Regulation

FIDA (EU Financial Data Access Regulation)

Expert-reviewed Updated: 2026-09-04 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

FIDA (Financial Data Access) is the EU regulation proposal that extends open finance to the insurance sector: customers gain a right to access their financial and insurance data, and data holders must provide it through standardised APIs.

Core elements

FIDA (Financial Data Access) is the regulation proposal published by the European Commission on 28 June 2023 (COM(2023) 360) that, for the first time, extends open finance in binding form to the insurance sector. Customers gain a right to access data held about them by a financial firm; so-called data holders – insurers, intermediaries, banks and other financial service providers – must make that data available on request, free of charge, in real time and through standardised application programming interfaces (APIs). Data users need authorisation as a Financial Information Service Provider (FISP); governance, technical standards and remuneration for data sharing are set by mandatory, industry-led Financial Data Sharing Schemes (FDSS).

Scope and state of negotiations

For insurance, the proposal covers non-life data in particular (property, liability, motor and others); life and health insurance are excluded to avoid the risk of financial exclusion through discriminatory risk selection. Smaller (re)insurers below certain premium or technical-provision thresholds are also exempt. Trilogue negotiations between the European Parliament and the Council have stalled since early 2026; contested points include the scope of data categories, the role of large platforms (“gatekeepers”) and the concrete implementation model. A phased rollout over roughly four years after entry into force is considered likely.

Practical relevance

FIDA builds on the PSD2 logic developed for the banking sector and applies it, for the first time, in binding form to insurance data; it supplements the GDPR with a sector-specific access right but does not replace it – data-protection principles continue to apply in parallel. For insurers and brokers, the regulation, if adopted, implies investment in API infrastructure and FDSS membership. For product-neutral reference resources such as this knowledge graph, no such obligation arises, since no customer or policy data is processed and neither a data-holder role nor a consent mechanism is required (see README.md, section “Positioning: no data-holder role, an open reference taxonomy”).

Legal basis

  • EU: COM(2023) 360 final, 2023/0205 (COD)