This article is general information for compliance and product teams and is not legal advice. Regulatory texts and timelines are still being finalized; confirm current obligations with primary sources and qualified counsel before acting.
Open banking turned a simple idea into a market: with a customer’s permission, a licensed third party can access their bank data or initiate a payment on their behalf. In the European Union that idea has been law since the second Payment Services Directive (PSD2) took effect, and it is now entering its next phase. PSD3 and a new directly applicable Payment Services Regulation (PSR) are set to modernize the payments rulebook, while a separate Financial Data Access (FIDA) framework aims to extend the model well beyond payment accounts into what is often called open finance. For fintechs and payment service providers, understanding where the rules are today and where they are heading is now a core compliance responsibility.
What Open Banking Actually Is
At its core, open banking rests on a few building blocks. Access to account (XS2A) is the right of a licensed third party to reach a customer’s payment account data or initiate payments, provided the customer consents. Two regulated roles sit on top of that right: account information service providers (AISPs), which read data to power budgeting, lending, or accounting tools, and payment initiation service providers (PISPs), which start a payment directly from the customer’s bank account. Access is delivered through dedicated interfaces (APIs) exposed by banks, and every access or payment is protected by strong customer authentication (SCA). For a deeper treatment of the authentication layer, see our guide to strong customer authentication under PSD2 and PSD3.
The Current Legal Basis: PSD2
PSD2 remains the operative regime for open banking in the EU today. It obliges banks to provide third-party access, defines the AISP and PISP roles, mandates SCA, and sets the licensing and conduct rules that fintechs operate under. It has been a genuine catalyst for competition and new products, but it has also drawn consistent criticism: API quality and availability vary widely between banks, consent and permission management is often clumsy for consumers, and enforcement has been uneven across member states. These well-documented pain points are precisely what the next wave of rules sets out to fix.
What Is Changing: PSD3 and the PSR
The European Commission’s payments package replaces PSD2 with two instruments. PSD3 is a directive covering licensing and authorization that member states transpose into national law. The Payment Services Regulation (PSR) is directly applicable across the EU, meaning its conduct-of-business rules, covering fraud, SCA, refunds, and data-access interfaces, apply uniformly without national transposition. Together they are designed to repeal and replace PSD2 and the E-Money Directive, folding payment and e-money licensing into a single, more harmonized framework.
For open banking specifically, several changes stand out. The rules push for better performing data-access interfaces, with clearer obligations on banks so that APIs are reliable rather than an afterthought. They introduce permission dashboards that let consumers see, in one place, which providers they have granted data access to and revoke that access easily. They aim to remove unjustified obstacles that some banks have placed in front of third-party access. And they strengthen the wider anti-fraud toolkit, including payee verification and expanded liability rules that connect to instant payments, a topic we cover in our guide to verification of payee and instant payments.
On timing, EU co-legislators reached provisional political agreement on the package in late 2025, with the texts moving through final approval steps during 2026 and publication in the Official Journal expected in the course of the year. Entry into force is then anticipated in 2027, followed by a transition period widely reported in the range of roughly 18 to 24 months depending on the instrument, with the PSR’s directly applicable rules generally taking effect before the PSD3 transposition deadline. Exact dates depend on final publication, so teams should track the Official Journal rather than plan around any single rumored date.
FIDA and the Move to Open Finance
Where PSD3 and the PSR modernize payments, the Financial Data Access (FIDA) framework proposes to extend the open banking model to a far wider set of financial data, including investments, pensions, insurance, mortgages, and loans. This is the shift from open banking to open finance: customers would be able to authorize sharing of much more of their financial life, and providers would access it through structured financial data sharing schemes, again supported by permission dashboards and, importantly, by defined arrangements for compensation between data holders and data users.
FIDA is less advanced than the payments package. It was proposed alongside PSD3 and the PSR and, as of 2026, remains under negotiation among the EU institutions, with real debate about its scope and cost. A realistic reading is that application would not arrive before roughly 2029 to 2030 even in a favorable scenario. For most firms, FIDA is therefore a strategic planning item today rather than an immediate compliance deadline, but it signals clearly where European financial data policy is heading.
Timeline at a Glance
| Framework | Status (2026) | Practical takeaway |
|---|---|---|
| PSD2 | In force; the current legal basis for open banking | Your live obligations still sit here |
| PSD3 (directive) | Provisional agreement reached; final steps and publication expected in 2026 | Licensing and authorization changes to prepare for |
| PSR (regulation) | Directly applicable; expected to take effect after entry into force in 2027 | Conduct rules apply EU-wide without transposition |
| FIDA (open finance) | Under negotiation; timeline uncertain | Strategic planning item; likely late-decade |
What This Means for Fintechs and PSPs
The practical agenda for the next two years is manageable if you start now. Confirm that your current activities are correctly licensed and mapped against your AISP or PISP permissions, since the transition from PSD2 to PSD3 will touch authorization. Review how you obtain, record, and manage customer consent, because permission dashboards and clearer revocation are central to the new rules. Assess your dependence on bank APIs and how you would handle performance or availability changes as data-access obligations tighten. Revisit your fraud and authentication controls in light of expanded SCA and payee-verification expectations. And treat FIDA as a horizon item in product strategy, so that if open finance arrives you are positioned rather than surprised. Firms that also handle e-money or wallets should read this alongside our guide to digital wallets and e-money compliance, since the licensing regimes are converging.
Frequently Asked Questions
Does PSD3 replace PSD2 immediately?
No. PSD2 remains in force until PSD3 and the PSR are published and take effect after a transition period. Plan for change, but keep meeting your current PSD2 obligations in the meantime.
What is the difference between PSD3 and the PSR?
PSD3 is a directive covering licensing that member states transpose into national law. The PSR is a regulation that applies directly and uniformly across the EU, carrying the conduct rules on fraud, SCA, refunds, and data access.
Is FIDA something we need to comply with now?
Not yet. FIDA is still under negotiation and, even in a favorable scenario, would apply toward the end of the decade. It is best treated as a strategic planning input rather than a near-term deadline.
Conclusion
European open banking is entering a more mature, more harmonized phase. PSD2 remains the law you comply with today, PSD3 and the PSR are the near-term change that will reshape licensing, fraud rules, and data access, and FIDA points toward a broader open finance future still some years away. The firms that navigate this well will be the ones that treat regulatory change as a roadmap rather than a fire drill, aligning consent management, API dependencies, and fraud controls ahead of the deadlines.
If your team needs help mapping these frameworks to your products and compliance operations, DanuSoft works with fintechs and PSPs on exactly this kind of readiness.
Disclaimer: This guide is provided for general information only and does not constitute legal or regulatory advice. Regulatory timelines and requirements are subject to change; verify against official sources and seek qualified professional advice for your specific circumstances.