FIDA Regulation: The Complete Compliance Guide for EU Financial Institutions
- Julius Šakalys
- Jul 6
- 6 min read
Updated: Jul 17
Introduction
The EU's Financial Data Access (FIDA) regulation is reshaping how financial institutions handle, share, and govern customer data. Whether you are a bank, insurer, pension fund, investment firm, or fintech, FIDA will impose new obligations on your data infrastructure — and the clock is already running.
This guide covers everything compliance officers, CTOs, and legal teams at EU financial institutions need to know: what FIDA is, who it applies to, what obligations it creates, when it applies, how it compares to PSD2 and PSD3, and what your organisation should be doing right now — even before the final text is adopted.
What Is FIDA Regulation?
FIDA — the Financial Data Access regulation — is an EU legislative proposal that establishes a framework for open finance across the European Union. It is the successor to PSD2's open banking regime, extending the principle of data portability from payment accounts to a far broader set of financial products and services.
Where PSD2 gave consumers the right to share their payment account data with third parties (Account Information Service Providers and Payment Initiation Service Providers), FIDA extends this principle to:
FIDA creates a right for customers to access their own data from financial institutions and share it with authorised third parties — the Financial Information Service Providers (FISPs) — through standardised APIs.
The governing infrastructure for this data sharing is the Financial Data Sharing Scheme (FDSS) — industry-led bodies that set the technical and commercial rules for how data is shared between data holders and FISPs.
FIDA was proposed by the European Commission in June 2023 as part of the European Financial Data Space initiative. It is currently in trilogue negotiations between the European Parliament, Council of the EU, and the European Commission.
Who Does FIDA Apply To?
Data Holders
Data holders are the institutions that hold financial data and must provide access to it under FIDA. Under the current negotiating text, data holders include:
The scope of who must comply has been narrowed through the political process. The latest Council text (December 2024) removed crypto-asset service providers and some payment service providers from the initial scope.
Financial Information Service Providers (FISPs)
FISPs are the third-party entities authorised to receive financial data from data holders under FIDA. They must be registered or licensed, participate in an FDSS scheme, and meet ongoing security and governance requirements.
Who Is NOT Covered (Currently)
Key Obligations Under FIDA
1. Data Access on Customer Request
Data holders must provide customers (natural persons and SMEs) with standardised, machine-readable access to their own financial data upon request. This access must be provided through secure APIs, free of charge to the customer.
2. FDSS Membership and Certification
Data holders and FISPs must participate in at least one Financial Data Sharing Scheme (FDSS). These industry-led bodies set the technical standards, data models, contractual frameworks, and liability rules for data sharing under FIDA.
Until FDSS schemes are formally established and certified, FIDA's operational layer cannot function. The formation of FDSS schemes is one of the most significant open questions in the FIDA implementation landscape.
3. Consent Management Infrastructure
Customers must be able to grant, manage, and revoke their consent for data sharing through a standardised permission dashboard. Data holders must build and maintain this consent management infrastructure.
4. FISP Validation and Authorisation Checks
Data holders must validate that any FISP requesting customer data is currently licensed, participates in a certified FDSS scheme, and is not subject to regulatory sanctions before releasing data.
5. Data Quality and Standardisation
FIDA imposes obligations on data holders to provide accurate, up-to-date, and standardised data. The European Banking Authority (EBA) and other regulators will define the technical standards for data formats and API specifications.
6. DORA Compliance for FIDA API Infrastructure
This is frequently overlooked: every API endpoint built for FIDA compliance must also comply with the Digital Operational Resilience Act (DORA). DORA's requirements for ICT risk management, incident reporting, and third-party risk management apply directly to FIDA API infrastructure.
Firms that treat FIDA and DORA as separate compliance programmes will face a guaranteed duplication of effort and a likely gap in their combined ICT risk posture. The correct approach is a unified ICT governance framework that satisfies both.
EU cloud sovereignty requirements add a further compliance layer for FIDA infrastructure. The Commission's
sets binding requirements for FDSS and FISP providers on data residency, portability, and switching — obligations that sit alongside FIDA's technical standards and must be addressed in your infrastructure stack.
FIDA Regulation Timeline
The FIDA implementation timeline is not yet fixed — it depends on when the trilogue process concludes and when the final regulation is published in the Official Journal of the EU.
Key planning implication: If FIDA enters into force in mid-2027, institutions have approximately 24 months from that point before Phase 1 obligations apply — meaning practical FIDA deadlines begin arriving in 2029.
The Delay Window: Why 2026 Matters
The pause in FIDA trilogue negotiations does not reduce the urgency for preparation. It creates a window — and that window has a cost.
One of the most common sources of confusion among compliance teams is how FIDA relates to PSD2, PSD3, and the Payment Services Regulation (PSR). These are distinct but connected frameworks.
PSD2 (In Force Since 2019)
PSD2 introduced open banking — the right for customers to share their payment account data with third parties. It established the framework for Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs).
PSD3/PSR (Adopted 2026, Application ~2028)
PSD3 modernises PSD2's payment account framework. The EU Parliament's ECON Committee adopted its position in 2024; formal adoption is expected in 2026, with application from approximately 2028.
FIDA: The Open Finance Layer
FIDA extends the PSD2/PSD3 principle from payment data to all financial data — a significantly broader scope. Where PSD2/PSD3 govern payment accounts, FIDA governs insurance, investments, pensions, mortgages, and savings.
The critical implication for infrastructure teams: Institutions that build their FIDA API infrastructure on the same technical foundations as their PSD2/PSD3 infrastructure will be able to leverage significant reuse. Those that treat them as separate projects will build twice.
What Should Your Organisation Be Doing Now?
Given that the FIDA text is not yet final, many compliance teams are in 'wait and see' mode. This is the wrong posture. The infrastructure decisions you make in the next 12–18 months will determine whether your organisation meets FIDA's obligations on time — or scrambles to catch up.
1. Map Your Data Holder Obligations Under the Current Draft
The current FIDA negotiating text is specific enough to map your data holder obligations with reasonable confidence. Begin with: which customer data categories does your institution hold? Which products are in scope? What APIs will you need to build?
2. Begin FDSS Scheme Participation Due Diligence
FDSS schemes are beginning to form across the EU. Early participation in scheme formation gives institutions influence over technical standards and commercial frameworks that will govern the market for years.
3. Build the API Consent Layer Now
The requirement for a FIDA-compliant consent management infrastructure will not change materially regardless of final text variations. Building the permission dashboard and consent API layer now allows you to iterate on a real product rather than an abstract requirement.
4. Align Your DORA and FIDA Workstreams
DORA is already in force. Every FIDA API endpoint your institution will build is also a DORA-regulated ICT system. Treating them as one integrated programme — not two parallel tracks — reduces cost and risk.
5. Define Your FISP Strategy and Licensing Roadmap
If your institution has any ambition to operate as a data user as well as a data holder under FIDA — consuming third-party financial data to build new products — now is the time to begin mapping the FISP licensing pathway.
Common Misconceptions About FIDA
“FIDA has been withdrawn.”
“FIDA only applies to banks.”
“The trilogue pause means we have more time.”
“We need to wait for EBA technical standards before doing anything.”
“PSD3 and FIDA are separate projects.”
How InfraFIDA Helps
InfraFIDA is the EU's specialist infrastructure consultancy for FIDA compliance. We work with data holders and FISPs across the EU to build the infrastructure they need to meet FIDA's obligations — API architecture, consent management, FDSS participation strategy, DORA alignment, and FISP licensing support.
FIDA Infrastructure Architecture
FDSS Participation Strategy
DORA × FIDA Integration — Unified ICT governance frameworks that satisfy both DORA's in-force requirements and FIDA's forthcoming obligations.
Regulatory Readiness Assessment — Gap analysis against current FIDA draft text, obligation mapping, sequencing roadmap.
FISP Licensing Support — Licensing pathway analysis, EBA framework monitoring, licence application support.
The firms that will meet FIDA's obligations without a crisis sprint are the ones building the right infrastructure now — before the text is final, while the standards are still forming, and while the scheme landscape is still open to influence. InfraFIDA exists to make sure your organisation is one of them.
Key Resources
Last updated: May 2026. FIDA regulation is an active legislative proposal. This guide reflects the current negotiating text and political trajectory as of the date of publication. InfraFIDA monitors FIDA developments continuously — check back for updates as the trilogue process progresses.