Calder & Vance International Sanctions & Compliance Counsel

Enforcement & Investigations · EU

Responding to regulator information requests under EU: the essentials

A mid-size European trading company receives a letter from the competent authority in its member state. The letter asks for transaction records, counterparty identification, and internal communications – all relating to a shipment that passed through a third country two years ago. The compliance team's first instinct is to respond quickly and completely. But speed without structure can waive privilege, disclose more than required, and prejudice a parallel investigation in another jurisdiction. What does responding to regulator information requests eu rules actually demand, and where does cross-border complexity change the answer?

Under EU sanctions law, the obligation to cooperate with competent-authority information requests is embedded in each thematic Council Regulation. Member-state authorities – not a single EU-level agency – administer and enforce these obligations. Responses are time-bound, typically subject to a defined statutory window, and errors carry civil and, in some member states, criminal exposure. The core rule is simple: provide what is required, within the deadline, without disclosing more than is lawfully compelled.

This briefing sets out the governing regime and the authority behind it, the procedure a recipient business should follow, the cross-regime dimension when OFAC or OFSI is also in the picture, the most common risk flags, and when to instruct sanctions counsel before you respond.

Who administers information requests under EU sanctions – and on what legal basis?

EU sanctions obligations – including the duty to supply information to competent authorities – arise from Council Regulations adopted under the EU's Common Foreign and Security Policy. Each Regulation applies directly in all member states without needing transposition. The obligation to cooperate is therefore uniform in its legal source, even though its enforcement sits with the competent authority designated by each member state.

Those competent authorities vary by jurisdiction and, within a jurisdiction, by subject matter. A financial institution in one member state deals with the authority that oversees financial-sanctions compliance. A freight forwarder in another may deal with a separate body that handles trade and export matters. For a multinational with entities across several member states, the same underlying Council Regulation can produce simultaneous requests from more than one national authority – each with its own procedural rules, deadlines, and enforcement toolkit.

At EU level, the Commission holds an oversight and coordination role. The European External Action Service contributes to sanctions design. The Council adopts the designations. But none of these EU-level bodies conducts direct enforcement investigations against private persons. Enforcement – including information requests – is a member-state function. Understanding which national body has issued the request, and under what domestic procedural statute it is acting, is the first step in any response.

As of April 2026, the EU is continuing to build convergence tools across member states, including guidance and best-practice alignment. Those tools do not yet create a single EU-wide investigation procedure. In our practice advising on EU sanctions matters, the jurisdictional question is often the first thing we resolve.

What does an EU information request typically require?

An EU competent-authority information request typically calls for one or more of the following: records of transactions involving specified parties or goods; identification of ownership and control chains for counterparties; internal screening logs and results; communications with the designated party or a related intermediary; and copies of contracts, payment instructions, and shipping documentation.

The scope of a request is bounded by the competent authority's statutory power under the relevant Council Regulation and, at national level, by the procedural statute that governs the authority's investigative functions. A request that goes beyond those limits is, in principle, contestable – but the threshold for challenge is high and the practical risk of appearing obstructive is real. In our experience, the better course is to assess the scope carefully, produce what is legally required, and flag in the response cover letter any category of material that falls outside the request's stated scope.

Privilege considerations are distinct and jurisdiction-specific. In some member states, legal professional privilege attaches to communications with in-house lawyers in a manner similar to external-counsel privilege. In others it does not. The rules under EU law on privilege in competition investigations – which are more developed than those in sanctions enforcement – provide a useful analytical frame, but sanctions-specific privilege claims should be assessed by reference to the member state's own procedural law.

A common error is over-production: providing more material than the request covers, in an effort to appear cooperative. That approach can inadvertently confirm facts not yet under inquiry and may disclose commercially sensitive information with no legal obligation to do so.

What is the procedure for responding – and what are the key deadlines?

The procedure for responding to an EU competent-authority information request follows a broadly consistent sequence, even though the exact deadlines and procedural formalities differ by member state.

The first stage is receipt and classification. A properly constituted request will identify the competent authority, cite the legal basis, specify the information required, and state the deadline. The compliance team should record the date of receipt, identify the lead authority, and assign internal ownership immediately. If the request is served on a subsidiary but implicates data held at parent level, that corporate chain must be mapped on day one.

The second stage is legal review. This means assessing whether the request is within the authority's statutory scope, whether any privilege or confidentiality claim applies, whether there are data-protection considerations that limit production, and whether parallel obligations in other jurisdictions are engaged. Under the EU's data-protection rules, transferring personal data to a national authority in response to a compelled request requires a lawful basis – ordinarily, compliance with a legal obligation. Where the authority is asking for data about third parties, that assessment adds a further layer.

The third stage is production. Documents should be produced in an organised form, with an accurate cover letter that identifies what has been provided, confirms no material has been withheld beyond any stated privilege claim, and requests written confirmation of receipt. The cover letter is also the appropriate place to flag any ambiguity in the request's scope.

The fourth stage is follow-up. Competent authorities frequently issue supplementary requests after a first production. Treating each request in isolation is a mistake. A well-maintained response file, updated in real time, prevents inconsistency between a first and second production that can itself attract regulatory scrutiny.

As to timing: the statutory deadline for compliance is set in the request itself, and extensions are granted in some member states but not others. Where no extension is available and the volume of material is large, interim production of the most directly relevant documents – with a note that the balance follows – can preserve the relationship with the authority without triggering a late-response finding.

How does the EU information-request obligation compare with OFAC and OFSI?

For a business that operates across the Atlantic or maintains a footprint in the UK, the EU obligation to respond to information requests does not sit in isolation. OFAC and OFSI have their own distinct powers to compel information, and the procedural rules, privilege landscape, and enforcement consequences differ in ways that matter for how a response strategy is built.

Under the US regime, OFAC's information-gathering powers arise under its IEEPA authority. A business subject to an OFAC administrative investigation may receive a subpoena or a written request. The voluntary self-disclosure (VSD) concept – whereby a business that proactively reports an apparent violation to OFAC can receive meaningful mitigation of any civil penalty – has no direct equivalent in EU sanctions enforcement, though some member states operate analogous self-reporting mechanisms. Where both OFAC and a member-state authority are investigating the same underlying transaction, the sequencing of responses and the content of any voluntary disclosure to OFAC must be managed with care to avoid prejudicing the EU proceeding, and vice versa.

OFSI, the UK's Office of Financial Sanctions Implementation, also issues information requests. OFSI's enforcement guidance places a premium on prompt and complete cooperation. The UK's Sanctions and Anti-Money Laundering Act ("SAMLA") provides the statutory basis for OFSI's investigative powers. In our cross-border practice, a business with both a UK and an EU entity facing related inquiries will often receive requests from OFSI and from one or more EU member-state authorities on similar or overlapping facts. The obligation to report knowledge or suspicion of a sanctions breach to OFSI – which the UK rules impose on a defined category of persons – has no direct structural equivalent in the EU framework, though reporting obligations to national financial intelligence units and other bodies may apply in some member states.

The practical implication of operating across regimes is that no response to one authority should be finalised without considering whether its content is consistent with, and does not prejudice, any concurrent or anticipated engagement with another. Does your internal escalation procedure capture multi-regime inquiries as a distinct category? If it does not, that gap should be addressed before the next request arrives.

What are the principal risk flags that arise in practice?

Several patterns of risk recur across EU information-request matters. Each is identifiable in advance, and each has a mitigation path.

The first is latent secondary-sanctions exposure. A request from an EU authority may relate to a transaction that also engaged US secondary-sanctions risk. Producing documents to the EU authority is legally required. But the same documents may disclose facts that, if they came to OFAC's attention, would support a US enforcement action. The existence of this tension does not create a right to withhold from the EU authority. It does require early coordination between EU and US counsel so that any US exposure is addressed proactively, including through an OFAC VSD if that option is appropriate.

The second risk is group-level data held in a non-EU jurisdiction. A request from an EU member-state authority may call for records held on servers in the United States, the United Kingdom, or a third country. The obligation to produce extends to records under the respondent's control, not merely those physically held in the EU. Producing records from a US server to an EU authority may engage US export-control or data-localisation considerations. It is worth assessing these constraints before production, not after.

The third risk is an informal pre-notification by the authority. Some member-state authorities signal a forthcoming formal request through an informal communication – a phone call or a preliminary letter. The period between informal notification and formal request is operationally valuable: it can be used to locate and preserve documents, identify privilege issues, and instruct counsel. Treating informal contact as merely administrative, rather than as the starting gun for the response process, is a mistake we see regularly.

The fourth risk is inconsistency across group entities. Where a parent and a subsidiary both receive requests, their productions must be internally consistent. Differences between what the parent characterises as the terms of a transaction and what the subsidiary's records show will attract precisely the kind of scrutiny the business is trying to avoid. A single coordinating team, with access to records across all responding entities, is the structural answer to this risk.

The fifth risk is missing or deleted records. EU member-state authorities are alert to incomplete productions. Where document-retention obligations apply – as they do under most thematic sanctions regulations, which specify a defined retention period – a failure to maintain records is itself a breach, independent of the underlying transaction question. Record-keeping requirements under EU sanctions rules apply for a substantial period; verify the current position under the applicable member-state implementation before relying on any shorter internal retention policy.

When does the myth of "full cooperation equals no liability" create its own risk?

A persistent myth in compliance practice holds that full and immediate disclosure to a regulator, regardless of what it reveals, will insulate a business from enforcement consequences. The reality is more precise.

Cooperation is a genuine mitigating factor in EU member-state sanctions enforcement. Authorities across the major jurisdictions – France, Germany, the Netherlands, Italy, and others – treat prompt and complete responses as evidence of good faith. But cooperation does not suspend the enforcement analysis. An authority that receives a complete and well-organised production can use that material to build a penalty case. Cooperation mitigates; it does not immunise.

The smarter position is calibrated cooperation: respond fully to what is legally required, within the deadline, with a well-structured cover letter, and without volunteering material that is outside the scope of the request. Where a self-reporting obligation applies under applicable national rules, follow it precisely. Where it does not apply, the decision whether to disclose apparent violations proactively is a separate strategic question that should be taken with legal advice, not resolved by the compliance team's instinct to be forthcoming.

In a recent matter, a financial services group with entities in three EU member states received simultaneous requests from two national competent authorities relating to payments processed through a common correspondent. We assessed the legal basis of each request, mapped the overlapping document sets, and produced a single coordinated response to both authorities that accurately addressed each request's scope without disclosing additional material. The matter proceeded to a supervisory review with no enforcement action taken. No outcome is ever guaranteed, but the approach of treating multi-authority requests as a unified matter rather than two separate administrative tasks consistently produces better outcomes in our experience.

How does enforcement proceed if a business fails to respond adequately?

Failure to respond to a competent-authority information request, or responding in a manner the authority considers incomplete or obstructive, triggers a distinct enforcement path under EU sanctions law.

At EU level, the relevant Council Regulation requires member states to establish effective, proportionate, and dissuasive penalties for breaches of the regulation, including cooperation obligations. The design and quantum of those penalties are set at national level. They range from administrative fines to criminal prosecution, depending on the member state and the severity of the breach. In several EU jurisdictions, obstructing a sanctions investigation carries the same criminal-law framework as an underlying sanctions breach.

An inadequate response – one that is incomplete, internally inconsistent, or submitted late without explanation – typically produces one of three outcomes: a supplementary formal request with a shorter deadline; a formal finding that the business has failed its cooperation obligation; or escalation to an on-site inspection. Each step raises the cost of the matter and narrows the options available to the business.

The enforcement posture of member-state authorities has become markedly more active in recent years. Cross-border coordination between EU authorities and between EU and UK or US authorities – facilitated by memoranda of understanding and EU-level cooperation mechanisms – means that a matter that begins as a single information request can expand into a multi-jurisdictional investigation. Early engagement with sanctions counsel, at the point of the first request, is the most effective way to manage that risk.

Related practices

Frequently asked questions

Who administers responding to regulator information requests under EU?
EU competent-authority information requests in sanctions matters are administered by the member-state authority designated under the relevant Council Regulation. There is no single EU-level enforcement body. The competent authority varies by member state and, within a state, by sector – financial authorities handle financial-sanctions compliance; trade or customs bodies handle export-related matters. For a business with entities in multiple member states, more than one authority may be engaged simultaneously on related facts.
What does EU prohibit in relation to responding to regulator information requests?
EU sanctions regulations do not frame the information-request obligation as a prohibition. They impose a positive duty: to provide information required by the competent authority within the specified period. The prohibitions that arise relate to failures – submitting incomplete, misleading, or obstructive responses, or failing to respond within the deadline. Some member states treat deliberate obstruction of a sanctions investigation as a criminal offence. The duty to maintain records for the applicable retention period is separate and applies independently of any investigation.
How is responding to regulator information requests enforced under EU?
Enforcement follows a member-state framework. Each EU state must set penalties that are effective, proportionate, and dissuasive. In practice, failure to respond adequately can produce an administrative fine, a formal breach finding, an escalation to on-site inspection, or criminal referral in the most serious cases. Cooperation with the authority – producing what is required, on time, in good order – is a recognised mitigating factor in member-state enforcement decisions, but it does not substitute for an accurate assessment of what the request legally requires.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.