Information Sharing under DORA
DORA's information-sharing pillar (Article 45) enables, but does not mandate, financial entities to exchange cyber threat information and intelligence within trusted communities to strengthen collective resilience.
What can be shared
Indicators of compromise, tactics, techniques and procedures, alerts, and configuration tools, provided the exchange protects confidentiality, complies with data-protection law, and is governed by clear arrangements.
Joining a trusted community, and telling your supervisor
Article 45 does not create a single EU-wide platform: it authorises financial entities to join existing trusted communities and sets the conditions those arrangements must meet. In practice this usually means a sector information-sharing and analysis centre (ISAC), such as the globally active FS-ISAC, or a national CERT-run or supervisor-run exchange, rather than an informal peer channel. Two obligations apply once an entity takes part: the arrangement itself must have rules of conduct that protect business confidentiality and personal data (so shared indicators cannot simply be forwarded outside the group), and the entity must notify its competent authority when its membership is confirmed, and again if it later leaves. Because participation is voluntary rather than required, supervisors generally treat active ISAC membership as one signal of a mature ICT risk-management posture under Article 6 rather than as a standalone compliance box to tick.
The GDPR basis, and the notification duty entities skip
Article 45 does not hand entities a GDPR exemption: indicators of compromise such as IP addresses and attacker email addresses can themselves be personal data, so an entity still needs a documented lawful basis, most often legitimate interest, for what it shares and receives inside an arrangement. Separately, Article 45(3) attaches a procedural duty that is easy to miss: the entity must notify its competent authority once its participation is confirmed, and again if it later leaves. Entities that join FS-ISAC or a national scheme and never make that notification have technically skipped a DORA requirement even though the sharing itself was lawful. Our full walkthrough of Article 45 covers the notification mechanics, the GDPR legitimate-interest assessment, and how to choose between a global ISAC and a national arrangement in more depth.
Frequently asked questions
Is information sharing mandatory under DORA?
No. Article 45 makes it voluntary, within trusted arrangements that protect confidentiality and comply with GDPR.
Does joining an information-sharing arrangement need to be reported?
Yes. A financial entity must notify its competent authority once its membership in a threat-information-sharing arrangement is confirmed, and again if it ceases to be a member.
Does DORA give threat-intelligence sharing a GDPR exemption?
No. Indicators such as IP addresses or attacker email addresses can be personal data, so an entity still needs a lawful basis under GDPR, typically legitimate interest, for what it shares within an Article 45 arrangement.