top of page

Search Results

70 results found with an empty search

  • Regulatory Alert: NEW CySEC Directive 73-2009-07 concerning the Digital Operational Resilience for the Financial Sector (Fees and Subscriptions)

    Further to the CySEC’s consultation paper (refer to link à  Consultation Paper (CP -01-2025 ) ,the new CySEC Directive ΟΔ 73-2009-07 (Fees & Subscriptions 2025) has been issued and published in the Official Gazette on 29 August 2025 , which is immediately into effect. Key points for consideration: SCOPE: Applies to financial entities falling under Regulation (EU) 2022/2554 (DORA), including CIFs, CASPs, issuers of asset-referenced tokens, CSDs, CCPs, trading venues, AIFMs, UCITS Management Companies, and crowdfunding service providers. ANNUAL SUBSCRIPTION: Microenteprise 2 : €2,000 Small enterprise 3 : €5,000 Medium enterprise  4 : €10,000 Other than microenterprise, small enterprise, or medium enterprise: €20,000   CYSEC NOTIFICATION:  Entities shall inform CySEC between 1 st  September – 15 th  September each year  on their category, based on the latest annual audited financial statements. Along with CySEC notification, entities shall provide to CySEC extracts of Financial Statements, where the annual turnover and balance sheet of the entity will be clearly presented, as well as the number of employees as at the date of submission. PAYMENT DEADLINE:  Annual subscription due by 30 November  of each year, for the period 1 st January – 31 st  December. ADDITIONAL FEES:  Entities conducting Threat-Led Penetration Testing (TLPT)  under Article 26 of DORA are required to pay a fee of €20,000 .   2025 TRANSITIONAL ARRANGEMENTS: Entities must notify CySEC of their classification between 2 nd – 31 st October 2025. Payment for the period 15 th August – 31 st December 2025  must take place by 31 December 2025 .   ACTIONS REQUIRED: Review the Entity’s classification (very small, small, medium, or large) based on the definitions stipulated above. Ensure timely submission of classification to CySEC along with the required information (i.e. extracts from latest audited FS and number of employees). Proceed with the required payment to CySEC. Perform an internal assessment as to whether the Entity is subject to TLTP based on DORA. If Yes, then additional fee of €20.000 shall be paid to CySEC.

  • Upcoming Changes to the EBA Guidelines on Internal Governance

    Introduction The European Banking Authority (“EBA”) has published revised draft guidelines on internal governance under Directive 2013/36/EU (“CRD”) (“Draft Guidelines”), reflecting regulatory and supervisory developments since the previous version of July 2021 (EBA/GL/2021/05). The revisions are designed to further harmonize internal governance arrangements, processes, and mechanisms across EU financial institutions and third-country branches (“TCBs”), in line with amendments introduced by Directive (EU) 2024/1619 (“CRD VI”) and other recent legislative acts, including the Digital Operational Resilience Act (DORA). Draft Guidelines will also reflect lessons learned from supervisory practices, the growing importance of ESG risks, the impact of digitalization, and the need for robust internal controls. Finally, the Draft Guidelines will incorporate findings from the EBA’s benchmarking of diversity practices and gender-neutral remuneration policies. Scope of Application / Addressees The Draft Guidelines clarify and expand their scope: Addressed to competent authorities, financial institutions (credit institutions & investment firms subject to CRD), and now also financial holding and mixed financial holding companies approved under Article 21a(1) CRD. Explicit extension to third-country branches (TCBs), with governance provisions tailored to their risks and specificities. Particularly relevant for significant CRR institutions under direct ECB supervision, aligning with the ECB’s Draft Guide on governance and risk culture (July 2024). Strengthened Role and Composition of the Management Body Role and Responsibilities The management body retains ultimate responsibility (Article 88(1) CRD). The Draft Guidelines reinforce: A clear distinction between executive (management) and non-executive (supervisory) functions. Written documentation of responsibilities and duties, plus an updated mapping of duties available to supervisors. Expanded scope of oversight to include: ESG risks (short, medium, long term) and concentration risks. ICT systems under DORA. A corporate culture promoting diversity and inclusion. Quantifiable targets for exposures to systemic central counterparties. Board Committees Risk, nomination, remuneration, and audit committees remain required for significant institutions. Members of remuneration committees must have skills to assess ESG impacts and align remuneration with ESG risk appetite. Risk committees must now also oversee fundamental rights, discrimination, and ICT risks. Internal Governance of Third-Country Branches (TCBs) New section introduced under Article 48g CRD: At least two persons located in the EU must direct the branch, with sufficient presence, independence, and expertise. Heads of risk, compliance, and audit in class 1 TCBs cannot be removed without supervisory function approval. TCBs must not operate as “empty shells”; EU substance is required. ICT and third-party risks must be managed in line with DORA. Back-to-back booking cannot systematically shift risk outside the EU. Remuneration policies must be gender neutral and ESG-consistent. Third-Party Risk Management Policy A renamed and expanded policy (formerly “outsourcing policy”): Must be approved, reviewed, and updated by the management body. Covers all ICT third-party arrangements under DORA (not only outsourcing). Confirms that third-party contracts do not relieve institutions of legal/regulatory obligations. Risk Culture and Corporate Values Development of an institution-wide risk-aware culture. Stronger emphasis on diversity, equality, and anti-discrimination. New indicators: gender representation across levels, age distribution, ratio of full-time vs part-time roles by gender. Clearer rules on conflicts of interest: Ban on simultaneously being chair of supervisory body and CEO. Restrictions on cross-group directorships. Cooling-off safeguards when a CEO transitions into a non-executive role. Internal Control Functions Key reinforcements: Independence  of risk, compliance, and audit functions. Heads of control functions  must be senior, independent, and report directly to the supervisory body. Combination of risk and compliance roles will no longer be permitted under one head. Risk management function (RMF)  must be led by an independent senior manager. Compliance function  now explicitly tasked with ensuring that all material management decisions account for legal risk. Internal audit remains independent but may be combined with other functions if safeguards exist. Business Continuity Management Institutions must establish a continuity policy , as well as response and recovery plans. Plans must be documented, tested, and updated; results reported to the management body. Business continuity requirements must align with DORA for ICT risk. Training and awareness programmes required to ensure resilience. Conclusion & Next Steps The Draft Guidelines represent a comprehensive upgrade  of the EU governance framework, aligning institutions with evolving supervisory expectations. 📅 The consultation runs until 7 November 2025 .

  • Robots Delivering Babies: Legal, Regulatory and Ethical Issues in Robotic Childbirth.

    A major announcement this week in Beijing has drawn worldwide attention: a Chinese robotics firm, Kaiwa Technology, revealed a humanoid robot prototype equipped with a fully functional artificial womb, designed to gestate and deliver human babies. The development, led by Dr. Zhang Qifeng, marks a potential turning point in reproductive technology. Who and What The invention, described as a “pregnancy robot”, is capable of creating an environment akin to a human womb. Nutrients are provided via a tube, simulating an umbilical cord, while the chamber replicates amniotic conditions. Unlike incubators, this technology claims to sustain an embryo through to live birth. Where and When The robot was showcased at the 2025 World Robot Conference in Beijing, with trials and prototypes expected to be further refined by 2026. The company, headquartered in Guangzhou, is already in dialogue with local authorities in Guangdong Province to address the ethical and legal implications of such work. Why Kaiwa Technology positions the innovation as a solution for infertile couples and those facing high-risk pregnancies. Cost is also presented as a factor: while international surrogacy can cost upwards of $100,000, the robot is estimated at around $14,000 per pregnancy, potentially widening accessibility. How Artificial womb technology is integrated into a humanoid robotic body, enabling full gestation cycles under controlled conditions. This is not merely a medical device, but a system presented as a functional substitute for human pregnancy. Legal, Regulatory and Ethical Considerations While technologically significant, this innovation poses immediate challenges for law, policy, and ethics: Legal Status and Parental Rights Who is the legal parent when birth is mediated by a machine? Surrogacy laws do not currently contemplate robots as intermediaries, raising unprecedented questions around parental rights, citizenship, and registration. Regulatory Oversight The technology sits at the intersection of healthcare, robotics, and reproductive law. National health regulators, as well as international bioethics bodies, will be pressed to determine whether artificial wombs can be licensed, supervised, and integrated into healthcare systems. Ethical Concerns Risk of commodification of childbirth, treating babies as products. Psychological and social impacts: the absence of maternal gestation may affect notions of bonding, family, and identity. Medical safety: critical biological processes such as hormonal signaling may not be replicable in a machine, raising long-term concerns for child health. Equity and Access Although cheaper than surrogacy, access remains limited by cost. Broader questions of reproductive justice and inequality will be at the forefront of global debate. Conclusion The introduction of humanoid pregnancy robots represents a significant development in reproductive technology. While this innovation may provide solutions for individuals and couples facing infertility or severe medical risks, it simultaneously raises profound challenges for legal systems, ethical theory, and social policy. In the legal domain, current frameworks governing parentage, custody, and the status of children lack provisions for gestation mediated by machines, necessitating the development of new rules and judicial interpretations. Ethical analysis must consider issues of human dignity, the potential commodification of reproduction, and the implications for the moral responsibilities traditionally associated with motherhood and parenthood. From a psychological perspective, particular attention must be given to the identity formation and emotional development of children born through such processes, as their understanding of family, origin, and belonging may be affected by non-traditional gestation. The critical question is not only whether such technologies can operate safely and effectively in a continuous innovative environment, but mainly whether societies can integrate them in ways that remain consistent with established legal norms, ethical principles, and the long-term welfare of children. _____________________________________ Sources: 1.     The New York Post https://nypost.com/2025/08/17/tech/pregnancy-robots-could-give-birth-to-human-children/?utm_source=chatgpt.com     2.     The Economic Times https://economictimes.indiatimes.com/news/international/us/game-changer-for-parents-pregnancy-robots-could-make-infertility-a-thing-of-the-past/articleshow/123371721.cms

  • Changing the Legal Landscape of “Trapped Buyers” in Cyprus: Legislative Amendments under Law 110(I)/2025

    Introduction The issue of trapped buyers  has, over the last decade, emerged as one of the most pressing social and legal concerns in the Cypriot real estate sector. The term refers to purchasers who, despite paying the full purchase price and fulfilling all contractual obligations, were unable to secure transfer of ownership because of pre-existing encumbrances (mortgages, court decisions, memos, prohibitions) registered by developers or their lenders. This phenomenon peaked between 2008 and 2015, exposing structural flaws in the financing of developers, the operation of the transfer system, and the balance between contractual rights of buyers and proprietary rights of creditors. Thousands of buyers remained without title deeds, deprived of legal certainty and unable to resell, mortgage, or safeguard their property against foreclosure actions initiated for debts of the developer. The concept of the trapped buyer A trapped buyer is typically one who has paid the purchase price and often has possession of the property, but cannot obtain ownership. Their only protection lay in depositing the sales contract with the Land Registry, which created a form of encumbrance but not ownership. This left them exposed to foreclosure proceedings by the seller’s creditors and unable to use the property as collateral or transfer it. From the sellers’ perspective, developers routinely mortgaged the entirety of their land to finance projects, selling individual units without first releasing encumbrances. Banks, in turn, relied on their security interests, enforcing foreclosures against developers and disregarding the position of end-buyers. The result was a severe loss of trust and stability in the property market. Legislative evolution The 2015 Amendment (Amending Law 139(I)/2015) introduced a mechanism allowing the Director of the Land Registry to transfer title directly to buyers, even without the creditors’ consent. However, in Civil Appeal 285/2018 (Supreme Court, 20 June 2024), these provisions were declared unconstitutional for infringing Article 23 of the Constitution (right to property). Applications under this law stalled, leaving buyers unprotected. The new Amendment of 2025 (Amending Law 110(I)/2025) published at 04.07.2025, aims to restore protection in a constitutionally compliant manner. It amends the Immovable Property (Transfer and Mortgage) Law, creating a more balanced framework on the Buyers' protection: Temporal limits : Only sales contracts signed or deposited with the Land Registry up to 31 December 2014 fall within the regime. Purchasers post-2015 are excluded. Requirement of a separate title : Buyers benefit only if a distinct title deed for the unit exists. Properties lacking titles due to planning or building irregularities remain outside protection. Encumbrances : Where prior mortgages or memos exist, the consent of the encumbrance holder is required for transfer. Judicial remedy for abusive refusal : If consent is unjustifiably withheld, and the buyer has fully paid, the court may substitute the lender’s consent upon application filed within 45 days. Suspension of auctions : Filing such an application suspends foreclosure or insolvency proceedings until the court decides, ensuring temporary buyer protection. Land Registry procedures : New notification forms (e.g. Type IHA) ensure that both buyers and lenders are formally informed of pending transfers and encumbrance adjustments. Mortgages are transferred from the developer’s entire landholding onto the specific unit sold, preserving creditor rights while allowing buyer ownership. Supreme Court procedural rules : The law authorises the Court to issue rules on time limits and procedural streamlining, preventing indefinite litigation and delays. Practical implications Buyers now enjoy an enforceable right to secure their title against unjustified creditor resistance, achieving greater legal certainty. Developers lose the ability to shift the risk of encumbrances onto end-buyers; they must confront their financing structures directly. Creditors remain protected, but their refusal to consent is subject to judicial review for abuse of rights. The property market benefits from enhanced transparency and restored confidence, encouraging investment. Constitutional balance and remaining gaps The 2025 reform strikes a balance between protecting buyers, safeguarding lenders’ security rights, and ensuring smoother market function. It adopts a proportionate model, avoiding the constitutional flaws of the 2015 regime, while providing judicial safeguards and respecting Article 23 of the Constitution. Nonetheless, gaps remain: Buyers of properties without a separate title (due to planning irregularities or incomplete division of land) remain excluded and effectively unprotected. These purchasers remain “trapped” in practice, dependent on the developer’s completion of outstanding planning or licensing steps, often subject to long delays or uncertainty. Conclusion Amending Law 110(I)/2025 represents a major step forward in addressing the trapped buyers’ problem. Its success will depend on effective cooperation among buyers, developers, lenders, and the Land Registry, as well as on consistent judicial application. While not a complete solution, it restores a measure of fairness and legal certainty in a sector where institutional trust had been deeply eroded.

  • ESMA Launches Call for Evidence on Simplifying Financial Transaction Reporting

    On 23 June 2025, the European Securities and Markets Authority (ESMA) published a Call for Evidence  on a comprehensive approach to the simplification of financial transaction reporting. This initiative reflects ESMA’s ongoing commitment to reduce regulatory burden while maintaining robust supervisory oversight. Why it matters Over the past decade, EU financial markets have been subject to multiple overlapping reporting regimes — MiFIR, EMIR, SFTR (and others such as REMIT and Securitisation). While each framework was designed with clear policy objectives, their coexistence has led to duplication, inconsistency, and high compliance costs. Industry estimates suggest reporting costs across MiFIR, EMIR and SFTR range between €1–4 billion annually. Key issues identified by ESMA Duplicative reporting of the same transactions under MiFIR, EMIR and REMIT. Inconsistent definitions and terminology, complicating reconciliation. Dual-sided reporting obligations under EMIR and SFTR, unique to the EU, adding operational complexity. Fragmented IT systems and reporting channels, increasing costs for firms and authorities alike. Simplification options under consideration ESMA is exploring two main avenues: 🔹 Option 1: Removal of duplication in current frameworks Sub-option 1a: Delineation by instrument (MiFIR = ETD, EMIR = OTC). Sub-option 1b: Delineation by event (MiFIR = transactions, EMIR = post-trade events). 🔹 Option 2: “Report once” principle Sub-option 2a: Full integration of MiFIR, EMIR and SFTR under a single template. Sub-option 2b: Expansion of “report once” to include other regimes such as REMIT or Solvency II. Next steps Stakeholders are invited to provide feedback by 19 September 2025. ESMA expects to publish a final report in early 2026, setting out preferred simplification options. Why firms should engage This consultation represents a unique opportunity for market participants to shape the future of EU transaction reporting. The choices made could redefine cost structures, compliance models, and supervisory data flows for years to come.

  • A Comprehensive Overview of the CBC Directive on Internal Governance of EMIs & PIs

    Understanding the Internal Organisation & Governance Directive of 2025 Introduction The Payment Institutions Internal Organisation & Governance Directive, issued in draft by the Central Bank of Cyprus (CBC), establishes comprehensive requirements for the development, application, and effective control of internal governance mechanisms for payment institutions. This Directive aims to ensure their effective and prudent management while aligning with international standards and practices. Purpose and Application Purpose The primary purpose of the CBC Directive is to set forth requirements regarding the development and effective control of internal governance mechanisms that payment institutions must implement. These measures are designed to ensure that institutions operate in a manner that is both effective and prudent, safeguarding the interests of all stakeholders. Application The Directive applies to licensed payment institutions established in the Republic. Institutions providing specific services exclusively may be exempt from certain requirements, subject to CBC approval. Proportionality and General Requirements General Requirements The Directive mandates strong governance with sound and effective management, including: A clear organizational structure with transparent and consistent lines of responsibility. Effective detection, management, monitoring, and reporting of risks, including non-compliance with regulatory frameworks. Internal control mechanisms, including compliance with anti-money laundering and counter-terrorism financing regulations. Procedures for monitoring and handling complaints and allegations. Administrative and accounting procedures. Proportionality Institutions must consider the nature, scale, and complexity of their activities and internal organization when developing and implementing internal governance arrangements. Management Body, Committees & Composition Roles & Responsibilities of the Board The Board of Directors (BoD) is responsible for the oversight, effective supervision, approval, and implementation of business strategies, key policies, risk strategies, and the governance framework. The BoD must ensure the establishment and effective implementation of a Conflicts of Interest Policy and regularly assess the effectiveness of governance arrangements. Board Composition The BoD's size and composition must reflect the institution's size, complexity, and activities. It must include at least two executive directors, one of whom is the CEO, and at least three non-executive, independent directors with the majority voting power. The chairman must be an independent non-executive director. Board Meetings The BoD must hold at least four regular or extraordinary meetings annually. Members can participate either physically or via videoconference, with physical attendance required at least once a year. Absences are limited to no more than two consecutive meetings or 25% of annual meetings. Annual Suitability Assessment The BoD, its committees, and its members must undergo an independent suitability assessment every three years, with the results reported to the CBC. Establishment of Board Committees The BoD must establish committees such as the Risk Management Committee and Audit Committee, primarily composed of non-executive directors. These committees are responsible for advising the BoD, monitoring risk management, and ensuring compliance.   Internal Governance Framework   The Three Lines of Defense Model The Directive emphasizes the Three Lines of Defense Model, ensuring a robust internal control system through clearly defined roles and responsibilities at various organizational levels. Corporate Values & Code of Conduct Institutions must establish a Code of Conduct based on international standards, promoting risk awareness, honesty, integrity, and compliance. Monitoring and training programs must ensure staff adherence to the Code. Customer Complaint Handling Institutions must maintain effective and transparent procedures for handling customer complaints, in line with ESMA Guidelines, and disclose relevant information on their websites. Internal Whistleblowing Policy & Procedure An internal whistleblowing mechanism must be in place, ensuring protection and confidentiality for whistleblowers. Institutions must comply with the Protection of Persons Who Report Breaches of Union and National Law. External Whistleblowing Mechanism Institutions must provide reliable mechanisms for staff to report potential or actual regulatory violations to the CBC, particularly when internal procedures may not be effective or pose risks to the whistleblower. Internal Controls System Institutions must develop and maintain a comprehensive internal control system, including regular external evaluations, to prevent money laundering and terrorism financing. Internal control functions may be outsourced, subject to stringent oversight.   Risk Management Framework Roles & Responsibilities The Risk Management function must have adequate authority, resources, and expertise to manage all institutional risks effectively. The Head of Risk Management directly reports to the BoD and ensures continuous risk monitoring and communication. New Products & Significant Changes Institutions must have a documented policy for approving new products and significant changes, covering compliance reviews, risk assessments, and regulatory adherence. Policy aspects: Ensures that all approved products and changes are aligned with the institution's risk strategy or undergo necessary reviews. Defines the scope for evaluating major changes, including new products, system modifications, risk management frameworks, and organizational restructuring. Incorporates significant process modifications, such as new external outsourcing arrangements and updates to technological systems. Establishes procedures for systematic pre-approval assessments and documented compliance reviews by the Compliance function. Covers parameters to consider before entering new markets, launching new products/services, or implementing substantial modifications. Provides clear definitions for key concepts such as "new product," "new market," and "significant changes." Outlines critical issues to address prior to approval, including regulatory compliance, accounting, pricing models, risk profile impact, profitability, resource availability, and internal tools for risk monitoring. Reporting to the Central Bank of Cyprus Institutions must submit various reports to the CBC, including minutes of BoD meetings, internal audit reports, risk management reports, compliance reports, and outsourcing assessment reports, all within specified timeframes. Timeline The new CBC Directive on Internal Governance of EMIs & PIs has undergone the final round of consultation and it is estimated to be officially issued by the CBC within H1 2025 - ealry H2 2025. Conclusion Overall, the CBC Directive on Internal Governance of EMIs & PIs  sets forth comprehensive requirements for payment institutions to ensure effective and prudent management. By adhering to these rules and guidelines, institutions will need to enhance their governance frameworks, manage risks effectively, and safeguard stakeholder interests.

  • Strengthening Crypto Market Oversight: ESMA’s New Guidelines for Supervisory Authorities

    On 29 April 2025, the European Securities and Markets Authority (ESMA) has introduced a set of detailed guidelines aimed at helping national regulators effectively prevent and detect market abuse within the EU’s crypto-assets markets. These guidelines are a crucial component of the implementation of the Markets in Crypto-Assets Regulation (MiCA), which came into force to establish a robust regulatory framework for digital assets. Why These Guidelines Are Critical Enhance Market Confidence:  Promote transparency and integrity in crypto trading. Prevent Market Abuse:  Detect and mitigate manipulation, insider trading, and other abusive practices. Harmonize Supervision:  Ensure consistent enforcement across all EU Member States, reducing regulatory gaps. Core Principles of the Guidelines ESMA emphasizes risk-based , proportionate  supervisory approaches tailored specifically for the unique environment of crypto markets. Proportionality:  Supervisory measures should align with the size, complexity, and risk profile of the market participants. Shared Supervisory Culture:  Foster collaboration and information sharing among NCAs through an open dialogue and mutual learning. Technology and Cross-Border Focus:  Address the specific challenges posed by social media, innovative technologies, and the inherently cross-border nature of crypto trading. Practical Supervisory Practices for NCAs The guidelines outline specific actions and frameworks for regulators to implement: Monitoring & Surveillance Establish ongoing, real-time monitoring systems tailored for crypto assets. Use advanced analytics and technology to identify suspicious activities. Engagement with Stakeholders Maintain open channels of communication with industry players, market participants, and other authorities. Conduct regular dialogues to understand emerging risks and best practices. Detection & Prevention Implement systems to identify suspicious transactions or activities promptly. Require entities to submit Suspicious Transaction or Order Reports (STORs) when anomalies are detected. Develop and refine internal procedures to prevent market abuse. Cross-Border Coordination Collaborate effectively with other NCAs for cross-jurisdictional cases of market abuse. Share intelligence, coordinate investigations, and enforce regulations uniformly across borders. Integration of Existing Practices Adapt current supervisory tools and processes to suit the crypto environment. Ensure that new surveillance and detection methods are compatible with existing legal and regulatory frameworks. Promoting Market Integrity Encourage industry initiatives aimed at self-regulation and ethical conduct. Organize awareness programs to educate market participants on market abuse risks. Reaction to Suspicious Activity Establish clear procedures for responding to suspicious transaction reports. Ensure swift, coordinated enforcement actions to address violations. ESMA and NCA Coordination Coordinate with ESMA and other national authorities to ensure a unified approach. Participate in cross-border enforcement actions and share best practices. Addressing Third-Country Obstacles Identify and mitigate barriers to effective supervision in cross-border crypto markets. Engage with non-EU regulators to facilitate cooperation and enforcement. Implementation Timeline Guidelines are to be finalized and communicated by June 30, 2025. Conclusion These comprehensive guidelines serve as a blueprint for EU regulators to strengthen oversight of crypto markets. By emphasizing risk-based, technology-driven, and collaborative supervision, ESMA aims to create a safer, more transparent environment that protects investors and enhances market integrity across Europe.

  • EU Parliament Green light for Postponement of CSRD and CSDDD Reporting & Due Diligence Rules

    📢 Good news for companies across Europe! On April 3, 2025, the European Parliament gave the green light to delay some of the upcoming sustainability rules. This move is part of the European Commission’s broader effort to make compliance easier and help businesses stay competitive. 🔔 What’s changing? CSRD (Corporate Sustainability Reporting Directive) The deadline for "large companies" to start reporting has been pushed back by two years. Instead of needing to report on their 2025 financial year, they’ll now do so for 2027, with reports published in 2028. For " listed small and medium-sized enterprises (SMEs)" , listed companies (like SMEs), the new deadline is 2028, with reports coming out in 2029. The second phase of the Omnibus plan will likely narrow which companies need to report, making things even simpler. CSDDD (Corporate Sustainability Due Diligence Directive) Member states now have until July 26, 2027, to put these rules into national law, giving companies an extra year to prepare. Starting in 2028, the biggest EU companies (over 5,000 employees and €1.5 billion in turnover) and some large non-EU companies will need to follow the new due diligence rules. Smaller big companies (over 3,000 employees and €900 million in turnover) will also be included from that year. ⛔ What’s next? This delay was approved under an urgent procedure, and now the legislation just needs formal approval from the EU Council. This gives businesses a bit more breathing room to get ready for the future. While some details about exactly which companies will need to report and what standards they’ll follow are still being worked out, this move provides much-needed certainty and helps companies avoid rushing to meet deadlines that are now pushed back. All in all, it’s good news for companies looking to balance sustainability goals with manageable compliance. The EU is clearly trying to make the process smoother while still pushing forward on important sustainability commitments.

  • Key Challenges for the EU in 2025 and beyond

    Introduction The European Union continues to lead the way in shaping global regulatory standards, balancing innovation, consumer protection, and sustainability. As we move further into 2025, the EU faces several complex challenges that will require adaptive, forward-thinking policies. Here are the ten key regulatory challenges on the horizon: 1. Ensuring Data Privacy and Sovereignty With the expansion of digital services and AI, protecting citizens’ personal data remains paramount. The EU must further refine its data privacy frameworks, such as the General Data Protection Regulation (GDPR), to address emerging technologies and cross-border data flows, while reinforcing data sovereignty. 2. Achieving Climate and Sustainability Goals The EU’s Green Deal and Fit for 55 package set ambitious targets for carbon neutrality. Regulators will need to oversee complex policies around sustainable finance, renewable energy, and circular economy practices, ensuring compliance while avoiding market distortions. 3. Digital Markets and Competition Policy With the dominance of Big Tech companies, the EU must continue to enforce competition laws, prevent monopolistic behaviors, and foster a fair digital marketplace. New regulations may be needed to address emerging concerns around data dominance and platform fairness. 4. Regulating Artificial Intelligence and Machine Learning AI's integration into healthcare, finance, and public services presents opportunities but also risks. The EU's proposed AI Act aims to establish a comprehensive regulatory framework, but implementing effective, proportionate rules that foster innovation while ensuring safety and ethics remains a challenge. 5. Cross-Border Regulatory Coordination As digital services and supply chains span multiple countries, effective cross-border regulation becomes critical. Harmonizing standards across EU member states, especially in areas like cybersecurity, financial services, and digital taxation, remains a key challenge. 6. Cybersecurity and Critical Infrastructure Protection Increasing cyber threats demand robust EU-wide cybersecurity policies. Protecting critical infrastructure—energy, transportation, financial systems—requires ongoing investment, updated standards, and international cooperation. 7. Managing the Rise of Cryptocurrencies and Digital Assets The rapid growth of digital assets necessitates comprehensive regulation to prevent money laundering, fraud, and market manipulation. The EU’s proposed Markets in Crypto-assets (MiCA) regulation aims to address this, but effective implementation is critical. 8. Ensuring Fair and Inclusive Digital Transformation Digital divides persist within the EU. Regulators need to promote inclusive access to digital services, reduce inequalities, and support digital literacy initiatives to ensure no citizen is left behind. 9. Adapting Consumer Protection Laws Emerging technologies like AI-powered platforms and personalized services require updated consumer protection rules. Ensuring transparency, fairness, and redress mechanisms will be vital in maintaining consumer trust. Conclusion The EU’s regulatory landscape in 2025 and beyond will be characterized by complexity and rapid change. Proactive, coherent policymaking that balances innovation with societal values will be essential. Addressing these ten challenges will help the EU maintain its leadership role in global regulation, ensuring a fair, sustainable, and technologically advanced future for its citizens.

  • Enhancing Order Execution Policies: A Detailed Overview of ESMA's New Regulatory Standards

    Introduction MiFID III, as entered into force on March 8, 2024, requires ESMA to develop regulatory technical standards (RTS) that specify criteria for evaluating the effectiveness of investment firms' order execution policies. The standards will impact how firms execute orders on behalf of both retail and professional clients. In that respect, on April 10, 2025, the European Securities and Markets Authority (ESMA) published a Final Report on the rules explaining how investment firms should establish their order execution policies and assess their effectiveness. In the draft Regulatory Technical Standards (RTS), ESMA specifies the rules, with the objective to enhance investment firms’ order execution and foster investor protection. The RTS includes requirements on:  the establishment of an investment firm’s order execution policy; this includes the classification of financial instruments in which firms execute client orders and the selection of venues for the order execution policy; the investment firm’s procedures and criteria to monitor and regularly assess the effectiveness of its order execution arrangements and order execution policy; the investment firm’s execution of client orders through own account dealing; and how an investment firm should deal with specific client instructions. In more detail but summarised form, the draft RTS deal with the following: General Criteria for Order Execution Policies Investment firms must define specific governance procedures for selecting execution venues. This includes: Ensuring venues are authorized by relevant authorities Maintaining an internal list that encompasses details such as the venue’s name, approval date, the classes of instruments, etc. Firms are required to implement robust valuation systems to ensure fair pricing, particularly for over-the-counter transactions. This is crucial for maintaining best execution standards, as mandated by regulatory articles Selection of Execution Venues When selecting execution venues, firms must consider client characteristics and needs. Key factors include: Order types and sizes relevant to clients Costs associated with execution, including trading fees and membership costs Comparisons of execution prices against reference datasets to ensure competitive pricing If a firm opts for a single execution venue, it must justify how this choice consistently delivers the best outcomes for clients. Order Routing Criteria Investment firms are required to specify the criteria for routing orders across multiple venues to secure optimal results. This involves: Assessing cost implications, including fees and commissions Considering the nature of the order and the client's profile (Retail Vs Professional) Utilizing historical market data to inform decisions For firms employing automated systems for order routing, clarity on system characteristics and safeguards to ensure best execution is necessary. Managing Client Instructions Investment firms must articulate how they handle specific client instructions that may deviate from their standard policies. This includes: Differentiating between general and specific instructions. Ensuring that any specific client request is processed accordingly, while other aspects of the order adhere to standard protocols Provide clients with the option to choose execution venues, ensuring transparency about potential costs associated with different venues. Dealing on Own Account When investment firms execute orders by dealing on their own account, they must outline: Strategies for ensuring best execution. Measures to identify and manage conflicts of interest. Risk assessment protocols for client orders. This component is especially pertinent for transactions involving over-the-counter products, where price fairness must be rigorously evaluated. Monitoring of the order execution policy Investment firms must monitor the effectiveness of their order execution policy to ensure compliance with established standards. Key elements to assess include the execution quality, price comparison against reference datasets, and adherence to predetermined thresholds for financial instruments. Firms should evaluate execution prices based on accepted deviations, traded volume percentages, and the number of client transactions meeting reference standards. Periodic assessment of the effectiveness of the order execution policy Investment firms are required to periodically assess the effectiveness of their order execution policy at least annually and in response to specific triggers, such as compliance concerns or material changes affecting execution ability. The assessment must include an evaluation of costs and fees, monitoring results, market developments impacting execution quality, and the emergence of new execution venues and their features. If an investment firm uses a single execution venue, it must assess whether this choice continues to provide the best results for clients compared to alternative venues. Any identified deficiencies in effectiveness must lead to updates in the order execution policies and internal arrangements within a reasonable timeframe, based on the severity of the issues. Implementation Timeline The new regulation will enter into force 20 days after publication in the Official Journal of the European Union  and will apply 18 months post-entry into force , estimated to be towards the end of 2026. Conclusion ESMA's new regulatory technical standards are critical for improving the order execution processes of investment firms across Europe. By adhering to these guidelines, firms can enhance client trust, ensure compliance, and ultimately deliver better financial outcomes. As the implementation timeline approaches, it is essential for firms to begin preparations to align their practices with the new standards.

  • CySEC Regulatory Alert Circular 700 - Major Incidents Reporting

    🔔 Legal / Regulatory Alert – Cyprus! CySEC has issued today Circular 700, which outlines the obligation of Regulated Entities: Cyprus Investment Firms (‘CIFs’) Central Securities Depositories (‘CSDs’) Trading Venues (‘TVs’) Crypto-Asset Providers (CASPs) Alternative Investment Fund Managers (‘AIFMs’) UCITS Management Companies (‘UCITS’) regarding the assessment of incidents related to ICT Services as well as the reporting of Major Incidents Reporting, as emanated by Article 19(1)of Regulation 2022/2554 on digital operational resilience for the financial sector (DORA) . 📊 Major Incidents Reporting - Step Approach Assess Impact : Determine the impact of the incident on ICT services to establish whether it qualifies as an ICT-related incident based on Articles 18(1) of DORA and Articles 1-7 of the Commission Delegated Regulation 2024/1772 . Classify Incident : If the incident is deemed ICT-related, classify it accordingly using the provided criteria. Evaluate Major Incident Thresholds : Refer to Articles 8-9 of the Commission Delegated Regulation 2024/1772 to assess if the incident meets the thresholds for a major ICT-related incident. Report to CySEC : If classified as a Major Incident, ensure that it is reported to CySEC in accordance with regulatory requirements. 📢 Phase Out Reporting & Submission Deadlines Initial Report:  Submit within four hours of classifying the incident as major, and no later than 24 hours after becoming aware of it. Intermediate Report:  Submit within 72 hours of the initial report, regardless of whether the incident's status has changed. An updated report must be submitted promptly, especially after regular activities are restored. Final Report:  Submit within one month of the intermediate report or the latest updated intermediate report. References: Commission Implementing Regulation (EU) 2025/302 with regard to the standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat Commission Delegated Regulation (EU) 2025/301 with regard to regulatory technical standards specifying the content and time limits for the initial notification of, and intermediate and final report on, major ICT-related incidents, and the content of the voluntary notification for significant cyber threats ⛔ Submission Process The Major ICT-related incident Form and the Significant Cyberthreats Template (Voluntary) (the ‘Incident Reporting Forms’) must be submitted to CySEC through the TRS system ONLY. The steps that the Regulated Entities have to follow for the successful submission of the template to the TRS, can be found here . After populating the required Excel fields in the Incident Reporting Forms, Regulated Entities should name the Excel file in accordance with the following naming convention: Username_DATDIR_IIRN-Version_YY.xlsx Example: XX_DATDIR_0000000001-0_25.xlsx

  • CySEC Regulatory Reporting Alert Circular 700 - Submission of DORA Register of Information

    🔔 Legal / Regulatory Alert – Cyprus! CySEC has issued today Circular 700, which outlines the obligation of Regulated Entities: Cyprus Investment Firms (‘CIFs’) Central Securities Depositories (‘CSDs’) Trading Venues (‘TVs’) Crypto-Asset Providers (CASPs) Alternative Investment Fund Managers (‘AIFMs’) UCITS Management Companies (‘UCITS’) regarding the submission of Register of Information, as emanated by Article 28(3) of Regulation 2022/2554 on digital operational resilience for the financial sector (DORA) . 📊 At which level the Register of Information shall be constructed The Register of Information should be: at individual entity level , where Regulated Entities are not part of a group of financial entities or where Regulated Entities are part of a group of financial entities and the parent undertaking is an entity outside of the Union and there is no Union parent undertaking. at the highest level of consolidation in the Union for groups of Regulated Entities that is available to the competent authorities. Further guidance for maintaining and updating the Register of Information, Frequently Asked Questions (FAQ) are shared by ESAs for guidance. 📢 Submission Deadline First submission due the deadline is Wednesday, April 30, 2025 , with a reference date of March 31, 2025. Going forward , Regulated Entities must fill in the Register of Information and submit it to CySEC on an annual basis, by February 28, each year , with reference date 31 December preceding the reporting date. Therefore, next reporting shall take place by February 28, 2026 with reference date 31 December 2025. ⛔ Submission Process The Register of Information Form should only be submitted via CySEC’s XBRL Portal . Once the Register of Information is completed, it should be zipped and submitted , through the Create filing. Regulated Entities may submit an XBRL file .

bottom of page