Council Regulation 269/2014 forms part of the EU sanctions regime against Russia and other listed persons and entities. Article 2 is a central provision, requiring freezing of funds and economic resources belonging to, owned, held, or controlled by designated persons listed in Annex I, and prohibiting any business operations to the benefit of such entities. No funds or economic resources shall therefore be made available, either directly or indirectly, to or for the benefit of listed persons.
In practice, this creates a tangible burden for businesses. Many entities are not expressly named in Annex I but include designated persons in the share register or otherwise as part of those shareholders with rights of inside, influence, and various levels of control. Their assets may therefore be covered by the asset-freeze regime, and business operations with such entities may fall within the scope of Article 2. This often affects payments, provision of services, contractual performance and the enforcement of judgements and awards. Article 2 is far-reaching by nature, and it is therefore important that authorities and operators do not extend its already intrusive reach even further.
The Regulation further distinguishes between ‘funds’ (financial assets and benefits of every kind, including but not limited to cash, deposits, account balances and interest) and ‘economic resources’ (assets of any kind that can be used to obtain funds, goods or services). Freezing means preventing any move, transfer, or other use of such assets to the benefit of listed persons.
The ownership test starts with the shareholders list and asks whether any listed persons are among them. The Regulation explicitly provides that ownership exists where a listed person holds 50% or more of the proprietary rights in an entity or has a majority interest in it.
Importantly, ownership can be aggravated. The shares held by several listed persons are added together; and if their cumulative shareholding reaches or exceeds 50%, the entity is treated as “owned” by listed persons for asset-freeze purposes.
In some circumstances, ownership may be established even below the 50% threshold. Where a person is able to exert a dominant influence in practice – for example through shareholders agreements, special voting rights or veto powers – mere percentage analysis is insufficient. The ownership test cannot therefore be limited to a shareholding calculation and must include the assessment of who is able to influence the decision-making in reality.
The control test places an even stricter compliance obligation on businesses, as control may be established even where the 50% ownership threshold is not met. The definition of control under the Regulation is broad and includes, among other things:
Union authorities proceed from a presumption that a listed person benefits from the assets of any non-listed entity it owns or controls. However, this presumption remains rebuttable, where the entity can demonstrate that the listed person does not exercise decisive influence in practice and that assets in question are genuinely outside the listed person’s control. In other words, the determination of control requires a factual assessment on a case-by-case basis, rather than a blanket approach.
Control is a factual assessment based on all available evidence. It cannot be presumed solely from group structures or historic relationships. The asset freeze is designed as a preventive arrangement designed to stop listed persons from obtaining financial or economic benefits through indirect structures.
The Court has also made clear that entities must have the possibility to overturn the presumption of ownership or control. The EU Best Practices confirm that where an entity has a separate legal personality and decision-making structure independent from a designated person, its assets are not automatically covered by the restrictive measures. Demonstrating this separate legal personality is therefore crucial in challenging asset-freeze determinations.
Recent CJEU jurisprudence clarified how Article 2 applies to structures designed to remove the formal ownership of a designated person. In judgements delivered in 2026, the Court held that asset-freeze rules apply based not only on formal legal title but on substantive ownership or control.
This means that assets may “belong to” or be “controlled by” a listed beneficiary even where use and control over the assets is formally limited. The decisive question is whether the person can use the assets, derive economic benefit from them, dispose of them or influence the trustee’s decisions. Compliance clauses and formal restrictions are not determinative if practical influence persists.
To manage this, the EU has developed guidance on firewalls, the frameworks designed to sever a designated person’s control over non-listed entities. Put simply, a firewall is a structural safeguard that removes the designated person’s control and decision-making influence and prevents participation in day-to-day business operations.
Firewalls are important because, if properly implemented, they may allow a non-designated entity to continue operating, while keeping the designated person’s assets out of their reach.
A firewall should be considered when there are indicators that a designated person may control, or be perceived as controlling, the entity.
EU guidance suggests that firewalls are primarily intended to enable uninterrupted operation of certain non-listed entities in sensitive sectors, especially where they employ a significant workforce in the EU and play an important role in the market. This includes sectors such as food production, pharmaceuticals, fertilisers, chemicals, water management, sanitation and nuclear power. That said, the absence of express prohibitions or strict criteria at the EU level means that the possibility of a firewall should not be excluded in other contexts either; what matters is whether the arrangement genuinely removes control.
The Commission guidance suggests two principal ways of establishing a firewall. First, it may be implemented by legislation, where a State or its body intervenes directly in the governance of the entity and appoints a temporary administrator. Second, it may be implemented by the operator itself, where the entity takes steps to sever the control of a designated person, even as a precaution, and appoints an independent auditor to verify the effectiveness of the firewall. Importantly, there is no Union-level mechanism for establishing a firewall, and the procedure remains national.
In Sweden, there is no legislative basis for firewalls, and only the proactive establishment by the company is technically possible. The Swedish Financial Supervisory Authority (sw. Finansinspektionen) is responsible for evaluating firewall arrangements in relation to day-to-day financial operations and the release of frozen funds. Other national authorities, such as the Inspectorate of Strategic Products (sw. Inspektionen för strategiska produkter) and the National Board of Trade (sw. Kommerskollegium), may also become involved if export or trade licences are required. In practice, the situation on firewalls in Sweden is unclear.
Consequently, for the firewall to be effective in another Member State, recognition is required. The European Commission favours recognition across Member States, but this still depends on the assessment by the relevant National Competent Authority where recognition is sought. The framework does not explicitly regulate the recognition of firewalls or identical arrangements established outside the EU, but in practice such arrangements may still be relevant if they satisfy the underlying criteria and show that control has genuinely been removed. From a practical perspective, the key question is a proper structuring of a firewall, so as it can, where necessary, be recognised not only in the State where initially established but also in other jurisdictions.
Given the existing jurisprudence, ownership and control analysis has become a core element of sanctions compliance and dispute-risk assessment. Three areas are of particular importance:
