Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-757355 → A-9-2024-0183

From
ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
To
A-9-2024-0183 Plenary report of 30 Apr 2024
Changes
Not comparable
Paragraphs
+506 added · −357 removed · 7 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 3 of 16: Paragraphs 121–180

Added(38) To ensure a level playing field in the area of sanctioning powers, Member States should be required to provide for effective, proportionate and dissuasive administrative sanctions, including periodic penalty payments, and administrative measures for the infringement of provisions of this Regulation. Those administrative sanctions, periodic penalty payments and administrative measures should meet certain minimum requirements, including the minimum powers that should be vested on competent authorities to be able to impose them, the criteria that competent authorities should consider when imposing them, and the obligation to publish and report. Member States should lay down specific rules and effective mechanisms regarding the application of periodic penalty payments.

RemovedIt is suggested that the ESAs should be jointly responsible for the register.

Added(39) In addition to administrative sanctions and administrative measures, competent authorities should be empowered to impose periodic penalty payments on financial information services providers and on those members of their management body who are identified as responsible for an ongoing infringement or who are required to comply with an order from an investigating competent authority. Since the purpose of the periodic penalty payments is to compel natural or legal persons to comply with an order from the competent authority to act, for example to accept to be interviewed or to provide information, or to terminate an ongoing breach, the application of periodic penalty payments should not prevent competent authorities from imposing subsequent administrative sanctions for the same infringement. Unless otherwise provided for by Member States, periodic penalty payments should be calculated on a daily basis.

RemovedRecital 47: (47) The Data Act [Regulation (EU) XX] establishes a horizontal framework for access to and use of data across the Union. This Regulation complements and specifies the rules laid down in the Data Act [Regulation (EU) XX] Therefore those rules also apply to the access of data governed by this Regulation. This includes provisions on the conditions under which data holders make data available to data recipients, on compensation, dispute settlement bodies to facilitate agreements between data access parties, technical protection measures, international access and transfer of data and on authorised use or disclosure of data.

Added(40) Irrespective of their denomination under national law, forms of expedited enforcement procedure or settlement agreements are to be found in many Member States and are used as an alternative to formal proceedings leading to imposing sanctions. An expedited enforcement procedure usually starts after an investigation has been concluded and the decision to start proceedings leading to imposing sanctions has been taken. An expedited enforcement procedure is characterised by being shorter than a formal one, due to simplified procedural steps. Under a settlement agreement usually the parties subject to the investigation by a competent authority agree to end that investigation early, in most cases by accepting liability for wrongdoing.

RemovedThe Data Act has meanwhile been adopted; publication in the OJ is forthcoming. Furthermore, it is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.

Added(41) While it does not appear appropriate to strive to harmonise at Union level such expedited enforcement procedures, which were introduced by many Member States, due to the varied legal approaches adopted at national level, it should be acknowledged that such methods allow competent authorities that can apply them, to handle infringement cases in a speedier, less costly and overall efficient way under certain circumstances, and should therefore be encouraged. However, Member States should not be obliged to introduce such enforcement methods in their legal framework nor should competent authorities be compelled to use them if they do not deem it appropriate. Where Member States choose to empower their competent authorities to use such enforcement methods, they should notify the Commission of such decision and of the relevant measures regulating such powers.

RemovedRecital 48: (48) Processing of personal data in the context of this Regulation should be carried out in accordance with Regulation (EU) 2016/679 and Regulation (EU) 2018/1725, as well as, where applicable, with Directive 2002/58/EC of the European Parliament and of the Council1a (ePrivacy Directive). Regulation (EU) 2016/679 provides for the rights of a data subject, including the right of access and right to port personal data. This Regulation is without prejudice to the rights of a data subject provided under Regulation (EU) 2016/679, including the right of access and right to data portability. This Regulation creates a legal obligation to provide access to and enable re-use of customer personal and non-personal data upon customer’s request and mandates the technical feasibility of access for all types of data within the scope of this Regulation. The granting of permission by a customer is without prejudice to the obligations of data users under Article 6 of Regulation (EU) 2016/679. Permission should not be construed as ‘consent’ or ‘necessity for the performance of a contract’ as defined in Regulation (EU) 2016/679. Personal data that are made available to a data user should only be processed for services provided by a data user where there is a valid legal basis under Article 6(1) of Regulation (EU) 2016/679 and, when applicable, where the requirements of Article 9 of that Regulation on the processing of special categories of data are met. / 1a Directive 2002/58/EC of the European P…

Added(42) National competent authorities should be empowered by Member States to impose such administrative sanctions and administrative measures to financial information service providers and other natural or legal persons where relevant to remedy the situation in the case of infringement. The range of sanctions and measures should be sufficiently broad to allow Member States and competent authorities to take account of the differences between financial information service providers, as regards their size, characteristics and the nature of their business.

RemovedSuggestions made by the EDPS in its opinion (points 9 and 18). It is useful to add clearer guidance on the interaction between the FiDA permission mechanism and the GDPR legal basis.

Added(43) The publication of an administrative penalty or measure for infringement of provisions of this Regulation can have a strong dissuasive effect against repetition of such infringement. Publication also informs other entities of the risks associated with the sanctioned financial information service provider before entering into a business relationship and assists competent authorities in other Member States in relation to the risks associated with a financial information service provider when it operates in their Member States on a cross-border basis. For those reasons, the publication of decisions on administrative penalties and administrative measures should, be allowed as long as it concerns legal persons. In taking a decision whether to publish an administrative penalty or administrative measure, competent authorities should take into account the gravity of the infringement and the dissuasive effect that the publication is likely to produce. However, any such publication referred to natural persons may impinge on their rights stemming from the Charter of Fundamental Rights and the applicable Union data protection legislation in a disproportionate manner. Publication should occur in an anonymised way unless the competent authority deems it necessary to publish decisions containing personal data for the effective enforcement of this Regulation, including in the case of public statements or temporary bans. In such cases the competent authority should justify its decision.

RemovedRecital 50: (50) This Regulation does not affect the provisions related to data access in Union financial services legislation, namely the following: (i) the provisions on access to benchmarks and the access regime for exchange-traded derivatives between trading venues and Central Counterparties laid down in Regulation (EU) No 600/2014 of the European Parliament and of the Council22 ; (ii) the rules on access of creditors to the database under Directive 2014/17/EU of the European Parliament and of the Council23 ; (iii) the rules on access to securitisation repositories under Regulation (EU) 2017/2402 of the European Parliament and of the Council24 ; (iv) the rules on the right to request from the insurer a claims history statement and on the access to central repositories to basic data necessary for the settlement of claims under Directive 2009/103/EC of the European Parliament and of the Council25 ; (v) the right to access and transfer all necessary personal data to a new pan-European Personal Pension Product provider under Regulation (EU) 2019/1238 of the European Parliament and of the Council26 ; and (vi) the provisions on outsourcing and reliance under Directive (EU) 2018/843 of the European Parliament and of the Council27 . Furthermore, this Regulation does not affect the application of EU or national rules of competition of the Treaty on the Functioning of the European Union and any secondary Union acts. This Regulation is also without prejudice to accessing and using data without …

Added(44) The exchange of information and the provision of assistance between competent authorities of the Member States is essential for the purposes of this Regulation. Consequently, cooperation between authorities should not be subject to unreasonable restrictive conditions.

RemovedIt is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.

Added(45) The cross-border access to data by information service providers should be allowed pursuant to the freedom to provide services or the freedom of establishment. A financial information service provider wishing to have access to data held by a data holder in another Member State, should notify its intention to its competent authority, providing information on the type of data it wishes to access, the financial data access scheme of which it is a member and the Member States in which it intends to access the data.

RemovedRecital 51: (51) As the access to data related to payment accounts is regulated under a different regime set out in Directive (EU) 2015/2366, it is deemed appropriate to set, in this Regulation, a review clause for the Commission to examine whether the introduction of the rules under this Regulation impacts the way AISPs access data and whether it would be appropriate to streamline the rules governing the access of data applicable to AISPs.

Added(46) The objectives of this Regulation, namely giving effective control of data to the customer and addressing the lack of rights of access to customer data held by data holders, cannot be sufficiently achieved by the Member States given their cross-border nature but can rather be better achieved at Union level, by means of the creation of a framework through which a larger cross-border market with data access could be developed. The Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve those objectives.

RemovedIt is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.

Added(47) Regulation (EU) 2023/2854 (Data Act) ▌establishes a horizontal framework for access to and use of data across the Union. This Regulation complements and specifies the rules laid down in Regulation (EU) 2023/2854. Therefore those rules also apply to the access of data governed by this Regulation. This includes provisions on the conditions under which data holders make data available to data recipients, on compensation, dispute settlement bodies to facilitate agreements between data access parties, technical protection measures, international access and transfer of data and on authorised use or disclosure of data.

RemovedRecital 52: (52) Given that EBA, EIOPA and ESMA should govern all objectives of this Regulation and be mandated to make use of their powers in relation to financial information service providers, it is necessary to ensure that they are able to exercise all of their powers and tasks in order to fulfil their objectives of protecting the public interest by contributing to the short, medium and long-term stability and effectiveness of the financial system, for the Union economy, its citizens and businesses and to ensure that financial information service providers are covered by Regulations (EU) No 1093/201028 , (EU) No 1094/201029 and (EU) No 1095/201030 of the European Parliament and of the Council. Those Regulations should therefore be amended accordingly.

Added(48) Processing of personal data in the context of this Regulation should be carried out in accordance with Regulation (EU) 2016/679 and Regulation (EU) 2018/1725, as well as, where applicable, with Directive 2002/58/EC of the European Parliament and of the Council andRegulation (EU) 2016/679 provides for the rights of a data subject, including the right of access and right to port personal data. This Regulation is without prejudice to the rights of a data subject provided under Regulation (EU) 2016/679, including the right of access and right to data portability. This Regulation creates a legal obligation to provide access to and enable re-use of customer personal and non-personal data upon customer’s request and mandates the technical feasibility of access ▌for all types of data within the scope of this Regulation. The granting of permission by a customer is without prejudice to the obligations of data users under Article 6 of Regulation (EU) 2016/679 notably permission should not be construed as consent or as necessity for the performance of a contract. Personal data that are made available to a data user should only be processed for services provided by a data user where there is a valid legal basis under Article 6(1) of Regulation (EU) 2016/679 and, when applicable, where the requirements of Article 9 of that Regulation on the processing of special categories of data are met. In the case of mixed datasets, where personal and non-personal data are inextricably linked, the protections in Union data protection legislation and in this Regulation concerning personal data should be fully applicable.

RemovedIt is important that the ESAs govern all the FiDA objectives. This was not or insufficiently the case for the EBA and PSD2, which created significant difficulties with the implementation of that Directive.

Added(49) This Regulation builds upon and complements the ‘open banking’ provisions under Directive (EU) 2015/2366 and is fully consistent with Regulation (EU) …/202.. of the European Parliament and of the Council on payment services and amending Regulation (EU) No 1093/2010 and Directive (EU) …/202.. of the European Parliament and of the Council on payment services and electronic money services amending Directives 2013/36/EU and 98/26/EC and repealing Directives 2015/2355/EU and 2009/110/EC. The initiative complements the already existing ‘open banking’ provisions under Directive (EU) 2015/2366 that regulate access to payment account data held by account servicing payment service providers. It builds on the lessons learned on ‘open banking’ as identified in the review of Directive 2015/2366/EU. This Regulation ensures coherence between financial data access and open banking where additional measures are necessary, including on permission dashboards, the legal obligations to grant direct access to customer data, and the requirement for data holders to put in place interfaces.

RemovedRecital 54: (54) The European Data Protection Supervisor was consulted in accordance with Article 42(2) of Regulation (EU) 2018/1725 of the European Parliament and of the Council31 and delivered an opinion on 22 August 2023.

Added(50) This Regulation does not affect the provisions related to data access ▌in Union financial services legislation, namely the following: (i) the provisions on access to benchmarks and the access regime for exchange-traded derivatives between trading venues and Central Counterparties laid down in Regulation (EU) No 600/2014 of the European Parliament and of the Council; (ii) the rules on access of creditors to the database under Directive 2014/17/EU of the European Parliament and of the Council; (iii) the rules on access to securitisation repositories under Regulation (EU) 2017/2402 of the European Parliament and of the Council; (iv) the rules on the right to request from the insurer a claims history statement and on the access to central repositories to basic data necessary for the settlement of claims under Directive 2009/103/EC of the European Parliament and of the Council; (v) the right to access and transfer all necessary personal data to a new pan-European Personal Pension Product provider under Regulation (EU) 2019/1238 of the European Parliament and of the Council; and (vi) the provisions on outsourcing and reliance under Directive (EU) 2018/843 of the European Parliament and of the Council. Furthermore, this Regulation does not affect the application of EU or national rules of competition of the Treaty on the Functioning of the European Union and any secondary Union acts. This Regulation is also without prejudice to accessing ▌and using data without making use of the data access obligations established by this Regulation on a purely contractual basis.

RemovedSee https://edps.europa.eu/data-protection/our-work/publications/opinions/2023-08-22-edps-opinion-382023-regulation-framework-financial-data-access_en.

Added(51) As the access to data related to payment accounts is regulated under a different regime set out in Directive (EU) 2015/2366, it is deemed appropriate to set, in this Regulation, a review clause for the Commission to examine whether the introduction of the rules under this Regulation impacts the way AISPs access data and whether it would be appropriate to streamline the rules governing the access of data applicable to AISPs.

RemovedArticle 1 – paragraph 1: This Regulation establishes rules on the access and re-use of categories of customer data in financial services listed in Article 2(1) of this Regulation.

Added(52) Given that the ESAs should govern all objectives of this Regulation and be mandated to make use of their powers in relation to financial information service providers, it is necessary to ensure that they are able to exercise all of their powers and tasks in order to fulfil their objectives of protecting the public interest by contributing to the short, medium and long-term stability and effectiveness of the financial system, for the Union economy, its citizens and businesses and to ensure that financial information service providers are covered by Regulations (EU) No 1093/2010 ▌, (EU) No 1094/2010 ▌ and (EU) No 1095/2010 ▌ of the European Parliament and of the Council. Those Regulations should therefore be amended accordingly.

RemovedIt is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit. Furthermore, is is suggested to clarify that FiDA enables the financial sector to offer financial services and products on the basis of the accessed data. Furthermore, more precise reference to the categories of customer data.

Added(53) The date of application of this Regulation should be deferred by [32] months in order to allow for the adoption of regulatory technical standards and delegated acts that are necessary to specify certain elements of this Regulation.

RemovedArticle 2 – paragraph 3 a (new): 3a. This Regulation does not apply to special categories of data referred to in Article 9(1) of Regulation (EU) 2016/679.

Added(54) The European Data Protection Supervisor was consulted in accordance with Article 42(2) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and delivered an opinion on 22 August 2023,

RemovedAs recommended by the EDPS in its opinion (points 32 and 33), it is suggested to explicitly exclude sensitive data (GDPR Article 9 data) from the scope of FiDA.

AddedHAVE ADOPTED THIS REGULATION:

Change 8

ChangedArticle 2 – paragraph 4: 4. This Regulation doesestablishes notrules affecton the application of other Union legal acts regarding accessaccess, to▌use and re-use of customer▌categories dataof referredcustomer todata in paragraphfinancial 1,services unlessreferred specificallyto providedin forArticle in2(1) of this Regulation.

Change 9

RemovedIt is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.

AddedThis Regulation also establishes rules concerning the authorisation and operation of financial information service providers.

RemovedArticle 2 – paragraph 4 a (new): 4a. The Commission is empowered to adopt delegated acts in accordance with Article 30 to supplement the list of categories of customer data in scope of this Regulation set out in paragraph 1 of this Article to allow potential other use cases in the interest of customers and after consultation with the European Supervisory Authorities.

AddedThis Regulation is without prejudice to Regulations (EU) 2016/679 and (EU) 2018/1725 and to Directive 93/13/EEC of the European Parliament and of the Council, Directive 2002/58/EC, Directive (EU) 2019/2161 of the European Parliament of the Council, and Directive 2011/83/EU of the European Parliament and of the Council.

RemovedTo make the FiDA framework future-proof, it is suggested that the European Commission, after consulting the ESAs, should be able to review the data scope established in the Regulation trough a delegated act.

AddedThis Regulation is also without prejudice to Directives 2014/17/EU, 2014/65/EU, (EU) 2016/97 and (EU) 2023/2225.

RemovedArticle 2 – paragraph 4 b (new): 4b. This Regulation is without prejudice to Union law and national law on the protection of personal data, privacy and confidentiality of communications and integrity of terminal equipment, which shall apply to personal data processed in connection with the rights and obligations laid down herein, in particular Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive 2002/58/EC, including the powers and competences of supervisory authorities and the rights of data subjects. Insofar as users are data subjects, the rights laid down in Chapter II of this Regulation shall complement the rights of access by data subjects and rights to data portability under Articles 15 and 20 of Regulation (EU) 2016/679. In the event of a conflict between this Regulation and Union law on the protection of personal data or privacy, or national legislation adopted in accordance with such Union law, the relevant Union or national law on the protection of personal data or privacy shall prevail.

Added1. This Regulation applies to the following categories of customer data, which are derived from financial services provided within the Union:

RemovedIt seems appropriate to refer more clearly to data protection regulation. This paragraph is copied from the Data Act (as adopted; publication in OJ forthcoming), Article 1(5).

Added(a) mortgage credit agreements as defined in Directive 2014/17/EU, credit agreements, and accounts, including credit card accounts, except payment accounts as defined in the Payment Services Directive (EU) 2015/2366 and technical accounts, including data on balance, conditions and transactions;

RemovedArticle 3 – paragraph 1 – point 1: (1) ‘consumer’ means a consumer as defined in Article 2(1) of Directive 2011/83/EU of the European Parliament and of the Council1a; / 1a Directive 2011/83/EU of the European Parliament and of the Council of 25 October 2011 on consumer rights, amending Council Directive 93/13/EEC and Directive 1999/44/EC of the European Parliament and of the Council and repealing Council Directive 85/577/EEC and Directive 97/7/EC of the European Parliament and of the Council (OJ L 304, 22.11.2011, p. 64).

Added(b) savings comprising term deposits, structured deposits, and savings accounts, investments in financial instruments, in accordance with Section C of Annex I to Directive 2014/65/EU and excluding derivative transactions used for risk management purposes, insurance-based investment products, crypto-assets as defined in Article 3(1), point (5), of Regulation (EU) 2023/1114 of the European Parliament and of the Council, real estate and other related financial assets as well as the economic benefits derived from such assets; including data collected for the purposes of carrying out an assessment of suitability and appropriateness in accordance with Article 25 of Directive 2014/65/EU of the European Parliament and of the Council;

RemovedIt is suggested to cross-refer to the definition of ‘consumer’ in the consumer rights Directive (Directive 2011/83/UE).

Added(c) pension rights in occupational pension schemes, in accordance with Directive 2009/138/EC and Directive (EU) 2016/2341 of the European Parliament and of the Council that are accessible for all interested consumers, with the exception of data related to sickness and health cover of a member or beneficiary;

RemovedArticle 3 – paragraph 1 – point 2: (2) ‘customer’ means a natural or a legal person residing in the Union who makes use of financial products and services;

Added(d) pension rights on the provision of pan-European personal pension products, in accordance with Regulation (EU) 2019/1238;

RemovedIt is suggested to insert a geographical limitation in line with other EU financial services legislation (such as PSD, GDPR, Data Act).

Added(e) non-life insurance products in accordance with Directive 2009/138/EC, with the exception of sickness and health insurance products; including data collected for the purposes of a demands and needs assessment in accordance with Article 20 of Directive (EU) 2016/97 of the European Parliament and Council, and data collected for the purposes of an appropriateness and suitability assessment in accordance with Article 30 of Directive (EU) 2016/97;

RemovedArticle 3 – paragraph 1 – point 2 a (new): (2a) ‘data’ means any digital representation of acts, facts or information and any compilation of such acts, facts or information, including in the form of sound, visual or audiovisual recording;

Added(f) data which forms part of a creditworthiness assessment of a firm which is collected as part of a credit agreement application process ▌. Data collected as part of a creditworthiness assessment of consumers shall be excluded;

RemovedDefinition of data taken from Data governance act (Regulation (EU) 2022/868) and Data Act (as adopted; publication in OJ forthcoming).

Added(fa) non-sensitive categories of data used by data holders to meet know-your-customer requirements for business customers.

RemovedArticle 3 – paragraph 1 – point 3: (3) ‘customer data’ means personal and non-personal data that is collected, stored and otherwise processed by a financial institution as part of its normal course of business and existing direct relationship with its customers in connection with its authorised activities. This covers both data provided by a customer and data generated as a result of customer interaction with the financial institution;

Added2. This Regulation applies to the following entities when acting as data holders or data users:

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
26 September 2026

Cite as

European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=3 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
  year = {2024},
  date = {2024-04-30},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=3}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=3},
  urldate = {2026-09-26},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}