When both criteria are met, the processing of the data falls under the scope of the EU’s specialised regime namely Directive 2016/680.
Financial Intelligence Units (FIUs), in the exercise of their mission to prevent, detect and combat money laundering and terrorist financing, fulfil both of these criteria and therefore qualify as competent authorities. Such qualification does not depend on the organisational structure of the FIU. In fact, EU legislation on combatting money laundering and terrorist financing3 requires FIUs to operate as independent and autonomous bodies with extensive powers to obtain information from law enforcement authorities and swiftly and decisively act against transactions that facilitate money laundering or terrorist financing. The missions, functions and powers of the FIUs demonstrate the importance of their role in crime detection and crime prevention in that field.4
Secondly, under EU law, a total prohibition on access to personal data held by FIUs may be compatible with their mission to safeguard strict confidentiality. However, any such restriction must comply with the principle of proportionality, which requires it to be limited in scope and duration to what is necessary to achieve the legitimate aim.
It must also be anchored in legislation that provides clear and precise rules governing its scope and application. This legislation must provide the minimum safeguards necessary to prevent data abuse or unlawful access, and enable the supervisory authority and the courts to exercise effective control over decisions regarding restrictions.
The conditions for restricting access rights in order to protect against misuse or unlawful access may be set out not only in a single legislative act, but also in a coherent set of legislative and subordinate acts that together define the limitations, provided that this set allows for a clear and precise understanding of the scope of the restriction and that it is foreseeable by the persons subject to it. However, in the present case, it does not seem that the applicable legal framework sets out clear conditions for restricting the right of access. It is for the national court to assess whether such restrictions comply with the standards set out in EU law.
Thirdly, to compensate for the absence of a direct right of access, the rights of data subjects must be indirectly protected through the supervisory authority. The authority must then be empowered to hold confidential discussions with FIUs to determine precisely which data are required for the data subject to obtain an effective judicial remedy.
Finally, EU law permits FIUs to refuse a data subject access request without providing reasons when disclosure would endanger the public interest. In such cases, however, the FIU must inform the data subject of the possibility of exercising their rights indirectly through the supervisory authority.
|
NOTE: The Advocate General’s Opinion is not binding on the Court of Justice. It is the role of the Advocates General to propose to the Court, in complete independence, a legal solution to the cases for which they are responsible. The Judges of the Court are now beginning their deliberations in this case. Judgment will be given at a later date. NOTE: A reference for a preliminary ruling allows the courts and tribunals of the Member States, in disputes which have been brought before them, to refer questions to the Court of Justice of the European Union about the interpretation of EU law or the validity of an EU act. The General Court has jurisdiction to deal with requests for a preliminary ruling coming exclusively within the following areas (1) the common system of value added tax (VAT), (2) excise duties, (3) the Customs Code, (4) the tariff classification of goods under the Combined Nomenclature, (5) compensation and assistance to passengers in the event of denied boarding or delay or cancellation of transport services, or (6) the system for greenhouse gas emission allowance trading. The Court of Justice has jurisdiction to deal with all other requests for a preliminary ruling. Neither the Court of Justice nor the General Court decides the national dispute itself. It is for the national court or tribunal to resolve the case in accordance with the ruling by the Court of Justice or by the General Court, which is similarly binding on other national courts or tribunals before which a similar issue is raised. |
1 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (the Law Enforcement Directive).
2 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
3 Directive (EU) 2015/849 of the European Parliament and of the Council of 20 May 2015 on the prevention of the use of the financial system for the purposes of money laundering or terrorist financing, amending Regulation (EU) No 648/2012 of the European Parliament and of the Council, and repealing Directive 2005/60/EC of the European Parliament and of the Council and Commission Directive 2006/70/EC.
4 The Advocate General considers that the Court of Justice's case law supports the conclusion that an entity acquires 'competent authority' status by virtue of its role in the data processing chain that underpins crime prevention, detection, and prosecution, precisely the function performed by FIUs (See Judgment of 30 April 2024 La Quadrature du Net and Others C-470/21 – see also Press release No 75/24, and Judgment of 21 June 2022 Ligue des droits humains C-817/19 – See also Press release No 105/22).



