In a few weeks the European Commission will publish its work programme for 2027, and with it the list of pending proposals it intends to withdraw. Whether the Financial Data Access Regulation, FiDA, appears on that list matters a great deal to insurers. If FiDA goes ahead, implementing it will demand heavy investment across the industry, for a customer benefit that has yet to be demonstrated.
Yet the homework for insurers is the same either way. That was my argument at the end of September at the Leipziger Gesprächskreis ‘Compliance im Versicherungsunternehmen’: standstill in Brussels, pressure at home. The pressure on how insurers handle customer identity, consent and data does not come from FiDA. It comes from several other directions — and most of it arrives before FiDA would.
Where FiDA stands
The Commission proposed FiDA in June 2023, in the same package as the revised payment services rules. The idea is simple: extend what PSD2 did for payment accounts to almost every other financial product, insurance included. Customers could let third parties access the data that banks, investment firms and insurers hold about them, in formats set by industry-run financial data sharing schemes.
Three years on, the file is stuck. There has been no political trilogue since June 2025. The Danish Council presidency tabled simplification drafts in the second half of 2025, but no new mandate. This spring the Commission floated an options paper that would phase obligations in through implementing acts. The Irish presidency’s priorities lie elsewhere, with the Savings and Investments Union and the digital euro.
Even the most lenient reading leaves a long runway. Take, point by point, whichever of the Commission proposal and the Council mandate is kinder to insurers, and assume entry into force in 2028. Scheme membership for motor insurance would then be due in 2029 and motor data sharing in 2030. The full insurance scope — the remaining non-life lines, insurance-based investment products and personal pensions — would follow around 2032. Health insurance and pure protection products such as term life and disability cover stay out of scope throughout.
For many firms, that looks like a good reason to wait.
Where the pressure comes from
The pressure that matters is already here, or arrives well before 2029.
AI agents already log into customer portals with customers’ own credentials. They read policies, compare offers and may cancel contracts on their owners’ behalf. No scheme, no standard and no dashboard governs any of this.
Every customer already has a right of access and a right to data portability under the GDPR. Answering those requests properly takes what FiDA would take: knowing which data you hold on whom, and being able to filter out other people’s data.
On 2 January 2027 Germany launches its EUDI Wallet, ‘d-you’. From 24 December 2027, financial services firms that require strong customer authentication must accept European Digital Identity Wallets whenever a customer chooses to use one; only micro and small enterprises are exempt.
A further point came from the discussion in the room. From 10 July 2027 the EU Anti-Money Laundering Regulation applies directly. For life insurers, that means establishing and verifying customer identity under uniform EU rules, with the wallet as one way to do it. It also means refreshing customer information at risk-based intervals: at least once a year for higher-risk customers and at least every five years for everyone else. For contracts that run for decades, that is a genuine change.
Payment services set the benchmark for what customers will expect. The Payment Services Regulation, politically agreed in November 2025 and expected to apply from 2028, obliges banks to offer a dashboard showing who has access to a customer’s account data, and to let the customer withdraw that access. Insurers are not in scope. Their customers, however, will learn the pattern at their bank — and ask why their insurer cannot do the same.
Build once
These requirements come from very different directions. At their core, they ask for the same four capabilities.
The first is a single customer identity across lines of business and channels: one person, one identity, whether a request comes through a broker, the portal, the wallet or an anti-money-laundering review. The second is a register of consents and permissions attached to the person rather than to the contract, with its own history. The third is a set of filter rules for third-party data and health data, applied before anything leaves the house. The fourth is data quality that stands up to scrutiny, maintained as a permanent task rather than a project.
Built once rather than once per regulation, these capabilities serve the GDPR, the wallet and anti-money laundering today, and they prepare an insurer for FiDA as well. This is governance as a design principle, not as a downstream compliance filter. Much of the groundwork already exists: the GDPR record of processing activities and the ICT asset inventory required under DORA mostly need to be connected, not rebuilt.
What can wait is what is specific to FiDA and expensive: real-time interfaces, the permission dashboard itself and contracts with a data sharing scheme. Those are worth building once the text is final.
What cannot wait is ownership. Someone has to hold customer data access together across data protection, IT, compliance and distribution, and watch the signals from Brussels. German supervisory law already makes the second part a compliance duty: under Section 29(2) of the Insurance Supervision Act (VAG), the compliance function must assess the impact of changes in the legal environment.
A permission is not a consent
For compliance teams, FiDA adds a fourth kind of ‘yes’ to the three insurers already manage: consent under the GDPR, the release from professional secrecy under Section 203 of the German Criminal Code for life, accident and health insurance, and consent to telephone and email marketing under the Act against Unfair Competition. Three traps follow.
First, a FiDA permission is not a consent. It is a condition for access, not a legal basis for processing. The data user needs its own legal basis under the GDPR, while the data holder relies on its legal obligation. The European Data Protection Board took the same line on the ‘explicit consent’ required under PSD2.
Second, a customer’s permission covers only the customer’s own data. Insurance files are full of other people’s data: the injured party in a liability claim, the other driver in a motor claim. The customer’s say-so does not release them.
Third, health data. Personal-injury data from accident or motor claims has to be filtered out, and the Council mandate excludes it explicitly.
What FiDA will not do
What FiDA will not provide is a framework for AI agents. The proposal knows data holders, data users and permissions; it does not know whether a person or a machine is asking. Through the customer’s own access right under Article 4 — free of charge, continuously and in real time — an agent holding a customer’s credentials would obtain more than it sees in the portal today.
FiDA governs who gets the data. Not who is asking.
Note & sources
This essay is based on my talk ‘Stillstand in Brüssel. Handlungsdruck im Haus: FiDA aus Compliance-Sicht’ at the Leipziger Gesprächskreis ‘Compliance im Versicherungsunternehmen’ of V.E.R.S. Leipzig, hosted by Wertgarantie SE in Hanover on 29 September 2026. Where the Commission proposal and the Council mandate differ, it follows whichever is more lenient for insurers; article numbers refer to the Commission proposal.
- Commission proposal for a Regulation on a framework for Financial Data Access, COM(2023) 360.
- Council general approach on FiDA, ST 16312/24.
- Regulation (EU) 2024/1624 on anti-money laundering (AMLR), and its Article 26 on updating customer information.
- eIDAS Regulation, Article 5f on reliance on European Digital Identity Wallets.
- ComputerBase, on the launch of ‘d-you’.
- Sopra Steria, on the state of play of the Payment Services Regulation.