Do I have to share customer information with my supplier under EU sanctions rules?
Last reviewed: 20 August 2026
Today we tackle the burning questions for many independent businesses in the EU – do you have to share the customer/end-user information with your suppliers under EU sanctions rules? Can they use the information to go around you and approach your customers?
As an SME or family business, it is often not feasible to hire a compliance officer or an external lawyer. This makes compliance a challenging topic, considering the various rules each company in the EU has to follow. Sanctions are no different. The EU sanctions regime is a dense, often vague web of rules, guidelines, and sanctioned entity lists.
What is due diligence under EU sanctions rules?
Before we get to the main question, the background of this topic is the European Union’s rules about due diligence in sanctions compliance. The EU expects each company to develop, implement, and routinely update their own internal EU sanctions compliance programme. This programme should be created based on their individual business model, geographic location, business sector and risk assessment. These programmes can help detect red flag transactions that could be evidence of another company trying to circumvent sanctions.
However, there is no one-size-fits-all definition of due diligence, as it all depends on your business’ characteristics.
Do I have to share customer information with my suppliers?
Let’s say that you have created an internal sanctions compliance programme, including vetting and checking your suppliers and customers based on a variety of criteria and questions. Then one of your suppliers comes to you with a form in which you have to fill out the details of the end-user you are re-selling to. Do you have to do it?
In general, yes, if they request such information, you are obliged to share it. This is done to ensure that each company down the supply chain is vetted against the supplier’s own due diligence procedure.
What if I provide a liability waiver for my supplier?
You might also ask yourself whether a document waiving the suppliers’ liability may be sufficient to avoid giving end-user information to the supplier. While it’s not entirely clear from EU rules, the answer is most likely “No”. That is because the due diligence obligation under EU sanctions rules is individual for every company and overrides any agreements between entities/companies.
A good analogy is the relationship between Incoterms and sanctions rules. Under EXW (Ex-works) clauses, most responsibilities related to the transportation and delivery of the goods are transferred to the buyer. This would mean that the seller would not be responsible for whatever happens with the goods, even if they end up in a sanctioned country. However, the EU has made it clear that EXW does not waive the seller’s responsibility to conduct due diligence, because private law agreements such as this do not take precedence over EU sanctions rules.
Thus, if you get your supplier to sign a waiver, stating that you have done your due diligence on buyers/end-users, so that they wouldn’t have to do any vetting and checks, the supplier’s own due diligence obligation still stands.
What about unfair competition (e.g. “stealing” customers)?
Even though the supplier can ask for the end-user’s information, they are only allowed to use it within the limits of sanction compliance. If they take the information and go directly to the end-user, then they might be abusing their position and going against competition law.
If you notice any such behaviour from suppliers, then it is best to contact a lawyer or your local competition authority.
If you want to learn more about sanctions compliance, visit our website and request the full guidance now!