Data Protection

ECB/2026/18: new personal data rules for supervised banks in Europe

E
Equipo Editorial CambiosLegales
16 Aug 2026 7 min 177 views

Key data

RegulationDecision (EU) 2026/1942 of the ECB — ECB/2026/18
PublicationAugust 14, 2026
Entry into forceAugust 14, 2026
Affected partiesCredit institutions under supervision, ECB and national competent authorities (NCA)
CategoryData Protection
Applicable legal frameworkGDPR and Regulation (EU) 2018/1725
Year2026
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

Banks under direct ECB supervision can no longer treat data protection as an exclusive internal matter: Decision ECB/2026/18 precisely establishes which entity—ECB or national NCA—is responsible at each stage of the supervisory process. Knowing that map is now an operational obligation, not an option.

The regulation enters into force on the same day as its publication, August 14, 2026, with no transitional period. It applies the framework of the General Data Protection Regulation (GDPR) and Regulation (EU) 2018/1725, which governs data processing by EU institutions.

What does this regulation establish?

Decision ECB/2026/18 resolves a gap that existed in the SSM: who is responsible for processing personal data when the ECB and NCA act jointly? The answer is clear: both are joint controllers in most supervisory procedures.

The regulation precisely defines which supervisory tasks involve joint data processing and, therefore, joint controllership:

Supervisory procedureResponsibility model
Fitness assessment procedures (fit & proper)ECB and NCA as joint controllers
Credit institution authorizationsECB and NCA as joint controllers
Ongoing supervisionECB and NCA as joint controllers
On-site inspectionsECB and NCA as joint controllers
Enforcement proceduresECB and NCA as joint controllers
Whistleblowing channel complaintsEach entity acts as sole controller
Specific individual proceduresEach entity acts as sole controller

Additionally, the regulation establishes the responsibilities of each party towards data subjects (the individuals whose data is processed) and towards data protection authorities. The stated objective is to guarantee transparency, legal certainty and regulatory compliance in the field of European banking supervision.

Economic and operational impact

This decision does not generate direct fees or costs for banks, but it does have a real operational impact in three areas:

  • Review of processing activity records: Supervised banks must update their records to reflect who is the controller—or joint controller—in each type of procedure.
  • Update of privacy notices: Data subjects (executives, employees, shareholders whose data is processed in fitness assessment or enforcement procedures) must be correctly informed of the identity of the controller.
  • Whistleblowing protocols: In reporting channels, each entity—ECB or NCA—acts as sole controller, which requires clearly separating data flows and information obligations.

Non-compliance with data protection obligations in the supervisory context may result in complaints to supervisory authorities and, ultimately, in sanctions under the GDPR. For larger banks, with frequent fitness assessment procedures or recurring on-site inspections, the volume of personal data jointly processed with the ECB or NCA is significant.

Who does it affect?

  • Credit institutions under direct ECB supervision (the so-called "significant banks" of the SSM): they are the most affected, as their fitness assessment procedures, authorizations and enforcement actions directly involve the ECB as joint controller.
  • Credit institutions under indirect supervision (less significant banks supervised by NCAs): also affected in procedures in which the ECB intervenes.
  • National Competent Authorities (NCA) of euro area countries: must adapt their internal procedures to reflect joint controllership and define coordination mechanisms with the ECB.
  • Data Protection Officers (DPO) of banking entities: responsible for updating records, notices and procedures.
  • Compliance and Legal departments of supervised banks: must review contracts, data flows and protocols for responding to data subject rights.

Practical example

A significant Spanish bank—directly supervised by the ECB—initiates a fitness assessment procedure to appoint a new chief executive officer. During this process, personal data of the candidate is processed: professional history, background, financial situation.

Before Decision ECB/2026/18, there was no express rule determining whether the controller was the ECB, the Bank of Spain or both jointly. With the new regulation, it is clear: ECB and Bank of Spain are joint controllers of that processing. This means that:

  • The candidate can exercise their rights of access, rectification or erasure with either of the two.
  • The bank must inform the candidate of this joint controllership in the privacy notice of the procedure.
  • If a security breach occurs during the procedure, both entities share responsibility for notification.

In contrast, if that same bank receives an internal complaint through its whistleblowing channel that is forwarded to the ECB, each entity manages the data of that complaint as sole controller of its part of the process, without joint controllership.

Do you need to track this and other regulations?

Consult the full details in CambiosLegales

What should companies do now?

  1. Identify which active supervisory procedures involve data processing with the ECB or NCA: fitness assessment, authorizations, inspections, enforcement or ongoing supervision. These are the areas of joint controllership.
  2. Update the Records of Processing Activities (RPA) to reflect ECB-NCA joint controllership in each affected procedure, indicating the legal basis and data processed.
  3. Review and update privacy notices directed to individuals whose data is processed in supervisory procedures (executives, candidates for positions, employees in inspections).
  4. Separate data flows from the whistleblowing channel from other procedures, given that in this case each entity acts as sole controller, not as joint controller.
  5. Coordinate with the DPO the review of protocols for responding to data subject rights, ensuring that a response can be provided regardless of whether the request is directed to the ECB, the NCA or the bank itself.
  6. Verify with the legal department whether there are contracts or agreements with the ECB or NCA that should be updated to reflect the new joint controllership structure.

Frequently asked questions

What does it mean that the ECB and NCA are "joint controllers" of data processing?

It means that both entities jointly determine the purposes and means of personal data processing in shared supervisory procedures. In practice, the data subject can exercise their rights (access, rectification, erasure) with either of the two entities, and both share responsibility before data protection authorities. Decision ECB/2026/18 establishes this regime for fitness assessment procedures, authorizations, ongoing supervision, on-site inspections and enforcement actions.

When does Decision ECB/2026/18 enter into force and is there an adaptation period?

The regulation entered into force on August 14, 2026, the same day as its publication. There is no explicit transitional period, so affected entities must adapt their records, privacy notices and protocols immediately.

What happens with whistleblowing channel data? Is there also joint controllership?

No. Decision ECB/2026/18 expressly establishes that in complaints through whistleblowing channels, and in certain specific procedures, each entity acts as sole controller of processing, without joint controllership with the other party. This requires separating the data flows and information obligations of these channels from the rest of supervisory procedures.

Which banks does this regulation affect: only large ones or also small ones?

It affects all credit institutions supervised within the SSM framework, both significant banks (directly supervised by the ECB) and less significant ones (supervised by NCAs with indirect ECB involvement). The intensity of impact is greater for significant banks, which have fitness assessment procedures, authorizations and inspections directly managed by the ECB.

What legal framework does this decision apply: GDPR or Regulation 2018/1725?

Both. Decision ECB/2026/18 applies the GDPR (for data processing by national NCAs) and Regulation (EU) 2018/1725 (for data processing by EU institutions, including the ECB). The regulation seeks to ensure consistency and legal certainty between both frameworks in the context of European banking supervision.

Official source

Consult complete regulation in official source

Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=CELEX:32026D1942



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts