Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ECON-PR-757355 → A-9-2024-0183
- From
- ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
- To
- A-9-2024-0183 Plenary report of 30 Apr 2024
- Changes
- Not comparable
- Paragraphs
- +506 added · −357 removed · 7 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 2 of 16: Paragraphs 61–120
Added(9a) Data users should comply with existing Union rules and guidelines when customer data is accessed under this Regulation for the purpose providing the customer with a financial service or product. This includes the rules applicable to carrying out consumer creditworthiness assessments as laid down in Directive (EU) 2023/2225 of the European Parliament and of the Council and Directive 2014/17/EU of the European Parliament and of the Council, and the duty of firms to act in the best interest of the customer when providing investment services in accordance with Directive 2014/65/EU of the European Parliament and of the Council or offering insurance products in accordance with Directive (EU) 2016/97 of the European Parliament and of the Council.
RemovedRecital 14: (14) Customer data related to the provision of non-life insurance are essential to enable insurance products and services important to the needs of customer like the protection of homes, vehicles, and other property. At the same time, the collection of such data is often burdensome and costly and can act as a deterrent against seeking optimal insurance coverage by customers. To address this problem, it is therefore necessary to include such financial services within the scope of this Regulation. Customer data on insurance products within scope of this Regulation should include both insurance product information such as detail on an insurance coverage and data specific to the consumers’ insured assets which are collected for the purposes of a demands and needs test. The access to and re-use of such data should allow for the development of personalised tools for customers, such as insurance dashboards that could help consumers better manage their risks. It could also help customers to obtain products that are better targeted to their demands and needs, including through more valuable advice. This can contribute to more optimal insurance coverage for customers and increased financial inclusion of otherwise underserved consumers, by offering new or increased coverage. Moreover, the unlocking and re-use of insurance data can be beneficial for more efficient supply of insurance including, in particular, at the stages of product design, underwriting, contract execution, including cl…
Added(10) Access to ▌customer data in the scope of this Regulation should be based on the explicit permission of the customer. Such permission should not solely be based on a “tick-the-box” approach or the use of generalising phrases. In seeking the explicit permission of the customer for the use of his or her data, data users should specify the purpose of the use of the data, subject to the customer’s consent. The legal obligation on data holders to enable access to customer data should be triggered once the customer has explicitly requested their data to be made accessible to a data user. Where permission has explicitly been granted, this request can be submitted by a data user acting on behalf of the customer. This Regulation sets out rules on gatekeepers designated pursuant to Article 3 of Regulation (EU) 2022/1925. Those rules should apply to data users owned or controlled by gatekeepers to ensure that gatekeepers do not circumvent those rules. Gatekeepers should not be eligible to become financial information service providers. A data user that is owned or controlled by a gatekeeper should be subject to a special assessment by the national competent authority of its registered office to ensure its eligibility under this Regulation. Where a data user is part of a group of companies in which one or more entities in the group has been designated as a gatekeeper, customer data should be accessed only by the entity of the group that acts as a data user. The data user should therefore not grant access to customer data under this Regulation to the gatekeeper that owns or controls it. Gatekeepers should not engage in behaviour that would undermine the effectiveness of the prohibitions and obligations laid down in this Regulation. The limitation on gatekeepers would not exclude them from the market or prevent them from offering their services, as voluntary agreements between gatekeepers and the data holders remain unaffected. Where the processing of personal data is involved, a data user should rely on one of the valid lawful bases for processing under Article 6(1)(a) or (b) of Regulation (EU) 2016/679. The customers’ data can be processed only for the agreed purposes in the context of the service provided. Under this Regulation, those purposes should be strictly limited to the provision of financial products, financial services or financial information services. The processing of personal data must respect the principles of personal data protection, including lawfulness, fairness and transparency, purpose limitation and data minimisation. A customer has the right to withdraw the permission given to a data user at any time. For example, when data processing is necessary for the performance of a contract, a customer should be able to withdraw permissions according to the contractual obligations to which the data subject is party. Similarly, when personal data processing is based on consent, a data subject should be able to withdraw his or her consent at any time and free of charge, as provided for in Regulation (EU) 2016/679. It should not be possible for the data user to transfer customer data to a third party, or even to another entity within the same group, without such explicit permission.
RemovedIt is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added(11) Enabling customers to unlock and re-use their data on their current investments can encourage innovation in the provision of retail investment services. Primary data collection to complete a suitability and appropriateness assessment of a retail investor is time-intensive for a customer and constitutes a significant cost factor for advisors and distributors of investment, some types of pension, and insurance-based investment products. The re-use of customer data on holdings of savings and investments in financial instruments including insurance-based investment products and data collected for the purposes of carrying out a suitability and appropriateness assessment can improve investment advice for consumers and has strong innovative potential, including in the development of personalised investment advice and investment management tools that can make retail investment advice more efficient. Such management tools are already being developed in the market and can develop more effectively in the context where a customer can re-use their investment-related data.
RemovedRecital 15: (15) The access to data on occupational and personal pension savings has strong innovative potential for consumers that are current members or beneficiaries of occupational pension schemes. Pension savers often lack sufficient knowledge about their pension rights, which is related to the fact that data on such rights are often dispersed across different data holders. The access to and re-use of data related to occupational and personal pension savings should contribute to the development of pension tracking tools that provide savers with a comprehensive overview of their entitlements and retirement income both within specific Member States and cross-border in the Union. Data on pension rights concerns in particular accrued pension entitlements, projected levels of retirement benefits, risks and guarantees of members and beneficiaries of occupational pension schemes. Access to data related to occupational pensions is without prejudice to national social and labour law on the organisation of pension systems, including membership of schemes and the outcomes of collective bargaining agreements, and should take due regard to constraints in the payroll declaration and the cyclicality of pension administration processing time. To avoid duplicative data management costs, data holders that contribute to existing national pension tracking schemes should be permitted to use existing technical interfaces and common standards that have already been developed as part of these schemes in or…
Added(12) Customer data on balance, conditions or transaction details related to mortgages, loans and savings can enable customers to gain a better overview of their deposits and better meet their savings needs based on credit data. This Regulation should cover customer data beyond payment accounts defined in Directive (EU) 2015/2366. Credit accounts covered by a credit line which cannot be used for the execution of payment transactions to third parties should be within the scope of this Regulation. This Regulation does not cover payment account data that are covered by Regulation (EU) [.../...] of the European Parliament and of the Council.
RemovedSurvivors’ pensions provide a pension to family members of deceased pension fund members. It is clarified that only ‘current’ members of a pension funds should be regarded as consumers within the FiDA framework. Furthermore, pension data depend on the payroll declaration chain, which involves employers, pension funds and tax authorities. Such data cannot be updated continuously and in real-time. Lastly, it is suggested to avoid an unnecessary duplication of existing pension tracking services.
Added(12a) To ensure the right of investment firms, insurance undertakings and insurance intermediaries to protect undisclosed know-how and business information when distributing investment products, the scope of the obligation to share data under this Regulation should be limited to relevant data that has been collected from the customer by the financial institution in order to comply with the regulatory obligation to perform a suitability and appropriateness assessment in accordance with Article 25 of Directive 2014/65/EU and Article 30 of Directive (EU) 2016/97. This is limited to data collected from the customer by the financial institution for the purposes of assessing the customer’s knowledge and experience, financial situation, and investment objectives, as provided for in those provisions. This does not include the result of the suitability or appropriateness assessment itself made by the financial institution on the basis of the data collected from the customer, the suitability report given to a customer, or any analysis or preparatory work for the purposes of such report, which should be excluded from the scope of this Regulation.
RemovedRecital 17: (17) As this Regulation is meant to oblige financial institutions to provide access to defined categories of data at the expressed request of the customer when acting as data holders, and allow the access to and re-use of data based on customer explicit permission when financial institutions act as data users, it should provide a list of the financial institutions that may act as either a data holder, a data user or both. Financial institutions should therefore be understood to mean those entities that provide financial products and financial services or offer relevant information services to customers in the financial sector. A data user should be able to receive any category of customer data listed in Article 2(1) of this Regulation and does not become a data holder by virtue of accessing or otherwise receiving customer data from a data holder.
Added(13) The customer data included in the scope of this Regulation should include available information on sustainability-related preferences, where applicable, that should enable customers to more easily access financial services that are aligned with their sustainability preferences and sustainable finance needs, in line with the Commission’s strategy for financing the transition to a sustainable economy. Access to data relating to sustainability which may be contained in balance or transaction details related to a mortgage, credit, loan and savings account, insurance-based investment products, as well as access to customer data relating to sustainability held by investment firms, such as a customer’s initital sustainability preferences, can contribute to facilitating access to data needed to access sustainable finance or make investments into the green transition. Moreover, customer data in the scope of this Regulation should include data which forms part of a creditworthiness assessment related to firms, including small and medium sized enterprises, and which can provide greater insight into the sustainability objectives of small firms. The inclusion of data used for the creditworthiness assessment related to firms should improve access to financing and streamline the application for loans. Such data should be limited to data on firms and should not infringe intellectual property rights. Sustainability preferences should include sustainability preferences of a customer collected by insurance intermediaries distributing insurance-based investment products as defined in Article 2(4) of Commission Delegated Regulation (EU) 2021/1257, and sustainability preferences collected by investment firms as defined in Article 2(7) of Commission Delegated Regulation (EU) 2017/565.
RemovedIt is suggested to more clearly delineate the roles and responsibilities of the data holder and the data user by explicitly stating that a data user does not become a data holder by virtue of accessing customer data, as this would create an unlimited chain and could potentially lead to a massive and uncontrolled spread of FIDA data.
Added(14) Customer data related to the provision of non-life insurance are essential to enable insurance products and services important to the needs of customer like the protection of homes, vehicles, and other property. At the same time, the collection of such data is often burdensome and costly and can act as a deterrent against seeking optimal insurance coverage by customers. To address this problem, it is therefore necessary to include such financial services within the scope of this Regulation. Customer data on insurance products within scope of this Regulation should include both insurance product information such as detail on an insurance coverage and data specific to the consumers’ insured assets which are collected for the purposes of a demands and needs test. The access to and re-use of such data should allow for the development of personalised tools for customers, such as insurance dashboards that could help consumers better manage their risks. It could also help customers to obtain products that are better targeted to their demands and needs, including through more valuable advice. This can contribute to more optimal insurance coverage for customers and increased financial inclusion of otherwise underserved consumers, by offering new or increased coverage. Moreover, the unlocking and re-use of insurance data can be beneficial for more efficient supply of insurance including, in particular, at the stages of product design, underwriting, contract execution, including claims management, and risk mitigation.
RemovedRecital 18: (18) Practices employed by data users to combine new and traditional customer data sources in the scope of this Regulation must be in the best interest of the customer and proportionate to ensure that they do not lead to financial exclusion risks for consumers. Practices that lead to a more sophisticated or comprehensive analysis of certain vulnerable segments of consumers, such as persons with a low income, may increase the risk of unfair conditions or differential pricing practices like the charging of differential premiums. The potential for exclusion is increased in the provision of products and services that are priced according to the profile of a consumer, notably in credit scoring and the assessment of creditworthiness of natural persons as well for products and services related to the risk assessment and pricing of natural persons in the case of life and health insurance. Given the risks, the use and re-use of data for these products and services should be subject to specific requirements to protect consumers and their fundamental rights.
Added(15) The access to of data on occupational and personal pension savings can create added value for consumers that are members or beneficiaries of occupational pension schemes. Especially in the absence of national pension tracking systems, pension savers often lack sufficient knowledge about their pension rights, which is related to the fact that data on such rights are often dispersed across different data holders. The access to and re-use of data related to occupational and personal pension savings should contribute to the development of pension tracking tools that provide savers with a comprehensive overview of their entitlements and retirement income both within specific Member States and cross-border in the Union or to the alignment of such access and re-use in terms of content and data formats with existing pension tracking systems that include entitlements from public and occupational pension schemes and in some cases also personal schemes. Alignment is also desirable with regard to emerging forms of data exchange between national pension tracking systems, in particular the European Tracking System. Data on pension rights concerns in particular accrued pension entitlements, projected levels of retirement benefits, risks and guarantees of members and beneficiaries of occupational pension schemes. Access to data related to occupational pensions is without prejudice to national social and labour law on the organisation of pension systems, including membership of schemes and the outcomes of collective bargaining agreements. To avoid duplicative data management costs, data holders that contribute to existing national pension tracking schemes should be permitted to use existing technical interfaces and common standards that have already been developed as part of these schemes in order to fulfil the obligations under this Regulation.
RemovedData use should always be in the best interest of the customer.
Added(16) Data which forms part of a creditworthiness assessment of a firm in the scope of this Regulation should consist of information which a firm provides to institutions and creditors as part of the loan application process ▌. This includes loan applications of micro, small, medium and large enterprises. It may include data collected by institutions and creditors as set out in Annex II of the European Banking Authority Guidelines on loan origination and monitoring. Such data may include financial statements and projections, information on financial liabilities and arrears in payment, evidence of ownership of the collateral, evidence of insurance of the collateral and information on guarantees. Additional data may be relevant if the purpose of the loan application relates to the purchase of commercial real estate or real estate development.
RemovedRecital 21: (21) Customers must have effective control over their data and confidence in managing permissions they have granted in accordance with this Regulation. Data holders should therefore be required to provide customers with common and consistent financial data access permission dashboards. The permission dashboard should empower the customer to manage their permissions in an informed and impartial manner and give customers a strong measure of control over how their personal and non-personal data is used. It should not be designed in a way that would encourage or unduly influence the customer to grant or withdraw permissions. For example, the procedure to withdraw permission should not be made more difficult than the procedure to give permission for access to data. The permission dashboard should take into account, where appropriate, the accessibility requirements under Directive (EU) 2019/882 of the European Parliament and of the Council14 . When providing a permission dashboard, data holders could use a notified electronic identification and trust service, such as a European Digital Identity Wallet issued by a Member State as introduced by the proposal amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity15 . Data holders may also rely on data intermediation service providers under Regulation (EU) 2022/868 of the European Parliament and of the Council16 , to provide permission dashboards that fulfil the requirements of this Regu…
Added(16a) Data required to conduct know-your-customer processes by financial firms, including SMEs, can be valuable when on-boarding new customers. Therefore, the access to and re-use of such data could significantly contribute to lowering barriers to switching providers and therefore result in increased competition and innovation for financial products and services to the benefit of customers.
RemovedThe procedure to withdraw a permission should not be more cumbersome than the procedure to grant a permission.
Added(17) As this Regulation is meant to oblige financial institutions to provide access to defined categories of data at the expressed request of the customer when acting as data holders, and allow the access to and re-use of data based on customer explicit permission when financial institutions act as data users, it should provide a list of the financial institutions that may act as either a data holder, a data user or both. Financial institutions should therefore be understood to mean those entities that provide financial products and financial services or offer relevant information services to customers in the financial sector. A data user that is a financial information service provider should not become a data holder by virtue of accessing or otherwise receiving customer data from a data holder.
RemovedRecital 22: (22) The permission dashboard should display the permissions given by a customer, including when personal data are accessed based on consent or are necessary for the performance of a contract. The permission dashboard should warn a customer in a standard way of the risk of possible contractual consequences of the withdrawal of a permission, but the customer should remain responsible for managing such risk. The permission dashboard should be used to manage existing permissions. Data holders should inform data users in real-time of any withdrawal of a permission. When a permission is re-established, data holders should inform customers, or enable data users to inform customers, of the terms and conditions applicable at that time. The permission dashboard should include a record of permissions that have been withdrawn or have expired for a period of up to two years to allow the customer to keep track of their permissions in an informed and impartial manner. Data users should inform data holders in real-time of new and re-established permissions granted by customers, including the duration of validity of the permission and a short summary of the purpose of the permission. The information provided on the permission dashboard is without prejudice to the requirements under Regulation (EU) 2016/679, in particular the information requirement.
Added(18) Practices employed by data users to combine new and traditional customer data sources in the scope of this Regulation must be in the best interest of the customer and proportionate to ensure that they do not lead to financial exclusion risks for consumers. Practices that lead to a more sophisticated or comprehensive analysis of certain vulnerable segments of consumers, such as persons with a low income, may increase the risk of unfair conditions or differential pricing practices like the charging of differential premiums. The potential for exclusion is increased in the provision of products and services that are priced according to the profile of a consumer, notably in credit scoring and the assessment of creditworthiness of natural persons as well for products and services related to the risk assessment and pricing of natural persons in the case of life and health insurance. Given the risks, the use and re-use of data for these products and services should be subject to specific requirements to protect consumers and their fundamental rights.
RemovedThe permission provided by a customer creates a legal relationship between a data user and the customer, which is subject to the terms agreed to between the data user and the customer at the time of the permission. A customer should be informed of the applicable terms also when a permission is re-established. Furthermore, all GDPR requirements should be taken into account.
Added(19) The data use perimeter thus established in this Regulation and in the accompanying regulatory technical standards and guidelines ▌to be developed by the European Banking Authority (EBA) and the European Insurance and Occupational Pensions Authority (EIOPA) should provide a proportionate framework on how personal data related to a consumer that falls within the scope of this Regulation should be used. The data use perimeter ensures consistency between the scope of this Regulation, which excludes data that forms part of a creditworthiness assessment of a consumer as well as data related to life, health and sickness insurance of a consumer, and the scope of the regulatory technical standards and guidelines, which set recommendations on how types of data originating from other areas of the financial sector that are in scope of this Regulation can be used to provide these products and services. The regulatory technical standards and guidelines developed by ▌ EBA should set out how other types of data that are in scope of this Regulation can be used to assess the credit score of a consumer. The regulatory technical standards and guidelines developed by EIOPA should set out how data in scope of this Regulation can be used in products and services related to risk assessment and pricing in the case of life, health and sickness insurance products. The regulatory technical standards and guidelines should be developed in a manner that is aligned to the needs of the consumer and proportionate to the provision of such products and services.
RemovedRecital 24: (24) This Regulation introduces a new legal obligation on financial institutions, when members of a financial data access scheme are acting as data holders, to provide data users with access to defined categories of data which are available in digital form. The obligation on data holders to provide access to data at the expressed request of the customer should be specified by making available generally recognised standards to also ensure that the data accessed is of a sufficiently high quality. The data holder should make customer data available only for the purposes and under the conditions for which the customer has explicitly granted permission to a data user for a specific service which is clearly identified by the customer, where relevant and technically feasible, on a continuous basis and in real-time. Continuous access could consist of multiple requests to make customer data available to fulfil the service agreed with the customer. It could also consist of a one-off access to customer data. While the data holder is responsible for the interface to be available and for the interface to be of adequate quality, the interface may be provided not only by the data holder but also by another financial institution, an external IT provider, an industry association or a group of financial institutions, or by a public body in a member state. For institutions for occupational retirement provision, the interface can be integrated into pension dashboards or existing pension tracking…
Added(20) EBA and EIOPA should closely cooperate with the European Data Protection Board when drafting the guidelines, which should build on existing recommendations on the use of consumer information in the area of consumer and mortgage credit, notably the rules on use of creditworthiness assessment under Directive 2008/48/EC of the European Parliament and of the Council of 23 April 2008 on credit agreements for consumers and repealing Council Directive 87/102/EEC, the European Banking Authority’s Guidelines on loan origination and monitoring, and the European Banking Authority guidelines on creditworthiness assessment developed under Directive 2014/17/EU, as well guidelines provided by European Data Protection Board on the processing of personal data.
RemovedCustomers should give explicit permission to grant access to their data. Furthermore, data should be available in digital form. Lastly, it is suggested to avoid an unnecessary duplication of existing pension tracking services.
Added(21) Customers must have effective control over their data and confidence in managing permissions they have granted in accordance with this Regulation. Data holders should therefore be required to provide customers with common and consistent financial data access permission dashboards. The permission dashboard should empower the customer to manage their permissions in an informed and impartial manner and give customers a strong measure of control over how their personal and non-personal data is used. It should not be designed in a way that would encourage or unduly influence the customer to grant or withdraw permissions. For example, the procedure to withdraw permission should not be made more difficult than the procedure to give permission for access to data. The data user should be responsible for the accuracy of the data provided to the data holder to fulfil its requirements with regards to the display of new permissions granted by the customer on the permission dashboard. The permission dashboard should take into account, where appropriate, the accessibility requirements under Directive (EU) 2019/882 of the European Parliament and of the Council. When providing a permission dashboard, data holders could use a notified electronic identification and trust service, such as a European Digital Identity Wallet issued by a Member State as introduced by the proposal amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity. Data holders may also rely on data intermediation service providers under Regulation (EU) 2022/868 of the European Parliament and of the Council, to provide permission dashboards that fulfil the requirements of this Regulation.
RemovedRecital 25: (25) In order to enable the contractual and technical interaction necessary for implementing data access between multiple financial institutions, data holders and data users should be required to be part of financial data access schemes. These schemes should develop data and interface standards, joint standardised contractual frameworks governing access to specific datasets, and governance rules related to data access and re-use. In order to ensure that schemes function effectively, it is necessary to establish general principles for the governance of these schemes, including rules on inclusive governance and participation of data holders, data users and customers (to ensure balanced representation in schemes), transparency requirements, and a well-functioning appeal and review procedure (notably around the decision-making of schemes). Financial data access schemes must comply with Union rules in the area of consumer protection and data protection, privacy, and competition. The participants in such schemes are also encouraged to draw up codes of conduct in accordance with Article 40 of Regulation (EU) 2016/679. While such schemes may build upon existing market initiatives, the requirements set out in this Regulation should be specific to financial data access schemes or parts thereof which market participants use to fulfil their obligations under this Regulation after the data of application of these obligations.
Added(22) The permission dashboard should display the permissions given by a customer, including when personal data are accessed based on consent or are necessary for the performance of a contract. The permission dashboard should warn a customer in a standard way of the risk of possible contractual consequences of the withdrawal of a permission, but should not encourage or influence a customer to grant access in a way that materially distorts or impairs their ability to make a free and informed decision, as the customer should remain responsible for managing such risk. To allow consumers to effectively stay in control of their data, the deployment of dark patterns and pre-ticked boxes in dashboards should be prohibited for the purpose of providing permissions to enable data access. The permission dashboard should be used to manage existing permissions. Data holders should inform data users in real-time of any withdrawal of a permission. The permission dashboard should include a record of permissions that have been withdrawn or have expired for a period of up to two years to allow the customer to keep track of their permissions in an informed and impartial manner. Data users should inform data holders in real-time of new and re-established permissions granted by customers, including the duration of validity of the permission and a short summary of the purpose of the permission. The information provided on the permission dashboard is without prejudice to the ▌requirements under Regulation (EU) 2016/679, in particular the information requirements. The permission dashboard may be combined with the permission dashboard established under Regulation ... [the Payment Services Regulation].
RemovedThe “in accordance with” follows a suggestion made by the EDPS in its opinion (point 47). The clarification aims at improving clarity and consistency.
Added(23) To ensure proportionality, certain financial institutions are out of the scope of this Regulation for reasons associated with their size or the services they provide, which would make it too difficult to comply with this regulation. These include institutions for occupational retirement provision which operate pension schemes which together do not have more than 15 members in total, as well as insurance intermediaries who are microenterprises or small or medium-sized enterprises. In addition, small or medium-sized enterprises acting as data holders that are within the scope of this Regulation should be allowed to establish an application programming interface jointly, reducing the costs for each of them. They can also avail themselves of external technology providers which run application programming interfaces in a pooled manner for financial institutions and may charge them only a low fixed usage fee and work largely on a pay-per-call basis. This Regulation should not apply to small enterprises until after ... [12 months from the date of application of this Regulation]. Small enterprises may at their own initiative choose to apply this Regulation before the deadline of the entry into force of this obligation. This could be important to ensure proportionate involvement of smaller enterprises in the development of financial data access schemes.
RemovedRecital 26: (26) A financial data access scheme should consist of a collective contractual agreement between data holders and data users with the objective of promoting efficiency and technical innovation in financial data access to the benefit of customers. In line with Union rules on competition, a financial data access scheme should only impose on its members restrictions which are necessary to achieve its objectives and which are proportionate to those objectives. It should not afford its members the possibility of preventing, restricting or distorting competition in respect of a substantial part of the relevant market.
Added(24) This Regulation introduces a new legal obligation on financial institutions acting as data holders to share provide data users with access to defined categories of data at request of the customer. The obligation on data holders to provide access to data at the expressed request of the customer should be specified by making available generally recognised standards to also ensure that the data accessed is of a sufficiently high quality. The data holder should make customer data available only for the purposes and under the conditions for which the customer has explicitly granted permission to a data user for a specific service clearly identified by the customer, where relevant and technically feasible continuously and in real-time. Continuous access should be strictly limited to the purposes for which the customer has granted permission. It could consist of multiple requests to make customer data available to fulfil the service agreed with the customer. It could also consist of a one-off access to customer data. Real-time access should not oblige a data holder to instantly update an account, policy or contract of a customer. The obligation of a data holder to make customer data available in real-time concerns the rate of access at which data should be transmitted to a customer or a data user. Customer data should be made available in the state that it is held by the data holder at the time access is requested by a data user. Real time access, for instance, is without prejudice to constraints in the payroll declaration and the cyclicity of pension administration processing time. While the data holder is responsible for the interface to be available and for the interface to be of adequate quality, the interface may be provided not only by the data holder but also by another financial institution, an external IT provider, an industry association or a group of financial institutions, or by a public body in a member state. For institutions for occupational retirement provisions, the interface can be integrated into pension dashboards or existing pension tracking services that cover a broader range of information, as long as it complies with the requirements of this Regulation.
RemovedIt is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added(25) In order to enable the contractual and technical interaction necessary for implementing data access between multiple financial institutions, data holders and data users should be required to be part of financial data access schemes. These schemes should develop data and interface standards, joint standardised contractual frameworks governing access to specific datasets, and governance rules related to data access and re-use. In order to ensure that schemes function effectively across the internal market, it is necessary to establish general principles for the governance of these schemes, including rules on inclusive governance and participation of data holders, data users and customers (to ensure balanced representation in schemes), transparency requirements, and a well-functioning appeal and review procedure (notably around the decision-making of schemes). Financial data access schemes must comply with Union rules in the area of consumer protection and data protection, privacy, and competition. The participants in such schemes are also encouraged to draw up codes of conduct in accordance with Article 40 of Regulation (EU) 2016/679. While such schemes may build upon existing market initiatives, the requirements set out in this Regulation should be specific to financial data access schemes or parts thereof which market participants use to fulfil their obligations under this Regulation after the data of application of these obligations.
RemovedRecital 28: (28) Data holders and data users should be allowed to use existing market standards and infrastructures for technical interfaces like application programming interfaces when developing common standards for mandatory data access.
Added(26) A financial data access scheme should consist of a collective contractual agreement between data holders and data users with the objective of promoting efficiency and technical innovation in financial data access to the benefit of customers. In line with Union rules on competition, a financial data access scheme should only impose on its members restrictions which are necessary to achieve its objectives and which are proportionate to those objectives. It should not afford its members the possibility of preventing, restricting or distorting competition in respect of a substantial part of the relevant market. In the setting up of financial data access schemes, all parties to the schemes should be involved. The Commission and competent authorities should also be available for consultation by those setting up the schemes, and be ready to offer advice on best practice and examples of other schemes set up during the period running up to the application of this Regulation. A financial data access scheme that is developed by scheme members established in the same Member State should be notified to the competent authority of the Member State of establishment. In accordance with the obligations of this Regulation, financial data access schemes that are national in composition should remain open to participation of new members on the same terms and conditions as those for existing members. Where the membership of such a financial data access scheme changes due to the addition of data holders and data users that are established in another Member State, the scheme should be notified to the European Banking Authority established by Regulation (EU) No 1093/2010 (EBA), the European Insurance and Occupational Pensions Authority established by Regulation (EU) No 1094/2010 (EIOPA) and the European Securities and Markets Authoriy established by Reguulation (EU) No 1095/2010, of the European Parliament and of the Council (together referred to as the ‘ESAs’). However, where changes to the membership of a financial data access scheme result in all members being established in the same Member State, the scheme should be notified to the competent authority of that Member State. All changes should be notified to the electronic central register maintained by EBA.
RemovedIt is suggested that the industry may build on existing infrastructures for technical interfaces, as this could be a cost-efficient method to ensure an efficient transition for financial institutions that may be out of scope of PSD3 but in scope of FiDA.
Added(27) In order to ensure the effectiveness of this Regulation, the power to adopt acts in accordance with Article 290 of the Treaty on the Functioning of the European Union should be delegated to the Commission in respect of specifying the modalities and characteristics of a financial data access scheme in case a scheme is not completely developed by the data holders and the data users. Before adopting such a delegated act, the Commisison should consult the European Data Protection Board and all relevant stakeholders and submit a report to the European Parliament and the Council setting out any grounds for intervention. It is of particular importance that the Commission carry out appropriate consultations during its preparatory work, including at expert level, and that those consultations be conducted in accordance with the principles laid down in the Interinstitutional Agreement of 13 April 2016 on Better Law-Making. In particular, to ensure equal participation in the preparation of delegated acts, the European Parliament and the Council receive all documents at the same time as Member States' experts, and their experts systematically have access to meetings of Commission expert groups dealing with the preparation of delegated acts.
RemovedRecital 29: (29) To ensure that data holders have an interest in investing in and providing high quality interfaces for making data available to data users, while at the same time avoiding excessive burdens on access to and the use of data which make data access no longer commercially viable, data holders should be able to request reasonable compensation from data users for costs incurred in providing access to the data, including the costs related to putting in place and maintaining application programming interfaces. Facilitating data access against compensation would ensure a fair distribution of the related costs between data holders and data users in the data value chain. In cases where the data user is an SME, proportionality for smaller market participants should be ensured by limiting compensation strictly to the costs incurred for facilitating data access, while ensuring that there are sufficient incentives to foster market adoption and effective competition. The model for determining the level of compensation should be defined as part of the financial data access schemes as provided in this Regulation. In accordance with Regulation (EU) [XXXX/XXXX] (Data Act), the Commission should adopt guidelines on the calculation of reasonable compensation.
Added(28) Data holders and data users should be allowed to use existing market standards and infrastructures for technical interfaces like application programming interfaces when developing common standards for mandatory data access. The European Data Innovation Board should issue guidelines to ensure Union-wide interoperable data standards related to customer data in the scope of this Regulation.
RemovedCloser alignment with Data Act (recital 46).
Added(29) To ensure that data holders have an interest in investing in and providing high quality interfaces for making data available to data users, while at the same time avoiding excessive burdens on access to and the use of data which make data access no longer commercially viable, data holders should be able to request reasonable compensation from data users for costs incurred in providing access to the data, including the costs related to putting in place and maintaining application programming interfaces. Facilitating data access against compensation would ensure a fair distribution of the related costs between data holders and data users in the data value chain. In cases where the data user is an SME, proportionality for smaller market participants should be ensured by limiting compensation strictly to the costs incurred for facilitating data access, while ensuring that there are sufficient incentives to foster market adoption and effective competition. The model for determining the level of compensation should be defined as part of the financial data access schemes as provided in this Regulation. The model should take into account levels of compensation prevalent in the market, including in market-led initiatives. In accordance with Regulation (EU) 2023/2854 of the European Parliament and of the Council, the Commission should adopt guidelines on the calculation of reasonable compensation.
Change 4
ChangedRecital 30: (30) Customers should know what their rights are in case problems arise when data is accessed and who to approach to seek compensation. Financial data access scheme members, including data holders and data users, should therefore be required to agree on the contractual liability for data breaches, customer compensation when data is misused, including when it is transferred to a third-partythird party without the customer’s explicit permission, as well as how to resolve potential disputes between data holders and data users regarding liability. Those requirements should focus on establishing, as part of any contract, liability rules as well as clear obligations and rights to determine liability between the data holder and the data user. Liability issues related to the consumers as data subjects should be based on Regulation (EU) 2016/679, notably the right to compensation and liability under Article 82 of that Regulation.
Change 5
RemovedFinancial data access schemes should provide compensation to customers in case of misuse of customer data.
Added(31) To promote consumer protection, enhance customer trust and ensure a level playing field, it is necessary to lay down rules on who is eligible to access customers’ data. Such rules should ensure that all data users are authorised and supervised by competent authorities. This would ensure that data can be accessed only by regulated financial institutions or by firms subject to a dedicated authorisation as financial information service providers’ (‘FISPs’) which is subject to this Regulation. Eligibility rules on FISPs, are needed to safeguard financial stability, market integrity and consumer protection, as FISPs would provide financial information services to customers in the Union and would access data held by financial institutions and the integrity of which is essential to preserve the financial institutions’ ability to continue providing financial services in a safe, sound and secure manner. Such rules are also required to guarantee the proper supervision of FISPs by competent authorities in line with their mandate to safeguard financial stability and integrity in the Union, which would allow FISPs to provide throughout the Union the financial information services for which they are authorised. FISPs should not use their license as financial information service providers to conduct activities regulated by existing sector-specific legislation. For example, they should not be authorised to provide financial advice regulated under Directive 2014/65/EU or carry out insurance distribution activities regulated under Directive (EU) 2016/97.
Change 6
ChangedRecital 32: (32) Data users within the scope of this Regulation should be subject to the requirements of Regulation (EU) 2022/2554 of the European Parliament and of the Council18Council and therefore be obliged to have strong cyber resilience standards in place to carry out their activities. This includes having comprehensive capabilities to enable a strong and effective information and communication technology (ICT) risk management, as well as specific mechanisms and policies for handling all ICT-related incidents and for reporting major ICT-related incidents. Data users authorised and supervised as financial information service providers under this Regulation should follow the same approach and the same principle-based rules when addressing ICT risks taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations. Financial information service providers should therefore be included in the scope of Regulation (EU) 2022/2554.
Change 7
RemovedIntroduction of the abbreviation “ICT”.
Added(33) In order to enable effective supervision and to eliminate the possibility of evading or circumventing supervision, financial information service providers must be ▌legally incorporated in the Union▌. An effective supervision by the competent authorities is necessary for the enforcement of requirements under this Regulation to ensure integrity and stability of the financial system and to protect consumers. ▌
RemovedRecital 33: (33) In order to enable effective supervision and to eliminate the possibility of evading or circumventing supervision, financial information service providers must only be provided by legal persons that have a registered office in a Member State in which they intend to carry out or do carry out substantive business activities . An effective supervision by the competent authorities is necessary for the enforcement of requirements under this Regulation to ensure integrity and stability of the financial system and to protect consumers. The requirement of legal incorporation of financial information service providers in the Union does not amount to data localisation since this Regulation does not entail any further requirement on data processing including storage to be undertaken in Union.
Added(34) A financial information service provider should be authorised in the jurisdiction of the Member State where its main establishment is located, that is, where the financial information service provider has its head office or registered office within which the principal functions and operational control are exercised. ▌
RemovedTo maintain a level playing field, in order not to jeopardise effective supervision of these new actors, and to protect customers against possible misuse of their data, is suggested to remove the possibility for undertakings that are not established in the EU to benefit from an authorisation as a FISP. Third country providers should not be allowed to conduct activities if they are not properly licensed for such activities in a specific member state. Such option does not exist under PSD2 either for e.g. AISPs and would therefore result in a discriminatory situation between FISPs and AISPs.
Added(35) To facilitate transparency regarding data access and financial information service providers, EBA should establish a register of financial information service providers authorised under this Regulation, as well as financial data ▌ access schemes agreed between data holders and data users.
RemovedRecital 34: (34) A financial information service provider should be authorised in the jurisdiction of the Member State where its main establishment is located, that is, where the financial information service provider intends to carry out substantive business activities and where it has its head office or registered office within which the principal functions and operational control are exercised.
Added(36) Competent authorities should be conferred with the powers necessary to supervise the way the compliance of the obligation on data holders to provide access to customer data established by this Regulation is exercised by market participants, as well as to supervise financial information service providers. Access relevant data traffic records held by a telecommunications operator as well as the ability to seize relevant documents on premises are important and necessary powers to detect and prove the existence of breaches under this Regulation. Competent authorities should therefore have the power to require such records where they are relevant to an investigation, insofar as permitted under national law. Competent authorities should also cooperate with the supervisory authorities established under Regulation (EU) 2016/679 in the performance of their tasks and the exercise of their powers in accordance with that Regulation.
RemovedIn order to maintain a level playing field, not to jeopardise effective supervision of these new actors, and to protect customers against possible misuse of their data, is suggested to remove the possibility for undertakings that are not established in the EU to benefit from an authorisation as a FISP. Third country providers should not be allowed to conduct activities if they are not properly licensed for such activities in a specific member state. Such option does not exist under PSD2 either for e.g. AISPs and would therefore result in a discriminatory situation between FISPs and AISPs.
Added(37) Since financial institutions and financial information service providers can be established in different Member States and supervised by different competent authorities, the application of this Regulation should be facilitated by close cooperation among relevant competent authorities, through the mutual exchange of information and the provision of assistance in the context of the relevant supervisory activities.
RemovedRecital 35: (35) To facilitate transparency regarding data access and financial information service providers, the European Supervisory Authorities should establish a register of financial information service providers authorised under this Regulation, as well as financial data access schemes agreed between data holders and data users.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=2
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=2 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
author = {{European Parliament}},
title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
year = {2024},
date = {2024-04-30},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=2}},
url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=2},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}