Key data
| Regulation | Decision (EU) 2026/1942 of the ECB — ECB/2026/18 |
|---|---|
| Publication | August 14, 2026 |
| Entry into force | August 14, 2026 |
| Affected parties | Credit institutions under supervision, ECB and national competent authorities (NCA) |
| Category | Data Protection |
| Applicable legal framework | GDPR and Regulation (EU) 2018/1725 |
| Year | 2026 |
Banks under direct ECB supervision can no longer treat data protection as an exclusive internal matter: Decision ECB/2026/18 precisely establishes which entity—ECB or national NCA—is responsible at each stage of the supervisory process. Knowing that map is now an operational obligation, not an option.
The regulation enters into force on the same day as its publication, August 14, 2026, with no transitional period. It applies the framework of the General Data Protection Regulation (GDPR) and Regulation (EU) 2018/1725, which governs data processing by EU institutions.
What does this regulation establish?
Decision ECB/2026/18 resolves a gap that existed in the SSM: who is responsible for processing personal data when the ECB and NCA act jointly? The answer is clear: both are joint controllers in most supervisory procedures.
The regulation precisely defines which supervisory tasks involve joint data processing and, therefore, joint controllership:
| Supervisory procedure | Responsibility model |
|---|---|
| Fitness assessment procedures (fit & proper) | ECB and NCA as joint controllers |
| Credit institution authorizations | ECB and NCA as joint controllers |
| Ongoing supervision | ECB and NCA as joint controllers |
| On-site inspections | ECB and NCA as joint controllers |
| Enforcement procedures | ECB and NCA as joint controllers |
| Whistleblowing channel complaints | Each entity acts as sole controller |
| Specific individual procedures | Each entity acts as sole controller |
Additionally, the regulation establishes the responsibilities of each party towards data subjects (the individuals whose data is processed) and towards data protection authorities. The stated objective is to guarantee transparency, legal certainty and regulatory compliance in the field of European banking supervision.
Economic and operational impact
This decision does not generate direct fees or costs for banks, but it does have a real operational impact in three areas:
- Review of processing activity records: Supervised banks must update their records to reflect who is the controller—or joint controller—in each type of procedure.
- Update of privacy notices: Data subjects (executives, employees, shareholders whose data is processed in fitness assessment or enforcement procedures) must be correctly informed of the identity of the controller.
- Whistleblowing protocols: In reporting channels, each entity—ECB or NCA—acts as sole controller, which requires clearly separating data flows and information obligations.
Non-compliance with data protection obligations in the supervisory context may result in complaints to supervisory authorities and, ultimately, in sanctions under the GDPR. For larger banks, with frequent fitness assessment procedures or recurring on-site inspections, the volume of personal data jointly processed with the ECB or NCA is significant.
Who does it affect?
- Credit institutions under direct ECB supervision (the so-called "significant banks" of the SSM): they are the most affected, as their fitness assessment procedures, authorizations and enforcement actions directly involve the ECB as joint controller.
- Credit institutions under indirect supervision (less significant banks supervised by NCAs): also affected in procedures in which the ECB intervenes.
- National Competent Authorities (NCA) of euro area countries: must adapt their internal procedures to reflect joint controllership and define coordination mechanisms with the ECB.
- Data Protection Officers (DPO) of banking entities: responsible for updating records, notices and procedures.
- Compliance and Legal departments of supervised banks: must review contracts, data flows and protocols for responding to data subject rights.
Practical example
A significant Spanish bank—directly supervised by the ECB—initiates a fitness assessment procedure to appoint a new chief executive officer. During this process, personal data of the candidate is processed: professional history, background, financial situation.
Before Decision ECB/2026/18, there was no express rule determining whether the controller was the ECB, the Bank of Spain or both jointly. With the new regulation, it is clear: ECB and Bank of Spain are joint controllers of that processing. This means that:
- The candidate can exercise their rights of access, rectification or erasure with either of the two.
- The bank must inform the candidate of this joint controllership in the privacy notice of the procedure.
- If a security breach occurs during the procedure, both entities share responsibility for notification.
In contrast, if that same bank receives an internal complaint through its whistleblowing channel that is forwarded to the ECB, each entity manages the data of that complaint as sole controller of its part of the process, without joint controllership.
What should companies do now?
- Identify which active supervisory procedures involve data processing with the ECB or NCA: fitness assessment, authorizations, inspections, enforcement or ongoing supervision. These are the areas of joint controllership.
- Update the Records of Processing Activities (RPA) to reflect ECB-NCA joint controllership in each affected procedure, indicating the legal basis and data processed.
- Review and update privacy notices directed to individuals whose data is processed in supervisory procedures (executives, candidates for positions, employees in inspections).
- Separate data flows from the whistleblowing channel from other procedures, given that in this case each entity acts as sole controller, not as joint controller.
- Coordinate with the DPO the review of protocols for responding to data subject rights, ensuring that a response can be provided regardless of whether the request is directed to the ECB, the NCA or the bank itself.
- Verify with the legal department whether there are contracts or agreements with the ECB or NCA that should be updated to reflect the new joint controllership structure.
Frequently asked questions
What does it mean that the ECB and NCA are "joint controllers" of data processing?
It means that both entities jointly determine the purposes and means of personal data processing in shared supervisory procedures. In practice, the data subject can exercise their rights (access, rectification, erasure) with either of the two entities, and both share responsibility before data protection authorities. Decision ECB/2026/18 establishes this regime for fitness assessment procedures, authorizations, ongoing supervision, on-site inspections and enforcement actions.
When does Decision ECB/2026/18 enter into force and is there an adaptation period?
The regulation entered into force on August 14, 2026, the same day as its publication. There is no explicit transitional period, so affected entities must adapt their records, privacy notices and protocols immediately.
What happens with whistleblowing channel data? Is there also joint controllership?
No. Decision ECB/2026/18 expressly establishes that in complaints through whistleblowing channels, and in certain specific procedures, each entity acts as sole controller of processing, without joint controllership with the other party. This requires separating the data flows and information obligations of these channels from the rest of supervisory procedures.
Which banks does this regulation affect: only large ones or also small ones?
It affects all credit institutions supervised within the SSM framework, both significant banks (directly supervised by the ECB) and less significant ones (supervised by NCAs with indirect ECB involvement). The intensity of impact is greater for significant banks, which have fitness assessment procedures, authorizations and inspections directly managed by the ECB.
What legal framework does this decision apply: GDPR or Regulation 2018/1725?
Both. Decision ECB/2026/18 applies the GDPR (for data processing by national NCAs) and Regulation (EU) 2018/1725 (for data processing by EU institutions, including the ECB). The regulation seeks to ensure consistency and legal certainty between both frameworks in the context of European banking supervision.
Official source
Consult complete regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=CELEX:32026D1942