EDPS Opinion 23/2026 on the Proposal for a Council Decision on the signing, on behalf of the European Union, of the additional Protocol to the Warsaw Convention
Opinion 23/2026
on the Proposal for a Council Decision on the signing, on behalf of the European Union, of the additional Protocol to the Warsaw Convention
0
The European Data Protection Supervisor (EDPS) is an independent institution of the EU, responsible under Article 52(2) of Regulation 2018/1725 ‘With respect to the processing of personal data… for ensuring that the fundamental rights and freedoms of natural persons, and in particular their right to data protection, are respected by Union institutions and bodies’, and under Article 52(3)‘… for advising Union institutions and bodies and data subjects on all matters concerning the processing of personal data’.
Wojciech Rafał Wiewiórowski was appointed as Supervisor on 5 December 2019 for a term of five years. The selection procedure for a new EDPS mandate for a term of five years is still ongoing.
Under Article 42(1) of Regulation 2018/1725, the Commission shall ‘following the adoption of proposals for a legislative act, of recommendations or of proposals to the Council pursuant to Article 218 TFEU or when preparing delegated acts or implementing acts, consult the EDPS where there is an impact on the protection of individuals’ rights and freedoms with regard to the processing of personal data’.
This Opinion relates to the Proposal for a Council Decision on the signing, on behalf of the European Union, of the additional Protocol to the Council of Europe Convention on Laundering, Search, Seizure and Confiscation of the Proceeds from Crime and on the Financing of Terrorism .
This Opinion does not preclude any future additional comments or recommendations by the EDPS, in particular if further issues are identified or new information becomes available. Furthermore, this Opinion is without prejudice to any future action that may be taken by the EDPS in the exercise of his powers pursuant to Regulation (EU) 2018/1725.
This Opinion is limited to the provisions of the Proposal that are relevant from a data protection perspective.
Executive Summary
On 13 July 2026, the European Commission issued the Proposal for a Council Decision on the signing, on behalf of the European Union, of the additional Protocol to the Council of Europe Convention on Laundering, Search, Seizure and Confiscation of the Proceeds from Crime and on the Financing of Terrorism (Warsaw Convention).
The Warsaw Convention is an international treaty covering both the prevention and the control of money laundering and the financing of terrorism. The Protocol aims to supplement and modernise the provisions of the Warsaw Convention. The objective of the Proposal is to obtain from the Council of the European Union the authorisation for the Commission to sign the Protocol on behalf of the European Union.
The EDPS recognises that serious and organised crime, including financial crimes and financing of terrorism, pose a significant threat to both security of the EU, as well as the functioning of the EU economy. He supports the efforts to devise new models of co-operation, including in the context of co-operation with third countries through international instruments, provided they are compatible with the EU laws and values.
This Opinion aims to provide advice with a view of ensuring that the level of data protection guaranteed by EU law is not undermined.
In that regard the EDPS positively notes the clear reference in the Protocol to the obligation for all Parties to the Protocol to adopt the measures that are necessary to comply with the applicable data protection legislation and to establish safeguards governing the processing of the information. The EDPS also welcomes that the Protocol provides for the possibility for a Party to refuse to transfer personal data where such data cannot be provided in compliance with its domestic (data protection) legislation; and/or the Party to which the data should be transferred is not bound by the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, as modernised by the protocol amending that convention (unless the receiving Party undertakes to afford such protection to the data as is required by the sending Party). The EDPS additionally welcomes that the Protocol provides for safeguards on security measures, as well as the reference to the principles of necessity and proportionality.
Finally, the EDPS highlights that, while the Warsaw Convention and its Protocol, as a typical cooperation instrument, can entail a legal basis for processing, they do not (and do not purport to) provide the necessary appropriate safeguards to serve as a basis for transfer of personal data. Therefore, when deciding on transfer data to a third country, another basis for transfer under Chapter V of GDPR/EUDPR/LED should always be identified, in order to ensure appropriate data protection safeguards for the transfer of personal data. The EDPS also reminds that any exchange of personal data with authorities of third countries within a joint investigation team still represents a transfer of personal data.
2
Contents
THE EUROPEAN DATA PROTECTION SUPERVISOR,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (‘EUDPR’) , and in particular Article 42(1) thereof,
HAS ADOPTED THE FOLLOWING OPINION:
1. Introduction
1. On 13 July 2026, the European Commission (‘the Commission’) issued the Proposal for a Council Decision on the signing, on behalf of the European Union, of the additional Protocol to the Council of Europe Convention on Laundering, Search, Seizure and Confiscation of the Proceeds from Crime and on the Financing of Terrorism (‘the Proposal’), along with an Annex containing the final text of this additional Protocol (‘the Protocol’).
2. The objective of the Proposal is to obtain from the Council of the European Union (‘the Council’) the authorisation for the Commission to sign the Protocol the on behalf of the European Union. The Commission also intends to submit a proposal for a Council Decision authorising the Commission to conclude the Protocol on behalf of the European Union as well as a proposal for a Council Decision authorising the Commission to conclude the Council of Europe Convention on Laundering, Search, Seizure and Confiscation of the Proceeds from Crime and on the Financing of Terrorism (CETS No. 198) (‘the Warsaw Convention’), on behalf of the European Union, at a later date .
3. The Warsaw Convention, adopted on 16 May 2005, is an international treaty covering both the prevention and the control of money laundering and the financing of terrorism.
4. On 13 June 2024, the Council authorised the Commission to participate, on behalf of the European Union, in the negotiations on the Protocol to the Convention. On 15 May 2026, the Committee of Ministers of the Council of Europe adopted the Protocol and agreed to open it for signature on 14 October 2026.
5. The purpose of the Protocol is to supplement and modernise the provisions of the Warsaw Convention . It contains provisions on confiscation measures; investigative and provisional measures; financial intelligence units; the establishment of asset recovery offices; asset management; principles of international cooperation; investigative assistance; standard forms; return and sharing of property; international cooperation on suspension or withholding of consent for suspicious transactions, accounts and business relationships; international cooperation between asset recovery offices; asset management as management of property frozen, seized or confiscated at the request of another Party; safeguards, training and resources, including safeguards and legal remedies for persons affected by measures set out in the Protocol.
6. The Protocol will enter into force on the first day of the month following the expiration of a period of three months after the date on which five signatories, including at least three Member States of the Council of Europe, have expressed their consent to be bound 7 8 by the Protocol . The EU can sign the Protocol as signatory to the Warsaw Convention .
7. The present Opinion of the EDPS is issued in response to a consultation by the European Commission of 13 July 2026, pursuant to Article 42(1) of EUDPR. The EDPS welcomes the reference to this consultation in Recital 11 of the Proposal. The EDPS regrets, however, that he was not consulted on the Recommendation for a Council Decision authorising the European Commission to participate, on behalf of the European Union, in the negotiations on the Protocol.
2. General remarks
8. The EDPS recognises that serious and organised crime, and in particular financial crime and financing of terrorism, poses a significant threat to both security of the EU, as well as the functioning of the EU economy. A defining characteristic of organised crime is its profit-driven nature: the proceeds generated through illicit activities are often reinvested in further criminal enterprises or used to infiltrate the legitimate economy. Depriving criminals of these illicit profits is therefore essential to the effective fight against organised crime .
9. The EDPS supports the efforts to devise new models of co-operation, including in the context of co-operation with third countries through international instruments, provided they are compatible with the EU laws and values .
10. Pursuant to Article 216(2) of the Treaty of the Functioning of the EU, international agreements concluded by the European Union ‘are binding upon the institutions of the Union and on the Member States’. Moreover, according to the settled case law of the Court of Justice of the European Union (‘CJEU’), international agreements become ‛an integral part of Community law’ from their coming into force and they have primacy over acts of secondary Union legislation .
11. Since the Protocol is a binding international instrument, the EDPS reminds that, in line with the case law of the CJEU, the ‘obligations imposed by an international agreement cannot have the effect of prejudicing the constitutional principles of the EC Treaty, which include the principle that all Community acts must respect fundamental rights, that respect constituting a condition of their lawfulness’ .
12. The EDPS reminds that any interference with the fundamental rights to privacy and data protection guaranteed by Articles 7 and 8 of the Charter of Fundamental Rights of the EU (the ‘Charter’), caused by the application of the Protocol, must fulfil the requirements of Article 52(1) of the Charter .
13. In this context, the EDPS recalls that the CJEU, in Opinion 1/15 on the international agreement between the EU and Canada regarding the transfer of Passenger Name Records (‘PNR’) data to Canada, found that ‘a transfer of personal data from the European Union to a non-member country may take place only if that country ensures a level of protection of fundamental rights and freedoms that is essentially equivalent to that guaranteed within the European Union’ .
14. Against this background, the EDPS considers of paramount importance to ensure that cooperation with third countries under the Protocol does not lead to weakening or otherwise prejudicing the protection of fundamental rights and freedoms of natural persons guaranteed under EU law, in particular their rights to data protection and privacy. The EDPS welcomes, in this regard, that the Protocol recognises the human rights and fundamental freedoms enshrined, in particular, in the Convention for the Protection of Human Rights and Fundamental Freedoms (ETS No. 5) and its protocols, and in the International Covenant on Civil and Political Rights as well as that it takes into account the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108) and its protocols .
15. This Opinion aims to provide advice with a view of ensuring that the level of data protection guaranteed by EU law is not undermined.
3. Relevant safeguards in the Convention
3.1. Applicable data protection legislation and safeguards
16. Articles 9, 12 and 17 of the Protocol provide for possibilities of access by national financial units and asset recovery offices to different information, as well as mechanisms for providing information on frozen, seized and confiscated property.
17. The EDPS recalls that EU law already provides possibilities to access financial information for the purposes of countering money laundering and the financing of terrorism or criminal offences . The EDPS welcomes the clear reference in the Protocol to the obligation for all Parties to the Protocol to adopt the measures that are necessary to comply with the applicable data protection legislation and to establish safeguards governing the processing of the information necessary to achieve the purpose of these articles . The EDPS considers this an important requirement to ensure effective protection of personal data across the Parties to the Protocol.
3.2. Transfers of personal data
18. Given that the Protocol would entail exchange of information (including personal data) between the Parties, thus also between the EU and its Member States and third countries, the EDPS welcomes that Article 19(3) of the Protocol explicitly provides for the possibility for a Party to refuse to transfer personal data obtained as a result of the execution of a request made under the Warsaw Convention or its Protocol where: a. such data cannot be provided in compliance with its domestic legislation; and/or b. the Party to which the data should be transferred is not bound by the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, done at Strasbourg on 28 January 1981, as modernised by the protocol amending that convention (CETS No. 223), done at Strasbourg on 10 October 2018, unless the latter Party undertakes to afford such protection to the data as is required by the former Party.
19. The EDPS considers Article 19(3) as an important safeguard to ensure that personal data should only be transferred to third countries provided an essentially equivalent protection is in place.
20. While positively noting the inclusion of a provision explicitly referring to data protection under point b), the EDPS underlines that the notion “domestic legislation” under point a) should be understood as encompassing both the EU and its Member States’ rules regarding data protection, in particular rules on transfers of personal data to third countries.
21. Such transfers are primarily regulated by Regulation (EU) 2016/679 (the ‘GDPR’), Directive (EU) 2016/680 (the ‘LED’) and the EUDPR, in particular by their Chapter V.
22. To ensure that the level of protection of natural persons guaranteed by the EU law is not undermined, Chapter V lays down specific conditions for the transfer of personal data to third countries.
23. In the absence of an adequacy decision issued by the Commission to enable personal data to be transferred to a given third country, transfers of personal data can still take place if appropriate data protection safeguards are provided in a legally binding instrument .
24. As the European Data Protection Board (‘the EDPB’) explains in its Guidelines 2/2020 and Guidelines 01/2023 , it is important to clarify from the outset what might constitute a legally binding instrument. First, it should be distinguished between the mere existence of an agreement on cooperation between Parties that entails the exchange of personal data, on the one hand and, on the other hand, the existence of an agreement that regulates the processing of personal data and adduces the necessary safeguards. It is not sufficient to have an agreement in place which provides for a legal basis for the cooperation between the Parties and the inherent data exchanges. Such an agreement does not qualify as a lawful mechanism for the international transfer of personal data under Article 46(2)(a) GDPR, Article 48(2)(a) EUDPR and Article 37(1)(a) LED, unless it contains appropriate data protection safeguards.
25. In light of the above, the EDPS emphasises that, while the Warsaw Convention and its Protocol, as a typical cooperation instrument, can entail a legal basis for processing in the sense of Article 6 GDPR, Article 5 EUDPR or Article 8 LED, they do not (and do not purport to) provide the necessary appropriate safeguards to serve as a basis for transfer within the meaning of Article 46(2)(a) GDPR, Article 48(2)(a) EUDPR and Article 37(1)(a) LED. Therefore, when deciding on a transfer to a third country, another basis for transfer under Chapter V of GDPR/EUDPR/LED must be identified to ensure appropriate data protection safeguards for the transfer of personal data.
26. The EDPS also notes the additional safeguard provided by paragraph 5 of Article 19 of the Protocol, providing for any Party, by a declaration addressed to the Secretary General of the Council of Europe, to require that, within the framework of procedures for which it could have refused or limited the transmission or the use of personal data in accordance with the provisions of the Convention or its Protocol, personal data which it has transmitted to another Party must not be used by the latter for the purposes of paragraph 1 of this Article unless with its previous consent.
27. For cases where the EU or a Member State decide not to use the possibility offered by the Convention or its Protocol to refuse the transfer or limit the use of the transferred data, the EDPS considers the requirement of prior consent of the Party for the use of those personal data transmitted to another Party remains an important safeguard for ensuring the control of the EU and its Member States over the transferred personal data.
28. The EDPS therefore suggests the EU and its Member States to make the declaration from Article 19(5), as provided for by Article 43 of the Protocol.
29. Finally, the EDPS notes that Article 19(2) of the Protocol enables transferred data to be used for any other purpose (other than the one for which it was transferred in the first place), if prior consent to that effect is given by the Party from which the data have been transferred or the data subject. When it comes to the consent of the data subject, the EDPS recalls that it must be ensured, in line with Article 4(11) GDPR, Article 3(15) EUDPR as well as Article 5(2) of the Convention 108 +, that any such consent be free, specific, informed and unambiguous.
30. Furthermore, the EDPS reminds that if the transfer of data under Article 19 of the Protocol would be carried out for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, pursuant to Recital 35 LED, ‘the consent of the data subject, as defined in Regulation (EU) 2016/679, should not provide a legal ground for processing personal data by competent authorities’. In such cases, in line with the last sentence of Recital 35 LED, the consent of the data subject under Article 19(2) of the Protocol should be considered as an additional safeguard, not as a legal ground for processing.
3.3. Safeguards and remedies
31. Article 31 provides that each Party must ensure that the establishment, implementation and application of the powers and procedures provided for in the Protocol are subject to the conditions and safeguards provided for under its domestic law, which shall ensure adequate protection of human rights and freedoms, and incorporate the principles of necessity and proportionality.
32. Privacy and data protection are fundamental rights protected under the Charter of Fundamental Rights of the European Union (‘the Charter’) and necessity and proportionality are foundational principles in EU data protection law. They serve as limits on the collection, use, and retention of personal data and ensure that interferences with the rights to privacy and data protection are justified. They derive not only from data protection legislation (secondary law) but also from EU primary law, particularly Articles 7, 8, and 52(1) of the Charter.
33. The EDPS therefore welcomes the obligation to provide for conditions and safeguards to ensure adequate protection of human rights and freedoms, as well as the references to the principles of necessity and proportionality.
34. Moreover, the EDPS welcomes the reference in Article 31(2) to the right to an effective legal remedy and to a fair trial, as well as to the rights of defence. As specified in the Explanatory Memorandum of the Proposal, “[c]ertain fundamental rights and freedoms enshrined in the Charter of Fundamental Rights of the European Union (‘the Charter’) are of particular relevance. This includes the right to property (Article 17), the right to a fair trial and an effective remedy (Article 47), the presumption of innocence and right to defence (Article 48) as well as the right to the protection of personal data (Article 8)” . The EDPS notes that data subject’s rights, such as the right to access personal data relating to them, can be functional and closely linked to due process rights referred to in the Protocol .
3.4. Security measures
35. Article 33 requires each Party to ensure that asset recovery offices undertake all necessary measures, including security measures, to ensure that information processed under Articles 9, 12, 17 and 29 of this Protocol is not accessed by unauthorised persons. Moreover, the Parties are obliged to take the necessary measures to ensure that communication between asset recovery offices is carried out through secure channels.
36. The EDPS emphasises that security measures should govern how personal data will be protected throughout their processing lifecycle. These measures should ensure confidentiality, integrity, and availability of personal data and to reduce the risk of unauthorised access, loss, alteration, or disclosure .
4. Joint investigation teams for the recovery of property liable to confiscation
37. The EDPS notes that under Article 23 of the Protocol, the competent authorities of Parties are enabled to establish and operate a joint investigation team in their territories for the purpose of the recovery of property liable to confiscation pursuant to the Warsaw Convention and the Protocol.
38. While recognising the benefits of such joint investigation teams, the EDPS reminds that any exchange of personal data with authorities of third countries within such a team still represents a transfer of personal data and should therefore meet the requirements for such transfers .
5. Conclusions
39. In light of the above, the EDPS makes the following recommendations: (1) Before transferring personal data to a third country that is a State Party to the Convention and its Protocol, the EU and Member States’ competent authorities should carefully assess whether the conditions of Chapter V of the GDPR/EUDPR/ LED are fulfilled as the Convention and its Protocol do not provide the necessary appropriate safeguards to serve as a basis for transfer within the meaning of Article 46(2)(a) GDPR, Article 48(2)(a) EUDPR and Article 37(1)(a) LED. (2) Where appropriate, EU and Member States’ competent authorities should make use of the grounds to refuse cooperation, in line with Article 19(3) of the Protocol. (3) For the EU and its Member States to make the declaration from Article 19(5), as provided for by Article 43 of the Protocol. Brussels, 10 September 2026 (e-signed) Wojciech Rafał WIEWIÓROWSKI 11
Fotnoter
- 1 COM(2026) 367 final. 1
- 2 OJ L 295, 21.11.2018, p. 39. 3 COM(2026) 367 final. 4 Idem, p. 1. The EU signed the Warsaw Convention on 2 April 2009 but has not ratified it yet. 6 See Article 1 of the Protocol. 4
- 7 See Article 38(1) of the Protocol. 8 See Article 37 of the Protocol. 9 See COM(2026) 367 final, p. 1. 10 See in particular para. 32 of this Opinion. 11 Judgment of the Court of Justice of 30 April 1974, R. & V. Haegeman v. Belgian State, C-181/73, ECLI:EU:C:1974:41, para. 5. 12 Intertanko and Others Judgment of the Court of Justice of 3 June 2008, , C-308/06, ECLI:EU:C:2008:312, para. 42. 5
- 13 Judgment of the Court of Justice of 3 September 2008, Kadi and Al Barakaat International Foundation v. Council, C-402/05 P and C-415/05, ECLI:EU:C:2008:461, para. 285. 14 See also the EDPS Guidelines on assessing the proportionality of measures that limit the fundamental rights to privacy and to the protection of personal data, issued on 19 December 2019. 15 Opinion of the Court of Justice of 26 July 2017, PNR Canada, ECLI:EU:C:2017:592, para. 214. 16 See the Preamble of the Protocol. 6
- 17 See in particular Article 4 (Access to and searches of bank account information by competent authorities) of Directive (EU) 2019/1153 of the European Parliament and of the Council of 20 June 2019 laying down rules facilitating the use of financial and other information for the prevention, detection, investigation or prosecution of certain criminal offences; Article 6 (Access to information) and 27 (Efficient management of frozen and confiscated property) of Directive (EU) 2024/1260 of the European Parliament and of the Council; for AML/CFT purposes, access to financial information is provided in particular by Regulation (EU) 2024/1624 and by Directive (EU) 2024/1640. 18 See para. 3 of Articles 9, 12 and 17 of the Protocol. 19 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (Text with EEA relevance) (OJ L 119, 4.5.2016, pp. 1). 20 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89). 7
- 21 Article 46(1) GDPR, Article 48(1) EUDPR and Article 37(1)(a) LED. 22 Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non- EEA public authorities and bodies, adopted on 15 December 2020. 23 Guidelines 01/2023 on Article 37 Law Enforcement Directive, adopted on 19 June 2024. 8
- 24 Explanatory memorandum, p. 7. 9
- 25 See for instance Judgment of the European Court of Human Rights of 8 January 2026, Ferrieri and Bonassisa v. Italy, § 105, “The Court concludes that even if there could be said to be a general legal basis for the impugned measures in Italian law, that law does not meet the quality requirements imposed under the Convention. In particular, even taking into account the Contracting States’ broad margin of appreciation in respect of bank data, that is to say purely financial information (see paragraph 58 above), and the importance of the aim of similar measures in the field of taxation (see paragraph 73 above), the Court considers that the domestic legal framework afforded the domestic authorities unfettered discretion with regard to both the conditions in which the contested measures could be implemented and the scope of those measures. At the same time, that framework did not provide sufficient procedural safeguards, as the contested measures were not subjected to a judicial or independent review. Therefore, the domestic legal framework did not provide the applicants with the minimum degree of protection to which they were entitled under the Convention. The Court finds that in these circumstances, it cannot be said that the interferences in question were “in accordance with the law” as required by Article 8 § 2 of the Convention. 106. There has accordingly been a violation of Article 8 of the Convention.” [emphasis added] 26 On the importance of data security, see Judgment of the Court of Justice of 8 April 2014, Joined Cases, Digital Rights Ireland and Seitlinger and Others, C-293/12 and C-594/12, ECLI:EU:C:2014:23, para 40. 27 For more details, see Section 3.2. of this Opinion. 10