In today’s bulletin, we take an in-depth look at the issue of access to information on the beneficial ownership of legal persons, a topic that has triggered a complex interplay between transparency, anti-money laundering requirements, and the protection of personal data.
The starting point is Legislative Decree of 31 December 2025, No. 210, which implements Article 74 of Directive (EU) 2024/1640. This provision had already been submitted to the opinion of the Data Protection Authority on 6 November 2025 (web doc no. 10195739), whose observations were largely incorporated into the final measure.
The path leading to the new rules on access to beneficial ownership information is the result of a multilevel legislative process involving the Court of Justice, the EU legislature, and the national legislature.
We analyse this journey by linking together:
- the judgment of the Court of Justice of the European Union in joined cases C-37/20 and C-601/20, a true interpretative turning point at EU level;
- the Opinion of the Data Protection Authority of 6 November 2025;
- Legislative Decree No. 210/2025, which aligns the Italian framework with Directive (EU) 2024/1640.
Anti-money laundering framework
The anti-money laundering framework is set out in Legislative Decree of 21 November 2007, No. 231, which requires “obliged entities” (banks, professionals, financial intermediaries, etc.) to comply with the following obligations, divided into five fundamental macro-areas.
1. Risk Assessment
Obliged entities do not apply the legislation uniformly, but must adopt a risk-based approach.
- Self-assessment: They must analyse and assess the risks of money laundering and terrorist financing to which they are exposed in the course of their activities, taking into account the nature of the customer, the geographical area, distribution channels, and the services offered.
- Mitigation procedures: They must adopt safeguards, controls, and procedures appropriate to their nature and size in order to mitigate such risks.
- Training: They must ensure ongoing staff training to enable the identification of suspicious transactions.
2. Record-keeping obligations
Obliged entities must retain documents, data, and information in order to allow the FIU or other authorities to reconstruct transactions.
- What must be retained: Copies of documents obtained for customer due diligence purposes and records relating to transactions, including date, amount, and purpose.
- Retention period: Documents must be retained for 10 years from the termination of the relationship or the execution of the occasional transaction.
- Methods: They must prevent data loss and ensure compliance with personal data protection rules.
3. Reporting obligations
There are several types of reporting obligations imposed on obliged entities vis-à-vis the competent authorities (primarily the FIU – Financial Intelligence Unit, or in Italy, the UIF, Unità di Informazione Finanziaria).
- Suspicious Transaction Reports (STRs): These must be submitted “without delay” to the FIU when there is knowledge, suspicion, or reasonable grounds to suspect that money laundering or terrorist financing is taking place, or that funds originate from criminal activity.
- Prohibition of disclosure (tipping-off): It is prohibited to inform the customer or third parties of the filing of a report or the existence of investigations.
- Objective reports: Periodic transmission to the FIU of data concerning risk-related transactions identified on the basis of objective criteria (thresholds, typologies), irrespective of suspicion.
- Reporting of cash-use violations: Obligation to notify the Ministry of Economy and Finance (and the Guardia di Finanza) of breaches of limits on the use of cash detected in the course of professional activities.