Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 13 Dec 2023
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
To · plenary report· 30 Apr 2024
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+506 added · −357 removed · 7 changed paragraphs, packaging included.
Part 1 of 16: DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION
7 unchanged paragraphs
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
(COM(2023)0360 – C90215/2023 – 2023/0205(COD))
(Ordinary legislative procedure: first reading)
The European Parliament,
– having regard to the Commission proposal to Parliament and the Council (COM(2023)0360),
– having regard to Article 294(2) and Article 114 of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C90215/2023),
– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,
Added:– having regard to the opinion of the European Economic and Social Committee of 14 December 2023,
– having regard to Rule 59 of its Rules of Procedure,
Changed:– having regard to the report of the Committee on Economic and Monetary Affairs (A90000/2023),(A9-0183/2024),
1. Adopts its position at first reading hereinafter set out;
2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;
3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.
Change 1
Removed:Recital 2: (2) Customers of financial institutions, both consumers and firms, should have effective ownership and control over their financial data and the opportunity to benefit from open, fair, and safe data-driven innovation in the financial sector. Those customers should be empowered to decide how and by whom their financial data is used and should have the option to grant firms secure access to their data for the purposes of obtaining financial and information services should they wish.
Added:AMENDMENTS BY THE EUROPEAN PARLIAMENT*
Removed:It is suggested to emphasise that customers keep ownership of their financial data, and that financial data access should be secure.
Added:to the Commission proposal
Removed:Recital 3: (3) The Union has a stated policy interest in enabling access of customers of financial institutions to their financial data. The Commission confirmed in its communication on a digital finance strategy and Communication on a capital markets union adopted in 2021 an intention to put in place a framework for financial data access to reap the benefits for customers of unlocking their data in the financial sector. Such benefits include the development and provision by the financial sector of data-driven financial products and financial services, made possible by the re-use of customer data. By creating synergies with data from other relevant sectors, the innovative potential of such financial products and financial services could be further enhanced to the benefit of customers and the overall data economy.
Added:---------------------------------------------------------
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit. Furthermore, is is suggested to clarify that FiDA enables the financial sector to offer financial services and products on the basis of the accessed data.
Added:Proposal for a
Removed:Recital 4: (4) Within financial services, and as a result of the revised Directive (EU) 2015/2366 of the European Parliament and of the Council7 , the access of payments account data in the Union based on customer permission has begun to transform the way consumers and businesses use banking services. In order to build upon the measures in that Directive, a regulatory framework should be established for the access of customer data across the financial sector beyond payment account data. This should also be a building block for fully integrating the financial sector into the Commission’s strategy for data8 which promotes data access across sectors.
Added:REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added:on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
Removed:Recital 5: (5) Ensuring customer control and trust is imperative to build a well-functioning and effective data access framework in the financial sector. Ensuring effective customers’ control over their data contributes to innovation as well as customer confidence and trust in using alternative service providers. As a result, effective control helps overcome customer reluctance to re-use their data. Under the current Union framework, the data portability right of a data subject in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council9 is limited to personal data and can be relied upon only where it is technically feasible to port the data. Customer data and technical interfaces in the financial sector beyond payment accounts are not standardised, rendering data access more costly. Further, the financial institutions are only legally obliged to make the payment data of their customers available.
Added:(Text with EEA relevance)
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added:THE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,
Removed:Recital 6: (6) The Union’s financial data economy therefore remains fragmented, characterised by uneven data access, barriers, and high stakeholder reluctance to engage in unlocking and re-using data beyond payments accounts. Customers accordingly do not benefit from individualised, data-driven products and services that may fit their specific needs. The absence of personalised financial products limits the possibility to innovate, by offering more choice and financial products and services for interested consumers who could otherwise benefit from data-driven tools that can support them to make informed choices, compare offerings in a user-friendly manner, and switch to more advantageous products that match their preferences based on their data. The existing barriers to business data re-use are preventing firms, in particular small and medium-sized enterprises (SMEs), to benefit from better, convenient and automated financial services.
Added:Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit. Furthermore, introduction of the abbreviation "SME".
Added:Having regard to the proposal from the European Commission,
Removed:Recital 7: (7) Making data available by way of high-quality technical interfaces like application programming interfaces is essential to facilitate seamless and effective access to data. Beyond the area of payment accounts, however, only a minority of financial institutions that are data holders indicate that they make data available through technical interfaces like application programming interfaces. As incentives to develop such innovative services are absent, market demand for data access remains limited.
Added:After transmission of the draft legislative act to the national parliaments,
Removed:To not be specific on the technology used (APIs are obviously the most prevalent form to date), it is suggested to use the same wording as in the second sentence of the recital.
Added:Having regard to the opinion of the European Economic and Social Committee,
Removed:Recital 9: (9) The data included in the scope of this Regulation should demonstrate high value added for financial innovation as well as low financial exclusion risk for consumers. This Regulation should therefore not cover data related to the sickness and health insurance of a consumer in accordance with Directive 2009/138/EC of the European Parliament and of the Council10 as well as data on life insurance products of a consumer in accordance with Directive 2009/138/EC other than life insurance contracts covered by insurance-based investment products. This Regulation should not cover data related to sickness and health cover of a member or beneficiary in accordance with Directive 2016/234110a. This Regulation should also not cover data collected as part of a creditworthiness assessment of a consumer. The access and use of customer data in the scope of this Regulation should respect the protection of confidential business data and trade secrets in accordance with Directive (EU) 2016/94310b, including mathematical and methodological approaches. / 10a Directive (EU) 2016/2341 of the European Parliament and of the Council of 14 December 2016 on the activities and supervision of institutions for occupational retirement provision (IORPs) (OJ L 354, 23.12.2016, p. 37). / 10b Directive (EU) 2016/943 of the European Parliament and of the Council of 8 June 2016 on the protection of undisclosed know-how and business information (trade secrets) against their unlawful acquisition, use and disclosur…
Added:Acting in accordance with the ordinary legislative procedure,
Removed:IORPs can also provide for benefits that cover sickness and health risks and are comparable to sickness and health insurance. As the financial exclusion risks are similar, it is suggested to also exclude such data from the scope of FiDA. See also the comments made in this regard by the EDPS in its opinion (point 13). Furthermore, it is suggested to include a reference to the Directive on the Protection of Trade Secrets.
Added:Whereas:
Removed:Recital 9 a (new): (9a) For the purpose of the provision of financial services and product in scope of this Regulation, data holders and data users should comply with existing Union rules and guidelines regarding the access to and use of personal data. This includes the rules applicable to carrying out consumer creditworthiness assessments as laid down in Directive [XXXX/XXXX] of the European Parliament and of the Council1a (Consumer Credits Directive) and Directive 2014/17/EU of the European Parliament and of the Council1b (Mortgage Credit Directive), or the duty of investment firms to act in the best interest of the customer when carrying out suitability assessments. / 1a COM(2021)0347. / 1b Directive 2014/17/EU of the European Parliament and of the Council of 4 February 2014 on credit agreements for consumers relating to residential immovable property and amending Directives 2008/48/EC and 2013/36/EU and Regulation (EU) No 1093/2010 (OJ L 60, 28.2.2014, p. 34).
Added:(1) A responsible data economy, which is driven by the generation and use of data, is an integral part of the Union internal market that can bring benefits to both Union citizens and the economy. Digital technologies relying on data are increasingly driving change in financial markets by innovating and producing new business models, products and ways for firms to engage with customers.
Removed:As recommended by the EDPS in its opinion (point 29), it is worth recalling the existence of sector-specific legislation and guidelines applicable to the eligible entities listed in Article 2(2), including legislation that applies to consumer credits.
Added:(2) Customers of financial institutions, both consumers and firms, should have effective control over their financial data and the opportunity to benefit from open, fair, and safe data-driven innovation in the financial sector. Those customers should be empowered to decide how and by whom their financial data is used and should have the option to grant firms secure access to their data for the purposes of obtaining financial and information services should they wish. The unlocking and re-use of customer data, based on permission by the customer, would enable customers to benefit from access to a wider range of financial services and products from across the internal market, which, in turn, would lead to the availability of more competitive, customer-focused and cheaper financial services and products.
Removed:Recital 10: (10) The access of customer data in the scope of this Regulation should be based on the explicit permission of the customer. Such permission should not solely be based on a “tick-the-box” approach or the use of generalising phrases. In seeking the explicit permission of the customer to use his or her data, the data users should specify what use they intend to make of the customer’s data, should the customer provide permission. The legal obligation on data holders to enable access to customer data should be triggered once the customer has explicitly requested their data to be made accessible to a data user. The data user should be able to demonstrate how the best interest of the customer will be served and preserved. In accordance with Regulation (EU) [XXXX/XXXX] of the European Parliament of the Council1a (Data Act), an undertaking providing core platform services that has been designated as a gatekeeper under Regulation (EU) 2022/19251b cannot be eligible as data user under this Regulation. The limitation on granting access to gatekeepers would not exclude them from the market and prevent them from offering its services, as voluntary agreements between them and the data holders remain unaffected. Where the processing of personal data is involved, a data user should rely on one of the valid lawful bases for processing under Article 6 of Regulation (EU) 2016/679. The customers data can be processed only for the agreed purposes in the context of the service provided. Under this…
Added:(3) The Union has a stated policy interest in enabling access of customers of financial institutions to their financial data. The Commission confirmed in its communication on a digital finance strategy and Communication on a capital markets union adopted in 2021 an intention to put in place a framework for financial data access to reap the benefits for customers of unlocking their data ▌ in the financial sector. Such benefits include the development and provision by the financial sector of data-driven financial products and financial services, made possible by the re-use of customer data. By creating synergies with data from other relevant sectors and enabling financial institutions to develop and provide tailor-made and data-driven financial products and services, the innovative potential of such financial products and financial services could be further enhanced to the benefit of customers and the overall data economy.
Removed:Clarifications and suggestions: data use should always be in the best interest of the customer; access to consumer data held by data holders should be conditional; gatekeepers under the DMA should not be able to access data under FiDA; more precise references to GDPR; customer consent should be required for any transfer of data. Furthermore, point (40) of the EDPS opinion is included.
Added:(4) Within financial services, and as a result of the revised Directive (EU) 2015/2366 of the European Parliament and of the Council, the access of payments account data in the Union based on customer permission has begun to transform the way consumers and businesses use banking services. In order to build upon the measures in that Directive, a regulatory framework should be established for the access of customer data processed by financial institutions across the financial sector which goes beyond payment account data. This should also be a building block for fully integrating the financial sector into the Commission’s strategy for data which promotes data access across sectors.
Removed:Recital 11: (11) Enabling customers to unlock and re-use their data on their current investments can encourage innovation in the provision of retail investment services. Primary data collection to complete a suitability and appropriateness assessment of a retail investor is time-intensive for a customer and constitutes a significant cost factor for advisors and distributors of investment, some types of pension, and insurance-based investment products. The re-use of customer data on holdings of savings and investments in financial instruments including insurance-based investment products and data collected for the purposes of carrying out a suitability and appropriateness assessment can improve investment advice for consumers and has strong innovative potential, including in the development of personalised investment advice and investment management tools that can make retail investment advice more efficient. Such management tools are already being developed in the market and can develop more effectively in the context where a customer can re-use their investment-related data.
Added:(5) Ensuring customer control and trust is imperative to build a well-functioning and effective data access framework in the financial sector. Ensuring effective customers’ control over their data ▌ contributes to innovation as well as customer confidence and trust in using alternative service providers. As a result, effective control may help overcome customer reluctance to re-use their data. Under the current Union framework, the data portability right of a data subject in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council is limited to personal data and can be relied upon only where it is technically feasible to port the data. Customer data and technical interfaces in the financial sector beyond payment accounts are not standardised, rendering data access more costly. Further, the financial institutions are only legally obliged to make the payment data of their customers available.
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added:(6) The Union’s financial data economy therefore remains fragmented, characterised by uneven data access, barriers, and high stakeholder reluctance to engage in unlocking and re-using data ▌ beyond payments accounts. Customers accordingly do not benefit from individualised, data-driven products and services that may fit their specific needs. The absence of personalised financial products limits the possibility to innovate, by offering more choice and financial products and services for interested consumers who could otherwise benefit from data-driven tools that can support them to make informed choices, compare offerings in a user-friendly manner, and switch to more advantageous products that match their preferences based on their data. The existing barriers to business data re-use are preventing firms, in particular small and medium-sized enterprises (SMEs), from benefitting from better, convenient and automated financial services.
Removed:Recital 12: (12) Customer data on balance, conditions or transaction details related to mortgages, loans and savings can enable customers to gain a better overview of their deposits and better meet their savings needs based on credit data. This Regulation should cover customer data beyond payment accounts defined in Directive (EU) 2015/236611 . This Regulation should not cover data on balance, conditions or transaction details related to accounts that can be used for the execution of payment transactions to and from a third party and that are covered by Regulation (EU) [XXXX/XXXX] of the European Parliament of the Council11a (PSR/PSD3). / 11a COM(2023)0367.
Added:(7) Making data available by way of high-quality technical interfaces like application programming interfaces is essential to facilitate seamless and effective access to data. Beyond the area of payment accounts, however, only a minority of financial institutions that are data holders indicate that they make data available through technical interfaces like application programming interfaces. As incentives to develop such innovative services are absent, market demand for data access remains limited. To foster efficient data access, data holders and data users are able to make use of existing application programming interfaces and common standards under Directive (EU) 2015/2366 and Commission Delegated Regulation (EU) 2018/389 where such interfaces and standards comply with this Regulation.
Removed:Payment accounts are regulated under PSD. The suggestion addition aims at ensuring legal certainty by more explicitly delineating which regime (PSD/FiDA) applies to which data set. The suggested deletion aims at signalling that such credit accounts should be covered by PSD as well, which would then enable the initiation of transactions between them by the customer. Covering them in the scope of FIDA would only allow AIS, and not customers to use PIS to transfer money between their own accounts.
Added:(8) A dedicated and harmonised framework for access to financial data is therefore desirable at Union level to respond to the needs of the digital economy and to remove barriers to a well-functioning internal market for data. Specific rules are required to address these barriers to promote better access to customer data and hence make it possible for consumers and firms to realise the gains stemming from better financial products and services. Data-driven finance could facilitate industry transition from the traditional supply of standardised products to tailored solutions that are better suited to the customers’ specific needs, including improved customer facing interfaces that enhance competition, improve user experience and ensure financial services that are focused on the customer as the end user.
Change 2
Changed:Recital 13: (13)(9) The customer data included in the scope of this Regulation should includedemonstrate availablehigh informationvalue onadded sustainability-relatedfor preferencesfinancial thatinnovation shouldas enablewell customersas tolow morefinancial easilyexclusion accessrisk financialfor servicesconsumers. thatThis areRegulation alignedshould withtherefore theirnot sustainabilitycover preferencesdata related to the sickness and sustainablehealth financeinsurance needs,of ina lineconsumer within theaccordance Commission’swith strategyDirective for2009/138/EC financingof the transitionEuropean toParliament aand sustainableof economy12the .Council Accessas towell as data relatingon tolife sustainabilityinsurance whichproducts mayof bea containedconsumer in balance or transactionaccordance detailswith relatedDirective to2009/138/EC aother mortgage,than credit,life loaninsurance andcontracts savingscovered account,by insurance-based investment products, asproducts. wellThis asRegulation accessshould tonot customercover data relatingrelated to sustainabilitysickness heldand byhealth investmentcover firms,of sucha asmember aor customer’sbeneficiary inititalin sustainabilityaccordance preferences,with canDirective contribute(EU) to2016/2341 facilitatingof accessthe toEuropean Parliament and of the Council. This Regulation should also not cover data neededcollected toas accesspart sustainableof financea orcreditworthiness makeassessment investmentsof intoa theconsumer. greenThe transition.access Moreover,and use of customer data in the scope of this Regulation should includerespect datathe whichprotection formsof partconfidential business data of aboth creditworthinessthe assessmentcustomer relatedand tothe firms,data includingholder. smallThis andRegulation mediumshould sizedtherefore enterprises,not andcover whichtrade cansecrets providewithin greaterthe insightmeaning intoof theDirective sustainability(EU) objectives2016/943 of smallthe firms.European TheParliament inclusionand of data usedthe forCouncil, theincluding creditworthinessbut assessmentnot relatedlimited to firmsmathematical shouldand improvemethodological accessapproaches. toThis financingRegulation andshould streamlinenot thecover applicationdata forderived loans.from Suchconfidential business data shouldof bethe limiteddata toholder or data onthat firmsis andgenerated shouldby nota infringefinancial intellectualinstitution propertyby rights.way Sustainabilityof preferencessignificantly shouldenriching includethe sustainabilitycustomer preferencesdata in scope of athis customerRegulation, collectedsuch byas insuranc…data that is the outcome of the use of proprietary algorithms.
Change 3
Removed:It is suggested to add insurance-based investment products to this list as they are in scope of Article 2(1)(b). Moreover, sustainability preferences could be a potentially promising use case of FiDA.As sustainability preferences are defined in two Delegated Regulations that are product specific (MiFID and IBIPs), it is suggested to refer to those Delegated Regulations in this recital.