Wiki / Banks & neobanks / Outsourcing at a Licensed Firm: EBA Rules, Third Countries and the Letterbox Test

Outsourcing at a Licensed Firm: EBA Rules, Third Countries and the Letterbox Test

mdCitemcp

A licensed payment institution, e-money institution (EMI), investment firm or crypto-asset service provider (CASP) rarely does everything itself. Card processing, cloud hosting, customer support, compliance analysts and the group's back office often sit with another company, sometimes outside the EU. EU financial law allows this on terms. The licence stays with the entity that obtained it, and that entity must still govern, control and answer for every function it hands over. The outsourcing rules set those terms; the letterbox test marks the point at which so much has been handed over that nothing licensable is left inside the firm.

Outsourcing and the licence

Why the licence limits delegation

In the regulators' sense, outsourcing is a function the firm would otherwise perform itself, carried out for it by a provider. The EBA guidelines therefore leave out of the concept a statutory audit, market information services, global card networks such as Visa and Mastercard, clearing and settlement, supervised financial messaging, correspondent banking, and services the firm would never perform itself, such as legal opinions, cleaning or catering.

What remains is permitted because specialist providers bring scale, expertise and cost savings a small licensee cannot build alone. It is policed because an authorisation is granted to an entity whose management, organisation and resources the supervisor has assessed. If those move to a provider the supervisor never examined, the licence no longer describes the business.

The legal result is the same in every sector: the licensee stays responsible. A payment institution remains fully liable for any acts of the entities to which it outsources (PSD2 Art. 20). An investment firm remains fully responsible for its MiFID II obligations (Delegated Regulation 2017/565 Art. 31(1)), and a CASP remains fully responsible for its obligations under Title V of MiCA (Art. 73(1)).

The three texts also share four limits. Under PSD2 Art. 19(6), outsourcing an important function may not delegate senior management's responsibility, change the firm's relationship and obligations towards its users, undermine the conditions of its authorisation, or remove or modify any of them. Delegated Regulation 2017/565 repeats the same four limits for investment firms, and MiCA Art. 73(1) uses almost the same wording for CASPs.

What can be delegated

Tasks, systems and staff: processing, hosting, software development, customer support, operational tasks of compliance or internal audit, and group shared services. The provider may be an outside vendor or a sister company.

What stays with the licensee

Responsibility and liability, the client relationship, the conditions of the authorisation, and enough expertise and resources to supervise the provider and manage the risks of the arrangement.

Four trade-offs

Every outsourcing decision buys something the licensee values and spends something the supervisor watches. The four recurring trade-offs:

Trade-offFirm gainsSupervisor asks
Scale vs controlExpertise and systems it could not build aloneIn-house expertise to supervise the provider and an exit route
Group efficiency vs independenceShared services across group entitiesThe same standards as for an outside vendor; intragroup is not presumed safer
Global delivery vs supervisory reachTeams and data centres outside the EUAccess to data and premises, cooperation between supervisors, data protection
Speed vs noticeNo approval step under PSD2Timely notice and dialogue before a critical or important function moves

The second row rests on the EBA's statement that intragroup outsourcing is subject to the same framework as outsourcing outside the group and is not necessarily less risky. Each trade-off maps onto a rule set: which rulebook applies, which functions count as critical or important, what is notified, what changes when the provider is outside the EU, and where the empty-shell line runs.

The regime as it stands on 24 September 2026:

Payment institutions and EMIsPSD2 Arts 19(6) and 20; EMD2 Art. 3(1) applies them to EMIs
Investment firmsMiFID II Art. 16(5); Delegated Regulation 2017/565 Arts 30–32
CASPsMiCA Art. 73; presence rules in Art. 59(2)
EBA guidelinesEBA/GL/2019/02 apply; EBA/GL/2026/09 published 18 September 2026, not yet applicable
ICT servicesDORA, applicable since 17 January 2025
Supervisor's roleInformation and timely notice; PSD2 Art. 19(6) sets no approval procedure
Functions outside the EUBanks, PIs and EMIs (authorised functions) and investment firms (portfolio management): supervised provider plus cooperation agreement; CASPs: provider cooperates with the supervisor (MiCA Art. 73(1)(d))
BulgariaZPUPS Art. 31 notice to the BNB; ZPFI Art. 65(1) item 13; FSC for CASPs

Which rulebook applies

The licence decides the text, but the texts converge. For payment institutions the rule is PSD2 Art. 19(6). EMIs are bound by the same rules through EMD2 Art. 3(1): as replaced by PSD2 Art. 111, it provides that PSD2 Art. 5, Arts 11–17, Art. 19(5) and (6) and Arts 20–31 apply to EMIs mutatis mutandis.

The EBA guidelines on outsourcing arrangements (EBA/GL/2019/02) add the operating detail. They are addressed to institutions subject to the Capital Requirements Regulation (CRR), to payment institutions and to EMIs; a provider of account information services only is outside their scope. They have applied since 30 September 2019 to arrangements entered into, reviewed or amended from that date.

Investment firms follow MiFID II Art. 16(5) and Arts 30–32 of Delegated Regulation 2017/565. CASPs follow MiCA Art. 73, which applies directly as a regulation. The table compares the four families on the three questions every regime asks.

LicenceOutsourcing ruleNon-EU providerSubstance anchor
Payment institution, EMIPSD2 Arts 19(6), 20; EMD2 Art. 3(1); EBA/GL/2019/02Authorised functions: supervised provider and cooperation agreement (GL para. 63)Head office and part of the business in the home state (PSD2 Art. 11(3)); GL para. 39
Investment firmMiFID II Art. 16(5); Reg. 2017/565 Arts 30–31Portfolio management: supervised provider and cooperation agreement (Art. 32)ESMA 2017 opinion: persons directing the business in the member state; no outsourcing beyond internal functions by a substantial margin
CASPMiCA Art. 73Provider must cooperate with the supervisor and meet EU data-protection standardsRegistered office, effective management and one EU-resident director (Art. 59(2))
Credit institutionEBA/GL/2019/02Authorised functions: supervised provider and cooperation agreement (GL para. 63)GL para. 39: no empty shells

Whatever the licence, the same three questions come back: is the function critical or important, can the supervisor still reach it, and is enough left inside the licensee.

The Digital Operational Resilience Act (DORA, Regulation 2022/2554) applies across all four rows. Since 17 January 2025 it has governed the ICT third-party risk of credit institutions, payment institutions, EMIs, investment firms and CASPs. Under Art. 28(3) they keep a register of information on all contractual arrangements for ICT services, report at least yearly on new arrangements, and inform the competent authority in a timely manner of any planned arrangement for ICT services supporting critical or important functions. The mandatory ICT contract terms, exit planning and the register itself are covered in DORA.

Critical or important functions

Most of the weight in these regimes falls on one classification. PSD2 and the MiFID delegated regulation define it the same way: a function is critical or important where a defect or failure in its performance would materially impair the firm's continuing compliance with its authorisation or other obligations, its financial performance, or the soundness or continuity of its services (PSD2 Art. 19(6); Reg. 2017/565 Art. 30).

The EBA guidelines (para. 29) add two cases that always count. The first is outsourcing operational tasks of internal control functions, unless their failure would not affect the control function. The second is outsourcing functions of banking or payment services to an extent that would require authorisation.

The label matters because it switches on the heavier layer. Timely notice to the supervisor, documented exit plans, the twelve contract conditions of Reg. 2017/565 Art. 31(2) and DORA's third-country checks for ICT all attach to critical or important functions. A non-critical arrangement still sits in the register and under the licensee's responsibility, but without most of that apparatus.

For CASPs, ESMA's supervisory briefing singles out internal control, IT control, risk assessment, compliance, "key management" and sector-specific functions as highly important functions that require special scrutiny. They may be outsourced only in part, and not where that would jeopardise the entity or effective supervision; responsibility for AML compliance always stays with the CASP. MiCA adds a narrower rule for custody: a custodian that uses other custody providers may use only CASPs authorised under MiCA and must inform its clients (Art. 75(9)).

What is not outsourcing, or not critical: 2 lists

Two texts carve out services that fall outside the heavier regime.

SourceCarved out
EBA/GL/2019/02 para. 28 (generally not outsourcing)Statutory audit; market information services; global card networks; clearing and settlement; supervised financial messaging; correspondent banking; services the firm would not perform itself
Reg. 2017/565 Art. 30(2) (not critical or important)Advisory and other non-investment services such as legal advice, training, billing and security of premises and staff; standardised services such as market information and price feeds

Other arrangements are classified on the defect-or-failure test.

Notice, register, contract and exit

Once a function is classified, the process layer follows. It starts before the licence: a PSD2 application must describe the applicant's outsourcing arrangements (Art. 5(1)(l)), and its security measures must cover the IT systems of the undertakings to which it outsources. After authorisation, notice duties differ by regime.

RegimeTriggerDuty
PSD2 Art. 19(6)A payment institution intends to outsource operational functions of payment servicesInform the home authority
PSD2 Art. 19(8)Any change in the use of entities to which activities are outsourcedCommunicate without undue delay
EBA/GL/2019/02 paras 58–59Planned critical or important outsourcing; a function becomes critical; material changes; severe eventsTimely notice or supervisory dialogue
DORA Art. 28(3)Planned ICT arrangement supporting a critical or important function; new ICT arrangementsTimely notice; report at least yearly
MiCA Art. 73(4)Request from the competent authorityProvide all information needed to assess the outsourced activities

None of these is a licence application. PSD2 Art. 19(6) sets a duty to inform; the expectation that notice of a critical or important arrangement comes early enough for a dialogue comes from para. 58 of the EBA guidelines, which applies without prejudice to Art. 19(6). The EMD2 cross-reference does not include Art. 19(8), so for EMIs the duty to report later changes rests on the guidelines and on national law, as in Bulgaria.

The outsourcing register

Banks, payment institutions and EMIs keep a register of all outsourcing arrangements that distinguishes critical or important ones (paras 52–55). On request they make it available to the competent authority, in full or in part, in a processable electronic form (para. 56). DORA runs a separate register of information for ICT arrangements.

Contract and supervisory access

The contract is where supervision is secured in advance. For investment firms, Reg. 2017/565 Art. 31(2) sets twelve conditions for critical or important functions. They include retaining the expertise and resources to supervise the provider, and a right to terminate where necessary, with immediate effect when that is in clients' interests, without harming continuity.

The firm, its auditors and the competent authority need effective access to data and to the provider's premises. Where the function requires it, there must be a disaster-recovery contingency plan with periodic testing of backup facilities. Art. 31(3) requires a written agreement and allows the provider to sub-outsource only with the firm's written consent.

MiCA Art. 73 is shorter but covers the same ground. The provider must cooperate with the CASP's competent authority and must not prevent supervision, including on-site access. A written agreement must set out both parties' rights and obligations and give the CASP a right to terminate. On the payments side, PSD2 Art. 23(1)(b) lets the competent authority carry out on-site inspections at any entity to which a payment institution's activities are outsourced.

Exit

Exit planning is the other half of the contract. For critical or important functions the EBA guidelines require a documented exit strategy covering termination, provider failure and deterioration of the service, with comprehensive, documented and, where appropriate, tested exit plans (paras 106–108). A CASP's outsourcing policy must include contingency plans and exit strategies (MiCA Art. 73(2)).

Providers outside the EU

A provider outside the Union adds a question the licensee cannot answer alone: whether its supervisor can still see the function. The conditions tighten with the importance of what moves.

ConditionWhere it appliesSource
Provider authorised and supervised in its country, plus a cooperation agreement between supervisorsBanking or payment functions that require authorisation; portfolio management of investment firmsGL para. 63; Reg. 2017/565 Art. 32
The supervisor can obtain information from the providerCASPsMiCA Art. 73(1)(d); ESMA briefing
EU data-protection standards and a risk-based choice of data locationAll licenseesGL paras 83–84; MiCA Art. 73(1)(g); GDPR
Insolvency law, urgent data recovery and enforceability of law in that country consideredICT services supporting critical or important functionsDORA Art. 29(2)
Provider designated as critical must set up an EU subsidiary within twelve monthsICT services from critical third-party providersDORA Art. 31(12)
No AML/CFT tasks to providers in third countries identified under AMLR Arts 29–31, including high-risk third countries, except to a group company under group-wide AMLR-standard policiesObliged entities, from 10 July 2027AMLR Art. 18(6)

The first row is the strictest. Under para. 63 of the EBA guidelines, the cooperation agreement (a memorandum of understanding, for instance) must give the EU authority information on request, access to data, documents, premises and personnel in the third country, prompt information on breaches and cooperation on enforcement. Reg. 2017/565 Art. 32 sets the same logic for portfolio management, and competent authorities publish the list of third-country supervisors with which they have such agreements.

Data follows the same logic. Transfers of personal data to a country without a Commission adequacy decision need other GDPR safeguards. Under DORA Art. 31(12), a financial entity may use a third-country ICT provider designated as critical only if that provider sets up a subsidiary in the Union within twelve months of designation; the ESAs published the first list of designated providers on 18 November 2025.

Sanctions law adds a separate constraint. An EU licensee may not use an outsourcing arrangement to provide services barred by Art. 5n of Regulation 833/2014 to entities established in Russia, and may not supply a provider established there with the enterprise-management or banking software listed in Annex XXXIX or give it access to trade secrets related to that software (Art. 5n(3) and (3a)). Nor may it make funds available, directly or indirectly, to or for the benefit of a person listed under Regulation 269/2014; how providers and their owners are screened is covered in sanctions screening.

The letterbox test

The outsourcing rules end in one prohibition. Under para. 39 of the EBA guidelines, banks, payment institutions and EMIs should keep sufficient substance at all times and not become "empty shells" or "letter-box entities". They should meet all conditions of their authorisation at all times and keep a clear and transparent organisational framework that lets them ensure compliance. Where operational tasks of internal control functions are outsourced, they should oversee them, and they need sufficient resources and capacities to do all of this.

The supervisors' position was set out in 2017, in opinions issued as firms moved activity from the United Kingdom into the EU. The EBA told supervisors not to let institutions outsource so much that they operate as empty shells, which do not meet regulatory requirements. ESMA expected the persons effectively directing an investment firm to be in its member state (para. 14). Firms should not outsource to an extent that exceeds by a substantial margin the functions performed internally (para. 43), and key functions should go outside the EU only under strict conditions (para. 47).

No single number decides the test. Supervisors read a set of signals:

SignalIndicatorsSource
Who decidesWhere the persons directing the business sit; where key management decisions are takenESMA 2017 para. 14; MiCA Art. 59(2), recital 74
Balance of functionsOutsourcing beyond internal functions by a substantial margin; more functions outside the EU than insideESMA 2017 para. 43; ESMA CASP briefing
Cost shareShare of total costs spent on outsourcing, as an indicatorESMA CASP briefing
Oversight capacityExpertise and resources to supervise providersGL para. 39; Reg. 2017/565 Art. 31(2); MiCA Art. 73(1)
Where business is doneHead office and part of the business in the home statePSD2 Art. 11(3); MiCA Art. 59(2)

The signals are read together rather than as thresholds; ESMA itself presents the cost share as an indicator.

Presence rules for CASPs and payment firms

MiCA writes presence into the licence. A CASP must have its registered office in a member state where it carries out at least part of its crypto-asset services, its place of effective management in the Union, and at least one director resident in the Union (Art. 59(2)). Recital 74 defines the place of effective management as where the key management and commercial decisions are taken.

ESMA goes further in its supervisory briefing, which is guidance rather than law. It expects at least one executive board member to be resident in the member state of authorisation, and the CEO as a rule to devote all of their time to the CASP, although national authorities may accept less. The same briefing says that a CASP outsourcing more functions outside the EU than it performs inside should be carefully assessed, while non-management IT or HR support abroad might not prevent robust operation in the EU. How these expectations shape an application is shown in the MiCA CASP licence.

For payment institutions the statutory test is where the business is actually run. PSD2 Art. 11(3) requires a payment institution to have its head office in the member state of its registered office and to carry out at least part of its payment business there. EMD2 applies that rule to EMIs.

The codified test for fund managers

Fund law states the test most precisely. Under Delegated Regulation 231/2013 Art. 82(1), an AIFM becomes a letter-box entity in any of four circumstances:

  • it no longer keeps the expertise and resources to supervise the delegated tasks;
  • it loses the power to take decisions in key areas of senior management;
  • it loses its contractual rights to inquire, inspect, access or instruct its delegates;
  • it delegates investment management to an extent that exceeds by a substantial margin the functions it performs itself.

The four limbs apply only to fund managers, but they describe the same failure the EBA and ESMA opinions describe; how they operate in delegation chains is covered in third-party management companies.

Substance also shapes the rest of the licence. Management suitability and local management are assessed in qualifying holdings and fit and proper, and a change in who owns or controls the licensee goes through the change-of-control assessment. Lithuanian practice is described in the Lithuanian EMI licence, and the Bulgarian company-law side in company in Bulgaria. Arrangements in which a licensee lends its licence to another business test the same line from the other side, as licence for rent explains. Tax substance is a separate question, covered in economic substance and the substance dossier.

Where costs sit also matters for capital. Under MiCA Art. 67, a CASP's prudential safeguards must be at least the higher of its permanent minimum capital and one quarter of the previous year's fixed overheads; how fixed overheads are computed is worked through in regulatory capital.

How the rules land in Bulgaria

Bulgaria transposes the PSD2 rule in the Payment Services and Payment Systems Act (ZPUPS). A payment institution that intends to entrust operational functions to a subcontractor notifies the Bulgarian National Bank (BNB) under Art. 31. Art. 43 applies Arts 30–31 to EMIs, and Art. 30(1) makes the institution liable for the acts of its subcontractors. Because Art. 43 carries the whole of Art. 31 over to EMIs, a Bulgarian EMI also reports later changes to the BNB.

The presence test is written into the licensing conditions: the registered seat and management address must coincide with the place where the applicant is actually managed, and the applicant must carry out at least part of its payment-service business in Bulgaria (ZPUPS Art. 10(4), item 4). The BNB has told the EBA that it complies with EBA/GL/2019/02, which form part of the legal framework of its supervisory review manual (compliance table last updated 22 October 2024).

ZPUPS Art. 31: 4 rules

ZPUPS Art. 31, in the consolidated text with the latest amendment in force on 7 August 2026, sets four rules:

  1. The institution notifies the BNB, giving the subcontractor's identification data and a detailed description of the services.
  2. Entrusting important functions, including ICT systems since the 2025 amendment, must not materially reduce internal control or the BNB's ability to supervise.
  3. Management functions may not be transferred.
  4. Any change must be notified to the BNB immediately.

Investment firms follow the Markets in Financial Instruments Act (ZPFI). Art. 65(1), item 13, requires effective mechanisms to limit operational risk when important operational functions are entrusted to a third party. Under Art. 68(3), the detailed requirements come from Delegated Regulation 2017/565 and an ordinance of the Financial Supervision Commission (FSC). For CASPs, MiCA Art. 73 applies directly: under the Markets in Crypto-Assets Act (ZPKA), the FSC licenses CASPs and receives MiCA notifications.

The licences themselves are described in the Bulgarian EMI licence, the Bulgarian investment firm and the Bulgarian CASP licence, with the split between the BNB and the FSC in Bulgaria's financial licences. Outsourcing of AML tasks and reliance under Bulgarian law are covered in the Bulgarian AML framework. Serving other member states through branches or agents is a passporting question, set out in EU passporting.

What changes next

The EBA regime is between two texts. On 18 September 2026 the EBA published final Guidelines on the sound management of third-party risk for non-ICT services (EBA/GL/2026/09). They are final and awaiting translation, their application date has not been set, and once they apply they will repeal EBA/GL/2019/02, which remain applicable until then.

The new guidelines cover non-ICT services supporting the functions of credit institutions, investment firms that are not small and non-interconnected, payment institutions and EMIs, issuers of asset-referenced tokens and certain mortgage creditors; ICT services stay under DORA.

The core carries over: the empty-shell prohibition (para. 45) and timely notice of planned critical or important arrangements, including for PSD2 Art. 19(6) (para. 65). So does the third-country condition, extended to the issuance of asset-referenced tokens (para. 70). Where the review and documentation of existing arrangements supporting critical or important functions are not finalised within two years of the application date, firms should inform the competent authority, with the measures planned to complete the review or an exit strategy (para. 20).

AML is the next layer. From 10 July 2027, Art. 18 of the AML Regulation (EU) 2024/1624 will require obliged entities to notify the supervisor before an outsourced AML/CFT task starts. It will forbid outsourcing the approval of the business-wide risk assessment and internal policies, decisions on customer risk profiles and on entering a business relationship, and the approval of criteria for detecting suspicious transactions; reporting to the financial intelligence unit may be outsourced only to an obliged entity of the same group established in the same member state. Art. 18(6) will also bar outsourcing AML/CFT tasks to providers residing or established in third countries identified under AMLR Arts 29–31: high-risk third countries, third countries with compliance weaknesses and third countries posing a specific and serious threat to the Union's financial system. The only exception is a provider in the same group, where the group applies AMLR-standard or equivalent policies and the home supervisor oversees them at group level. The design of that programme is covered in the compliance stack, and the timetable in the EU AML package.

Two further points close the picture. ESMA's 2021 cloud guidelines were revised on 11 July 2025 to exclude financial entities within DORA's scope; they now apply only to certain AIFMD and UCITS depositaries outside DORA. And the payments reform is not yet law: PSD3 and the Payment Services Regulation reached provisional agreement on 27 November 2025 and the European Parliament's ECON committee approved the texts on 5 May 2026, but neither is adopted or in force, with the plenary vote forecast, as of September 2026, for 14 December 2026. The reform is followed in PSD3 and PSR.

Q/A

What may be outsourced

Can our whole tech team sit in a group company outside the EU?

It can, within limits. Intragroup outsourcing is held to the same standard as an outside vendor. If the function is critical or important, the EBA guidelines require timely notice, an exit plan and data-protection safeguards, and DORA adds its ICT register and third-country checks. The licensee must keep the expertise to supervise the team, and for CASPs ESMA scrutinises structures that do more outside the EU than inside.

Is customer support a critical or important function?

It depends on the defect-or-failure test in PSD2 Art. 19(6) and Reg. 2017/565 Art. 30: whether poor performance would materially impair compliance, financial performance or the continuity of services. The result is recorded in the outsourcing register, which distinguishes critical or important arrangements, and decides whether notice, exit planning and the stricter contract terms apply.

Can compliance or internal audit be outsourced?

Their operational tasks can be, but the EBA guidelines always treat that as critical or important, and the licensee must oversee the work. ESMA allows a CASP to outsource compliance, internal control and risk assessment only in part; responsibility for AML compliance stays with the firm. From 10 July 2027, AMLR Art. 18 will forbid outsourcing certain AML decisions altogether and will bar outsourcing AML/CFT tasks to providers in third countries identified under AMLR Arts 29–31 outside the group.

Notice and third countries

Does outsourcing need the regulator's approval?

Not under PSD2. Art. 19(6) requires a payment institution to inform its home authority, and Art. 19(8) to report later changes without undue delay. The EBA guidelines add timely notice or supervisory dialogue before critical or important functions are outsourced, and in Bulgaria ZPUPS Art. 31 requires a notification to the BNB.

What extra conditions apply to a provider outside the EU?

For functions that require authorisation, the provider must be authorised and supervised in its own country, and a cooperation agreement between the supervisors must give the EU authority access to information, data and premises. Data transfers need GDPR safeguards. DORA adds checks on insolvency law, data recovery and enforceability for critical ICT services, and requires critical third-country ICT providers to set up an EU subsidiary.

Do ESMA's cloud guidelines still apply to us?

Not if the firm is within DORA's scope. ESMA revised the guidelines on 11 July 2025 so that they now cover only certain depositaries outside DORA; cloud arrangements of DORA entities are governed by DORA.

Substance and reform

When does a regulator call a licensee an empty shell?

When the licensee no longer meets its authorisation conditions from inside, lacks the resources to oversee its providers, or has moved decision-making elsewhere. Supervisors look at where directors and key staff sit, the balance of internal and outsourced functions, and, for CASPs, the share of costs spent on outsourcing.

Must directors live in the EU?

For CASPs, MiCA Art. 59(2) requires at least one director resident in the Union, and ESMA expects at least one executive board member resident in the member state of authorisation. For payment institutions and EMIs the statutory test is where the business is actually managed: PSD2 Art. 11(3) and, in Bulgaria, ZPUPS Art. 10(4) item 4.

Do the new EBA guidelines already apply?

No. EBA/GL/2026/09 were published on 18 September 2026 but have no application date yet; EBA/GL/2019/02 continue to apply until the new guidelines replace them.

Download the offer «Outsourcing at a Licensed Firm»

How we approach such matters, the stages, the team and the contacts in one short document.

If you have questions or need a consultation, our experts will be glad to help.

Gordey Bolotko
Gordey BolotkoPartner, Corporate & Commercial

Request a callback

Your contacts are used to answer this request. No mailing lists.