← current version of this provision

TFR Article 25 — held text

This page is a held version, frozen at the capture below. It is a source for review. It is not advice, and it does not determine whether this provision applies to you.

Article 25 Data protection 1. The processing of personal data under this Regulation is subject to Regulation (EU) 2016/679. Personal data that is processed pursuant to this Regulation by the Commission or EBA is subject to Regulation (EU) 2018/1725. 2. Personal data shall be processed by payment service providers and crypto-asset service providers on the basis of this Regulation only for the purposes of the prevention of money laundering and terrorist financing and shall not be further processed in a way that is incompatible with those purposes. The processing of personal data on the basis of this Regulation for commercial purposes shall be prohibited. 3. Payment service providers and crypto-asset service providers shall provide new clients with the information required pursuant to Article 13 of Regulation (EU) 2016/679 before establishing a business relationship or carrying out an occasional transaction. That information shall be provided in a concise, transparent, intelligible and easily accessible form in accordance with Article 12 of Regulation (EU) 2016/679 and shall, in particular, include a general notice concerning the legal obligations of payment service providers and crypto-asset service providers under this Regulation when processing personal data for the purposes of the prevention of money laundering and terrorist financing. 4. Payment service providers and crypto-asset service providers shall ensure at all times that the transmission of any personal data on the parties involved in a transfer of funds or a transfer of crypto-assets is conducted in accordance with Regulation (EU) 2016/679. The European Data Protection Board shall, after consulting EBA, issue guidelines on the practical implementation of data protection requirements for transfers of personal data to third countries in the context of transfers of crypto-assets. EBA shall issue guidelines on suitable procedures for determining whether to execute, reject, return or suspend a transfer of crypto-assets in situations where compliance with data protection requirements for the transfer of personal data to third countries cannot be ensured.
CELEX: 32023R1113 · provision: 25
Locator: Article 25; PDF page 26; derived-text line 721
Held artifact: docs_evidence/eu-legislation/eurlex-full-text/20260823T093000Z/32023R1113.pdf
Artifact SHA-256: d7502c011527b67c3e12a221ad74afd6adaf7b2f93171e0f52d101dadbf25527
Captured: 20260823T093000Z
Extracted with: pdftotext version 4.00
Official source: EUR-Lex
This version: /celex/32023R1113/ART_25/20260823-d7502c01/
Corpus Merkle root: 581628a5b36518981241d2b51f048aa46384f30a74bf648ef542c652028cdeff
Membership proof: 10 hashes — see corpus-proof.json
Modal verbs, counted verbatim (not a legal characterisation): 'shall not': 1 · 'shall': 9 · 'must': 0 · 'may not': 0 · 'may': 0 · 'should': 0

To verify independently: fetch the official source above, extract it with the named tool, and confirm the artifact SHA-256 matches. Then check this provision's leaf against the published Merkle root using the proof in corpus-proof.json.