The complaint that recurs most often when an account is restricted is not about the restriction. It is about the silence.
Customers describe support agents who repeatedly say the matter is under review, do not say what is being reviewed, and cannot provide a date. That experience is real, and a substantial part of it is produced by law rather than by poor service.
This does not make every unexplained restriction acceptable. It does mean the distinction between what a provider is prohibited from telling you and what it is choosing not to tell you is worth knowing, because your rights differ in each case.
The tipping-off prohibition
Where a payment provider files a suspicious transaction report with a national financial intelligence unit, it is prohibited from telling the customer.
In Malta, where Blackcat’s issuer Papaya Ltd. is licensed, this falls under Regulation 16 of the Prevention of Money Laundering and Funding of Terrorism Regulations, whichprohibits disclosing that a report has been submitted or that the financial intelligence unit has requested information. Every EU Member State has an equivalent provision. For provider-specific procedures, refer to the blackcat official site.
The prohibition covers more than a direct admission. Guidance to Maltese subject persons makes clear that communications made for other purposes should not be worded in a way that might lead to the customer.
That is why the language customers find so unsatisfying — “under review”, “we are unable to provide further detail” — is the language that gets used. A more informative answer risks a criminal offence.
The reason for the rule is that the alternative undermines the point of reporting. An investigation that begins with the subject being notified is not an investigation. Whether the balance struck is the right one is a legitimate policy question, and the European Banking Authority has itselfnoted the tension between the right to be told why an account was closed and the prohibition on tipping off.
Where the prohibition does not apply
Most account reviews are not suspicious transaction reports. A verification request, an expired document, a sanctions name match, a source-of-funds question, a limit issue, a technical fault — none of these engages the tipping-off rule, and in these cases a provider can and should tell you what it needs.
This is the practical value of understanding the rule. If a provider will not say what it needs, one of two things is true: the matter is one it cannot discuss, or it is a matter it could discuss and is handling badly.
You cannot tell which from the outside, but you can force the distinction by asking a specific question in writing. A provider that cannot answer will decline to answer; a provider that has not looked properly often answers once the question is on the formal record.
Information you can request under the data protection law
Separate from the payment relationship, you hold data protection rights against the provider as a data controller. Under Article 15 of the GDPR, you can request access to the personal data held about you.
Where a decision was taken by automated means with legal or similarly significant effects, Article 15(1)(h) entitles you to meaningful information about the logic involved.
The Court of Justice of the European Union strengthened this in February 2025 in Case C-203/22, which concerned an automated creditworthiness assessment.
The Court held that a controller must explain the procedure and the principles it applied in practice, in a way the data subject can understand, and that national rules cannot exclude the right of access as a general matter merely because a trade secret is involved; the competing interests have to be balanced case by case.
The limits are real, though. Article 23 of the GDPR permits Member States to restrict access rights where necessary and proportionate for objectives including the prevention and detection of criminal offences, and the European Data Protection Board has recognised anti-money-laundering as a context in which such restrictions arise.
A subject access request will not produce the contents of a suspicious transaction report. It can produce the identity documents on file, the account records, the categories of recipients of your data, and information about automated decision-making, which is often more than a support conversation produces.
What to ask for, and how
| Request | Basis | Realistic outcome |
| What specifically do you require from me? | Contractual and complaint-handling duties | Usually answered, unless the matter cannot be discussed |
| A copy of my personal data | GDPR Article 15 | Documents, account records and processing information; not report contents |
| Information on automated decision-making affecting me | GDPR Article 15(1)(h) | The principles and procedure applied, per Case C-203/22 |
| The reason for closure or termination | Contract and PAD, where a basic account applies | May be withheld where the tipping-off rule bites |
| A written response to my complaint | Complaint-handling requirements | A formal reply, which starts the escalation clock |
Requests available to a customer during an account review, and their realistic scope.
Source: Compiled from GDPR Articles 15 and 23, PMLFTR Regulation 16 (Malta), and EBA guidance on de-risking.
Two points of technique. Put requests in writing to the provider’s formal address rather than in a chat window, because a chat transcript is not a record you control and does not reliably start any procedural clock.
And separate your requests: a message that asks for documents, an explanation, compensation and an apology at once tends to be answered on the easiest point.
Judging whether the silence is justified
There is no way to be certain from the customer’s side, and any article claiming otherwise is overreaching. What you can assess is whether the provider is following its own process: acknowledging correspondence, responding within the period its terms commit to, telling you what it can do, and providing a route to escalate.
A provider who does those things while declining to explain a restriction is acting in accordance with the legal constraints.
A provider not doing those things is a different problem, and one for which the escalation route exists.
Frequently asked questions
Why will my provider not tell me why my account was blocked?
Where a suspicious transaction report has been filed, the provider is prohibited by law from disclosing it, including indirectly. Many reviews are not of that kind, however, and in those cases, the provider can tell you what it needs.
Can I use a GDPR request to find out what is happening?
You can request access to your personal data under Article 15, which may reveal documents, records and information about automated decisions. It will not produce the contents of a suspicious transaction report, as Member States may restrict access rights for crime-prevention purposes.
Am I entitled to a reason if my account is closed?
It depends on the account type and the reason. Consumer protections around account closure exist in EU law. Still, the right to be told can conflict with the prohibition on tipping off, a tension the European Banking Authority has expressly acknowledged.
This article discusses the legal constraints on what payment providers in the European Union may disclose during an account review, and the data protection rights available to customers. It is general information and not legal advice. The interaction between anti-money-laundering confidentiality rules and data subject rights is complex, varies across Member States, and is the subject of ongoing case law. Anyone whose account has been restricted and who believes their rights have not been respected should consider taking independent legal advice alongside using their provider’s complaints procedure.


