Image related to ECCTA – A practical guide for compliance professionals

ECCTA – A practical guide for compliance professionals

This article is a free excerpt from inCOMPLIANCE, ICA's bi-monthly, member exclusive magazine. To gain access to more articles like this, sign in to the Learning Hub or become a member of ICA.

Ruth Paley and Nigel Kirby explain what the ECCTA information‑sharing powers allow, who can use them, and importantly, how firms can implement them safely and effectively.

Information sharing between regulated firms has long been recognised as a valuable tool in preventing and detecting economic crime. However, in practice, firms have often been cautious, particularly where customer data is involved. Concerns around confidentiality, data protection, tipping‑off and civil liability have meant that information sharing to date has been limited, inconsistent, or avoided altogether. The Economic Crime and Corporate Transparency Act 2023 (ECCTA) introduces a new statutory gateway for information sharing between firms in the regulated sector. Sections 188 and 189 provide a clear legal basis for sharing customer information for defined economic crime purposes, with specific conditions and protections.

What’s new?

Sections 188 and 189 of ECCTA create a statutory gateway, enabling firms in the regulated sector to share customer information for the purposes of preventing, detecting or investigating economic crime. The gateway is designed to be operationally practical and provides firms with protection from breach of confidence and civil liability where information is lawfully shared. Section 188 supports direct information sharing between regulated firms where either the request condition or the warning condition is met. Section 189 supports indirect sharing through a third party intermediary when the warning condition is met.

Who can use the powers?

The direct information sharing gateway under section 188 is available to all firms within the UK anti money laundering regulated sector, as defined in Part 1 of Schedule 9 to the Proceeds of Crime Act 2002 (POCA). This includes, but is not limited to, banks and other credit and financial institutions; payment service providers and electronic money institutions; accountants and auditors; independent legal professionals; tax advisers; estate agents and other regulated businesses.

The indirect information sharing gateway under section 189 is also available to all firms within the UK anti money laundering regulated sector, as well as large or very large firms (as defined by s.55 Finance Act 2022 [1]), permitting information sharing via a third-party intermediary where the statutory warning condition is met.

speech marks

Intelligence generated through sharing is increasingly informing the design of new automated controls and identifying activity that was previously undetectable.

The warning and request conditions

The warning condition applies where a firm has taken, or is proposing to take, safeguarding action in relation to a customer because of economic crime concerns. It may warn another regulated firm of that action where such a warning may assist in the prevention, detection or investigation of economic crime.

Safeguarding action includes decisions to terminate a relationship, refuse a product or service, or restrict access to a product or service. Even where the action has not yet been taken – it is sufficient that there is a clear intent to do so. Firms should ensure this intention is clearly documented in their records.

The request condition allows a firm to request information from another regulated firm – where it has reason to believe that the other firm holds information that may assist it to prevent, detect or investigate economic crime.

Warnings and requests are entirely voluntary and do not transfer knowledge or suspicion to the receiving firm – which must make its own independent assessment of risk.

Other legal considerations

Information sharing under ECCTA remains subject to UK GDPR and the Data Protection Act 2018. Any information shared must be limited to what is necessary and proportionate, must not include privileged disclosures and must comply with UK data protection requirements.

Recent legislative developments have clarified the availability of legitimate interests as a lawful basis for crime‑related sharing. Part 5 [2] of the Data Use and Access Act (DUAA) 2025 introduced ‘recognised legitimate interests’ as a lawful basis for processing and information sharing. Crime Prevention, detection and investigation are cited as legitimate interests without the need to conduct the full balancing test. This strengthens the data protection basis for voluntary sharing, while maintaining requirements of necessity, proportionality and compliance with UK GDPR principles.

Where information is shared within scope and for a permitted purpose, ECCTA provides statutory protection against breaches of confidentiality and related civil liability. This mitigates many of the risks that have historically constrained voluntary information sharing and supports the implementation of structured, defensible processes.

The protection applies only where firms stay within the legal boundaries of the gateway; it does not remove the need for governance and accountable decision making.

Interaction with SARs and other disclosure regimes

ECCTA information sharing sits alongside – rather than replacing – existing disclosure and information gathering mechanisms. Information sharing under ECCTA does not require a Suspicious Activity Report (SAR) to have been submitted, nor does it require the existence of suspicion that meets the SAR threshold.

In practice, ECCTA sharing may inform a SAR decision and may occur before, after, or independently of SAR reporting. Firms should avoid referencing the existence of SARs when sharing information, as this is rarely necessary and introduces avoidable risk. When used correctly, ECCTA sharing should not give rise to POCA ‘tipping‑off’ concerns.

speech marks

ECCTA offers something genuinely powerful: the ability to link fragments of information that no single firm could assemble alone, surface hidden patterns, and intervene early enough to change outcomes and have real world impact.

Operationalising within firms

Using section 188 effectively depends on operational readiness and clear, documented processes. Firms should focus on a small number of practical building blocks.

First, firms should complete a Data Protection Impact Assessment capturing their organisational approach to processing personal data under both the request and warning conditions. This should be supported by standardised templates for issuing warnings, making and responding to requests, together with clear internal triggers for when section 188 sharing should be considered.

Second, firms should establish clear governance. Most organisations will concentrate operational use within specialist financial crime teams, supported by a named section 188 gatekeeper or small approval group. Targeted training, reinforced by oversight such as a short checklist focused on purpose, relevance and proportionality will help maintain consistency without introducing unnecessary delay.

Third, firms should minimise and structure the information shared. It should be limited to what is necessary to achieve the purpose and not include extraneous detail. As a general rule, firms should avoid referencing SARs, as this is rarely relevant and introduces avoidable risk.

Finally, a concise record of purpose, scope, recipient, and content makes its use easier to defend if challenged by supervisors or the courts. Many firms pilot with trusted peers to refine processes, build confidence, and target the scenarios where sharing has the greatest impact.

Why use voluntary powers?

The UK has long been a global leader in public-private partnership on economic crime, with voluntary gateways such as section 7 of the Crime and Courts Act 2013 underpinning the Joint Money Laundering Intelligence Taskforce (JMLIT) model. The ECCTA builds on this foundation rather than replacing it. It complements existing gateways by enabling targeted private to private sharing between regulated firms, closing visibility gaps that no single institution or mandated mechanism can address alone.

In practice, ECCTA sharing frequently generates intelligence that allows statutory powers to be used more precisely and at greater speed – including account freezing and asset recovery. The result is a more integrated ecosystem in which voluntary, mandated, and private sector sharing reinforce one another to identify threats earlier, disrupt networks faster, and strengthen protection of the UK’s financial system.

Firms often ask whether private to private sharing under ECCTA genuinely makes a difference. The experience of early adopters across the banking sector is clear that it does. It is often described as a force multiplier that reveals hidden risk and accelerating disruption. In one example, a network of individuals and small businesses conducted high volume cash deposits before layering funds across multiple banks. Viewed in isolation, no single firm had sufficient insight to identify organised criminality. An ECCTA warning issued by one bank triggered investigations across others, collectively exposing a coordinated pattern that had been invisible through conventional controls. Several firms took prompt action, and Law Enforcement subsequently seized criminal proceeds.

Crucially, ECCTA also strengthens prevention. Intelligence generated through sharing is increasingly informing the design of new automated controls and identifying activity that was previously undetectable. In one case, this led directly to the recovery of more than half a million pounds through Asset Freezing Orders. Banks consistently report that high quality ECCTA warnings deliver stronger outcomes than traditional transaction monitoring alerts, precisely because they combine behavioural insight with cross institutional context. In a recent pilot, more than 60% of warnings resulted in direct preventative action, with one firm reporting that 80% of warnings received led to timely intervention.

Sharing to build a stronger defence

ECCTA gives AML regulated firms a clear, practical gateway to share customer information for economic crime purposes. Now the legal framework is clear, the challenge shifts to culture and operational implementation.

When implemented with clear purpose tests, proportionate sharing, focused governance and concise records, ECCTA information sharing can be a routine, defensible, and high impact part of a firm’s financial crime framework. In fast moving and complex risk environments, the gateway provides a lawful and structured way to connect intelligence across the regulated sector to inform timely decisions and actions.

ECCTA offers something genuinely powerful: the ability to link fragments of information that no single firm could assemble alone, surface hidden patterns, and intervene early enough to change outcomes and have real world impact. Used effectively, it represents not merely a compliance tool, but a strategic capability that enhances collaboration across the sector, complements the use of statutory powers, and materially improves the UK’s collective ability to prevent, detect, and investigate economic crime.

About the authors

Ruth Paley & Nigel Kirby

Ruth Paley, Partner at Michelman Robinson, is a leading authority on corporate crime, financial regulation, and investigations, with particular expertise in AML and enforcement strategy. Nigel Kirby is Director Intelligence and Nominated Officer at Lloyds Banking Group.