FIDA: open banking for everything that is not a payment account

FIDA, the EU regulation on a framework for financial data access, would take the logic of open banking and apply it to the rest of a customer's financial life. PSD2 opened the payment account. FIDA would open savings, loans, mortgages, investments, insurance and pension rights, on the customer's instruction, through APIs the data holder has to provide.

This page goes below open banking in Germany, which names FIDA in one section, and below PSD3, which answers whether FIDA is part of it. It is not: FIDA is a separate regulation on a separate track. Here the subject is the detail a bank or insurer has to plan against, and the honest state of a file that has not finished.

Phone showing financial data permissions beside an EU regulation book

How FIDA sits beside PSD3 and the PSR

Three instruments, one direction, different scopes. The Payment Services Regulation keeps the PSD2 access to payment accounts, free of charge, and tightens it. PSD3 handles the licensing and supervision of payment institutions. FIDA governs everything else: the data a bank, insurer or investment firm holds that is not a payment account, and it is a regulation, so it would apply directly in each member state without a national transposition.

The practical separation matters when a project is scoped. A team building for the PSR extends an existing PSD2 interface. A team building for FIDA opens data domains that have never had an external API, in systems that were never designed to expose them, often in an insurance or securities platform, not in the core banking system. Core banking in Germany covers what those systems look like.

The data categories in scope and the ones left out

The scope is wide. The proposal and the negotiating positions cover mortgage and consumer credit, accounts and savings, investment instruments, crypto-asset holdings, non-life insurance products, pension rights and creditworthiness assessment data. Simmons & Simmons records that the Commission, Parliament and Council versions diverge significantly on exactly how far that goes.

What is proposed to stay out is as interesting as what is in. Input data for suitability and appropriateness assessments, third-party data and the data generated inside a loan application process have been put forward for exclusion, as Deloitte notes, and life insurance and sickness products have been contested throughout. A bank planning its data inventory should treat the boundary as unsettled and inventory more than the minimum.

Financial data sharing schemes

FIDA would not have the legislator write the API. Instead, data holders and data users have to join a financial data sharing scheme, a governance body with the data holders, the data users and consumer organizations in it, which sets the common standards, the interfaces and the terms. Membership would be compulsory for the firms in scope.

That design is why the SPAA scheme and the Berlin Group's openFinance work matter commercially: a functioning industry scheme is a candidate to become the FIDA scheme for its domain. The unresolved questions are substantial, and Simmons & Simmons lists them: how a scheme operates across borders, who supervises it, how compensation gets determined inside it, and whether every data type needs a scheme at all when customer demand for some of them is unproven.

The permission dashboard

Every data holder would have to give the customer a permission dashboard: one place to see which firms have access to which of their data, for what purpose, and to withdraw a permission. For a customer, that is the single most visible part of FIDA, and the only part most will ever touch.

For an institution it is harder than it looks. A dashboard has to aggregate permissions granted through different channels and different schemes into one view, in something close to real time. Whether it has to let the customer change a permission there or only display it has been argued over, since a read-only dashboard is far simpler to build and far less useful. A bank that already runs the PSD2 consent machinery described on the Berlin Group API standard has the foundation for it.

Compensation: what a data holder may charge

FIDA would allow a data holder to be compensated for making data available, which is the structural difference from PSD2, where access is free. The compensation would be set within the data sharing scheme and not by each firm, and for banks it turns a compliance cost into a possible revenue line.

How the amount is determined is one of the open points, and it is the point the industry cares most about. Set too low, the API is a pure cost and institutions build the minimum. Set too high, no data user can afford the data and the regulation delivers nothing. That is the same calculation the market is running voluntarily through SPAA, and variable recurring payments show how the price question can stall a product for years.

Where the file stands and what the timeline looks like

FIDA has been in trilogue between Parliament, Council and Commission since 2025 and has not concluded. As of autumn 2026 no date for further trilogue meetings is fixed, and continuation of the negotiations is uncertain, which makes it reasonable to question whether the file will be completed in the current Commission term. Any date given with confidence should be treated with suspicion.

The transition period is also unsettled, and the three institutions differ: the Commission proposed 24 months after entry into force, Parliament 30 to 38 months, and the Council between 18 and 48 months depending on the data type. That spread puts realistic application somewhere around 2028 to 2029, and the German implementation view puts the transition at 24 to 48 months after entry into force.

What a German bank or insurer has to prepare

As a regulation, FIDA would apply directly in Germany without a German implementing act, with BaFin supplementing it through supervisory guidance and authorizing the new category of financial information service provider, the FISP, which needs its own license, insurance cover and a real establishment instead of a shell. An insurer falls under it as squarely as a bank, which insurtech in Germany covers.

The sensible preparation is not a FIDA project. It is a data inventory that answers which customer data the house holds, in which system, in what quality, and who owns it internally. The governance, IT and third-party risk work overlaps heavily with MaRisk, BAIT and DORA, so a bank that did those properly is not starting from zero. The part that cannot be borrowed is the API operation of data that has never left the house.

What is FIDA?

FIDA is the proposed EU regulation on a framework for financial data access, sometimes called the open finance regulation. It would oblige banks, insurers, investment firms and other financial institutions to share customer data with authorized data users on the customer's instruction, through APIs and under the rules of financial data sharing schemes, against compensation.

Is FIDA part of PSD3?

No. FIDA is a separate regulation on its own legislative track. PSD3 and the Payment Services Regulation cover payment services and keep access to payment account data free. FIDA covers other financial data and introduces compensation. The two are related in intent and separate in law, and they will not arrive at the same time.

When will FIDA apply?

No date is fixed. The regulation is still in trilogue and the three institutions have proposed transition periods ranging from 18 to 48 months after entry into force. On the published positions, application around 2028 or 2029 is the realistic expectation, and in autumn 2026 the negotiations had no scheduled continuation.

FIDA and Finance Loop

Finance Loop brings the people who would have to build FIDA together before the text is final: the bank and insurer teams doing the data inventory, the providers that would become FISPs, and the lawyers tracking a trilogue that keeps moving. Finance Loop is the meeting place for payments and financial data in Europe, with meetups and conferences on open banking and regulation. Finance Loop keeps those dates in its event calendar.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.