FactBox.

EUR-Lex · 14 Aug 2026 · 9 vistas

European Central Bank and National Authorities Become Joint Data Controllers

Por FactBox Admin

The Governing Council of the European Central Bank (ECB) has adopted Decision (EU) 2026/1942 (ECB/2026/18), published in the Official Journal of the European Union on 14 August 2026, setting out how personal data are processed in the prudential supervision of credit institutions. Under the new framework, the ECB and the national competent authorities (NCAs) act as joint controllers of that data within the Single Supervisory Mechanism (SSM). The decision, signed by ECB President Christine Lagarde in Frankfurt am Main, was taken on 30 July 2026.

The text implements the joint-controllership provisions of Regulation (EU) 2018/1725 (Article 28) and of the GDPR (Regulation (EU) 2016/679, Article 26) in the setting of banking supervision under Council Regulation (EU) No 1024/2013, the SSM Regulation. It allocates the respective responsibilities of the ECB and each NCA when personal data are processed in supervisory tasks, replacing case-by-case arrangements with a single framework agreed in consultation with the NCAs. It is addressed to the NCAs of the participating Member States and takes effect on the day of its notification to them.

Seven supervisory tasks covered

The decision applies to the processing of personal data in seven blocks of supervisory work within the SSM:

  • fit and proper procedures for significant supervised entities;
  • authorisation procedures, including qualifying holdings, branches and cross-border services;
  • ongoing supervision of significant supervised entities;
  • enforcement and sanctions;
  • on-site inspections of significant supervised entities;
  • oversight of the supervision of less significant supervised entities;
  • supervision of less significant supervised entities.

Outside that scope, the ECB or the NCA concerned remains the sole controller for reports of breaches of Union or national law submitted through whistleblowing mechanisms, and NCAs processing data under legal bases other than the SSM Regulation act alone. Certain enforcement and sanction procedures are also excluded.

Clear responsibilities towards data subjects

Each joint controller must publish a data protection notice on its website, and the controller that starts a processing operation informs the data subject. For data submitted through the Information Management System (IMAS) portal that controller is the ECB; in other cases the responsible body varies by task, with the relevant NCA handling fit-and-proper and authorisation procedures and the ECB handling ongoing supervision, enforcement, on-site inspections and oversight of less significant entities.

Data subjects may exercise their rights against each joint controller. A controller aware of a personal data breach must notify the other joint controllers within 24 hours, and the responsible controller manages the breach; the ECB must in all cases inform the European Data Protection Supervisor, unless the breach is unlikely to pose a risk to individuals.

Liability, compensation and review

The joint controllers are jointly and severally liable for damage caused by infringements, with compensation distributed according to the actual degree of responsibility. Disagreements on compensation are settled by an independent panel that issues a reasoned, non-binding recommendation within three months, notified to the President of the ECB; the Governing Council must review the arrangements no later than five years after the decision takes effect.

What data, and whose

Seven annexes detail, for each supervisory task, the purpose, legal basis, data subjects and categories of data. They cover staff, members of management bodies, shareholders, customers and their guarantors, creditors, service providers, consultants and external auditors of supervised entities, as well as close relatives and associates of appointees in fit-and-proper assessments. Processed categories include identification and contact data, professional and financial details, criminal records and information on investigations and proceedings, and even sound recordings of an appointee’s voice.

For banks and bank customers in the euro area, the decision brings legal certainty: every person whose data are handled in SSM supervision now has a clear contact point to exercise their rights and a defined authority responsible for breaches and compensation. It is the first time the division of data-protection duties between Frankfurt and the national supervisors is codified in a single legal act.


Source: Official Journal of the European Union, L series, 14 August 2026 (official reference: CELEX L_202601942 — Decision (EU) 2026/1942 (ECB/2026/18)).