Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-757355 → A-9-2024-0183

From
ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
To
A-9-2024-0183 Plenary report of 30 Apr 2024
Changes
Not comparable
Paragraphs
+506 added · −357 removed · 7 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 10 of 16: Paragraphs 541–600

RemovedArticle 14 – paragraph 7 – subparagraph 1 – point a: (a) does not make use of the authorisation within 12 months, requests the competent authority to withdraw the authorisation or has ceased to engage in business for more than 6 months;

Added1b. When developing the draft delegated act for the purpose of paragraph 1, point (a), of this Article the Commission shall consult the European Data Protection Supervisor pursuant to Article 42(1) of Regulation (EU) 2018/1725.

RemovedMore precise wording.

Added1. A legal person shall be eligible to access customer data under Article 5(1) for the provision of financial information services if it is authorised by the competent authority of a Member State.

RemovedArticle 14 – paragraph 7 – subparagraph 1 – point c: (c) no longer meets the conditions for granting the authorisation or fails to inform the competent authority on major developments in this respect; or

Added2. A legal person that intends to provide financial information services shall apply to the competent authority of the Member State of establishment of its registered office for authorisation as a financial information service provider. It shall submit the application for authorisation together with the following:

RemovedClarification that fulfilment of one of the conditions is sufficient.

Added(a) a programme of operations setting out in particular the type of access to data and financial information services envisaged;

RemovedArticle 14 – paragraph 7 – subparagraph 1 – point d: (d) would constitute a risk to consumer protection or the security of data.

Added(b) a business plan including, where applicable, a forecast budget calculation for the first 3 financial years which demonstrates that the applicant is able to employ the appropriate and proportionate systems, resources and procedures to operate soundly;

RemovedA risk to consumer protection or a risk to the security of date should be a sufficient condition.

Added(c) a description of the applicant’s governance arrangements and internal control mechanisms, including administrative, risk management and accounting procedures, as well as arrangements for the use of ICT services in accordance with Regulation (EU) 2022/2554 of the European Parliament and of the Council, which demonstrates that those governance arrangements, control mechanisms and procedures are proportionate, appropriate, sound and adequate;

RemovedArticle 14 – paragraph 7 a (new): 7a. The European Supervisory Authorities or the competent authority of any host Member State may at any time request the competent authority of the home Member State to examine whether the financial information service provider still complies with the conditions under which the authorisation was granted, when there are grounds to suspect that this may no longer be the case.

Added(d) a description of the procedure in place to monitor, handle and follow up a security incident and security related customer complaints, including an incident reporting mechanism which takes account of the notification obligations laid down in Chapter III of Regulation (EU) 2022/2554;

RemovedIn the event of suspected non-compliance, the ESAs or host Member States NCAs should be able to require the competent authority of the home Member State to verify that a given FISP is still in compliance with FiDA. The wording is inspired by MiCA Article 67(4).

Added(e) a description of business continuity arrangements including a clear identification of the critical operations, effective ICT business continuity policy and plans and ICT response and recovery plans, and a procedure to regularly test and review the adequacy and efficiency of such plans in accordance with Chapter II of Regulation (EU) 2022/2554;

RemovedArticle 15 – paragraph 1 – point a: (a) the authorised financial information service providers, including the name, the address and, where applicable, the authorisation number, and a description of the financial information services offered;

Added(f) a security policy document, including a detailed risk assessment in relation to its operations and a description of security control and mitigation measures taken to adequately protect its customers against the risks identified, including fraud;

RemovedIncluding more information about and a description of the financial information services offered by authorised FISPs in the register improves transparency and could help to promote the innovative potential of open finance.

Added(g) a description of the applicant’s structural organisation, as well as a description of outsourcing arrangements;

RemovedArticle 15 – paragraph 2: deleted

Added(h) the identity of directors and persons responsible for the management of the applicant and, where relevant, persons responsible for the management of the data access activities of the applicant, as well as evidence that they are of good repute and possess appropriate knowledge and experience to access data as determined in this Regulation;

RemovedThe purpose of the register seems somewhat defeated if it only contains anonymised data. It is therefore suggested to delete this provision.

Added(i) the applicant’s legal status and articles of association;

RemovedArticle 15 – paragraph 3: 3. The register shall be publicly available on EBA’s website and shall allow for easy searching and accessing the information listed, free of charge.

Added(j) the address of the applicant’s head office and, where available, the legal entity identifier (LEI);

RemovedAlignment with PSD2 Article 15 paragraph 1 and PSD3 proposal Article 18 paragraph 2.

Added(k) where applicable, the written agreement between the financial information service provider and the legal representative evidencing the appointment, the extent of liability and the tasks to be carried out by the legal representative in accordance with Article 13.

RemovedArticle 15 – paragraph 5: 5. The competent authorities of the Member States where financial information service providers are authorised shall communicate without delay, and where possible in an automated way, to EBA the information necessary to fulfil its tasks pursuant to paragraphs 1 and 4. Competent authorities shall be responsible for the accuracy of the information specified in paragraphs 1 and 3 and for keeping that information up to date. They shall, where technically possible, transmit this information to EBA in an automated way.

AddedFor the purposes of the first subparagraph, points (c), (d) and (g) the applicant shall provide a description of its audit arrangements and the organizational arrangements it has set up with a view to taking all reasonable steps to protect the interests of its customers and to ensure continuity and reliability in the performance of its activities.

RemovedClarification that this task should be performed by the “home” NCAs, and ideally in an automated way. It is further sugggested to correct a wrong reference.

AddedThe security control and mitigation measures referred to in the first subparagraph, point (f), shall indicate how the applicant will ensure a high level of digital operational resilience in accordance with Chapter II of Regulation (EU) 2022/2554, in particular in relation to technical security and data protection, including for the software and ICT systems used by the applicant or the undertakings to which it outsources the whole or part of its operations.

RemovedArticle 16 – paragraph 1 – point b: (b) it shall take reasonable steps to ensure continuity and regularity in the performance of its activities. To that end the financial information service provider shall employ appropriate and proportionate systems, human and technical resources and procedures to ensure the continuity of its critical operations, have in place contingency plans and a procedure to test and review regularly the adequacy and efficiency of such plans;

Added3. Financial information service providers shall hold a professional indemnity insurance or other comparable guarantee covering the territories in which they offer financial information services, and shall ensure the following:

RemovedClarification.

Added(a) an ability to cover their liability resulting from professional negligence, non-authorised or fraudulent access to or non-authorised or fraudulent use of data;

RemovedArticle 16 – paragraph 1 – point c: (c) when relying on a third party for the performance of functions which are critical for the provision of continuous and satisfactory service to customers and the performance of activities on a continuous and satisfactory basis, that it takes reasonable steps to avoid undue additional operational risk. Outsourcing of important operational functions may not be undertaken in such a way as to impair materially the quality of its internal control and the ability of the competent authority to monitor the financial information service provider’s compliance with all obligations;

Added(b) an ability to cover the value of any excess, threshold or deductible from the insurance or comparable guarantee;

RemovedAs “supervisor” is a non-defined term, it is suggested to refer to the competent authority.

Added(c) monitoring of the coverage of the insurance or comparable guarantee on an ongoing basis.

RemovedArticle 16 – paragraph 1 – point e: (e) its directors and persons responsible for its management as well as the persons responsible for the management of the financial information service activities of the financial information service provider are of good repute and possess appropriate knowledge, skills and experience, both individually and collectively, to perform their duties in relation to the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations;

AddedAs an alternative to holding a professional indemnity insurance or other comparable guarantee as required in the first sub-paragraph, the undertaking as referred in the previous subparagraph shall hold initial capital of EUR 50 000, which shall, without undue delay,be replaced by a professional indemnity insurance or other comparable guarantee on liability after it commences its activity as financial information service provider ▌.

RemovedThe suggested replacement of “data access” by “financial information service” follows from the suggested insertion in Article 3 of a definition of “financial information service”. Furthermore it seems adequate to more closely align the good repute criteria with Article 6 GDPR.

Added3a. Financial information service providers authorised in accordance with Article 14 shall at all times meet the conditions for their authorisation.

RemovedArticle 16 – paragraph 1 – point f: (f) it shall establish and maintain effective and transparent procedures to ensure the confidentiality, availability and integrity of data in the event of a security incident and for the prompt, fair and consistent monitoring, handling and follow up of a security incident and security related customer complaints, including a reporting mechanism which takes account of the notification obligations laid down in Chapter III of Regulation (EU) 2022/2554;

Added4. EBA in cooperation with ESMA and EIOPA shall, after consulting all relevant stakeholders, develop draft regulatory technical standards specifying:

RemovedIt is suggested to include an additional security requirement relating to ensuring the confidentiality, availability and integrity of data in case of a security incident.

Added(a) the information to be provided to the competent authority in the application for the authorisation of financial information service providers, including the requirements laid down in paragraph 2, points (a) to (k);

RemovedArticle 17 – paragraph 1: 1. Member States shall designate the competent authorities responsible for carrying out the functions and duties provided for in this Regulation, including the supervision of financial data access schemes and compliance of financial information services providers with this Regulation. Member States shall notify those competent authorities to the Commission.

Added(b) a common assessment methodology for granting authorisation as a financial information service provider, under this Regulation;

RemovedIt is suggested to explicitly refer to the competent authorities’ responsibility of overseeing financial data access schemes and compliance of FISPs with the Regulation.

Added(c) what is a comparable guarantee, as referred in paragraph 3, which should be interchangeable with a professional indemnity insurance;

RemovedArticle 17 – paragraph 2 – subparagraph 2: Member States shall ensure that those competent authorities have the necessary human and technical resources, notably in terms of dedicated staff, in order to comply with their tasks as per the obligations under this Regulation.

Added(d) the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance or other comparable guarantee referred to in paragraph 3.

RemovedClarification.

AddedIn developing these draft regulatory technical standards, EBA shall take account of the following:

RemovedArticle 18 – paragraph 3: 3. In the exercise of their investigatory and sanctioning powers, including in cross border cases, competent authorities shall cooperate effectively with each other, with the supervisory authorities under Regulation (EU) 2016/679, and with the authorities from any sector concerned as applicable to each case and in accordance with national and Union law, to ensure the exchange of information and the mutual assistance necessary for the effective enforcement of administrative sanctions and administrative measures.

Added(a) the risk profile of the undertaking;

RemovedGiven the foreseeable data protection dimensions, it seems adequate to explicitly refer to the supervisory authorities under the GDPR.

Added(b) whether the undertaking provides other types of services or is engaged in other business;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=10 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
  year = {2024},
  date = {2024-04-30},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=10}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=10},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}