Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-757355 → A-9-2024-0183

From
ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
To
A-9-2024-0183 Plenary report of 30 Apr 2024
Changes
Not comparable
Paragraphs
+506 added · −357 removed · 7 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 6 of 16: Paragraphs 301–360

RemovedIt is suggested to introduce a provision to prevent gatekeepers under the Digital Markets Act to access data under FiDA. The wording is inspired by Article 6 paragraph 2 point (d) of the Data Act (as adopted; publication on OJ forthcoming).

Added1. The data holder shall, upon explicit request from a customer to do so submitted through a dedicated online or mobile customer interface, make available to a data user that acts on behalf of the customer the customer data listed in Article 2(1) only for the purposes relating to the specific service for which the customer has given explicit permission for the use of their data▌. The customer data shall be made available to the data user without undue delay, continuously and in real-time.

Change 10

ChangedArticle 6 –2. paragraphA 4data –holder pointmay f:claim (f)compensation wherefrom thea data user is partfor ofmaking acustomer groupdata ofavailable companies,pursuant customerto dataparagraph listed1 inonly Articleif 2(1)the shallcustomer onlydata beis made available to anda processeddata byuser thein entityaccordance ofwith the grouprules thatand actsmodalities asof a financial data user.access scheme, as provided in Articles 9 and 10, or if it is made available pursuant to Article 11.

Change 11

ChangedArticle 5(1) refers3. toWhen making data available insteadpursuant ofto beingparagraph accessed.1, the data holder shall:

Change 12

RemovedArticle 7 – paragraph 1: 1. The processing of customer data referred to in Article 2(1) of this Regulation shall be limited to what is necessary in relation to the purposes for which they are processed.

Added(a) make customer data available to the data user in a format based on generally recognised standards and at least in the same quality available to the data holder;

RemovedIt is suggested not to limit the scope of this provision to only personal data. This is also in line with Article 6(4) point (a), which relates to both personal and non-personal customer data.

Added(b) communicate securely with the data user by ensuring an appropriate level of security for the processing and transmission of customer data;

RemovedArticle 7 – paragraph 1 a (new): 1a. [EBA, ESMA and EIOPA] shall develop draft regulatory technical standards the implementation of paragraph 1 of this Article for products and services related to the credit score of the consumer. / [EBA, ESMA and EIOPA] shall submit those draft regulatory technical standards to the Commission by ... [12 months from the date of entry into force of this amending Regulation]. / Power is delegated to the Commission to supplement this Regulation by adopting regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

Added(ba) where personal data is processed, request data users to demonstrate that they have a valid legal basis pursuant to Article 6(1), point (a) or (b), of Regulation (EU) 2016/679;

RemovedGuidance at level 2 is useful to prevent the risk of consumer data being misused.

Added(c) request data users to demonstrate that they have obtained the permission of the customer to access the customer data held by the data holder;

RemovedArticle 7 – paragraph 2: 2. In accordance with Article 16 of Regulation (EU) No 1093/2010, the European Banking Authority (EBA) shall develop guidelines on the implementation of paragraph 1 of this Article for products and services related to the credit score of the consumer, to mortgage credit agreements, to the provision of payment services and to investment products.

Added(d) provide the customer with a permission dashboard to monitor and manage permissions in accordance with Article 8.

RemovedGuidance at level 2 is useful to prevent the risk of consumer data being misused.

Added(e) protect the confidentiality of trade secrets and intellectual property rights of a data holder.

RemovedArticle 7 – paragraph 3: 3. The European Insurance and Occupational Pensions Authority (EIOPA) shall develop draft regulatory technical standards on the implementation of paragraph 1 of this Article for products and services related to risk assessment and pricing of a consumer in the case of life, health and sickness insurance products. To avoid certain consumers becoming unable to access insurance due to overly granular risk assessments, those regulatory technical standards shall include provisions on how data may be used to avoid excessive granularity that undermines the "risk sharing" principle of insurance. / The EIOPA shall submit the draft regulatory technical standards referred to in the first subparagraph to the Commission by ... [XX]. / Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

Added1. A data user shall only be eligible to access customer data pursuant to Article 5(1) if that data user is▌ a financial institution or▌ a legal person that has been authorised as financial information service provider pursuant to Article 14.

RemovedStrong and binding measures are necessary in this area to prevent the risk of consumer data being misused. It is therefore suggested to mandate the ESAs to develop RTSs that list a finite set of data that may be collected and used for each of the use cases covered in Article 7. This is in line with the GDPR Article 5(1) principles of “purpose limitation” and “data minimisation”, while preserving a degree of flexibility as RTSs can be updated to reflect new developments.

Added1a. Consumers shall not be prevented from accessing a financial product by a data user solely because they did not give permission to their data being accessed in the manner set out in Article 5(1). For the purpose of implementing this paragraph, the burden of proof shall be on the data user to show that permission was given.

RemovedArticle 7 – paragraph 4: 4. When preparing the guidelines and draft regulatory standards referred to in paragraphs 2 and 3 of this Article, EIOPA and EBA shall formally consult the European Data Protection Board established by Regulation (EU) 2016/679.

Added2. A data user shall only request and access any type of customer data made available under Article 5(1) that is adequate, relevant and necessary for the purposes and under the conditions for which the customer has granted its permission. They shall relate only to the specific service for which the customer has given its explicit permission. A data user shall delete that customer data, including all backups, without undue delay when it is no longer necessary for the purposes for which the permission has been granted by a customer.

RemovedFormal consultation of EDPB follows a recommendation made by the EDPS in its opinion (point 30).

Added2a. A data user shall ensure that any data access request to a customer provides the customer with fair, transparent and adequate information that is easily understandable for the customer of the financial product or service, including on the specific types of customer data to which the data user seeks access.

RemovedArticle 7 – paragraph 4 a (new): 4a. Consumers shall not be denied access to a financial product on the sole basis of not giving permission to their data being accessed via the framework established by this Regulation. For the purposes of the implementation of this paragraph, the burden of proof shall lie with the data user.

Added2b. A data user shall ensure that any data access request to a customer is not designed in a way that would encourage or unduly influence the customer to grant access, in a way that is not in the best interests of the customer, or in a way that materially distorts or impairs the ability of the customer to make free and informed decisions.

RemovedConsumers should not be denied access to a financial product only because they do not give permission to their data being accessed via the FiDA framework. This suggestion is in line with the EDPS opinion (point 22) and aims at preventing risks of financial exclusion of customers having regard to both eligibility for and pricing of financial products and services.

Added2c. The ESAs may jointly develop draft regulatory technical standards on the implementation of this Article for specific practices, including pre-ticked boxes and behavioural nudges. When preparing those draft regulatory standards, the ESAs shall formally consult the European Data Protection Board established by Regulation (EU) 2016/679.

RemovedArticle 8 – paragraph 1: 1. A data holder shall provide the customer with an easily accessible permission dashboard to monitor and manage the permissions a customer has provided to data users.

Added3. A customer shall be able to withdraw the permission it has granted to a data user at any time and, where data access is based on consent in accordance with Regulation (EU) 2016/679, free of charge. When processing is necessary for the performance of a contract, a customer may withdraw the permission it has granted to make customer data available to a data user according to the contractual obligations to which it is subject.

RemovedThe permission dashboard should be easily accessible.

Added4. To ensure the effective management of▌ data, a data user shall:

RemovedArticle 8 – paragraph 2 – point -a (new): (-a) empower the customer to manage each permission in an informed and impartial manner.

Added(-a) identify itself and securely communicate with the data holder when accessing customer data;

RemovedIn line with point 38 of the EDPS opinion, it is suggested to reflect this sentence from recital 21 also in the enacting provision.

Added(a) not process any customer data for purposes other than for performing the service explicitly requested by the customer in the best interest of the customer;

RemovedArticle 8 – paragraph 2 – point a – introductory part: (a) provide the customer at any time with an overview of each ongoing permission given to each data user, including:

Added(aa) not transfer customer data to any third party, including in an outsourcing scheme, without the customer’s explicit permission;

RemovedCustomers should at any time have the right to know which of their data is used by which data user.

Added(b) protect the confidentiality of trade secrets and intellectual property rights of a data holder when customer data is made available in accordance with Article 5(1);

RemovedArticle 8 – paragraph 2 – point a – point -i (new): (-i) the date when the customer has given the permission;

Added(ba) respect the data protection rights of consumers and the level of protection guaranteed by Regulation (EU) 2016/679;

RemovedTo enable customers to effectively manage their permissions, it is useful to include the date of permission in this overview.

Added(c) put in place adequate technical, legal and organisational measures in order to prevent the transfer of or access to▌ customer data that is unlawful under Union law or the national law of a Member State;

RemovedArticle 8 – paragraph 2 – point a – point iv: (iv) the categories of data to which access has been granted;

Added(d) take necessary measures to ensure an appropriate level of security for the storage, processing and transmission of ▌customer data;

RemovedAlignment of wording with point (ii).

Added(e) only contact customers for direct marketing purposes subject to their prior consent or with offers for products or services similar to the ones for which they have accessed customer data and under the conditions provided by Article 13(2) of Directive 2002/58/EC;

RemovedArticle 8 – paragraph 2 – point a – point iv a (new): (iva) the location where the data is stored;

Added(f) where the data user is part of a group of companies, or one of the entities of the group has been designated as a gatekeeper under Article 3 of Regulation (EU) 2022/1925, customer data listed in Article 2(1) shall only be made available to and processed by the entity of the group that acts as a data user.

RemovedThe dashboard should enable customers to know the exact location where their data is stored, at any time.

Added4a. Personal data under this Regulation shall be processed in the Union unless the conditions laid down in Chapter V of Regulation (EU) 2016/679 are complied with.

RemovedArticle 8 – paragraph 2 – point b: (b) allow the customer to withdraw a permission given to a data user at any time;

Added4b. Data users that are owned or controlled by an undertaking that has been designated as a gatekeeper under Article 3 of Regulation (EU) 2022/1925 shall be prohibited from combining customer data referred to in Article 2(1) of this Regulation with other data relating to the customer that the designated gatekeeper may already collect, store, or otherwise possess for purposes outside this Regulation.

RemovedA customer should be able to withdraw a permission at any time.

Added1. The processing of customer data referred to in Article 2(1) of this Regulation ▌ shall be limited to what is necessary in relation to the purposes for which they are processed. Customers that refuse to grant permission to access their data shall not be refused access to financial products solely for this reason.

RemovedArticle 8 – paragraph 2 – point c: (c) allow the customer to re-establish any permission withdrawn at any time;

Added1a. The ESAs shall develop draft regulatory technical standards for the implementation of paragraph 1 of this Article for products and services related to the credit score of the consumer.

RemovedA customer should be able to re-establish a withdrawn permission at any time.

AddedThe ESAs shall submit those draft regulatory technical standards to the Commission by ... [12 months from the date of entry into force of this Regulation].

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=6 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
  year = {2024},
  date = {2024-04-30},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=6}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=6},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}