The EU's FiDA Regulation: A Guide to Open Finance and the Expansion of Data Sharing to Investments, Mortgages, and Crypto
The European Union is finalizing a sweeping new framework that will force financial institutions to share customer data across mortgages, investments, and crypto-assets.
By Factlen Editorial Team
- Traditional Financial Institutions
- Banks and insurers facing significant compliance costs but welcoming the shift to cost-based compensation.
- Fintech & Crypto Innovators
- Startups and digital asset platforms eager to leverage standardized data to build cross-platform services.
- EU Policymakers
- Regulators focused on digital sovereignty, market competition, and preventing monopolization by global tech giants.
- Data Infrastructure Providers
- Entities focused on the technical implementation of Financial Data Sharing Schemes (FDSS) and APIs.
What's not represented
- · Retail Consumers
- · Small and Medium Enterprises (SMEs)
Why this matters
FiDA will fundamentally change how Europeans interact with their money, allowing consumers to seamlessly share their mortgage, investment, and crypto data across different apps to unlock personalized financial advice and better rates.
Key points
- FiDA expands data-sharing mandates beyond payment accounts to include mortgages, investments, pensions, and crypto-assets.
- The regulation allows financial institutions to charge cost-based compensation for providing data access.
- Big Tech companies designated as 'gatekeepers' under the Digital Markets Act are banned from accessing the data.
- Consumers will manage their data permissions through a centralized, real-time consent dashboard.
- The rules will roll out in three phases, with the first implementation wave expected in 2027.
For years, European consumers have been able to link their basic bank accounts to budgeting apps and payment services, a system known as Open Banking. But the rest of their financial lives—mortgages, investment portfolios, pension funds, and crypto assets—have remained locked inside the proprietary silos of individual institutions.
That fragmentation is about to end. The European Union is finalizing the Financial Data Access (FiDA) regulation, a sweeping legislative framework designed to transition the continent from Open Banking to a comprehensive Open Finance ecosystem.
FiDA mandates that financial institutions must make nearly all customer data available to authorized third parties in real-time, provided the customer explicitly consents. The regulation aims to turn financial data into a portable asset co-owned by the consumer, rather than a proprietary resource hoarded by the institution that collected it.
The scope of the new regulation is vast. While its predecessor, the Payment Services Directive (PSD2), only covered payment accounts, FiDA extends data-sharing obligations to savings accounts, mortgage credit agreements, non-life insurance products, and occupational pensions.

Crucially, the regulation explicitly includes crypto-assets. By naming digital assets directly, FiDA aligns with the EU’s Markets in Crypto-Assets (MiCA) framework, bringing crypto data out of the regulatory gray area and placing it on the exact same footing as traditional equities and bonds.
The mechanics of this new ecosystem rely on two primary actors: 'Data Holders' and 'Data Users.' Data Holders are the traditional banks, insurers, and investment firms that currently store the information. Data Users, officially termed Financial Information Service Providers (FISPs), are the licensed fintechs and third parties seeking access to build new services.[1]
To facilitate this massive exchange of information, market participants will be required to establish Financial Data Sharing Schemes (FDSS). These governed consortiums will define the technical API standards, liability models, and operational rulebooks that make cross-platform data sharing technically feasible.
One of the most significant departures from previous open banking rules is the introduction of a compensation model. Under PSD2, banks were forced to build APIs and share payment data for free, a mandate that caused widespread industry resentment.
FiDA corrects this by allowing Data Holders to charge 'cost-based compensation' for the data they provide. This shift transforms compliance from a pure sunk cost into a potential revenue stream, incentivizing traditional institutions to build higher-quality, more reliable data interfaces.
FiDA corrects this by allowing Data Holders to charge 'cost-based compensation' for the data they provide.
For consumers, the cornerstone of the FiDA experience will be the mandatory 'consent dashboard.' Every Data Holder must provide a centralized, real-time interface where customers can view exactly who has access to their data, what it is being used for, and for how long.[1]
This dashboard empowers users to revoke access with a single click, ensuring that control remains firmly in the hands of the data subject. The European Commission is also pushing for these dashboards to integrate with the upcoming EU Digital Identity Wallet to standardize strong customer authentication.[1]
While FiDA is designed to foster competition, the EU is acutely aware of the geopolitical risks associated with opening up vast troves of financial data. A major sticking point in the legislative negotiations has been the potential for massive technology conglomerates to exploit the new rules.[1]
To prevent monopolization, the regulation includes a targeted exclusion: companies designated as 'gatekeepers' under the Digital Markets Act (DMA)—such as Alphabet, Amazon, and Meta—are explicitly banned from obtaining FISP licenses. This ensures that Big Tech cannot use its existing market dominance to swallow the European financial sector.[1]
The legislative journey for FiDA has been complex. Introduced in June 2023, the framework received political agreement from the Council of the EU in late 2024. Trilogue negotiations between the Commission, Parliament, and Council resumed in mid-2025 to iron out the final details.[1]

Formal adoption of the regulation is expected by late 2025, but the financial industry will not be forced to flip a switch overnight. Recognizing the immense technical complexity of the mandate, policymakers have agreed on a phased implementation timeline.
Phase 1, expected to take effect 24 months after the regulation enters into force, will cover foundational products like savings accounts, consumer credit agreements, and motor insurance.
Phase 2, slated for 36 months post-adoption, will bring the most complex and highly anticipated asset classes into the fold. This phase includes investments in financial instruments, mortgages, personal pensions, and crypto-assets.
Finally, Phase 3 will roll out at the 48-month mark, encompassing occupational pensions, business creditworthiness assessments, and the remaining non-life insurance products.

For financial institutions, the runway to compliance is short. Banks and insurers must begin auditing their internal systems immediately, mapping where their data lives and addressing the technical debt that could hinder real-time API connectivity.
Ultimately, FiDA represents a fundamental rewiring of the European financial system. By breaking down data monopolies and establishing a secure, standardized framework for sharing, the regulation sets the stage for a new generation of personalized, cross-platform financial services.[2]
How we got here
June 2023
The European Commission introduces the initial FiDA legislative proposal.
December 2024
The Council of the EU reaches a political agreement on the framework.
June 2025
Trilogue negotiations resume between the Commission, Parliament, and Council.
Late 2025
Expected formal adoption and entry into force of the regulation.
2027
Anticipated launch of Phase 1 data sharing for savings and motor insurance.
Viewpoints in depth
Traditional Financial Institutions
Banks and insurers facing significant compliance costs but welcoming the shift to cost-based compensation.
For legacy banks and insurance providers, FiDA represents a monumental technical challenge. Decades of technical debt and siloed mainframe architecture make real-time data sharing difficult and expensive. However, the industry has largely welcomed the regulation's departure from the PSD2 model, which forced them to provide data for free. By allowing cost-based compensation, FiDA enables traditional institutions to monetize their infrastructure investments, potentially turning compliance mandates into a new revenue stream.
Fintech & Crypto Innovators
Startups and digital asset platforms eager to leverage standardized data to build cross-platform services.
The fintech sector views FiDA as the ultimate catalyst for innovation. By gaining standardized access to a user's entire financial footprint—from mortgages to crypto holdings—these companies can build holistic wealth management tools, automated switching services, and highly personalized credit models. For the crypto industry specifically, explicit inclusion in the regulation is seen as a major legitimizing milestone, fully integrating digital assets into the traditional European financial data ecosystem.
EU Policymakers
Regulators focused on digital sovereignty, market competition, and preventing monopolization by global tech giants.
From a regulatory perspective, FiDA is as much about geopolitics as it is about finance. European policymakers are determined to foster a competitive internal market while protecting it from external dominance. The explicit ban on Digital Markets Act (DMA) 'gatekeepers' acting as Financial Information Service Providers reflects a deep-seated fear that companies like Amazon, Google, or Meta could weaponize their existing data advantages to monopolize European financial services.
What we don't know
- How much financial institutions will actually be allowed to charge under the 'cost-based compensation' model.
- Whether retail consumers will trust third-party applications enough to share their most sensitive investment and mortgage data.
- Exactly how the technical standards for the Financial Data Sharing Schemes (FDSS) will be governed and enforced.
Key terms
- FiDA
- Financial Data Access, the EU regulation mandating the sharing of broad financial data upon customer request.
- FISP
- Financial Information Service Provider, a licensed third party authorized to access and use customer financial data.
- FDSS
- Financial Data Sharing Scheme, a governed framework defining the legal and technical rules for data exchange.
- Open Finance
- The extension of data-sharing principles beyond basic payment accounts to include investments, mortgages, and insurance.
- DMA Gatekeeper
- Large technology companies designated under the Digital Markets Act, which FiDA excludes from accessing financial data.
Frequently asked
Does FiDA cover my health insurance data?
No, the current draft of the regulation explicitly excludes data related to health and life insurance policies.
Will banks be forced to share my data for free?
Unlike previous open banking rules, FiDA allows data holders to charge cost-based compensation for providing access to their data.
Can Big Tech companies access my investment data?
No, FiDA includes provisions that block designated 'gatekeepers' under the Digital Markets Act, such as Google or Meta, from becoming licensed data users.
When will these rules actually take effect?
Following expected adoption in late 2025, the rules will roll out in phases, with the first wave of data sharing mandates beginning in 2027.
Sources
[1]AxwayEU Policymakers
The European Commission is refining its approach to the Financial Data Access Regulation (FiDA)
Read on Axway →[2]Factlen Editorial TeamData Infrastructure Providers
Synthesis by Factlen editorial team
Read on Factlen Editorial Team →
Every angle. Every day.
Get guides stories with full source coverage and perspective breakdowns delivered to your inbox.




