Key data
| Regulation | Resolution of August 7, 2026, from the State Secretariat for Justice — Agreement between the Ministry of the Presidency, Justice and Relations with Parliament / UNESPA / TIREA |
|---|---|
| Official Gazette Publication | August 15, 2026 |
| Effective Date | July 1, 2026 (date of agreement signature) |
| Direct Affected Parties | Spanish insurance and reinsurance entities (96% of the market) |
| Category | Regulatory Changes |
| Year | 2026 |
| Signatory Organizations | Ministry of the Presidency, Justice and Relations with Parliament · UNESPA · TIREA |
| Beneficiary Organization | ORGA (Office for Asset Recovery and Management) |
| European Framework | Directive 2014/42/EU on the freezing and confiscation of crime-linked assets |
Spanish insurance companies have a new operational obligation from July 2026: to provide policy information to the Office for Asset Recovery and Management (ORGA) when requested by courts or prosecutors in the context of criminal investigations. The agreement signed on July 1, 2026 between the Ministry of the Presidency, Justice and Relations with Parliament, UNESPA and TIREA converts this collaboration into a structured, technological and mandatory mechanism for the sector.
The regulation was published in the Official Gazette on August 15, 2026 through the Resolution of the State Secretariat for Justice, with reference BOE-A-2026-17810. The agreement is already in force from the date of its signature.
What does this regulation establish?
The agreement regulates a formal and secure channel through which ORGA can access insurance data when acting in support of courts and prosecutors. The information flow works as follows:
- A court or prosecutor detects the need to locate insured assets of a person under investigation in a criminal proceeding.
- The request reaches ORGA, which acts as an intermediary and channels it to the insurance sector.
- TIREA (Information Technology and Networks Entity for Insurance Entities) acts as the technological platform that manages queries securely and efficiently.
- Insurance companies that are members of UNESPA respond with relevant policy data.
The stated objective is to facilitate the seizure and confiscation of crime-linked assets, especially in cases linked to organized crime. The legal framework of reference is European Directive 2014/42/EU on the freezing and confiscation of instruments and proceeds of crime.
The processing of personal data is governed by the Code of Conduct approved by the AEPD (Spanish Data Protection Authority), which ensures that access to policy information complies with current privacy regulations.
Economic and operational impact
For insurance companies, the impact is not direct costs in fees or fines, but rather operational and compliance. These are the concrete implications:
- Adaptation of internal systems: Entities must be connected to or compatible with the TIREA platform to respond to ORGA queries in a timely manner.
- Response protocols: It is necessary to define internally who manages judicial requests, in what timeframes and with what level of authorization.
- Compliance with the AEPD Code of Conduct: Data processing must comply with the code approved by the Spanish Data Protection Authority, which may require review of internal privacy policies.
- Scope of 96% of the market: Virtually the entire sector is bound, meaning there is no room to remain outside the agreement if operating under the UNESPA umbrella.
For citizens under criminal investigation, the impact is that their insurance policies—life, savings, liability, property—can be located and communicated to justice without their prior knowledge, in the context of a criminal proceeding.
Who does it affect?
- Spanish insurance and reinsurance entities that are members of UNESPA (96% of the market): direct obligation to collaborate and provide data.
- TIREA: acts as the technological operator of the query channel; must ensure the security and efficiency of transmissions.
- Courts and prosecutors: benefit from structured access to insurance information for their investigations.
- ORGA (Office for Asset Recovery and Management): intermediary that channels judicial requests to the insurance sector.
- Citizens under criminal investigation: their insured assets can be located and subject to seizure or confiscation.
- Compliance and Data Protection departments of insurance companies: must review and adapt their internal protocols.
Practical example
A court opens a criminal case for money laundering linked to organized crime. The judge needs to know if the person under investigation has insured assets—for example, a life insurance policy with surrender value, a savings insurance or insured real estate—that could be seized or confiscated.
Before the agreement, locating those assets required individual requests to each insurance company, with the delays and dispersion that entails. With the new mechanism, the court transfers the request to ORGA, which channels it through TIREA to all insurance companies bound by the agreement. Within days, the court receives consolidated information about the person under investigation's policies across 96% of the Spanish insurance market, enabling it to act on those assets quickly and effectively.
For the insurance company holding that policy, the obligation is clear: respond to the query in accordance with the established protocol and the AEPD Code of Conduct, with no possibility of refusing based on the constitutional duty to cooperate with Justice.
What should companies do now?
- Verify UNESPA membership: Confirm whether the entity is within the 96% of the market covered by the agreement and therefore subject to the collaboration obligation.
- Review TIREA integration: Check that internal systems are compatible with the TIREA technological platform to receive and respond to ORGA queries without operational friction.
- Update internal protocols for responding to judicial requests: Define the internal flow: who receives the request, who authorizes it, in what timeframe it is responded to and how it is documented.
- Review compliance with the AEPD Code of Conduct: Ensure that the processing of policy data in the context of judicial requests complies with the code approved by the Spanish Data Protection Authority.
- Train Compliance and Data Protection teams: Internal managers must understand the agreement, their obligations and the limits of the duty to cooperate in order to act correctly on each request.
- Document each response to ORGA: Maintain a record of queries received and responses provided, both for internal traceability and for possible data protection audits.
Frequently asked questions
What insurance data can justice request from insurance companies?
The agreement allows courts and prosecutors—through ORGA—to request information about insurance policies of persons under investigation in criminal proceedings. The objective is to locate insured assets subject to seizure or confiscation, especially in cases of organized crime. The processing of that data must comply with the Code of Conduct approved by the AEPD.
Are all Spanish insurance companies required to comply with this agreement?
Insurance and reinsurance entities that are members of UNESPA, representing 96% of the Spanish insurance market, are required to provide this collaboration. The obligation is based on the constitutional duty to cooperate with Justice and on European Directive 2014/42/EU.
When did the obligation to provide data to ORGA come into force?
The agreement was signed on July 1, 2026, the date from which it came into force. The Resolution of the State Secretariat for Justice that publishes it was published in the Official Gazette on August 15, 2026 (reference BOE-A-2026-17810).
What role does TIREA play in this agreement?
TIREA (Information Technology and Networks Entity for Insurance Entities) acts as the technological platform that securely and efficiently channels ORGA queries to insurance companies. It is the technical intermediary between justice and the insurance sector.
What should Compliance departments of insurance companies review?
They should verify integration with TIREA, update internal protocols for responding to judicial requests and ensure that data processing complies with the Code of Conduct approved by the AEPD. It is also advisable to document each response provided to ORGA to maintain traceability for possible audits.
Official source
View complete regulation in official source
Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://www.boe.es/diario_boe/txt.php?id=BOE-A-2026-17810