Skip to content
EU Parl Watch

Changes between two versions

What changed between the draft committee report and the plenary report

From · draft committee report· 13 Dec 2023

ECON-PR-757355

on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554

To · plenary report· 30 Apr 2024

A-9-2024-0183

on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554

These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).

+506 added · −357 removed · 7 changed paragraphs, packaging included.

Part 11 of 16: Paragraphs 601–628

Removed:Article 19 – paragraph 1: 1. Without prejudice to Article 20, Member States may lay down rules enabling their competent authorities to close an investigation or formal sanctioning proceedings concerning an alleged breach of this Regulation, following a settlement agreement in order to put an end to the alleged breach and its consequences before formal sanctioning proceedings are started or to close formal sanctioning proceedings by way of settlement.

Added:(c) the size of the activity;

Removed:To take into account that applicable law is not harmonised across the EU.

Added:(d) the specific characteristics of comparable guarantees and the criteria for their implementation.

Removed:Article 20 – paragraph 1 – point d: (d) infringements of Articles 12, 13 and 16;

Added:EBA, shall submit those draft regulatory technical standards referred to in the first subparagraph to the Commission by [OP please insert the date = 9 months after entry into force of this Regulation].

Removed:It is suggested that infringements of Article 12, in particular regarding the obligation to hold indemnity insurance, should also be subject to administrative measures.

Added:Power is conferred to the Commission to adopt the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

Removed:Article 28 – paragraph 2 – subparagraph 1 – point a: (a) the name, the address and, where applicable, the authorisation number and the Legal Entity Identifier (LEI) of the financial information service provider;

Added:In accordance with Article 10 of Regulation (EU) 1093/2010, EBA shall review and if appropriate, update these regulatory technical standards.

Removed:The ISO 17742 Legal Entity Identifier (LEI), as a global, readily-available, and machine-readable standard, would provide an efficient way to help verify the identity of any FISP.

Added:4a. A registered account information service provider as defined in Directive (EU) 2015/2366 may only access data under Article 5(1) if it has been authorised as a financial information service provider.

Removed:Article 28 – paragraph 2 – subparagraph 1 – point d: (d) the financial data access schemes of which it is a member.

Added:4b. This Article shall not apply to an undertaking providing core platform services for which one or more of such services has been designated as a gatekeeper pursuant to Article 3 of Regulation (EU) 2022/1925, or to any entity that is owned or controlled by such an undertaking.

Removed:More precise wording.

Added:▌

Removed:Article 28 – paragraph 2 – subparagraph 1 – point d a (new): (da) a description of the service it intends to provide.

Added:Article 14 Granting and withdrawal of authorisation of financial information service providers

Removed:To ensure that NCAs are informed of FISPs’ access to customer data located in other MS, it is suggested to oblige FISPs to communicate to the home NCA a description to the services they intend to provide. The home NCA should then share this information with host NCAs in accordance with paragraph 3.

Added:1. The competent authority shall grant an authorisation if the information and evidence accompanying the application complies with▌ the requirements laid down in Article 12(1), (2) and (3) and if the competent authority’s overall assessment, having scrutinised the application, is favourable. Before granting an authorisation, the competent authority shall consult other relevant public authorities, in particular the supervisory authorities established pursuant to Regulation (EU) 2016/679.

Removed:Article 28 – paragraph 4 a (new): 4a. Where the competent authority of a host Member State has reasonable grounds for believing that a financial information service provider acting within its territory under the freedom to provide services or the freedom of establishment infringes the provisions of this Regulation as regards its use of the data of customers located within the host Member State, the competent authority of such host Member State shall have the power to temporarily suspend transmission of data of those customers from data holders to that financial information service provider, until the competent authority of the home Member State has taken the necessary measures to make infringements cease.

Added:▌

Removed:It is suggested to strengthen the powers of host competent authorities where consumer protection is affected by misconducts of FISPs established in another Member State and acting in the host Member State under the freedom to provide services or the freedom of establishment. Any host competent authority should be allowed to suspend the transmission of customer data from data holders to such FISP in order to cease infringements to FiDA that are conducive of harms to consumer interests in the host Member State, notably when there is a suspected fraud.

Added:3. The competent authority shall grant an authorisation only if, taking into account the need to ensure the sound and prudent management of a financial information service provider, the financial information service provider has robust governance arrangements for its information service business. This includes a clear organisational structure with well-defined, transparent and consistent lines of responsibility, effective procedures to identify, manage, monitor and report the risks to which it is or might be exposed, and adequate internal control mechanisms, including sound administrative and accounting procedures. Those arrangements, procedures and mechanisms shall be comprehensive and proportionate to the nature, scale and complexity of the information services provided by the financial information service provider.

Removed:Article 31 – paragraph -1 (new): -1. By ... [one year from the date of entry into application of this Regulation], and every year thereafter, the European Supervisory Authorities shall present a joint annual public report to the European Parliament, the Council and the Commission on the application of this Regulation. / The report referred to in subparagraph 1 shall contain at least the following: / a) a description of developments in the activities of financial information service providers; / b) an appraisal of whether any changes are needed to the measures set out in this Regulation to ensure the protection of customers and to foster the development of innovative services.

Added:4. The competent authority shall grant an authorisation only if the laws, regulations or administrative provisions governing one or more natural or legal persons with which the financial information service provider has close links, or difficulties involved in the enforcement of those laws, regulations or administrative provisions, do not prevent the effective exercise of its supervisory functions.

Removed:It is important to identify any risks in terms of consumer protection or obstacles to the development of new financial information services under the FiDA framework well ahead of the potential legislative review. It is therefore suggested to oblige the ESAs to annually produce a joint report on the application of the FiDA Regulation.

Added:5. The competent authority shall grant an authorisation only if it is satisfied that any outsourcing arrangements will not render the financial information service provider a letterbox entity or that they are not undertaken as a means to circumvent the provisions of this Regulation.