Confidentiality
Article 80
1. All information, including the holdings of all accounts, all transactions made, the unique unit identification code of the allowances held or affected by a transaction, held in the EUTL and the Union Registry shall be considered confidential except as otherwise required by Union law, or by provisions of national law that pursue a legitimate objective compatible with this Regulation and are proportionate. The first subparagraph also applies to any information gathered pursuant to this Regulation and held by the central administrator or the national administrator. 2. The central administrator and the national administrators shall ensure that all persons who work or who have worked for them or entities to whom tasks are delegated, as well as experts instructed by them, are bound by the obligation of professional secrecy. They shall not divulge any confidential information which they may receive in the course of their duties, without prejudice to requirements of national criminal or taxation law or the other provisions of this Regulation. 3. The central administrator or national administrator may provide data stored in the Union Registry and the EUTL or gathered pursuant to this Regulation to the following entities: (a) the police or another law enforcement or judicial authority and tax authorities of a Member State; (b) the European Anti-fraud Office of the European Commission; (c) the European Court of Auditors; (d) Eurojust; (e) the competent authorities referred to in Article 48 of Directive (EU) 2015/849; (f) the competent authorities referred to in Article 67 of Directive 2014/65/EU; (g) the competent authorities referred to in Article 22 of Regulation (EU) No 596/2014; (h) European Securities and Markets Authority, established by Regulation (EU) No 1095/2010 of the European Parliament and of the Council ( 22 ) ; (i) Agency for the Cooperation of Energy Regulators established by Regulation (EC) No 713/2009 of the European Parliament and of the Council ( 23 ) (j) competent national supervisory authorities; (k) the national administrators of Member States and the competent authorities referred to in Article 18 of Directive 2003/87/EC; (l) the authorities mentioned in Article 6 of Directive 98/26/EC; (m) the European Data Protection Supervisor and the competent national data protection authorities. 4. Data may be provided to the entities referred to in paragraph 3 upon their request to the central administrator or to a national administrator if such requests are justified and necessary for the purposes of investigation, detection, prosecution, tax administration or enforcement, auditing and financial supervision of activities involving allowances, or of money laundering, terrorism financing, other serious crime, market abuse for which the accounts in the Union Registry may be an instrument, or of breaches of Union or national law ensuring the functioning the EU ETS. Without prejudice to requirements of national criminal or taxation law, the central administrator, the national administrators or other authorities, bodies natural or legal persons, which receive confidential information pursuant to this Regulation, may use it only in the performance of their duties and for the exercise of their functions, in the case of the central administrator and the national administrators, within the scope of this Regulation or, in the case of other authorities, bodies or natural or legal persons, for the purpose for which such information was provided to them and/or in the context of administrative or judicial proceedings specifically relating to the exercise of those functions. Any confidential information received, exchanged or transmitted pursuant to this Regulation shall be subject to the conditions laid down in this Article. Nevertheless, this Article shall not prevent the central administrator and the national administrators from exchanging or transmitting confidential information in accordance with this Regulation. This Article shall not prevent the central administrator and the national administrators from exchanging or transmitting, in accordance with national law, confidential information that has not been received from the central administrator or a national administrator of another Member State. 5. An entity receiving data in accordance with paragraph 4 shall ensure that the data received is only used for the purposes stated in the request in accordance with paragraph 4 and is not made available deliberately or accidentally to persons not involved in the intended purpose of the data use. This provision shall not preclude these entities to make the data available to other entities listed in paragraph 3, if this is necessary for the purposes stated in the request made in accordance with paragraph 4. 6. Upon their request, the central administrator may provide access to transaction data which do not allow the direct identification of specific persons to the entities referred to in paragraph 3 for the purpose of looking for suspicious transaction patterns. Entities with such access may notify suspicious transaction patterns to other entities listed in paragraph 3. 7. Europol shall obtain permanent read-only access to data stored in the Union Registry and the EUTL for the purposes of Article 18 of Regulation (EU) 2016/794 of the European Parliament and of the Council ( 24 ) . Europol shall keep the Commission informed of the use it makes of the data. 8. National administrators shall make available through secure means to all other national administrators and the central administrator the name, nationality and date and place of birth of persons for whom they refused to open an account in accordance with points (a), (b) and (c) of Article 19(2), or whom they refused to nominate as an authorised representative in accordance with points (a) and (b) of Article 21(5), and the name, nationality and birth date of the account holder and the authorised representatives of accounts to which access has been suspended in accordance with Articles 30(1)(c), 30(2)(a), 30(3)(a) and (b) and Article 30(4) or of accounts that have been closed in accordance with Article 28. National administrators shall ensure that the information is kept up to date and no longer shared when the grounds giving rise to sharing cease to exist. The information shall not be shared for more than five years. National administrators shall inform the persons concerned about the fact that their identity was shared with other national administrators and about the duration of this information sharing. The persons concerned may object to the information sharing at the competent authority or the relevant authority under national law within 30 calendar days. The competent authority or the relevant authority shall instruct the national administrator either to stop sharing the information or maintain the sharing of information in a reasoned decision, subject to requirements of national law. The persons concerned may require the national administrator sharing information pursuant to the first subparagraph to present them the personal data that was shared concerning them. National administrators shall comply with such requests within 20 working days of receiving the request. 9. National administrators may decide to notify to national law enforcement and tax authorities all transactions that involve a number of units above the number determined by the national administrator and to notify any account that is involved in a number of transactions within a period that is above a number determined by the national administrator. 10. The EUTL and the Union Registry shall not require account holders to submit price information concerning allowances. 11. The auction monitor appointed pursuant to Article 24 of Regulation (EU) No 1031/2010 shall have access to all information concerning the auction collateral delivery account held in the Union Registry.