Skip to main content
DORA Auditor

guide

DORA Article 45 Information Sharing: A Practical Guide

DORA Article 45 allows cyber threat intel sharing, but only within trusted arrangements with a notification duty and GDPR basis. Updated August 2026.

DORA Auditor Editorial Team·Published

DORA's Article 45 does not force financial entities to share cyber threat intelligence, it removes the legal doubt around doing so. Entities may exchange indicators of compromise, attack tactics, and threat data within a trusted arrangement, provided the arrangement has rules protecting confidentiality and personal data, and the entity tells its competent authority when it joins or leaves.

What Article 45 actually permits

Article 45 sits in DORA's information-sharing pillar, the smallest and least prescriptive of the five. Unlike the ICT risk-management framework or incident reporting, Article 45 does not create a standalone obligation to build anything. Instead it authorises a specific activity: financial entities may exchange amongst themselves cyber threat information and intelligence, including indicators of compromise, tactics, techniques and procedures, security alerts, and configuration tools, to strengthen their own and the sector's collective resilience.

Before DORA, this kind of sharing sat in a grey area. Passing an attacker's IP address, a malware hash, or an email header between two banks could touch GDPR, since some of that data qualifies as personal data, and it could also raise competition-law questions if handled carelessly. Article 45 does not disapply either body of law, but it gives entities a clear framework for doing this kind of sharing lawfully, which is why supervisors and industry bodies alike describe it as enabling rather than mandating participation.

What can be shared, and what the arrangement must guarantee

Article 45(2) is specific about scope. In scope: indicators of compromise, tactics, techniques and procedures, cyber security alerts, and configuration tools, to the extent that sharing improves detection, response, or recovery capabilities. The arrangement itself, not just each member's own conduct, has to meet two conditions before any of that can happen:

  1. Confidentiality and data protection. The arrangement must have rules of conduct in full respect of business confidentiality and the protection of personal data under the GDPR, so information shared inside the group cannot simply leak or be forwarded outside it.
  2. Competition-law compliance. Sharing threat data between competitors is still subject to EU competition rules, so the arrangement needs safeguards that keep it limited to security information and away from anything that looks like coordination on price or strategy.

This is the detail that trips up entities that assume "voluntary" means "informal." An ad hoc group chat between security teams at two banks is not what Article 45 has in mind. A financial entity that wants the legal protection Article 45 offers needs a documented arrangement, not a personal relationship between analysts.

Joining a recognised arrangement: FS-ISAC and the national alternatives

Most financial entities do not build a threat-sharing arrangement from scratch. In practice, entities join an existing structure that already satisfies Article 45's conditions. The most widely used cross-border option is FS-ISAC, the global Financial Services Information Sharing and Analysis Centre, which publishes guidance specifically mapping its membership offerings to Article 45's requirements. Several member states also run their own bank-CERT or supervisor-coordinated arrangements, and national computer emergency response teams frequently operate sector channels that smaller entities join instead of, or alongside, a global ISAC.

Which option makes sense depends on scale. A cross-border banking group with operations in several EU countries usually gets more value from a global ISAC that aggregates threat data across jurisdictions and sectors. A domestically focused payment institution or smaller investment firm may be better served by a national arrangement with lower membership overhead. Some crypto-asset service providers now entering DORA's scope have less established sector-specific channels and often start with the same cross-border ISACs banks use, since crypto-native threat-sharing arrangements are still maturing.

The GDPR problem hiding inside "voluntary" sharing

Article 45 does not create a new GDPR exemption. Indicators of compromise such as IP addresses, attacker email addresses, and file hashes can qualify as personal data, and sharing them still needs a lawful basis under the GDPR, most commonly legitimate interest under Article 6(1)(f). That means the arrangement, and each member's participation in it, should be backed by a documented legitimate-interest assessment covering what is shared, why, with whom, and what safeguards apply, not just a reference to Article 45 as if it were self-executing legal cover. Entities that treat threat-intel sharing as a pure security decision, without looping in data protection, are the ones most likely to discover a gap when a supervisor or a data subject asks how the sharing was justified.

The notification duty in Article 45(3) that gets missed

Article 45(3) attaches a procedural obligation that is easy to overlook next to the more prominent parts of the article: a financial entity must notify its competent authority once its participation in an information-sharing arrangement is confirmed, and again if it ceases to be a member. This is not optional paperwork. It gives supervisors visibility into which entities are participating in collective threat-intelligence efforts, which feeds into the broader supervisory picture built through incident reporting and the register of information. Entities that join FS-ISAC or a national scheme and never tell their supervisor have technically skipped a DORA requirement even though the sharing itself was lawful. General DORA enforcement, covered in our penalties overview, applies to the regulation as a whole, so a missed notification is not automatically ignored just because it looks minor next to a major-incident reporting failure.

Where Article 45 fits in the wider DORA picture

Information sharing is the pillar most directly connected to the other four. Threat intelligence received through an Article 45 arrangement feeds detection and response inside the ICT risk-management framework, can sharpen how quickly an entity recognises and classifies a major incident, and often informs the scenarios used in resilience testing. None of that makes participation mandatory. DORA deliberately leaves Article 45 as an enabling provision, in line with the overall principle of proportionality that runs through the regulation, so a small entity that judges the overhead is not worth it for its risk profile is not in breach for staying out. What is not optional is getting the mechanics right for entities that do join: a real arrangement with rules of conduct, a GDPR basis for what gets shared, and the Article 45(3) notification to the supervisor.

Practical steps before joining an arrangement

  • Confirm the arrangement itself is documented, with rules of conduct covering confidentiality, data protection, and competition-law safeguards, before treating participation as Article 45-compliant.
  • Get a GDPR legitimate-interest assessment in writing for what your entity will share and receive, rather than assuming Article 45 supplies its own legal basis.
  • Calendar the Article 45(3) notification to your competent authority both on joining and on any future exit, and keep evidence of both filings.
  • Decide global versus national based on your entity's footprint: a single-country institution rarely needs the overhead of a global ISAC that a cross-border group would use.
  • Check the wider framework is ready to use the intelligence, since threat data an entity cannot act on operationally has limited value; a DORA readiness assessment or gap assessment can confirm the detection and response capacity is there to receive it.

Frequently asked questions

Does DORA require financial entities to share cyber threat information?
What can be shared under a DORA Article 45 arrangement?
Do financial entities need to notify their supervisor about information sharing?
Does GDPR still apply to threat intelligence shared under Article 45?
How do financial entities usually join an Article 45 arrangement?
Can crypto-asset service providers join DORA information-sharing arrangements?

Sources

Last updated: 17 August 2026.

#information-sharing#article-45#cyber-threat-intelligence#gdpr

More from the blog