECCTA eligibility has not changed, so the SAR makes no difference.

Source

ECCTA sections 188(2) and 189(2) protect against breach of an obligation of confidence and civil liability. [1] Section 333A of POCA makes it an offence to disclose that a SAR has been made, or that an investigation is contemplated or under way, where the disclosure is likely to prejudice an investigation. [11] The government guidance says firms that share after submitting a SAR must make sure they do not breach the tipping-off or prejudicing-investigation provisions. [4]

Application

The first half of the option is right: eligibility under ECCTA is unchanged. The conclusion does not follow. Whether the proposed disclosure would reveal or imply the SAR or a contemplated investigation, and whether it is likely to prejudice one, is a question the ECCTA protections do not answer. A disclosure that reveals neither may still be possible, but that has to be tested before it is sent.

Action

Do not send on the strength of ECCTA eligibility. Put the SAR boundary test before the disclosure and take it to the nominated officer.

Best supported by the evidence B. Escalate to the nominated officer and do not share yet. Test whether anything in the proposed disclosure would reveal or imply the SAR or a contemplated investigation, and whether it is likely to prejudice one. Decide which route fits, including a section 339ZB disclosure with its required notification to the NCA, or no disclosure, and record why.

Source

Section 333A applies to a disclosure that reveals a SAR or a contemplated investigation and is likely to prejudice an investigation. Section 333D provides that there is no offence where the person does not know or suspect that the disclosure is likely to have that effect, and for a disclosure made in good faith by virtue of section 339ZB. [11] Section 339ZB requires a request, a required notification made to the NCA before the disclosure, and the discloser's satisfaction that the disclosure will or may assist in determining a matter connected with a suspicion of money laundering. [12] The NCA publishes a required notification form and procedure. [14] A section 339ZB disclosure may not include information obtained from a UK law enforcement agency without that agency's consent. [12]

Application

The option separates the SAR boundary from the route. ECCTA settles question 1 and the nominated officer owns question 3. Section 339ZB can fit only if the facts support a suspicion of money laundering and the notification is made first, and here the police-supplied information would have to be left out unless consent is given. Until those questions are answered the safe outcome is to escalate and not share yet.

Action

Escalate to the nominated officer, who decides what, if anything, can be said and in what words. Do not reveal or imply the SAR in any reply. If a disclosure that reveals neither can be made, the scenario 1 controls apply. If not, consider section 339ZB with its notification, or decline for a reason that does not reveal the SAR. Record the decision and the reasons.

Not supported by the evidence C. Reply that Bank A cannot help because a SAR has been made.

Source

Section 333A(2) describes the matters whose disclosure is the offence, namely that a disclosure under Part 7 has been made to a constable, an HMRC officer, a nominated officer or an NCA officer. [11]

Application

Giving the SAR as the reason for declining is itself a disclosure of the matter that section 333A(2) describes. Whether it is likely to prejudice an investigation is the other element, and it is not a risk to take for the sake of a tidy reply. The reason given in a reply is a disclosure like any other.

Action

Do not give the reason. If the decision is to decline or to hold, the nominated officer approves a reply that neither reveals nor implies a SAR.

Contains a true point, stops short D. Share everything, including the SAR reference, relying on section 333C because both firms are banks.

Source

Section 333C permits a disclosure by a credit institution to another credit institution only where it relates to a client or former client of both, a transaction involving both, or a service involving both, is for the purpose only of preventing an offence under Part 7 of POCA, the recipient is in the UK or an EEA state or a country with equivalent money laundering requirements, and both firms are subject to equivalent duties of professional confidentiality and data protection. [11]

Application

Section 333C is a real exception and the two banks share a client, so the option has a true point. It stops short. The purpose must be only the prevention of a Part 7 offence, which cannot be assumed for a request about a fraud-related account, and every condition has to be met and recorded. The section addresses the tipping-off offence only, so confidentiality and data protection still need their own answers. Nothing in Bank B's stated decision explains why the SAR reference would be needed, and the police-supplied material raises a separate consent question.

Action

Do not use section 333C as a default. If the nominated officer considers it, record how each condition is met and why disclosing the SAR is necessary, and answer questions 1 and 2 separately.

Decision Record

Facts
The scenario 1 facts, plus a SAR submitted four weeks ago and acknowledged by the NCA. The nominated officer cannot say whether an investigation is contemplated. Bank B's request does not mention a SAR. Part of the file came from a police force.
Assumptions
The SAR concerns the same person and the same suspicion. The ECCTA conditions are still met. Bank B's request is authentic.
Indicators
A SAR on file, no clarity on any investigation, and police-supplied information in the case file.
Mitigants
Nominated officer review, drafting that reveals neither the SAR nor any investigation, and the section 339ZB route with its notification as an alternative.
Decision
Escalate and do not share yet.
Rationale
ECCTA eligibility answers only the confidence and civil liability question. Whether the disclosure would reveal or imply the SAR or prejudice an investigation is unresolved, and the nominated officer decides it.

What Would Change My Decision?

Towards sharing under ECCTA: the nominated officer confirms in writing that the proposed disclosure reveals neither the SAR nor any contemplated investigation and is not likely to prejudice one, and the scenario 1 controls are all met.

Towards the section 339ZB route: both banks hold a suspicion of money laundering, a request that meets section 339ZC is made, and the required notification is made to the NCA before anything is disclosed.

Towards not sharing: content that would reveal or imply the SAR cannot be separated from what Bank B needs, or the only way to answer is to rely on police-supplied information without the agency's consent.

Red Team Questions

Put these to your own decision before anything is sent. A disclosure that cannot answer them is not ready, and a missing answer is a finding in its own right.

These are questions for the person approving the disclosure. They test the decision and make no claim about the law, which is set out in the sequence above.

  1. Purpose. Which sentence names the decision this disclosure will serve, and whose customer is that decision about?
  2. Route. Which section of which Act are you relying on, and which of its conditions would you find hardest to show to the Financial Ombudsman Service or the ICO?
  3. Scope. If the person were not your customer or former customer, or the recipient's action were not about its own customer, would the route still hold?
  4. Necessity. Which item in the disclosure could be removed without changing the recipient's decision?
  5. Accuracy. If the allegation is wrong, what would the person lose, and how would it be corrected?
  6. Protected data. Could the purpose be met with underlying facts instead of the allegation label?
  7. SAR boundary. Does any sentence reveal or imply that a SAR exists or that an investigation is contemplated, and has the nominated officer seen the draft?
  8. Recipient use. What has the recipient said it will check independently before it acts on what you send?
  9. Record. Could someone who was not in the room rebuild why you shared exactly this and nothing else?

One-screen summary

The framework on one page. Every line restates wording from the sections above and adds no new claim.

Eight steps

  1. Purpose. What precise economic-crime decision would the sharing assist?
  2. Route. Is this ECCTA direct sharing, ECCTA indirect sharing, POCA section 339ZB sharing, a permitted post-SAR disclosure, or ordinary sharing outside those protections?
  3. Scope. Are the sender, recipient, customer and proposed use within the chosen route?
  4. Data protection. What is the Article 6 basis, and are necessity, purpose compatibility, minimisation, accuracy, security and transparency documented?
  5. Protected data. Are allegations or suspicions criminal offence data, and which Schedule 1 condition and policy document apply?
  6. SAR boundary. Has a SAR been made or an investigation contemplated, and could the disclosure reveal it or prejudice an investigation?
  7. Recipient use. How may the recipient use what it receives?
  8. Record. What must the record show?

Four outcomes

  1. Share under the identified route. The route conditions are met, the data protection and SAR boundary answers are recorded, and nothing beyond the ordinary record is needed.
  2. Share after specified controls. The route fits, but named controls must be in place first, such as verifying the requester, minimising the data, confirming the policy document and agreeing handling conditions.
  3. Escalate and do not share yet. An answer to the data protection or SAR boundary question is missing, or a SAR or investigation may be in play.
  4. Do not share under this route. A route condition is not met, for example the recipient is outside the regulated sector, the person is not within the route, or the purpose is not economic crime.

Choose the route first. Then ask what the route protects, and what it does not.

Risk, Signal, Response

Five ways an information-sharing decision goes wrong. Each card names the risk, the signal that shows it in the record, and the response.

1. The Shield Swap

A confidentiality shield is traded for a data protection basis.

Risk
ECCTA eligibility is treated as permission to share.
Signal
The record cites sections 188 or 189 and says nothing about the lawful basis or the Schedule 1 condition.
Response
Answer the three questions separately and cite a source for each.

2. The Full File

The whole case file goes out because the route fits.

Risk
More personal data is shared than the stated decision needs.
Signal
Third-party names and allegation labels appear in a disclosure whose purpose does not need them.
Response
Build the minimum set from the stated purpose and leave out the rest.

3. The Silent SAR

A reply says more about reporting than it should.

Risk
A reply reveals or implies that a SAR exists or that an investigation is contemplated.
Signal
A refusal explains itself by reference to reporting, or the nominated officer has not seen the draft.
Response
The nominated officer approves any reply, and it is drafted so that nothing reveals or implies a SAR.

4. The Borrowed Verdict

Another firm's information becomes this firm's conclusion.

Risk
Received intelligence is treated as proof and used as an automatic exit instruction.
Signal
The recipient's file cites only the sender's information as its reason.
Response
Record the independent checks, corroborate before acting and keep the complaint route open.

5. The Missing Minutes

The decision cannot be reconstructed afterwards.

Risk
The firm cannot show why it shared what it shared.
Signal
The request, route, data shared and approvals sit in different inboxes.
Response
Complete one decision record before sending.

FAQ

Does ECCTA let me ignore the UK GDPR?

No. Sections 188(11) and 189(10) say nothing in them authorises a disclosure that would contravene the data protection legislation, or prevents civil liability arising under it. [1] The ICO describes recognised legitimate interest as a lawful basis and not an exemption. [7]

Is recognised legitimate interest automatic permission to share?

No. The crime condition covers processing necessary for detecting, investigating or preventing crime, so the firm must be able to show the sharing is necessary for that purpose. [5] The ICO says the firm must also meet the other data protection requirements, tell people it relies on the basis and which condition, and allow them to object. [7]

Is ECCTA sharing a Super SAR?

No. The government guidance uses Super SAR for the joint disclosure report under POCA section 339ZB. [4] ECCTA sharing under sections 188 and 189 is a separate route and creates no joint report. [1] [12]

Can I share after submitting a SAR?

Not on ECCTA eligibility alone. The government guidance says firms that share after a SAR must make sure they do not breach the tipping-off or prejudicing-investigation provisions. [4] Section 333A turns on whether the disclosure reveals the SAR or a contemplated investigation and is likely to prejudice one, and the nominated officer should decide what, if anything, can be said. [11]

Does received intelligence justify exiting a customer?

Not on its own. The government guidance says the measures are not designed to give sectors additional powers to exclude customers inappropriately and should assist risk-based decision making. [4] The recipient owns the decision and the evidence for it, and should treat what it receives as an input to its own assessment.

Which parts of the government and ICO material are out of date?

The October 2025 government guidance says the recognised legitimate interest provisions will come into force in 2026. They came into force on 5 February 2026, so the commencement instrument and the ICO's March 2026 guidance are the better guide. [4] [6] [7] The ICO's pages on criminal offence data conditions and on sharing to prevent scams and fraud are marked as under review, and this guide uses them only for operational controls. [9] [10]

What should the record contain?

The request, the purpose, the route, the data shared and the data withheld, the approvals, the handling restrictions, the retention period, the decision and the complaint or correction route. The government guidance encourages an audit trail of all information shared and a record of key decision points. [4]

Sources and methodology

Scope: UK sharing of customer information between firms for the purpose of preventing, detecting or investigating economic crime, as it stands in the primary sources below. It does not cover reporting to the NCA through a SAR, sharing with law enforcement, sharing outside the UK, group-internal sharing, sanctions information or the Terrorism Act equivalents. This is decision support for practitioners, not legal advice.

Method: Each source was read from its publisher's website on 4 October 2026. Statute text was read as revised on legislation.gov.uk on that date, and the ICO and government pages were read for the passages used here. The two scenarios are synthetic and describe no real firm, customer or case. The eight-step sequence, the four outcome labels and the scenario conclusions are our assessments.

Evidence separation: Source blocks state what an authority says. Application and Action blocks are FinCrimeRadar analysis and recommendation, and they are labelled as ours.

Limits: The October 2025 government guidance says the recognised legitimate interest provisions will come into force in 2026. They came into force on 5 February 2026, and this guide relies on the commencement instrument for that point. The ICO pages on criminal offence data conditions and on sharing to prevent scams and fraud are marked as under review, so they are used only for operational controls and for the ICO's table of policy document requirements. The regulations that sections 188(3) and 189(3) allow the Secretary of State to make were not analysed. The Explanatory Notes and the government guidance read section 188(3) as covering AML-regulated firms. No case law was analysed, so the position on a duty of confidence outside the routes, and the interpretation of the tipping-off offence, are not decided here. The NCA's required notification page carries no date, and its operational detail may change. An independent review of the ECCTA, data protection, criminal offence data and tipping-off conclusions was carried out against the primary sources. It found the route model and the Scenario 2 outcome defensible and required three corrections, which were made: the section 189 protections for the intermediary and the eventual recipient are now stated separately, the preparation-for-disclosure limb of Schedule 1 paragraph 10(2) is stated, and Scenario 1 no longer treats the absence of a SAR as excluding a contemplated or current investigation. A short recheck of the three corrected passages against the cited primary sources was completed on 4 October 2026 and passed.

  1. Economic Crime and Corporate Transparency Act 2023, sections 188 to 193, as revised, read 4 October 2026.
  2. Economic Crime and Corporate Transparency Act 2023, Schedule 11 (economic crime offences), as revised, read 4 October 2026.
  3. Explanatory Notes to the Economic Crime and Corporate Transparency Act 2023, sections 188 and 189.
  4. Home Office and other departments, Guidance on the information sharing measures in the Economic Crime and Corporate Transparency Act 2023, updated 3 October 2025.
  5. Data (Use and Access) Act 2025, section 70 and Schedule 4, read 4 October 2026.
  6. The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (SI 2026/82), made 29 January 2026.
  7. Information Commissioner's Office, Recognised legitimate interest, published 23 March 2026.
  8. Data Protection Act 2018, Schedule 1, paragraphs 5, 10, 14, 15, 36 and 39 to 41, as revised, read 4 October 2026.
  9. Information Commissioner's Office, Criminal offence data: what are the conditions for processing?, marked as under review, read 4 October 2026.
  10. Information Commissioner's Office, Sharing personal information when preventing, detecting and investigating scams and frauds, marked as under review, read 4 October 2026.
  11. Proceeds of Crime Act 2002, sections 333A to 333D, as revised, read 4 October 2026.
  12. Proceeds of Crime Act 2002, sections 339ZB to 339ZG, as revised, read 4 October 2026.
  13. Criminal Finances Act 2017, section 11 and the Explanatory Notes to it.
  14. National Crime Agency, Required notification under s.339ZC of Proceeds of Crime Act 2002, no date shown, read 4 October 2026.

Last reviewed: 4 October 2026. Recheck when ECCTA sections 188 to 193 or the UK GDPR provisions are amended, when the ICO replaces its under-review pages, when regulations are made under sections 188(3) or 189(3), and before release.