
The EU’s Financial Data Access Regulation (FiDA) is central to building an open finance ecosystem. It expands financial data sharing while safeguarding customer privacy through strict security and confidentiality requirements. FiDA covers a wide range of financial data types, including mortgages, savings, investments, pensions, cryptoassets, and non-life insurance, as well as the entities handling them.
FiDA’s Objectives
Previously, access to financial data was inconsistent, with weak technical interfaces and no clear regulation, limiting competition and innovation. FiDA builds on the open banking rules of PSD2 and broadens data sharing. Its objectives are to improve financial products through enhanced data access and to protect customer privacy with high security standards and user consent. FiDA aligns with GDPR and requires compliance with the Digital Operational Resilience Act (DORA).
Data and Entities Covered
FiDA extends beyond PSD2 payment accounts to include:
• Mortgages, loans, and non-payment accounts.
• Savings, investments, IBIPs, crypto-assets, real estate, and related data.
• Retirement products.
• Non-life insurance (excluding health), including suitability and needs assessments.
• Company creditworthiness data collected for loans or ratings.
Core Roles
Alongside customers, data holders, and data users, FiDA introduces financial information services providers (FISPs). These authorized entities can access customer data, and non-EU FISPs must appoint a legal representative in an EU Member State.
Data Sharing Mechanism
Data sharing is organized through the Financial Data Sharing Scheme (FDSS), a framework agreement among data holders, users, and customer representatives. Customers control consent via dashboards to monitor, update, or revoke access. FDSS members must uphold strict security and confidentiality standards and ensure secure communication when processing or transmitting data.
Potential Impact
FiDA enables third-party providers, fintechs, and others to develop new financial, investment, and insurance services. Customers gain access to more tailored offerings, while expanded access increases competition between traditional institutions and new entrants.
The promise of open finance under FiDA introduces regulatory complexities. Aligning with GDPR raises challenges, such as obtaining meaningful consent for broad data reuse while respecting purpose limitation and transparency rules.
This requires precise governance and clear data classification to ensure only lawful data is shared. S8fe’s solutions deliver this clarity through accurate labeling, enabling firms to meet FiDA’s obligations while upholding GDPR privacy.
