Luxembourg Financial Regulator (CSSF) Introduces New Rules On The Access Of A Luxembourg Entity To IT Resources Of The Same Group

On 7 January 2013, the Luxembourg financial regulator, the Commission de Surveillance du Secteur Financier (CSSF) adopted circular CSSF 13/554 on the use and control of IT resources and the management of access to these resources. The circular has entered into force with immediate effect.

The CSSF found that, in practice, international financial groups often have a general access tool (e.g., IBM RAFC) for IT resources at the group level, which allows the uniform and simplified management of IT resources and facilitates access to intragroup IT resources (e.g. user accounts, printers, computers, IT services, etc.).

According to the CSSF, for the Luxembourg entity of such a group, this set-up could result in a loss of control over the IT resources for which it is responsible, which could conflict with the compliance and governance requirements applicable to the entity as a financial sector professional ('FSP") within the meaning of the Financial Sector Act 1993. The CSSF considers such a loss of control to be likely to further weaken the protection afforded confidential data under Luxembourg bank secrecy principle.

Thus, when a multinational financial group with a Luxembourg entity (FSP)...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT