Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ECON-PR-757355 → A-9-2024-0183
- From
- ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
- To
- A-9-2024-0183 Plenary report of 30 Apr 2024
- Changes
- Not comparable
- Paragraphs
- +506 added · −357 removed · 7 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 5 of 16: Paragraphs 241–300
RemovedA data user should at all times protect the confidentiality of trade secrets and intellectual property rights.
Added(7) ‘financial information service provider’ means an entity providing a financial information service that is established in the Union and authorised under Article 14 to access the customer data listed in Article 2(1) for the provision of financial information services;
RemovedArticle 6 – paragraph 1: 1. A data user shall only be eligible to provide financial information services within the Union if that data user is a financial institution or a legal person established in the Union that has been authorised as financial information service provider pursuant to Article 14.
Added(8) ‘financial institution’ means the entities listed in Article 2(2), points (a) to (n), who are either data holders, data users or both for the purposes of this Regulation;
RemovedTo maintain a level playing field, in order not to jeopardise effective supervision of these new actors, and to protect customers against possible misuse of their data, is suggested to remove the possibility for undertakings that are not established in the EU to benefit from an authorisation as a FISP. Third country providers should not be allowed to conduct activities if they are not properly licensed for such activities in a specific member state. Such option does not exist under PSD2 either for e.g. AISPs and would therefore result in a discriminatory situation between FISPs and AISPs.
Added▌
RemovedArticle 6 – paragraph 2: 2. A data user shall only request and access any type of customer data made available under Article 5(1) that is adequate, relevant and necessary for the purposes and under the conditions for which the customer has granted its permission. Those purposes shall be strictly limited to the provision of a financial product or a financial service. They shall relate only to the specific service for which the customer has given its explicit permission. The permission granted by the customer shall be free, specific, informed and unequivocal. A data user shall delete received customer data, including any backups, without undue delay when it is no longer necessary for the purposes for which the permission has been granted by a customer.
Added(10) ‘non-personal data’ means data other than personal data ▌;
RemovedAs recommended by the EDPS in its opinion (point 24). Furthermore it is suggested to add “without undue delay" to align more closely with the "right to be forgotten" in Regulation 2018/1725.
Added(11) ‘personal data’ means personal data as defined in Article 4(1) of Regulation 2016/679;
RemovedArticle 6 – paragraph 2 a (new): 2a. A data user shall ensure that any data access request to a customer provides the customer with fair, transparent and adequate information that is easily understandable for the target audience of the financial product or service, including on the specific types of customer data the data user seeks access to.
Added(12) ‘credit institution’ means a credit institution as defined in Article 4(1), point (1), of Regulation (EU) No 575/2013 of the European Parliament and of the Council;
RemovedThis amendment aims at improving customer protection, including by taking into account a recommendation made by the EDPS in its opinion (point 23).
Added(13) ‘investment firm’ means an investment firm as defined in Article 4(1), point (1), of Directive 2014/65/EU;
RemovedArticle 6 – paragraph 2 b (new): 2b. A data user shall ensure that any data access request to a customer is not designed in a way that would encourage or unduly influence the customer to grant access, in a way that is not in the best interest of the customer, or in a way that materially distorts or impairs the ability of the customer to make free and informed decisions.
Added(14) ‘crypto asset service provider’ means a crypto asset service providers as referred to in Article 3(1), point (15) of Regulation (EU) 2023/1114 of the European Parliament and of the Council;
RemovedData users should be left no possibility to request permission from the customer for an unspecified purpose, as this could lead to data being used for more purposes than intended by the customer. Any use of data should always be in the best interest of the customer.
Added(15) ‘issuer of asset referenced tokens’ means an issuer of asset referenced tokens authorised under Article 21 of Regulation (EU) 2023/1114;
RemovedArticle 6 – paragraph 2 c (new): 2c. The European Supervisory Authorities may develop draft regulatory technical standards on the implementation of this paragraph for specific practices, including pre-ticked boxes and behavioural nudges.
Added(16) ‘payment institution’ means a payment institution as defined in Article 4(4), of Directive (EU) 2015/2366;
RemovedThis provision might benefit from further guidance at level 2.
Added(17) ‘account information service provider’ means an account information service provider as referred to in Article 33(1) of Directive (EU) 2015/2366;
RemovedArticle 6 – paragraph 4 – introductory part: 4. To ensure the effective management of data, a data user shall:
Added(18) ‘electronic money institution’ means an electronic money institution as defined in Article 2(1), of Directive 2009/110/EC;
RemovedTrade secrets could be seen as outside customer data.
Added(19) ‘electronic money institution exempted pursuant to Directive 2009/110/EC’ means an electronic money institution benefitting from a waiver as referred to in Article 9(1) of Directive 2009/110/EC;
RemovedArticle 6 – paragraph 4 – point -a (new): (-a) identify itself and securely communicate with the data holder when accessing customer data;
Added(20) ‘manager of alternative investment funds’ means a manager of alternative investment funds as defined in Article 4(1), point (b), of Directive 2011/61/EU of the European Parliament and of the Council;
RemovedAnalogous to PSD2/3, FISPs should be obliged to identify themselves and communicate securely with the data holder.
Added(21) ‘management company of undertakings for collective investment in transferable securities’ means a management company as defined in Article 2(1), point (b), of Directive 2009/65/EC of the European Parliament and of the Council;
RemovedArticle 6 – paragraph 4 – point a: (a) not process any customer data for purposes other than for performing the service explicitly requested by the customer in the best interest of the customer;
Added(22) ‘insurance undertaking’ means an insurance undertaking as defined in Article 13(1) of Directive 2009/138/EC;
RemovedIt is suggested to specify that processing the customer data for performing the service should be “in the best interest of the customer”.
Added(23) ‘reinsurance undertaking’ means a reinsurance undertaking as defined in Article 13(4) of Directive 2009/138/EC;
RemovedArticle 6 – paragraph 4 – point b: (b) protect the confidentiality of trade secrets and intellectual property rights when customer data is made available in accordance with Article 5(1);
Added(24) ‘insurance intermediary’ means an insurance intermediary as defined in Article 2(1), point (3), of Directive (EU) 2016/97 of the European Parliament and of the Council;
RemovedIt is suggested that the data user should “protect” and not only “respect” trade secrets and intellectual property rights. Furthermore, Article 5(1) refers to making data available instead of being accessed.
Added(25) ‘ancillary insurance intermediary’ means an ancillary insurance intermediary as defined in Article 2(1), point (4), of Directive (EU) 2016/97;
RemovedArticle 6 – paragraph 4 – point b a (new): (ba) respect the data protection rights of consumers and the level of protection guaranteed by General Data Protection Regulation.
Added(26) ‘institution for occupational retirement provision’ means an institution for occupational retirement provision as defined in Article 6(1), of Directive (EU) 2016/2341;
RemovedIt seems adequate to also refer to data protection regulation in this list of obligations to data users to ensure the effective management of customer data.
Added▌
RemovedArticle 6 – paragraph 4 – point c: (c) put in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to customer data that is unlawful under Union law or the national law of a Member State;
Added(27a) ‘credit agreement’ means credit agreement as defined in Article 3, point (4), of Directive (EU) 2021/2167 of the European Parliament and of the Council;
RemovedIt is suggested not to limit the scope of this provision to only non-personal customer data only.
Added(28) “PEPP provider” means a PEPP provider as defined in Article 2, point (15), of Regulation (EU) 2019/1238 of the European Parliament and of the Council;
RemovedArticle 6 – paragraph 4 – point c a (new): (ca) not transfer customer data to any third party without the customer’s explicit permission.
Added(28a) ‘crowdfunding service provider’ means a crowdfunding service provider as defined in Article 2(1), point (e), of Regulation (EU) 2020/1503 of the European Parliament and of the Council;
RemovedThe customer's permission is required for the transfer of data to another group entity as per point (f) in this paragraph. A fortiori, such permission should also be required prior to any transfer to another entity that is not part of the group.
Added(28b) ‘trade secret’ means trade secret as defined in Article 2(1), point (1), of Directive (EU) 2016/943;
RemovedArticle 6 – paragraph 4 – point d: (d) take necessary measures to ensure an appropriate level of security for the storage, processing and transmission of customer data;
Added▌
RemovedIt is suggested not to limit the scope of this provision to only non-personal customer data.
Added(29a) ‘permission’ means the clear and unambiguous authorisation to a data user to access customer data, provided by customers themselves, based on which a data holder is required to make the requested data available for the specified purpose.
RemovedArticle 6 – paragraph 4 – point e: (e) only contact customers for direct marketing purposes subject to their prior consent or with offers for products or services similar to the ones for which they have accessed customer data and under the conditions provided by Article 13(2) of the ePrivacy Directive;
Added(29b) 'small and medium-sized enterprises' means a small and medium sized enterprises as defined in Article 4(1), point (13), of Directive 2014/65/EU;
RemovedAs recommended by the EDPS in its opinion (point 25), this suggestion aims a increasing legal certainty and reducing the risks of targeted advertising which is not expected by the data subject.
Added(29c) ‘legal entity identifier’ means a unique alphanumeric reference code based on the ISO 17442 standard assigned to a legal entity;
RemovedArticle 6 – paragraph 4 – point e a (new): (ea) not make the data it receives available to an undertaking designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925.
AddedThe data holder shall, upon request from a customer submitted through a dedicated online or mobile customer interface make the data listed in Article 2(1) available to the customer via that customer interface in an easily readable format reflecting the state in which those data are readily available to the data holder at the time that access is requested by a customer, without undue delay, free of charge, continuously and in real-time.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=5
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 27 September 2026
Cite as
European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=5 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
author = {{European Parliament}},
title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
year = {2024},
date = {2024-04-30},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=5}},
url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=5},
urldate = {2026-09-27},
publisher = {EU Parl Watch Research},
note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}