Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ECON-PR-757355 → A-9-2024-0183
- From
- ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
- To
- A-9-2024-0183 Plenary report of 30 Apr 2024
- Changes
- Not comparable
- Paragraphs
- +506 added · −357 removed · 7 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 12 of 16: EXPLANATORY STATEMENT
RemovedEXPLANATORY STATEMENT
Added6. Within 2 months of receipt of a complete application▌, the competent authority shall inform the applicant whether the authorisation is granted or refused. The competent authority shall present to the applicant a detailed report on the grounds of its decision where it refuses an authorisation.
Removed1. Background
Added7. The competent authority may withdraw an authorisation issued to a financial information service provider only if the provider:
RemovedOn 28 June 2023, the European Commission adopted a proposal for a Regulation of the European Parliament and the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) No 2022/2554 (“FiDA”).
Added(a) does not make use of the authorisation within 12 months, requests the competent authority to withdraw the authorisation or has ceased to engage in business for more than 6 months;
RemovedThe FiDA proposal aims to enable consumers and firms to more efficiently control access to their financial data beyond payments, thus allowing them to benefit from financial products and services that are tailored to their needs while keeping in check associated risks. This represents a shift from open banking with PSD2 towards open finance that should also promote the digital transformation and speed up the adoption of data-driven business models in the EU financial sector.
Added(b) has obtained the authorisation through false statements or any other irregular means;
RemovedThe 2020 Digital Finance strategy and the 2021 Communication on a Capital Markets Union announced the Commission’s intention to promote data-driven finance with a legislative proposal. Against this background, in her 2022 State of the Union letter of intent, Commission President von der Leyen confirmed data access in financial services as a key Commission initiative for 2023.
Added(c) no longer meets the conditions for granting the authorisation or fails to inform the competent authority on major developments in this respect; or
RemovedThe main provisions in FiDA relate to:
Added(ca) has breached its obligations under Union data protection law according to a supervisory authority established pursuant to Regulation (EU) 2016/679;
Removed Enhancing customer trust in data sharing;
Added(d) would constitute a risk to consumer protection or the security of data.
Removed Obliging data holders to share customer data with data users;
AddedThe competent authority shall give reasons for any withdrawal of an authorisation and shall inform those concerned accordingly. The competent authority shall make public the withdrawal of an authorisation▌.
Removed Promoting standardisation of customer data and interfaces; and
Added7a. The ESAs or the competent authority of any host Member State may at any time request the competent authority of the home Member State to examine whether the financial information service provider still complies with the conditions under which the authorisation was granted, when there are grounds to suspect that this may no longer be the case.
Removed Promoting implementation of high-quality interfaces for customer data sharing.
Added1. EBA shall develop, operate and maintain an electronic central register which contains the following information:
Removed2. Procedure in the European Parliament
Added(a) the authorised financial information service providers, including the name, the address and, where applicable, the authorisation number, and a description of the financial information services offered;
RemovedThe Committee on Economic and Monetary Affairs (ECON) was appointed as the lead Committee to deal with the proposal.
Added(b) the financial information service providers that have notified their intention to access data in a Member State other than their home Member State;
Removed3. Draft report
Added(c) the financial data access schemes agreed between data holders and data users;
RemovedBuilding on data combination and aggregation, open finance facilitates the provision of new financial products and services that may better service customer needs, for example in areas such as financial advice, insurance, or pension preparation. An enhanced customer experience will empower customers to make better informed financial decisions and effectively reap tangible benefits from FiDA.
Added(ca) the information listed in Article 28(2).
RemovedYour Rapporteur enthusiastically welcomes the FiDA proposal and fully supports both its overall objective and general direction. He is nevertheless of the opinion that the proposal can be positively amended concerning several key features, and suggests slight modifications along the following main axes.
Added▌
Removed Enhancing customer trust
Added3. The register shall be publicly available on EBA’s website, shall be machine readable, and shall allow for easy searching and accessing the information listed, free of charge.
RemovedYour Rapporteur defends a customer-centric approach. For a safe and successful implementation of the FiDA framework, customers should first and foremost have full confidence in its safety, reliability, and fairness. Any access to customers’ financial data should have due consideration for data privacy. Upholding strong consumer protection also requires strong safeguards, most notably related to permission and liability.
Added4. EBA shall enter in the register referred to in paragraph 1 any withdrawal of authorisation of financial information service providers or termination of a financial data access scheme.
RemovedIn line with the opinion delivered by the European Data Protection Supervisor (EDPS), your Rapporteur therefore more clearly circumscribes the categories of personal data that can made available under FiDA, taking into account the risks for individuals whose personal data would be accessed and used. To further prevent risks of financial exclusion, he also provides for an explicit prohibition on the denial of financial services to consumers who do not want to make their data available through the FiDA permission dashboard, suggests more granular guidance at level 2 for delineating appropriate uses of personal data, and fosters consistency between the application and implementation of FiDA and EU data protection law.
Added5. The competent authorities of the Member States shall communicate without delay, and where possible in an automated way, to EBA the information necessary to fulfil its tasks pursuant to paragraphs 1 and 4. Competent authorities shall be responsible for the accuracy of the information specified in paragraphs 1 and 3 and for keeping that information up to date. They shall, where technically possible, transmit this information to EBA in an automated way.
RemovedNo other jurisdiction has to date adopted an open finance framework as broad as FiDA. Keeping in mind the importance of ensuring secure cross-border data flows that protect fundamental rights of EU consumers and business customers, especially when data are of a highly sensitive nature, your Rapporteur therefore suggests removing the possibility for undertakings that are not established in the EU to benefit from an authorisation as a financial information service provider. Following the same logic, he further recommends preventing designated gatekeepers under the Digital Markets Act from accessing data under FiDA.
AddedOrganisational requirements for financial information service providers
Removed Promoting innovation
AddedA financial information service provider shall comply with the following organisational requirements:
RemovedYour Rapporteur believes that open finance is not about sharing the customers’ data, but about enabling customers to unlock and re-use their data in a secure way, as they see fit and at their own will, so that they can profit from a wider choice of service providers whilst maintaining full confidentiality. To focus the FiDA framework more clearly on such a data access right for consumers and business customers, he recommends adapting the narrative accordingly.
Added(a) it shall establish policies and procedures sufficient to ensure its compliance, including its managers and employees with its obligations under this Regulation;
RemovedAdequate incentives are a prerequisite for fostering market adoption. Your Rapporteur’s suggestions aim at contributing to ensure that data holders build and maintain the necessary infrastructure for making data available. Most notably, provisions on compensation are more closely aligned with the market-driven approach under the Data Act.
Added(b) it shall take reasonable steps to ensure continuity and regularity in the performance of its activities. To that end the financial information service provider shall employ appropriate and proportionate systems, human and technical resources and procedures to ensure the continuity of its critical operations, have in place contingency plans and a procedure to test and review regularly the adequacy and efficiency of such plans;
Removed Improving interoperability and supervision
Added(c) when relying on a third party for the performance of functions which are critical for the provision of continuous and satisfactory service to customers and the performance of activities on a continuous and satisfactory basis, that it takes reasonable steps to avoid undue additional operational risk. Outsourcing of important operational functions may not be undertaken in such a way as to impair materially the quality of its internal control and the ability of the competent authority to monitor the financial information service provider’s compliance with all obligations;
RemovedThe long-term success of the FiDA framework requires a minimum level of technical interoperability for data and data access infrastructures, alongside regulatory interoperability among different frameworks. Your Rapporteur suggests a number of modifications to foster such interoperability, including by more closely aligning FiDA with other EU legislation such as the GDPR, the Data Act, and the Data governance Act.
Added(d) it shall have sound governance, administrative and accounting procedures, internal control mechanisms, effective procedures for risk assessment and management, and effective control and safeguard arrangements for information processing systems;
RemovedThere is merit in further strengthening the role of the European Supervisory Authorities vis-à-vis that of the national competent authorities, e.g. by requiring the assessment of the financial data access scheme to take place at European level. This avoids differing assessments by national authorities that could jeopardise a level playing field. Your Rapporteur makes some preliminary suggestions in that direction, to be worked out should the Parliament negotiating team support this approach.
Added(e) its directors and persons responsible for its management as well as the persons responsible for the management of the financial information service activities of the financial information service provider are of good repute and possess appropriate knowledge, skills and experience, both individually and collectively, to perform their duties including in relation to the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations;
Removed4. Stakeholder consultation
Added(f) it shall establish and maintain effective and transparent procedures to ensure the confidentiality, availability and integrity of data in the event of a security incident and for the prompt, fair and consistent monitoring, handling and follow up of a security incident and security related customer complaints, including a reporting mechanism which takes account of the notification obligations laid down in Chapter III of Regulation (EU) 2022/2554;
RemovedWhilst the amendments in the draft report contain the views of your Rapporteur only, he and his team are grateful for the input received from a variety of stakeholders, including:
Added1. Member States shall designate the competent authorities responsible for carrying out the functions and duties provided for in this Regulation, including the supervision of financial data access schemes and compliance of financial information services providers with this Regulation. Member States shall notify those competent authorities to the Commission.
Removed American Express;
Added2. Member States shall ensure that the competent authorities designated under paragraph 1 possess all the powers necessary for the performance of their duties.
Removed Association for Financial Markets in Europe (AFME);
AddedMember States shall ensure that those competent authorities have the necessary human and technical resources, notably in terms of dedicated staff, in order to comply with their tasks as per the obligations under this Regulation.
Removed Better Finance;
Added3. Member States who have appointed within their jurisdiction more than one competent authority for matters covered by this Regulation shall ensure that those authorities cooperate closely so that they can discharge their respective duties effectively.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=12
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 27 September 2026
Cite as
European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=12 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
author = {{European Parliament}},
title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
year = {2024},
date = {2024-04-30},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=12}},
url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=12},
urldate = {2026-09-27},
publisher = {EU Parl Watch Research},
note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}