Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-757355 → A-9-2024-0183

From
ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
To
A-9-2024-0183 Plenary report of 30 Apr 2024
Changes
Not comparable
Paragraphs
+506 added · −357 removed · 7 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 8 of 16: Paragraphs 421–480

RemovedArticle 10 – paragraph 1 – point h – subparagraph 1 – point v: (v) it should be devised to gear compensation towards the lowest levels prevalent on the market, while ensuring that there are sufficient incentives to foster market adoption and effective competition; and

Added(b) withdraw the data; and

RemovedData holders should be sufficiently incentivised to build and maintain the necessary infrastructure for making data available.

Added(c) without undue delay, erase all data received as a result of the data access permission granted by the customer.

RemovedArticle 10 – paragraph 1 – point h – subparagraph 2: Where the data user is a micro, small or medium enterprise, as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC of 6 May 200342 , any compensation agreed shall not exceed the costs directly related to making the data available to the data user and which are attributable to the request.

Added3. The data holder shall ensure:

RemovedAs the term “data recipient” is not defined in Article 3, it is suggested to use the term “data user” instead.

Added(a) that the permission dashboard is easy to find in its user interface and that, in accordance with Union data protection and consumer legislative frameworks, in particular Regulation (EU) 2016/679, Council Directive 92/13/EECand Directives 2011/83/EU and (EU) 2019/2161; and

RemovedArticle 10 – paragraph 1 – point h – subparagraph 2 a (new): The Commission shall adopt guidelines on the calculation of reasonable and proportionate compensation, taking into account the advice of the European Data Innovation Board (EDIB) established by Regulation (EU) 2022/868.

Added(b) that the information displayed on the dashboard is clear, neutral, accurate and easily understandable for the customer and that it is exclusively limited to information provided by the relevant data user.

RemovedIn line with Article 9 paragraph 6 of the Data Act (as adopted; publication on OJ forthcoming), it is suggested to provide for level 2 guidance on the calculation of compensation and to refer to the EDIB as established by the Data Governance Act.

Added4. The data holder and the data user for which permission has been granted by a customer shall cooperate to make information available to the customer via the dashboard in real-time. For the purposes of paragraph 2▌:

RemovedArticle 10 – paragraph 1 – point i a (new): (ia) a financial data access scheme shall provide for a mechanism of financial compensation to customers for any loss of data, damage or fraud suffered by those customers;

Added(a) the data holder shall inform the data user, in real time, of changes made to a permission, including withdrawal, concerning that data user made by a customer via the dashboard.

RemovedCustomers that gave permission to access their data should be compensated by data holders and/or data users in the event of misuse, loss or fraud involving this data. Financial data access schemes should therefore provide rules on such compensation to customers.

Added(b) a data user shall inform the data holder, in real time, of a new permission granted by a customer regarding customer data held by that data holder, including:

RemovedArticle 10 – paragraph 4: 4. A financial data access scheme set up in accordance with this Article shall be notified to the European Supervisory Authorities.

Added(i) the purpose of the permission granted by the customer, in a clear and comprehensible manner for the user;

RemovedIt suggested that the schemes are assessed at European level by the ESAs rather than at national level by the competent authorities. The Commission proposal already suggested a certain level of centralisation by the establishment of the register proposed in Article 15, including schemes. It would be more logical, therefore, to leave also the assessment to the ESAs, in order to avoid differing assessments of schemes by national authorities that could jeopardise a level playing field.

Added(ii) the period of validity of the permission

RemovedArticle 10 – paragraph 6 – subparagraph 1: Within 1 month of receipt of the notification pursuant to paragraph 4, the European Supervisory Authorities shall assess whether the financial data access scheme’s governance modalities and characteristics are in compliance with paragraph 1. When assessing the compliance of the financial data access scheme with paragraph 1, the European Supervisory Authorities may consult other competent authorities, including the supervisory authorities under Regulation (EU) 2016/679.

Added(iii) the categories of data concerned.

RemovedThe Commission proposal already suggested a certain level of centralisation at EU level in the Article 15 register. To avoid differing assessment of schemes by NCAs that could jeopardise a level playing field, it is suggested to further increase the role of the ESAs. Furthermore, a suggestion made by the EDPS in its opinion (point 49) is taken on board: given the foreseeable data protection implications, it seems adequate to explicitly refer to the supervisory authorities under the GDPR.

Added(iiia ) the legal basis under Article 6(1) of Regulation (EU) 2016/679 and, where relevant, the exception under Article 9(2) of that Regulation that the data user intends to rely on to access personal data contained in the customer data.

RemovedArticle 10 – paragraph 6 – subparagraph 2: Upon completion of its assessment, the European Supervisory Authorities shall include the notified financial data access scheme in the register defined in Article 15.

Added(ba) A data user shall be responsible for the accuracy of the data provided to the data holder.

RemovedThis paragraph is no longer needed if the process is streamlined by giving this task to ESAs rather than to the NCA. It is instead suggested that notified financial data access scheme is included in the central register defined in Article 15.

Added4a. For the purpose of this Article, more than one data holders may, collectively, provide a single permission dashboard to customers, provided that such a single permission dashboard fulfils the requirements set out in paragraphs 1 to 4.

RemovedArticle 10 – paragraph 6 a (new): 6a. The European Supervisory Authorities shall undertake regular comprehensive reviews of data access schemes’ governance arrangements set out in Article 10(1). Those reviews shall include a thorough and documented assessment whether the schemes’ arrangements are appropriate and credible for the purposes of ensuring the responsible treatment of customer data.

Added1. By ... [30 months from the date of entry into force of this Regulation], data holders and data users shall become members of a financial data access scheme governing access to the customer data in accordance with Article 10.

RemovedIt is suggested to require the ESAs to regularly undertake a comprehensive review of the governance arrangements that goes beyond a purely formalistic “box-ticking” exercise of the criteria set out in Article 10(1).

Added1 a. The implementation of a financial data access scheme shall be structured as follows:

RemovedArticle 11 – paragraph 1 – introductory part: In the event that a financial data access scheme is not completely developed for one or more categories of customer data listed in Article 2(1) and there is no realistic prospect of such a scheme being completed within a reasonable amount of time, the Commission is empowered to adopt a delegated act in accordance with Article 30 to supplement this Regulation by specifying the following modalities under which a data holder shall make available customer data pursuant to Article 5(1) for that category of data:

Added(a) by ... [12 months from the date of entry into force of this Regulation], members shall agree on the general rules applicable to a financial data access scheme in accordance with Article 10(1), points (a) to (f) and Article 10(1), points (i)to (j) (‘development phase’);

RemovedClarification that the financial data access scheme should be complete.

Added(b) by ... [26 months from the date of entry into force of this Regulation], members shall agree on common standards and a model to determine compensation in accordance with the requirements laid down in Article 10(1) points (g) and (h). Members shall also notify a financial data access scheme in accordance with Article 10(4) (‘implementation phase’);

RemovedArticle 11 – paragraph 1 a (new): When developing a delegated act for the purpose of the first subparagraph that specifies the modalities referred to in point (a), the Commission shall consult the European Data Protection Supervisor pursuant to Article 42(1) of Regulation (EU) 2018/1725.

Added(c) by ... [30 months from the date of entry into force of this Regulation], members shall ensure that all elements of a financial data access scheme are fully operational (‘operationalisation phase’).

RemovedThis follows a suggestion by the EDPS in its opinion (point 46).

Added2. Data holders and data users may become members of one or more▌ financial data access schemes.

RemovedArticle 12 – paragraph 1: 1. A legal person shall be eligible to access customer data under Article 5(1) and provide financial information services if it is authorised by the competent authority of a Member State.

AddedAny access of data shall be▌ granted in accordance with the rules and arrangements of a financial data access scheme of which both the data user and the data holder are members.

RemovedAt the moment of application, the company is not yet a FISP as per the definition in Article 3(7). Wording with “legal person” inspired by the crowdfunding regulation.

Added1. A financial data access scheme shall include the following elements:

RemovedArticle 12 – paragraph 2 – subparagraph 1 – introductory part: A legal person who intends to provide financial information services shall apply to the competent authority of the Member State for authorisation as a financial information service provider, that is, where it intends to carry out substantive business activities, together with the following:

Added(a) the members of a financial data access scheme shall include:

RemovedAt the moment of application, the company is not yet a FISP as per the definition in Article 3(7). Wording with “legal person” inspired by the crowdfunding regulation. Furthermore, FISPs should be established in the EU, with a registered office in a Member State where they carry out or intend to carry out substantive business activities.

Added(i) data holders and data users representing a significant proportion of the market of the product or service concerned, with each side having fair▌ representation in the internal decision-making processes of the scheme as well as every member having equal weight within their side in any voting procedures; where a member is both a data holder and data user, its membership shall be counted equally towards both sides;

RemovedArticle 12 – paragraph 2 – subparagraph 1 – point a: (a) a programme of operations setting out in particular the type of access to data and financial information services envisaged;

Added(ii) customer organisations and consumer associations with expertise in financial services.

RemovedIt is suggested to extend the provision on the content of the programme of operations to the financial information services that the applicant intends to provide.

Added(b) the rules applicable to the financial data access scheme members shall apply equally to all the members and there shall be no unjustified favourable or differentiated treatment between members;

RemovedArticle 12 – paragraph 2 – subparagraph 1 – point c: (c) a description of the applicant’s governance arrangements and internal control mechanisms, including administrative, risk management and accounting procedures, as well as arrangements for the use of ICT services in accordance with Chapter II of Regulation (EU) 2022/2554 of the European Parliament and of the Council, which demonstrates that those governance arrangements, control mechanisms and procedures are proportionate, appropriate, sound and adequate;

Added(c) the membership rules of a financial data access scheme shall ensure that the scheme is open to participation by any data holder and data user based on objective criteria and that all members shall be treated in a fair and equal manner;

RemovedMore precise reference to DORA.

Added(d) a financial data access scheme shall not impose any controls or additional conditions for the access or re-use of data other than those provided in this Regulation or under other applicable Union law;

RemovedArticle 12 – paragraph 2 – subparagraph 1 – point e: (e) a description of business continuity arrangements including a clear identification of the critical operations, effective ICT business continuity policy and plans and ICT response and recovery plans, and a procedure to regularly test and review the adequacy and efficiency of such plans in accordance with Chapter II of Regulation (EU) 2022/2554;

Added(e) a financial data access scheme shall include a mechanism through which its rules can be amended, following an impact analysis and the agreement of the majority of each community of data holders and data users respectively;

RemovedMore specific reference to DORA.

Added(f) a financial data access scheme shall include rules on transparency and where necessary, reporting to its members;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=8 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
  year = {2024},
  date = {2024-04-30},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=8}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=8},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}