Opinion 6/2026 on the Commission Proposal for a Regulation as regards the further development of capital market integration and supervision within the Union
on the Regulation on the further development of capital market integration and supervision within the Union
0
The European Data Protection Supervisor (EDPS) is an independent institution of the EU, responsible under Article 52(2) of Regulation 2018/1725 ‘With respect to the processing of personal data… for ensuring that the fundamental rights and freedoms of natural persons, and in particular their right to data protection, are respected by Union institutions and bodies’, and under Article 52(3)‘… for advising Union institutions and bodies and data subjects on all matters concerning the processing of personal data’.
Wojciech Rafał Wiewiórowski was appointed as Supervisor on 5 December 2019 for a term of five years. The selection procedure for a new EDPS mandate for a term of five years is still ongoing.
Under Article 42(1) of Regulation 2018/1725, the Commission shall ‘following the adoption of proposals for a legislative act, of recommendations or of proposals to the Council pursuant to Article 218 TFEU or when preparing delegated acts or implementing acts, consult the EDPS where there is an impact on the protection of individuals’ rights and freedoms with regard to the processing of personal data’.
This Opinion relates to the Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) No 1095/2010, No 648/2012, No 600/2014, No 909/2014, 2015/2365, 2019/1156, 2021/23, 2022/858, 2023/1114, No 1060/2009, 2016/1011, 2017/2402, 2023/2631 and 2024/3005 as regards the further development of capital market integration and supervision within the Union. This Opinion does not preclude any future additional comments or recommendations by the EDPS, in particular if further issues are identified or new information becomes available. Furthermore, this Opinion is without prejudice to any future action that may be taken by the EDPS in the exercise of his powers pursuant to Regulation (EU) 2018/1725. This Opinion is limited to the provisions of the Proposal that are relevant from a data protection perspective.
Executive Summary
On 4 December 2025, the European Commission adopted the Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) No 1095/2010, No 648/2012, No 600/2014, No 909/2014, 2015/2365, 2019/1156, 2021/23, 2022/858, 2023/1114, No 1060/2009, 2016/1011, 2017/2402, 2023/2631 and 2024/3005 as regards the further development of capital market integration and supervision within the Union.
The EDPS welcomes the objectives of the Proposal, in particular in relation to the centralisation of supervision of EU laws at EU level (in this case, within the European Securities and Markets Authority). The EDPS recalls that objectives related to regulatory simplification are not incompatible - and, in fact, should be pursued together with - robust protections for individuals in the EU, as investors and as data subjects under EU data protection legislation.
The EDPS positively notes that the Proposal acknowledges that the information collected by ESMA may include personal data only if it is relevant and necessary for the exercise of ESMA’s tasks, in compliance with the applicable EU rules on the protection of personal data. As the Proposal would empower ESMA to enter into administrative arrangements and arrangements for the exchange of information with third countries and international organisations, the EDPS recalls that he should issue an authorisation to ESMA under the EUDPR before ESMA can enter into such administrative arrangements or agreements based on Article 48(3)(b) EUDPR.
The Proposal would require ESMA to set up a platform to facilitate the collection, storage, access to and processing of information as provided under the ESMA Regulation and other Union acts mandating the use of this platform. The EDPS understands that ESMA would process personal data in the platform as a processor under EU data protection law, but notes that it is not clear who it would be processing personal data on behalf of. Therefore, the EDPS recommends clarifying the role and obligations under EU data protection law of ESMA and of the entities submitting and accessing information in the data platform.
The EDPS recalls that information submitted via the European Single Access Point should only contain personal data where this is required by Union or national law or constitutes a necessary element of the information about the entity’s economic activities. When accessing it, ESMA must comply with specific obligations stemming from Union law. The EDPS recommends recalling the relevant requirements in a Recital of the Proposal.
Lastly, the EDPS considers it important to empower the Commission to lay down, via delegated or implementing act, requirements for obliged entities that must assess and report to ESMA on the good repute of the persons mentioned in the regulations that would be amended by the Proposal, including by specifying the personal data to be processed in that context.
2
THE EUROPEAN DATA PROTECTION SUPERVISOR,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (‘EUDPR’) , and in particular Article 42(1) thereof,
HAS ADOPTED THE FOLLOWING OPINION:
1. Introduction
1. On 4 December 2025, the European Commission issued the Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) No 1095/2010 (‘ESMA Regulation’) , No 648/2012 (‘EMIR’) , No 600/2014 (‘MiFIR’) , No 909/2014 (‘CSDR’) , 2015/2365 (‘SFTR’) , 2019/1156 (‘CBDR’) , 2021/23 (‘CCPRRR’) , 2022/858 (‘DLTPR’) , 2023/1114 (‘MiCA’) , No 1060/2009 (‘CRA Regulation’) , 2016/1011 (‘Benchmarks 4
2. The objective of the Proposal is to remove barriers stemming from the lack of harmonisation of EU rules and supervisory approaches resulting in the fragmentation and underperformance of EU capital markets. The Proposal aims to integrate EU capital markets and improve the functioning of the EU single market in financial services for the benefit of investors, businesses and the wider EU economy. This would entail making supervision more effective, conducive to cross-border activities, and responsive to emerging risks, by strengthening and increasing the supervisory convergence tools of the European Securities and Markets Authority (’ESMA’). The Proposal would also adapt the existing financial services rulebook to accommodate new technologies, like Distributed Ledger Technologies (‘DLT’), thereby implementing the Commission’s Digital Finance Strategy .
3. The Proposal fits within the goal of pursuing regulatory simplification, to make crossborder activities more cost-effective. This would be achieved by moving certain provisions from directives to regulations; narrowing the scope for nationally imposed measures; refining empowerments for the adoption of delegated and implementing acts; and streamlining supervisory arrangements.
4. The present Opinion of the EDPS is issued in response to a consultation by the European Commission of 4 December 2025, pursuant to Article 42(1) of EUDPR. The EDPS welcomes the reference to this consultation in Recital 108 of the Proposal. In this regard, the EDPS also positively notes that he was already previously informally consulted pursuant to recital 60 of EUDPR.
5. The EDPS recalls that he was consulted and issued Opinions on some on the legislative proposals that led to the adoption of the Regulations that the Proposal would amend.
2. General remarks
6. The EDPS welcomes the objectives of the Proposal, in particular in relation to centralizing supervision of EU laws at EU level (in this case, within ESMA). The EDPS recalls that objectives related to regulatory simplification are not incompatible - and, in fact, should be pursued together with - robust protections for individuals in the EU, as investors and as data subjects under EU data protection legislation.
7. The EDPS notes that Regulation (EU) 2016/679 (‘GDPR’) would apply when personal data would be processed in the context of the Proposal. There would also be cases where EU bodies covered by the Proposal such as ESMA would be subject to the EUDPR (e.g., when assisting a national competent authority in carrying out an on-site inspection). The EDPS would thus recommend including a reference to the application of both the GDPR and EUDPR in a Recital of the Proposal.
3. ESMA’s supervisory tasks
8. Article 1(26) of the Proposal would add a new Chapter IIa to the ESMA Regulation, to define the powers of ESMA over financial market participants under ESMA’s supervision. Within that Chapter, Articles 39b, c, and d would specify the information that ESMA may request from market participants and obtain during investigations and on-site inspections.
9. Article 8(22) of the Proposal would insert a new Chapter 6 in Title VII of the DLTPR, thereby granting supervisory responsibilities, powers and competences to ESMA with respect to crypto-asset service providers. Similar amendments are foreseen under the other frameworks that would be amended by the Proposal to grant supervisory powers to ESMA over the obliged entities under those frameworks.
10. The EDPS welcomes that Recital 13 of the Proposal clarifies that the information collected by ESMA may include personal data, to the extent that it is relevant and necessary for the exercise of ESMA’s tasks, and that the processing of such data should comply with the applicable EU rules on the protection of personal data, in particular the principles of necessity, proportionality and purpose limitation.
11. The EDPS welcomes that new Article 39i of the ESMA Regulation would limit the issuance of public statements by ESMA identifying the person responsible for a breach where this publication is deemed necessary by ESMA to protect the stability of the financial markets or to ensure the effective enforcement of the ESMA Regulation, provided that the publication is limited to what is strictly necessary to ensure those objectives and properly justified. In the same vein, the EDPS welcomes that Article 39k would not entitle ESMA to disclose personal data when publishing fines and periodic penalty payments.
12. Article 9(22) of the Proposal, amending Regulation (EU) 2023/1114 on crypto-assets, would introduce Article 138d allowing ESMA to conclude administrative agreements on the exchange of information with third countries in relation to supervisory responsibilities, powers and competences of ESMA with respect to crypto-asset service providers. The EDPS welcomes that the information disclosed would be subject to professional secrecy and the reference to the fact that ESMA shall apply the EUDPR with regards to transfers of personal data to third countries.
13. The EDPS also welcomes that Article 1(23) of the Proposal would empower ESMA to enter into administrative arrangements with third country regulatory and supervisory authorities and international organisations for the purpose of fostering international supervisory cooperation, including through the exchange of information and/or staff. The EDPS notes that such an arrangement shall include provisions governing professional secrecy and take due account of applicable data protection legislation.
14. However, the EDPS recommends clarifying in Article 1(23) of the Proposal that the ESMA shall apply the EUDPR in case personal data is transferred under the administrative arrangement to third countries, also with a view to ensure consistency with the provisions of Article 9(22) of the Proposal. It is also recommended to make clear, both under Article 1(23) and Article 9(22) of the Proposal, that a prior authorisation of the EDPS should be obtained by ESMA before the signature of the administrative arrangement or agreement in case the transfer is based on Article 48(3)(b) EUDPR.
4. Data platform
15. Article 1(25) of the Proposal would impose an obligation on ESMA to set up a platform to facilitate the collection, storage, access to and processing of information as provided under the ESMA Regulation and other Union acts mandating the use of this platform.
16. According to the Proposal, this data platform would contribute to high-quality data governance consistent with ‘FAIR’ principles (Findable, Accessible, Interoperable, Reusable) and include the supervisory technology and other tools to enhance analysis and monitoring capabilities of the relevant authorities and information.
17. Recital 12 of the Proposal provides that the ‘Agency’ (which the EDPS presumes refers to the ‘Authority’, i.e., ESMA) would be acting a processor of personal data. In that capacity, ESMA would be expected to implement appropriate technical and organisational measures to ensure the security, availability, maintenance and development of the software and IT infrastructure of the platform. ESMA should also limit its processing of personal data in the platform to what is necessary to facilitate the collection, storage, access to and processing of the information submitted in accordance with the Union acts mentioned in paragraph 12 of this Opinion.
18. The EDPS understands that ESMA would process personal data in the platform as a processor under EU data protection law, but notes that it is not clear who it would be processing personal data on behalf of. Therefore, the EDPS recommends clarifying the role and obligations under EU data protection law of ESMA and of the entities submitting and accessing information in the data platform in Article 1(25) of the Proposal, in line with Article 3(12) EUDPR for the role of processor and Article 3(8) for the role of controller. The EDPS also recommends clarifying the roles and responsibilities of entities submitting and accessing information in the data platform under the GDPR and the EUDPR.
5. European Single Access Point
19. Article 3(17) of the Proposal would replace Article 23a of the MiFIR in what concerns accessibility of information via the European Single Access Point (‘ESAP’) established under Regulation (EU) 2023/2859 .
20. The EDPS notes that the information transmitted via the ESAP would need to indicate whether it contains personal data. The EDPS recalls that entities submitting information via the ESAP should remove personal data therefrom, except where the personal data are required by Union or national law or constitute a necessary element of the information about the entity’s economic activities.
21. In addition to its obligations under the EUDPR, the EDPS recalls that ESMA must also comply with the obligations laid down in Article 11(3) of Regulation (EU) 2023/2859 in relation to personal data it accesses via the ESAP. For the sake of clarity, the EDPS recommends recalling these obligations by way of a recital.
6. Good repute
22. Article 2(15) of the Proposal would add Articles 22a to 22e to the EMIR, thereby conferring powers to the ESMA over significant central counterparties (‘CCPs’). Article 22c(5) would mandate ESMA to refuse or subsequently withdraw the appointment of the person or persons referred to in Article 27 of the EMIR if it is not satisfied that the person is of sufficiently good repute.
23. The EDPS recommends empowering the Commission to lay down, via a delegated or implementing act, requirements for CCPs to assess and report to ESMA on the good repute of the persons referred to in Article 27 of the EMIR, including by specifying the personal data to be processed in that context. While such an empowerment already exists under MiCA , an equivalent empowerment should be granted to the Commission in relation to the requirements stemming from: a. novel Article 2d(1) of the MiFIR as proposed by Article 3(3) of the Proposal in relation to the members of the management body of a market operator and the members or participants of investment firms; c. the amended version of Article 5(5) of the DLTPR as proposed under Article 8(6) of the Proposal in relation to participants in DLT settlement systems.
7. Conclusions
24. In light of the above, the EDPS makes the following recommendations: (1) to include a reference to the application of the GDPR and EUDPR in a Recital of the Proposal; (2) to clarify in Article 1(23) of the Proposal that ESMA shall apply the EUDPR in case personal data is transferred under the administrative arrangement to third countries; (3) to clarify that, both under Article 1(23) and Article 9(22) of the Proposal, a prior authorisation of the EDPS should be obtained by ESMA before the signature of the administrative arrangement or agreement in case the transfer is based on Article 48(3)(b) EUDPR; (4) to clarify the roles and responsibilities under the GDPR and the EUDPR of ESMA and of the entities submitting and accessing personal data in the data platform proposed under Article 1(25) of the Proposal; (5) to recall the obligations of ESMA and of the entities submitting information via the ESAP under the EUDPR and Regulation (EU) 2023/2859 in relation to personal data they access and submit via the European Single Access Point; and (6) to empower the Commission to lay down via a delegated or implementing act requirements for obliged entities under the Union acts that would be amended by the Proposal to assess and report to ESMA on the good repute of the persons mentioned in those acts, including by specifying the personal data to be processed under those acts. Brussels, 29 January 2026 (e-signed) Wojciech Rafał WIEWIÓROWSKI
Fotnoter
- 1 COM(2025) 943 final. 1
- OJ L 295, 21.11.2018, p. 39. Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/77/EC, OJ L 331, 15.12.2010, pp. 84–119. Regulation (EU) No 648/2012 of the European Parliament and of the Council of 4 July 2012 on OTC derivatives, central counterparties and trade repositories, OJ L 201, 27.7.2012, pp. 1–59. Regulation (EU) No 600/2014 of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Regulation (EU) No 648/2012, OJ L 173, 12.6.2014, pp. 84–148. Regulation (EU) No 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No 236/2012, OJ L 257, 28.8.2014, pp. 1–72. Regulation (EU) 2015/2365 of the European Parliament and of the Council of 25 November 2015 on transparency of securities financing transactions and of reuse and amending Regulation (EU) No 648/2012, OJ L 337, 23.12.2015, pp. 1–34. Regulation (EU) 2019/1156 of the European Parliament and of the Council of 20 June 2019 on facilitating cross-border distribution of collective investment undertakings and amending Regulations (EU) No 345/2013, (EU) No 346/2013 and (EU) No 1286/2014, OJ L 188, 12.7.2019, pp. 55–66. Regulation (EU) 2021/23 of the European Parliament and of the Council of 16 December 2020 on a framework for the recovery and resolution of central counterparties and amending Regulations (EU) No 1095/2010, (EU) No 648/2012, (EU) No 600/2014, (EU) No 806/2014 and (EU) 2015/2365 and Directives 2002/47/EC, 2004/25/EC, 2007/36/EC, 2014/59/EU and (EU) 2017/1132, OJ L 22, 22.1.2021, pp. 1–102. Regulation (EU) 2022/858 of the European Parliament and of the Council of 30 May 2022 on a pilot regime for market infrastructures based on distributed ledger technology, and amending Regulations (EU) No 600/2014 and (EU) No 909/2014 and Directive 2014/65/EU, OJ L 151, 2.6.2022, pp. 1–33. Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937, OJ L 150, 9.6.2023, pp. 40–205. Regulation (EC) No 1060/2009 of the European Parliament and of the Council of 16 September 2009 on credit rating agencies, OJ L 302, 17.11.2009, pp. 1–31.
- 13 14 15 Regulation’) , 2017/2402 (‘Securitisation Regulation’) , 2023/2631 (‘EGBR’) and 2024/3005 (‘ESGRR’) as regards the further development of capital market integration and supervision within the Union (‘the Proposal’).
- 13 Regulation (EU) 2016/1011 of the European Parliament and of the Council of 8 June 2016 on indices used as benchmarks in financial instruments and financial contracts or to measure the performance of investment funds and amending Directives 2008/48/EC and 2014/17/EU and Regulation (EU) No 596/2014, OJ L 171, 29.6.2016, pp. 1–65. 14 Regulation (EU) 2017/2402 of the European Parliament and of the Council of 12 December 2017 laying down a general framework for securitisation and creating a specific framework for simple, transparent and standardised securitisation, and amending Directives 2009/65/EC, 2009/138/EC and 2011/61/EU and Regulations (EC) No 1060/2009 and (EU) No 648/2012, OJ L 347, 28.12.2017, pp. 35–80. 15 Regulation (EU) 2023/2631 of the European Parliament and of the Council of 22 November 2023 on European Green Bonds and optional disclosures for bonds marketed as environmentally sustainable and for sustainability-linked bonds (OJ L, 2023/2631, 30.11.2023, ELI: http://data.europa.eu/eli/reg/2023/2631/oj). 16 Regulation (EU) 2024/3005 of the European Parliament and of the Council of 27 November 2024 on the transparency and integrity of Environmental, Social and Governance (ESG) rating activities, and amending Regulations (EU) 2019/2088 and (EU) 2023/2859 (OJ L, 2024/3005, 12.12.2024, ELI: http://data.europa.eu/eli/reg/2024/3005/oj). 17 COM(2025) 943 final. 18 Explanatory Memorandum of the draft Proposal, p. 2 and 3. 19 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52020DC0591. 20 Explanatory Memorandum of the draft Proposal, p. 3. 21 See, for example, and EDPS Opinion 6/2021 on the Proposal for a Pilot Regime for Market Infrastructures based on Distributed Ledger Technology, issued on 23 April 2021, and EDPS Opinion 9/2021 on the Proposal for a Regulation on Markets in Cryptoassets, and amending Directive (EU) 2019/1937, issued on 24 June 2021. 5
- 22 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1). 6
- 23 Publication of personal data related to persons who have been sanctioned for an infringement under the draft Proposal should only occur in duly justified exceptional cases, as making such types of personal data available to the general public could be considered as a serious interference with their fundamental rights enshrined in Articles 7 and 8 of the Charter. 24 See in this regard also the EDPS Decision concerning the use of the IOSCO-ESMA Administrative Arrangement by the European Securities and Markets Authority, of 13 March 2019, as well as EDPS Decision on the EDPS Model Administrative Arrangement for Transfers of Personal Data under Regulation (EU) 2018/1725 from European Union Institutions, Bodies, Offices and Agencies to International Organisations (Case 2020-0809), of 31 July 2024. 25 This would include Article 6(11) and (15) of the Proposal, in relation to the exchange of information and documentation between competent authorities in relation to marketing notifications and de-notifications of Alternative Investment Funds (AIFs) and Undertakings for Collective Investment in Transferable Securities). 26 Recital 11 of the Proposal. 7
- 27 See, as a good example, Article 6 of Commission Implementing Regulation (EU) 2024/607 of 15 February 2024 on the practical and operational arrangements for the functioning of the information sharing system pursuant to Regulation (EU) 2022/2065 of the European Parliament and of the Council (Digital Services Act) (OJ L, 2024/607, 16.2.2024, ELI: http://data.europa.eu/eli/reg_impl/2024/607/oj). 28 Regulation (EU) 2023/2859 of the European Parliament and of the Council of 13 December 2023 establishing a European single access point providing centralised access to publicly available information of relevance to financial services, capital markets and sustainability, OJ L, 2023/2859, 20.12.2023, ELI: http://data.europa.eu/eli/reg/2023/2859/oj 29 Article 3(1)(f) and (5) of Regulation (EU) 2023/2859. 8