Changes between two versions
What changed between the draft committee report and the plenary report
From · draft committee report· 13 Dec 2023
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
To · plenary report· 30 Apr 2024
on the proposal for a regulation of the European Parliament and of the Council on a framework for Financial Data Access and amending Regulations (EU) No 1093/2010, (EU) No 1094/2010, (EU) No 1095/2010 and (EU) 2022/2554
These two texts have too little in common to compare paragraph by paragraph: they are different documents rather than versions of one (for example one group’s motion and the joint text that was adopted).
+506 added · −357 removed · 7 changed paragraphs, packaging included.
Part 7 of 16: Paragraphs 361–420
Removed:Article 8 – paragraph 3: 3. The data holder shall ensure that the permission dashboard is easy to find in its user interface and that information displayed on the dashboard is clear, objective, accurate and easily understandable for the customer and exclusively limited to information provided by the relevant data user.
Added:Power is delegated to the Commission to supplement this Regulation by adopting regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.
Removed:The suggested addition aims at clarifying that the permissions dashboard should not be allowed to display any (speculative) information, which has not been provided by the data user.
Added:2. In accordance with Article 16 of Regulation (EU) No 1093/2010, the European Banking Authority (EBA) shall develop guidelines on the implementation of paragraph 1 of this Article for products and services related to the credit score of the consumer, mortgage credit agreements, accounts including credit card accounts, and investment products. When doing so, EBA shall duly take into account the relevant provisions of Directive (EU) 2023/2225, including subsequent implementing legislation and guidelines.
Removed:Article 8 – paragraph 3 a (new): 3a. The data holder shall ensure that the permission dashboard is not designed in a way that would encourage or unduly influence the customer to grant or withdraw permissions, in a way that is not in the best interest of the customer, or in a way that materially distorts or impairs the ability of the customers to make free and informed decisions.
Added:3. The European Insurance and Occupational Pensions Authority (EIOPA) shall develop draft regulatory technical standards on the implementation of paragraph 1 of this Article for products and services related to risk assessment and pricing of a consumer in the case of life, health, motor, home and sickness insurance products. To avoid certain consumers becoming unable to access insurance due to overly granular risk assessments, these regulatory technical standards shall include provisions on how data may be used to avoid excessive granularity that undermines the "risk sharing" principle of insurance.
Removed:In line with point 38 of the EDPS opinion, it is suggested to reflect this sentence from recital 21 also in the enacting provision.
Added:EIOPA shall submit the draft regulatory technical standards referred to in the first subparagraph to the Commission by ... [XX].
Removed:Article 8 – paragraph 4 – introductory part: 4. The data holder and the data user for which permission has been granted by a customer shall cooperate to make information available to the customer via the dashboard in real-time. To fulfil the obligations in paragraph 2 of this Article:
Added:Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.
Removed:These specific references are redundant.
Added:3a. For the purpose of paragraph 3, regulatory technical standards should address how the ‘right to be forgotten’ of survivors of cancer or other chronic diseases and mental conditions shall be applicable in relation to non-credit related insurance policies, including life and health insurance.
Removed:Article 8 – paragraph 4 – point a: (a) The data holder shall inform the data user of changes made to a permission, including a withdrawal, concerning that data user made by a customer via the dashboard.
Added:4. When preparing the draft regulatory technical standards and guidelines referred to in paragraphs 2 and 3 of this Article, EIOPA and EBA shall closely cooperate with and shall formally consult the European Data Protection Board established by Regulation (EU) 2016/679.
Removed:A withdrawal of a permission also constitutes a change to the permission. It is suggested to mention this explicitly for the sake of clarity.
Added:4a. The ESAs shall develop guidelines on the processing of customer data referred to in Article 2(1), point (fa), of this Regulation that constitutes non-sensitive data.
Removed:Article 8 – paragraph 4 a (new): 4a. For the purpose of this Article, different data holders may collectively provide a permission dashboard to customers, provided that such a collective permission dashboard fulfils the requirements set out in paragraphs 1 to 4 of this Article.
Added:4b. Additional human and financial resources shall be provided to the ESAs for the fulfilment of their tasks under this Regulation.
Removed:Instead of having a multitude of data holders providing separate permission dashboards to customers, it might be more effective to have central permission dashboards. That way, customers are less likely to lose track of which permission they have given to whom. It is therefore suggested to allow data holders to work together to provide a collective permission dashboard.
Added:4c. The ESAs shall undertake regular comprehensive reviews of data users' compliance with the provisions set out in this Article. Those reviews shall include a thorough and documented assessment of the data processed by data users in the provision of financial services for the purposes of ensuring that the data processed is in line with the data use perimeter rules as set out in this Article.
Removed:Title IV: Financial Data Access Schemes / (This amendment applies throughout the text.)
Added:1. A data holder shall provide the customer with a permission dashboard, integrated into its user interface, to monitor and manage the permissions a customer has provided to data users.
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added:2. The permission dashboard as referred to in paragraph 1shall:
Removed:Article 9 – paragraph 2 – subparagraph 2: Any access of data shall be made in accordance with the rules and modalities of a financial data access scheme of which both the data user and the data holder are members.
Added:(a) provide the customer, at any time and in a format that is easy to understand, to the extent that the information is in the possession of the data holder, with an overview of each ongoing permission given to each data user, including:
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added:(i) the name of the data user to which access has been granted
Removed:Article 10 – paragraph 1 – point a – point i: (i) data holders and data users representing a significant proportion of the market of the product or service concerned, with each side having fair and equal representation in the internal decision-making processes of the scheme as well as every member having equal weight within their side in any voting procedures; where a member is both a data holder and data user, its membership shall be counted equally towards both sides;
Added:(ii) the customer account, financial product or financial service to which access has been granted;
Removed:Fair and equal representation deserves a clarification, to avoid that large companies would interpret this provision wrongly by advocating a distribution of voting rights according to company size, which is not the intention of the legislator. Decision making processes that are not dominated by a small number of large companies would moreover incentivise SMEs to join data access schemes.
Added:(iii) the purpose of the permission;
Removed:Article 10 – paragraph 1 – point a – point ii: (ii) customer organisations and consumer associations in relation to the financial sector.
Added:(iv) the categories of data to which access has been granted;
Removed:The cusomer organisations and consumer associations involved in the financial data access schemes should have expertise in relation to the financial sector.
Added:(v) the period of validity of the permission;
Removed:Article 10 – paragraph 1 – point d: (d) a financial data access scheme shall not impose any controls or additional conditions for the access or re-use of data other than those provided in this Regulation or under other applicable Union law;
Added:(vi) the dates on which the data was accessed.
Removed:It is suggested to use language that focuses more clearly on establishing data access rights for consumers and business customers. FiDA should first and foremost enable customers to take control over their data so that they can access and re-use it as they see fit.
Added:(b) allow the customer, at any time and free of charge, to withdraw a permission given to a data user;
Removed:Article 10 – paragraph 1 – point g: (g) a financial data access scheme shall include the common standards for the data and the technical interfaces to allow customers to request data access in accordance with Article 5(1). The common standards for the data and technical interfaces that scheme members agree to use shall draw on existing international or industry-recognized standards or may be developed by scheme members or by other parties or bodies in coordination with the European Data Innovation Board established by Regulation (EU) 2022/868;
Added:▌
Removed:By creating synergies with data from other relevant sectors, the innovative potential of such financial products and financial services could be further enhanced to the benefit of customers and the overall data economy. To promote the use of cross-sector data, it is suggested to refer to the EDIB as established by the Data Governance Act.
Added:(ca) allow the customer to opt out from data access with third parties in a general way for all present and future data access permission requests;
Removed:Article 10 – paragraph 1 – point g a (new): (ga) a financial data access scheme shall include the minimum technical and organisational measures that financial data access scheme members shall implement to ensure an appropriate level of security for exchanged data.
Added:(d) include a record of permissions that have been withdrawn or that have expired for a duration of two years.
Removed:This follows a suggestion by the EDPS in its opinion (point 45).
Added:(da) be consistent with the Regulation (EU) [..../....] [Payment Services Regulation] dashboards and allow data holders to manage data permissions pursuant to this Regulation and the Payment Services Regulation through a single dashboard upon the request of the user.
Removed:Article 10 – paragraph 1 – point h – subparagraph 1 – introductory part: (h) a financial data access scheme shall establish a model to determine the maximum compensation that a data holder is entitled to charge the data user for making data available through an appropriate technical interface for enabling the data user to access data in line with the common standards developed under point (g). The model shall be based on the following principles:
Added:2a. The ESAs shall jointly, in close cooperation with the European Data Protection Board established by Regulation (EU) 2016/679, develop guidelines specifying the categories of data referred to in paragraph 2 so that data are easily understandable for customers. Those guidelines shall ensure that the dashboard is designed in a way that does not:
Removed:Clarification to more closely align with Article 5.
Added:(a) encourage or unduly influence the customer to grant or withdraw permissions, including through the use of dark patterns or pre-ticked boxes;
Removed:Article 10 – paragraph 1 – point h – subparagraph 1 – point i: (i) it should be limited to reasonable and proportionate compensation related to the costs incurred in making the data available to the data user and which is attributable to the request. When agreeing on any compensation, the scheme members shall take into account in particular the costs necessary for the formatting of data, dissemination via electronic means and storage, and investments in the collection and production of data, where applicable, taking into account whether other parties contributed to obtaining, generating, or collecting the data in question. The compensation may also depend on the volume, format and nature of the data;
Added:(b) deceive or manipulate the customer, or otherwise materially distorts or impairs the ability of the customer to make free and informed decisions;
Removed:Closer alignment with Article 9 paragraphs 2 and 3 of the Data Act (as adopted; publication on OJ forthcoming). The deletion of the word “directly” aims at more clearly delineating the exemption in the final subparagraph of point (h).
Added:(c) make the procedure to withdraw permission more difficult than the procedure to grant access.
Removed:Article 10 – paragraph 1 – point h – subparagraph 1 – point ii: (ii) it should be based on an objective, transparent and non-discriminatory methodology agreed by the scheme members and may include a margin;
Added:2b. Where, pursuant to paragraph 2, point (b), a customer decides to withdraw data access, the data user concerned shall:
Removed:Closer alignment with Article 9 paragraph 1 of the Data Act (as adopted; publication on OJ forthcoming).
Added:(a) cease using the data;