Skip to main content
DORA Auditor

Information Sharing under DORA

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

DORA's information-sharing pillar (Article 45) enables, but does not mandate, financial entities to exchange cyber threat information and intelligence within trusted communities to strengthen collective resilience.

What can be shared

Indicators of compromise, tactics, techniques and procedures, alerts, and configuration tools, provided the exchange protects confidentiality, complies with data-protection law, and is governed by clear arrangements.

Joining a trusted community, and telling your supervisor

Article 45 does not create a single EU-wide platform: it authorises financial entities to join existing trusted communities and sets the conditions those arrangements must meet. In practice this usually means a sector information-sharing and analysis centre (ISAC), such as the globally active FS-ISAC, or a national CERT-run or supervisor-run exchange, rather than an informal peer channel. Two obligations apply once an entity takes part: the arrangement itself must have rules of conduct that protect business confidentiality and personal data (so shared indicators cannot simply be forwarded outside the group), and the entity must notify its competent authority when its membership is confirmed, and again if it later leaves. Because participation is voluntary rather than required, supervisors generally treat active ISAC membership as one signal of a mature ICT risk-management posture under Article 6 rather than as a standalone compliance box to tick.

The GDPR basis, and the notification duty entities skip

Article 45 does not hand entities a GDPR exemption: indicators of compromise such as IP addresses and attacker email addresses can themselves be personal data, so an entity still needs a documented lawful basis, most often legitimate interest, for what it shares and receives inside an arrangement. Separately, Article 45(3) attaches a procedural duty that is easy to miss: the entity must notify its competent authority once its participation is confirmed, and again if it later leaves. Entities that join FS-ISAC or a national scheme and never make that notification have technically skipped a DORA requirement even though the sharing itself was lawful. Our full walkthrough of Article 45 covers the notification mechanics, the GDPR legitimate-interest assessment, and how to choose between a global ISAC and a national arrangement in more depth.

Frequently asked questions

Is information sharing mandatory under DORA?
Does joining an information-sharing arrangement need to be reported?
Does DORA give threat-intelligence sharing a GDPR exemption?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex