The Malta Independent 5 August 2026, Wednesday
View E-Paper

Local Banks to warn clients on SWIFT data protection risks

Malta Independent Sunday, 20 May 2007, 00:00 Last update: about 13 years ago

All Maltese banks are to start warning their clients that their personal data could be transferred to the United States authorities, including the Treasury Department and the Central Intelligence Agency, when they use the SWIFT system to carry out money transfers

The Malta Data Protection Commission informed The Malta Independent on Sunday that an agreement has been reached on a common approach for compliance with an obligation to inform customers that their personal data may be disclosed to US authorities through the SWIFT system.

The warning will be made in the form of a notice, with the text, agreed between local parties, reading: “Personal data in relation to transactions effected via SWIFT (Society for Worldwide Interbank Financial Telecommunication) may be required to be disclosed to the United States authorities in order to comply with legal requirements applicable in the United States for the prevention of crime”.

The development follows a meeting held between Data Protection Commissioner Paul Mifsud-Cremona, himself a member of the so-called Article 29 working party looking into the matter, earlier this month.

The meeting was attended by the Malta Bankers Association, the Central Bank of Malta and local banks using SWIFT services.

Banks are to begin implementing the notification process. There are a number of possible ways in which the notices would be implemented, but the Malta Bankers Association was not in a position this week to spell out the details given the fact that its head is currently abroad.

As to the exact implementation of the notice to clients, there are a number of possible ways the notice could be delivered to clients. These could include informing new clients as part of the banks’ terms and conditions, or informing clients when they are to make a financial transaction using the SWIFT system.

The SWIFT system is commonly used for international financial transactions, but another matter of concern is that, due to the efficiency and cost-effectiveness of the SWIFT system, it is also sometimes used to communicate between Maltese banks.

Such transactions although undertaken strictly within Malta, nevertheless end up on SWIFT’s databases and as such have been at risk of being handed over to US authorities. There are, however, a number of other such systems that can be used toward the same end.

The motion that banks would need to inform their clients their personal data could be passed over to the US authorities as part of the fight against terrorism since 9/11, was made by the Article 29 working party.

In December the working party had found that all European banks using the SWIFT service must inform clients that US authorities could be given access to their personal, banking and financial data as a result.

It had also found that any European bank using the SWIFT system for financial transactions shares culpability, to varying degrees, for the wide-scale handing over of personal data and banking details, in which millions of European records have been made available to US authorities.

The working party had concluded, “All financial institutions in the EU using the SWIFT service, including the Central Banks, have to make sure that their clients are properly informed about how their personal data are processed and which rights the data subjects have.”

The working party found that while SWIFT bears primary responsibility, financial institutions also bear some responsibility for the processing of their clients’ personal data.

“The financial institutions are responsible for having sufficient knowledge of the different payment systems and their technical and legal characteristics and risks. If financial institutions did not strive (sufficiently) to obtain such knowledge, they would accept substantial legal and client risks in breach of their fundamental duty of care.”

The working party had also noted that “the hidden, systematic, massive and long-term transfer of personal data by SWIFT to the UST in a confidential, non-transparent and systematic manner for years without effective legal grounds and without the possibility of independent control by public data protection supervisory authorities, constitutes a violation of fundamental European principles as regards data protection and is not in accordance with Belgian and European law”.

The European Parliament recently called on the European Commission to look, as a “matter of urgency”, into similar instances in which European personal data have been handed over, by means of US subpoenas for ongoing terrorism investigations – issued under the Safe Harbour agreement – by other companies operating in financial services, insurance and telecommunications.

  • don't miss