Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ECON-PR-757355 → A-9-2024-0183
- From
- ECON-PR-757355 report parliamentary committee draft of 13 Dec 2023
- To
- A-9-2024-0183 Plenary report of 30 Apr 2024
- Changes
- Not comparable
- Paragraphs
- +506 added · −357 removed · 7 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 9 of 16: Paragraphs 481–540
RemovedArticle 12 – paragraph 2 – subparagraph 1 – point j: (j) the address of the applicant’s head office office and, where available, the Legal Entity Identifier (LEI);
Added(g) a financial data access scheme shall include the common standards for the data and the technical interfaces to allow customers to request data access in accordance with Article 5(1). The common standards for the data and technical interfaces that scheme members agree to use shall draw on existing international or industry-recognised standards or may be developed by scheme members or by other parties or bodies;
RemovedThe ISO 17742 Legal Entity Identifier (LEI), as a global, readily-available, and machine-readable standard, would provide an efficient way to help verify the identity of any applicant FISP that wishes to access customer data under the FIDA framework.
Added(ga) a financial data access scheme shall include the minimum technical and organisational measures that financial data access scheme members shall implement to ensure an appropriate level of security for exchanged data, including security measures to prevent and mitigate the risk of fraud;
RemovedArticle 12 – paragraph 3 – subparagraph 1 – introductory part: Financial information service providers shall hold a professional indemnity insurance covering the territories in which they offer financial information services, or some other comparable guarantee on liability, and shall ensure the following:
Added(h) a financial data access scheme shall establish a model to determine the maximum compensation that a data holder is entitled to charge the data user for making data available through an appropriate technical interface for enabling the data users to access data in line with the common standards developed under point (g).
RemovedClarification.
AddedThe model shall be based on the following principles:
RemovedArticle 12 – paragraph 3 – subparagraph 1 – point a: (a) an ability to cover their liability resulting from professional negligence, non-authorised or fraudulent access to or non-authorised or fraudulent use of data;
Added(i) it should be limited to reasonable and proportionate compensation▌ related to the costs incurred in making the data available to the data user and which is attributable to the request and agreements to award any compensation shall ensure that the scheme members take into account in particular the costs necessary for the formatting of data, dissemination via electronic means and storage, and investments in the collection and production of data, where applicable, taking into account whether other parties contributed to obtaining, generating, or collecting the data in question, as well as the volume, format and nature of the data;
RemovedIt is suggested that professional negligence should be covered by the professional indemnity insurance or other comparable coverage.
Added(ii) it should be based on an objective, transparent and non-discriminatory methodology agreed by the scheme members and may include a margin;
RemovedArticle 12 – paragraph 3 – subparagraph 2: As an alternative to holding a professional indemnity insurance or other comparable guarantee as required in the first sub-paragraph, the undertaking as referred in the previous subparagraph shall hold initial capital of EUR 50 000, which shall, without undue delay, be replaced by a professional indemnity insurance or other comparable guarantee on liability after it commences its activity as financial information service provider.
Added(iii) it should be based on comprehensive market data collected from data users and data holders on each of the cost elements to be considered, clearly identified in line with the model;
RemovedGiven the importance of appropriate insurance coverage, it should be mandatory to conclude a professional indemnity insurance or comparable guarantee.
Added(iv) it should be periodically reviewed and monitored to take account of technological progress;
RemovedArticle 12 – paragraph 3 a (new): 3a. Financial information service providers authorised in accordance with Article 14 shall at all times meet the conditions for their authorisation.
Added(v) it should be devised to gear compensation towards the lower levels prevalent on the market, while ensuring that there are sufficient incentives to foster market adoption and effective competition;
RemovedIt seems adequate to state explicitly that a FISP should at all times comply with the conditions of its authorisation.
Added(vi) it should be limited to the requests for customer data under Article 2(1) or proportionate to the related datasets in the scope of that Article in the case of combined data requests.
RemovedArticle 12 – paragraph 4 – subparagraph 1 – point a: (a) the information to be provided to the competent authority in the application for the authorisation of financial information service providers, including the requirements laid down in paragraph 2, points (a) to (k);
Added(ha) taking into account the level of compensation in the market, in particular regarding the developments in the calculation, the ESAs, on the basis of their respective competences, shall publicly report to the Commission on a yearly basis on the evolution of compensation fees. The Commission may adopt a delegated act in accordance with Article 30 to address market failures using proportionate and appropriate tools. The ESAs shall consult data holders and data users upon the drafting of those reports.
RemovedCorrection of a wrong reference. This relates to paragraph 2, in which there is no point (l).
AddedWhere the data user is a micro, small or medium enterprise, as defined in Article 2 of the Annex to Commission Recommendation 2003/361/EC of 6 May 2003, any compensation agreed shall not exceed the costs directly related to making the data available to the data user and which are attributable to the request.
RemovedArticle 12 – paragraph 4 – subparagraph 1 – point c: (c) what is a comparable guarantee, as referred in paragraph 3, which should be interchangeable with a professional indemnity insurance;
AddedThe guidelines adopted by the Commission on the calculation of reasonable compensation in accordance with Article 9(5) of the Regulation (EU) 2023/2854 shall also apply to this Regulation;
RemovedCorrection of a wrong reference.
Added(i) a financial data access scheme shall determine the contractual liability of its members, including in case the data is inaccurate, or of inadequate quality, or data security is compromised or the data are misused. In case of personal data, the liability provisions of the financial data access scheme shall be in accordance with the provisions in Regulation (EU) 2016/679;
RemovedArticle 12 – paragraph 4 – subparagraph 2 – introductory part: In developing these draft regulatory technical standards, EBA shall take account of the following:
Added(ia) a financial data access scheme shall provide for a mechanism of financial compensation to customers for any loss of data, damage or fraud suffered by these customers;
RemovedTo be more precise.
Added(j) a financial data access scheme shall provide for an independent, impartial, transparent and effective dispute resolution system to resolve disputes among scheme members and membership issues, in accordance with the quality requirements laid down by Directive 2013/11/EU of the European Parliament and of the Council.
RemovedArticle 12 – paragraph 4 – subparagraph 4: Power is conferred to the Commission to adopt the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.
Added2. Membership in financial data access schemes shall remain open to new members on the same terms and conditions as those for existing members at any time.
RemovedCorrection of a wrong reference.
Added3. A data holder shall communicate to the competent authority of the Member State of its establishment the financial data access schemes it is part of, within one month of joining a scheme. The competent authority of the Member State shall communicate this notification to the ESAs as applicable, based on their respective competences.
RemovedArticle 12 – paragraph 4 a (new): 4a. Any undertaking designated as a gatekeeper, pursuant to Article 3 of Regulation (EU) 2022/1925, shall not be eligible for authorisation as a financial information service provider under this Regulation.
Added4. A financial data access scheme set up in accordance with this Article shall be notified directly to the ESAs, based on their respective competences, shall carry out the assessment referred to in paragraph 6. Where a financial data access scheme set up in accordance with this Article is developed by scheme members which are established in the same Member State, a financial data access shall be notified to the competent authority of the Member State of establishment which shall carry out the assessment referred to in paragraph 6.
RemovedIt is suggested to prevent gatekeepers under the Digital Markets Act to access data under FiDA. The wording is inspired by Article 5 paragraph 3 of the Data Act (as adopted; publication on OJ forthcoming).
AddedWhere the membership of a financial data access scheme changes due to the addition of data holders and data users that are established in another Member State, the scheme shall be notified to the ESA concerned. However, where changes to the membership of a financial data access scheme result in all members being established in the same Member State, the scheme shall be notified to the competent authority of that Member State. All changes shall be notified to the register referred to in Article 15. The relevant ESA or the competent authority to which the change has been notified may in that case proceed to a new assessment as referred to in paragraph 6.
RemovedArticle 13: deleted / (deleted) / (deleted) / (deleted) / (deleted) / (deleted) / (deleted)
Added5. The notification in accordance with paragraph 4 shall take place within 1 month of setting up the financial data access scheme and shall include its governance modalities and characteristics in accordance with paragraph 1.
RemovedIn order to maintain a level playing field, not to jeopardise effective supervision of these new actors, and to protect customers against possible misuse of their data, is suggested to remove the possibility for undertakings that are not established in the EU to benefit from an authorisation as a FISP. Third country providers should not be allowed to conduct activities if they are not properly licensed for such activities in a specific member state. Such option does not exist under PSD2 either for e.g. AISPs and would therefore result in a discriminatory situation between FISPs and AISPs.
Added6. Within 1 month of receipt of the notification pursuant to paragraph 4 of this Article, the ESA concerned and, where appropriate, the competent authority referred to in paragraph 4 of this Article, shall assess whether the financial data access scheme’s governance modalities and characteristics are in compliance with paragraph 1. When assessing the compliance of the financial data access scheme with paragraph 1 of this Article, the ESA concerned shall consult the supervisory authorities established pursuant to Regulation (EU) 2016/679 and the other ESAs. Where the competent authorities referred to in paragraph 4 of this Article is assessing compliance of the financial data access scheme with paragraph 1, it shall consult the supervisory authorities established pursuant to Regulation (EU) 2016/679 and the relevant ESAs based on their respective competences.
RemovedArticle 14 – paragraph 1: 1. The competent authority shall grant an authorisation if the information and evidence accompanying the application complies with the requirements laid down in Article 12(1) and (2) and if the competent authority’s overall assessment, having scrutinised the application, is favourable. Before granting an authorisation, the competent authority may, where relevant, consult other relevant public authorities, including the supervisory authorities under Regulation (EU) 2016/679.
AddedUpon completion of this assessment, the ESA concerned and, where appropriate, the competent authority referred to in paragraph 4, shall inform the members of a▌ financial data access scheme that satisfies the provisions of whether the scheme fulfils the requirements set out in paragraph 1. After a positive assessment, a scheme notified▌ in accordance with this paragraph shall be recognised in all the Member States for the purpose of accessing data pursuant to Article 5(1) and shall be made available on the register defined in Article 15.
RemovedThis follows a suggestion by the EDPS in its opinion (point 49). Given the foreseeable data protection implications, it seems adequate to explicitly refer to the supervisory authorities under the GDPR. Furthermore closer alignment with PSD2 / proposal on PSD3 and correction of a reference (Article 12 instead of Article 11).
Added6. The ESAs shall undertake regular comprehensive reviews of data access schemes’ governance arrangements set out in Article 10(1). Those reviews shall include a thorough and documented assessment whether the schemes’ arrangements are appropriate and credible for the purposes of ensuring the responsible treatment of customer data.
RemovedArticle 14 – paragraph 2: deleted / (deleted) / (deleted) / (deleted) / (deleted) / (deleted)
Added-1. Where a financial data access scheme is not developed or implemented within the relevant time-frame as referred to in Article 9, members of a prospective financial data access scheme shall work with the relevant competent authorities to develop or implement the scheme, taking account of experiences across the market and the need to ensure the standardisation of schemes.
RemovedTo maintain a level playing field, in order not to jeopardise effective supervision of these new actors, and to protect customers against possible misuse of their data, is suggested to remove the possibility for undertakings that are not established in the EU to benefit from an authorisation as a FISP. Third country providers should not be allowed to conduct activities if they are not properly licensed for such activities in a specific member state. Such option does not exist under PSD2 either for e.g. AISPs and would therefore result in a discriminatory situation between FISPs and AISPs.
Added1. In the event that a financial data access scheme is not completely developed or implemented in accordance with Article 9(1a) for one or more categories of customer data listed in Article 2(1) and there is no realistic prospect of such a scheme being completed within a reasonable amount of time, the Commission is empowered to adopt a delegated act in accordance with Article 30 to supplement this Regulation by specifying the following arrangements under which a data holder shall make available customer data pursuant to Article 5(1) for that category of data:
RemovedArticle 14 – paragraph 4 a (new): 4a. The competent authority shall grant an authorisation only if it is satisfied that the governance arrangements of the financial information service provider demonstrate that it intends to carry out substantive business activities in the Member State where it has its registered office.
Added(a) common standards for the data and, where appropriate, the technical interfaces to allow customers to request data to be made available under Article 5(1);
RemovedFISPs should be established in the EU, with a registered office in a Member State where they carry out or intend to carry out substantive business activities. Competent authorities should verify compliance with these requirements during the authorisation process.
Added(b) a model to determine the maximum compensation that a data holder is entitled to charge for making data available;
RemovedArticle 14 – paragraph 6: 6. Within 3 months of receipt of a complete application, the competent authority shall inform the applicant whether the authorisation is granted or refused. The competent authority shall give reasons where it refuses an authorisation
Added(c) the liability of the entities involved in making the customer data available.
RemovedIt should not be possible to obtain authorisation on the basis of an incomplete application. The 3 months period should only start once the NCAs have received all information (so a complete application).
Added1a. The Commission shall, before adopting the delegated act pursuant to paragraph 1, consult the European Data Protection Board and all relevant stakeholders and submit a report to the European Parliament and the Council setting out any grounds for intervention by the Commission. The report shall take account of any existing work towards a scheme already undertaken by the industry and shall describe the arrangements for making available customer data as referred to in paragraph 1.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=9
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 28 September 2026
Cite as
European Parliament (2024). “Changes between ECON-PR-757355 and A-9-2024-0183”. Text, 30 April 2024. from ECON-PR-757355, to A-9-2024-0183. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=9 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-30,
author = {{European Parliament}},
title = {{Changes between ECON-PR-757355 and A-9-2024-0183}},
year = {2024},
date = {2024-04-30},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=9}},
url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-757355/compare/A-9-2024-0183?all=1&part=9},
urldate = {2026-09-28},
publisher = {EU Parl Watch Research},
note = {Text. from ECON-PR-757355, to A-9-2024-0183. Data: European Parliament Open Data (CC BY 4.0)}
}