A failing interface would delay open finance, not fix it
Eine schlechte Schnittstelle verzögert die offenen Finanzdaten — repariert wird sie nicht
Europe’s open banking rules gave third parties a right of access and said almost nothing enforceable about the quality of the interface behind it. Correcting that omission took a full legal replacement and, counting from the day the access rules first applied to the day the replacement was politically agreed, seven years and ten months. The successor file — the Financial Data Access regulation, which extends access to investments, insurance, savings, mortgages and pensions — makes the same delegation again. And the option currently on the negotiating table goes one step further: under it, a badly built interface would not trigger enforcement. It would trigger a postponement of the law.
The rule that was written, and the rule that was not
The second Payment Services Directive obliged banks to let licensed third parties reach a customer’s payment account. It did not fix, in the legislative text, a measurable standard for how well that had to work. What followed is documented by the supervisor itself rather than by the firms that complained.
On 4 June 2020 the European Banking Authority published an opinion on obstacles in the interfaces banks had built (EBA/OP/2020/10), setting out which practices were unlawful. Eight months later, on 18 February 2021, it published a second opinion (EBA/Op/2021/02) whose subject was that the first one had not been enough. In it the EBA records that national authorities had acted and many banks had removed the obstacles, but that it “continues to observe that some ASPSPs across the EU have still not removed them and are preventing the competition-enhancing objective of the PSD2 from materialising in full”. It asked national authorities to take supervisory action by 30 April 2021, and named the escalation available to them: withdrawing the exemption from the contingency mechanism, or fines.
Two supervisory opinions and a deadline are what a framework produces when the obligation is qualitative. The Commission’s own review reached the same place from the other direction. Its impact assessment concluded that the directive’s objectives had been “only partially met”, and among the four problems it named was that “the open banking market functions imperfectly, especially as regards data exchange” — the wording is from the European Parliament’s research service, summarising the Commission’s assessment in a briefing of August 2025 that is explicitly not an official position of the Parliament. The same briefing records what the Commission’s review found on both sides of the interface: third parties reported that the dedicated interfaces “vary in quality and performance”; banks reported significant costs to build them and objected that the directive prevented them from charging for access at all.
That last complaint is the important one, and it is not a bad-faith argument. A bank asked to fund, at its own expense, an interface whose purpose is to let competitors reach its customers has a commercial reason to build something adequate and no commercial reason to build something good. Adequate was the specification, and adequate was delivered.
The replacement framework attaches the missing obligations. The Council and the Parliament reached a provisional political agreement on the payment services regulation and its accompanying directive on 27 November 2025, according to the Council’s own press release of that date; the compromise texts were endorsed by member state representatives on 22 April 2026 and published the following day. The regulation requires at least one dedicated interface, enumerates prohibited obstacles instead of banning obstruction in the abstract, and requires performance parity with a bank’s own customer interface. The access rules of the directive it replaces applied from 13 January 2018. From that date to the provisional agreement is seven years and ten months — arithmetic on two dates, both of them published by the institutions involved.
What the open finance file delegates, and to whom
The Financial Data Access proposal was tabled by the Commission on 28 June 2023, the same day as the payments package. Its architecture is set out in the Commission’s own explanatory material: data holders must make customer data available to authorised data users on the customer’s instruction, “in a standardised way and of the same quality” as they hold it themselves, and the technical detail of how that happens is not in the regulation.
It sits instead in what the proposal calls financial data sharing schemes — contractual arrangements between data holders and data users, described in the Commission’s presentation of September 2023 as a “market driven arrangement” that establishes common standards for the data and the technical interfaces, contractual liability, a dispute resolution system, and a model for determining compensation. Compensation is the deliberate correction of the omission the banks complained about: under the payments framework, access had to be free; under this one, a data holder can be paid for making data available, and the method for calculating that payment is set by the scheme.
The regulation’s answer to a scheme that never appears is a delegated act. If no scheme is developed for a category of customer data, the Commission is empowered to specify the modalities itself. That is a backstop the payments framework never had, and it deserves to be stated at full strength rather than waved at.
Meanwhile the standards work is happening, outside the law and ahead of it. CEN/TC 445, the European standards committee for digital information interchange in the insurance industry, announced that 45 experts from nine European countries had finalised draft European standards for customer data access and portability in insurance, including Open API specifications in machine-readable form, with the formal comment period running from May to July 2026. The Commission’s non-paper of 6 April 2026 records that the Council took on board an approach delegating the development of standards and APIs for data sharing to the European standardisation organisations, and describes those standards as voluntary.
The case for building it this way
The argument for delegation is not weak, and its strongest form is worth setting out before the objection.
An interface specification written into a regulation is frozen at the moment of adoption and can only be changed by amending the regulation. Financial data is not one thing: a motor insurance policy, a mortgage, a portfolio of financial instruments and a savings account have almost nothing structurally in common, and a single legislative schema would either be so abstract as to be useless or so detailed as to be wrong for most of its scope within three years. Standards bodies and industry schemes revise their work continuously. Legislatures do not.
Second, the compensation mechanism is a genuine repair of the incentive that broke open banking. If a data holder is paid per call, a fast and complete interface is a revenue-generating asset rather than a cost imposed for a competitor’s benefit. That inverts the economics that produced eight years of supervisory opinions, and it does so without anyone having to specify a latency threshold.
Third, the population being regulated is larger and more varied than a single schema can serve. The European Banking Authority’s register held 737 payment institutions and 338 electronic money institutions when the Parliament’s research service counted it in August 2025, against 939 and 400 respectively over the register’s history. The second pair is the more interesting one: on those figures roughly a fifth of all payment institutions ever registered, and a sixth of all e-money institutions, are gone. Whatever standard is written has to be affordable for those that remain.
Fourth, the delegated act under the proposal’s Article 11 is not decorative. The Commission’s April 2026 non-paper describes it as an empowerment “to impose the modalities of data sharing” that schemes are supposed to agree — governance, data and interface standards, compensation rules, contractual liability and dispute resolution — “in case of suboptimal outcomes at scheme level”, and says explicitly that it could be used “to fix issues that may be identified in the preceding phase”. A named actor with the power to write the standard if the market does not is precisely what the payments framework lacked, and it is why the two files are not simply the same mistake twice.
Where the file actually stands
It stands still. The Commission’s non-paper of 6 April 2026, circulated to the Council’s working party on open finance as document WK 5041/2026, opens its section on next steps with the observation that “there have been no developments on FiDA in the European Parliament following the second trilogue meeting in June 2025”.
Two weeks earlier, the Council presidency had circulated a questionnaire to member states, document WK 4626/2026 of 25 March 2026, with a deadline of 10 April. Its first question asks each government to confirm, in writing, that there is “political will from the MS to engage constructively in order to further work on the FiDA Regulation, with the aim to resume trilogue negotiations”. A presidency that has to ask twenty-seven governments to confirm in writing that they still want to negotiate is describing the state of the file more precisely than any commentary could.
The same documents show what is being traded away to get it moving. The non-paper lists exclusions that found substantial support in the Council: credit rating agencies, large corporates, small investment firms and fund managers, issuers of asset-referenced and electronic money tokens, with further support for excluding small insurance intermediaries and credit unions, and confirmation of the earlier exclusion of occupational pension data with a national opt-in. A majority of member states support excluding terminated contracts. The definition of customer data has been narrowed so that only data which “has not undergone substantial modification” is in scope. On how far back the right reaches, the non-paper reports “more support for a phased approach starting at two years than for a blanket approach with a seven-year cut-off” — the same right to the same data, with a range of three and a half to one still open in April 2026. A range that wide is not a finding about the right answer. It is an admission that the question is being settled politically rather than analytically.
One issue is recorded as unresolved. On whether platforms designated as gatekeepers under the Digital Markets Act should be excluded from the regime entirely or only partly, the non-paper states that “the Council has yet to reach a sufficient degree of convergence”. The presidency questionnaire puts the same question to governments as a binary: full exclusion, or partial.
The phase gate, and what it does to enforcement
The mechanism now on the table is the one worth reading closely. Both Council documents describe it. The obligation on data holders to make data available directly to data users — Article 5 of the proposal — would enter into application in three phases: the first 24 months after the regulation enters into force, covering data on consumer credit agreements, accounts, savings and motor insurance; the second from 36 months, covering residential mortgage credit, investments in financial instruments, crypto-assets and pan-European personal pension products; the third from 48 months, covering the remaining credit agreements, business creditworthiness data, non-motor insurance and insurance-based investment products.
The change is that movement between the phases would no longer be automatic. Each subsequent phase would apply only after the Commission adopts an implementing act, and only after an assessment of the phase before it. The presidency questionnaire’s annex lists what the assessment covers: whether schemes have been created and are fully operational, including governance, datasets, data and interface standards and compensation rules; “whether third-party APIs have been implemented and are fully functional”; and whether data users are accessing data and paying compensation.
One distinction is preserved: only Article 5 would be phased. The non-paper states that customers themselves should have access to their own data under Article 4 on the Commission’s original timeline. That is the right instinct, and it is also where the exercise could lose its point — a customer who may read their insurance data but cannot have it moved from one provider to another has a statement, not portability, and the difference between those two things is the reason the regulation was drafted.
Read that as an enforcement design rather than a timetable. The question the payments framework could not answer — is the interface actually any good? — is now the question that decides whether the next tranche of the law applies at all. If the answer is no, the consequence falls on the data users who were waiting for the next dataset, and on the customers who would have been able to move it. The data holder whose interface did not work is not, by that act, made to fix it. The pressure runs the wrong way down the chain.
The counter is real: the Article 11 power exists in parallel, and the Commission says it may be used to rectify modalities that did not work. But the two instruments are not symmetrical in cost. Declining to activate a phase is an omission, defensible as caution, requiring no drafting and no confrontation with a data holder. Imposing modalities by delegated act is an act, contestable, and it makes the Commission the author of a technical standard it will then have to maintain. Where a regulator has a cheap option and an expensive one, the observable pattern in this field is that the cheap one is the one that gets used — which is the lesson of the two EBA opinions above, where the escalation available on paper was fines and revoked exemptions, and what was issued was a second opinion.
The arithmetic
Nobody has published this sum, so here it is with its inputs named. The phase timings are the Council’s, from the annex to WK 4626/2026 and the annex to WK 5041/2026. Entry into force is twenty days after publication in the Official Journal, per the standard formula. Everything else is a conditional.
Assume, generously, that the trilogue restarts and produces a political agreement during 2026, and that the text is published in the Official Journal in 2027 — roughly the interval the payments package took from provisional agreement in November 2025 to endorsement in April 2026, plus lawyer-linguist work and two formal votes. Phase 1 of direct data access then applies in 2029. Phase 2 is not before 2030, phase 3 not before 2031, and neither is automatic. Payment account data has been accessible to licensed third parties since January 2018. On those assumptions the gap between the two halves of a customer’s financial life — the payment account, and everything else — is about thirteen years.
This is arithmetic on a published timetable, not a forecast, and the mechanism is named rather than assumed: the 24, 36 and 48-month intervals are in the Council’s own annex, and the two gates between them are the subject of the questionnaire that governments answered in April 2026.
Degrees of confidence
Firmly held: the quality standard for the interface is not in the regulation, and the file was not moving in the Parliament between June 2025 and April 2026. Both come from documents the institutions wrote themselves.
Held with reasonable confidence: the phase gate transfers the cost of a bad interface from the party that built it to the parties waiting for it. This follows from how the mechanism is described, not from evidence of it operating, because it has not operated.
Held cautiously: that the Article 11 power will be used less than the phase gate. That is an inference from how a comparable escalation was used under the payments framework, and one adopted delegated act would weaken it considerably.
What this does not tell you
It does not tell you what is in the final text, because there is no final text. Everything above about the phase gate comes from a presidency questionnaire and a Commission non-paper, both marked LIMITE, both explicitly options rather than agreed positions — the non-paper carries a disclaimer that it “has not been adopted or endorsed by the European Commission”. The Parliament’s position on the phasing is not reflected in either document, and the Parliament is one of the two co-legislators.
It does not tell you that delegation to schemes produces bad interfaces. It tells you that the payments framework, which delegated less and specified less, produced interfaces the supervisor had to write about twice. Whether compensation is sufficient to change that behaviour is an empirical question no one can answer yet, and it is the single most likely way for this article’s argument to be wrong.
And it does not tell you the current state of play as of today. This research found no record of a political agreement on the file, and the most recent primary documents it located date from March and April 2026. An absence in a search is not proof of an absence in Brussels.
What the case teaches
The pattern is not specific to financial data. A legislature that can agree on a right but not on the standard that makes the right usable will delegate the standard — to a supervisor, to a standards body, to a scheme, or to itself in the form of a later act. The delegation is always defensible on the merits, and it is usually defended in the language of flexibility and technical neutrality. It reappears, years later, as the reason the right did not work, and the correction takes a legislative cycle.
The same shape is visible elsewhere in European payments law. Strong customer authentication was specified in technical standards rather than in the directive, and the fraud it displaced turned up in the categories the standard did not cover. The payee-name check was mandated without a corresponding reallocation of loss, and the warning now exists while the liability sits where it always did. In each case the instrument was written and the consequence was left to be discovered.
What makes the open finance file worth watching is that it is the first time the discovery has been designed into the law. The phase gate is an honest admission that nobody knows whether the interfaces will work, and an honest attempt to avoid extending an obligation into a market that cannot carry it. It is also, read as an incentive, a promise to the reluctant data holder that a poor interface has no consequence except a smaller obligation later. Both readings are correct. Which one describes the outcome depends entirely on whether the Commission is willing to use the harder of its two powers — and that is not a question the text can settle, because a discretionary power is worth exactly what its holder is prepared to spend on it.
Die europäischen Regeln zum offenen Bankwesen haben Dritten ein Zugangsrecht gegeben und über die Güte der Schnittstelle dahinter fast nichts Durchsetzbares gesagt. Diese Auslassung zu heilen hat einen vollständigen Rechtsersatz gekostet und, gerechnet vom Tag, an dem die Zugangsregeln galten, bis zum Tag der politischen Einigung über den Nachfolger, sieben Jahre und zehn Monate. Die Verordnung über den Zugang zu Finanzdaten, die dasselbe Prinzip auf Anlagen, Versicherungen, Sparguthaben, Immobilienkredite und Altersvorsorge ausdehnen soll, überträgt die Frage erneut. Und die Fassung, die derzeit auf dem Verhandlungstisch liegt, geht einen Schritt weiter: Eine schlecht gebaute Schnittstelle löst darin keine Durchsetzung aus, sondern eine Verschiebung des Gesetzes.
Die Regel, die geschrieben wurde, und die, die fehlte
Die zweite Zahlungsdiensterichtlinie verpflichtete Banken, zugelassene Dritte an das Zahlungskonto eines Kunden zu lassen. Einen messbaren Maßstab dafür, wie gut das zu funktionieren hat, enthielt der Gesetzestext nicht. Was daraus folgte, ist nicht durch die Klagen der Betroffenen belegt, sondern durch die Aufsicht selbst.
Am 4. Juni 2020 veröffentlichte die Europäische Bankenaufsichtsbehörde eine Stellungnahme zu Hindernissen in den von Banken gebauten Schnittstellen (EBA/OP/2020/10) und legte darin fest, welche Praktiken rechtswidrig sind. Acht Monate später, am 18. Februar 2021, folgte eine zweite Stellungnahme (EBA/Op/2021/02), deren Gegenstand war, dass die erste nicht gereicht hatte. Die EBA hält darin fest, die nationalen Aufsichtsbehörden hätten gehandelt und viele Banken die Hindernisse beseitigt, sie beobachte jedoch weiterhin, dass einige Institute in der EU sie nicht entfernt hätten und damit verhinderten, dass sich das wettbewerbsfördernde Ziel der Richtlinie vollständig entfalte. Sie forderte aufsichtliches Handeln bis zum 30. April 2021 und benannte die verfügbare Eskalation: Entzug der Ausnahme vom Notfallmechanismus oder Geldbußen.
Zwei Aufsichtsstellungnahmen und eine Frist sind das, was ein Rahmen hervorbringt, dessen Pflicht qualitativ formuliert ist. Die Kommission kam von der anderen Seite zum selben Ergebnis. Ihre Folgenabschätzung stellte fest, die Ziele der Richtlinie seien nur teilweise erreicht worden, und benannte als eines von vier Problemen, dass der Markt für offenes Bankwesen unvollkommen funktioniere, besonders was den Datenaustausch angeht. Diese Formulierung stammt aus einem Kurzdossier des Wissenschaftlichen Dienstes des Europäischen Parlaments vom August 2025, das ausdrücklich keine offizielle Position des Parlaments darstellt. Dasselbe Dossier hält fest, was die Überprüfung der Kommission auf beiden Seiten der Schnittstelle vorfand: Dritte berichteten, die eigens eingerichteten Schnittstellen unterschieden sich in Güte und Leistung erheblich; Banken berichteten erhebliche Baukosten und beanstandeten, dass die Richtlinie ihnen verbot, für den Zugang überhaupt etwas zu verlangen.
Der letzte Punkt ist der wichtige, und er ist kein Vorwand. Eine Bank, die auf eigene Kosten eine Schnittstelle bauen soll, deren Zweck darin besteht, Wettbewerbern den Weg zu ihren Kunden zu öffnen, hat einen kaufmännischen Grund, etwas Ausreichendes zu bauen, und keinen, etwas Gutes zu bauen. Ausreichend war die Vorgabe, und ausreichend wurde geliefert.
Der Nachfolgerahmen trägt die fehlenden Pflichten nach. Rat und Parlament erzielten am 27. November 2025 eine vorläufige politische Einigung über die Zahlungsdiensteverordnung und die begleitende Richtlinie — so die Pressemitteilung des Rates von diesem Tag; die Kompromisstexte wurden am 22. April 2026 von den Vertretern der Mitgliedstaaten gebilligt und tags darauf veröffentlicht. Die Verordnung verlangt mindestens eine eigens eingerichtete Schnittstelle, zählt verbotene Hindernisse einzeln auf, statt Behinderung allgemein zu untersagen, und fordert Gleichstand mit der Leistung der bankeigenen Kundenschnittstelle. Die Zugangsregeln der abgelösten Richtlinie galten seit dem 13. Januar 2018. Von dort bis zur vorläufigen Einigung sind es sieben Jahre und zehn Monate — eine Rechnung aus zwei Daten, die beide von den beteiligten Institutionen selbst veröffentlicht wurden.
Was die Verordnung überträgt, und an wen
Den Vorschlag zum Zugang zu Finanzdaten legte die Kommission am 28. Juni 2023 vor, am selben Tag wie das Zahlungspaket. Sein Aufbau ergibt sich aus dem Erläuterungsmaterial der Kommission selbst: Dateninhaber müssen Kundendaten auf Weisung des Kunden zugelassenen Datennutzern zur Verfügung stellen, und zwar in standardisierter Form und in derselben Güte, in der sie sie selbst vorhalten. Wie das technisch geschieht, steht nicht in der Verordnung.
Es steht in dem, was der Vorschlag Systeme für den Austausch von Finanzdaten nennt — vertragliche Vereinbarungen zwischen Datenhaltern und Datennutzern, die die Kommission in ihrer Präsentation vom September 2023 als marktgetriebene Vereinbarung beschreibt: gemeinsame Standards für die Daten und die technischen Schnittstellen, vertragliche Haftung, ein Verfahren zur Streitbeilegung und ein Modell zur Bestimmung der Vergütung. Die Vergütung ist die bewusste Korrektur genau jener Auslassung, über die sich die Banken beschwert hatten: Im Zahlungsrahmen musste der Zugang unentgeltlich sein, hier darf ein Datenhalter für die Bereitstellung Geld verlangen, und wie sich dieses Geld berechnet, legt das System fest.
Die Antwort der Verordnung auf ein System, das nie entsteht, ist ein delegierter Rechtsakt. Wird für eine Kategorie von Kundendaten kein System entwickelt, kann die Kommission die Modalitäten selbst festlegen. Das ist ein Auffangnetz, das der Zahlungsrahmen nie hatte, und es verdient, in voller Stärke genannt und nicht nur gestreift zu werden.
Die Normungsarbeit läuft unterdessen — außerhalb des Gesetzes und vor ihm. Das europäische Normungsgremium CEN/TC 445 für den digitalen Informationsaustausch in der Versicherungswirtschaft teilte mit, 45 Fachleute aus neun europäischen Ländern hätten Entwürfe europäischer Normen für Zugang und Übertragbarkeit von Kundendaten im Versicherungsbereich fertiggestellt, einschließlich maschinenlesbarer Schnittstellenbeschreibungen; die förmliche Kommentierungsphase lief von Mai bis Juli 2026. Das Non-Paper der Kommission vom 6. April 2026 hält fest, dass der Rat den Ansatz übernommen hat, die Entwicklung von Standards und Schnittstellen den europäischen Normungsorganisationen zu übertragen — und beschreibt diese Standards als freiwillig.
Was für diese Bauweise spricht
Das Argument für die Übertragung ist nicht schwach, und seine stärkste Form gehört vor den Einwand.
Eine Schnittstellenbeschreibung, die in einer Verordnung steht, ist im Augenblick ihrer Verabschiedung eingefroren und nur durch Änderung der Verordnung zu bewegen. Finanzdaten sind nicht eine Sache: Eine Kraftfahrzeugversicherung, ein Immobilienkredit, ein Wertpapierdepot und ein Sparkonto haben strukturell kaum etwas gemeinsam. Ein einziges gesetzliches Datenmodell wäre entweder so abstrakt, dass es nichts nützt, oder so genau, dass es für den größten Teil seines Anwendungsbereichs binnen drei Jahren falsch ist. Normungsgremien und Marktsysteme überarbeiten ihre Arbeit fortlaufend. Gesetzgeber tun das nicht.
Zweitens ist die Vergütung eine echte Reparatur des Anreizes, an dem das offene Bankwesen zerbrochen ist. Wird ein Datenhalter je Abruf bezahlt, ist eine schnelle und vollständige Schnittstelle ein ertragbringendes Gut und nicht mehr eine Kostenstelle zugunsten der Konkurrenz. Das dreht die Wirtschaftlichkeit um, die acht Jahre Aufsichtsstellungnahmen hervorgebracht hat — und zwar ohne dass irgendjemand eine Antwortzeit in Millisekunden festschreiben müsste.
Drittens ist der Kreis der Regelungsadressaten größer und ungleichartiger, als ein einziges Datenmodell ihn bedienen kann. Im Register der Europäischen Bankenaufsichtsbehörde standen 737 Zahlungsinstitute und 338 E-Geld-Institute, als der Wissenschaftliche Dienst des Europäischen Parlaments im August 2025 nachzählte — gegenüber 939 beziehungsweise 400 über die gesamte Geschichte des Registers. Das zweite Zahlenpaar ist das interessantere: Danach ist rund ein Fünftel aller je eingetragenen Zahlungsinstitute und etwa ein Sechstel aller E-Geld-Institute nicht mehr da. Welcher Maßstab auch immer geschrieben wird, er muss für die tragbar sein, die übrig bleiben.
Viertens ist der delegierte Rechtsakt nach Artikel 11 des Vorschlags keine Zierde. Das Non-Paper der Kommission vom April 2026 beschreibt ihn als Ermächtigung, die Modalitäten des Datenaustauschs vorzugeben, auf die sich die Systeme eigentlich einigen sollen — Verwaltung, Daten- und Schnittstellenstandards, Vergütungsregeln, vertragliche Haftung und Streitbeilegung —, und zwar bei unzureichenden Ergebnissen auf Systemebene; ausdrücklich könne er dazu dienen, Probleme zu beheben, die in der vorangegangenen Phase erkannt wurden. Ein benannter Akteur mit der Befugnis, den Standard zu schreiben, wenn der Markt es nicht tut, ist genau das, was dem Zahlungsrahmen fehlte. Deshalb sind die beiden Vorhaben nicht schlicht derselbe Fehler zweimal.
Wo das Verfahren tatsächlich steht
Es steht still. Das Non-Paper der Kommission vom 6. April 2026, das der Ratsarbeitsgruppe als Dokument WK 5041/2026 zuging, eröffnet seinen Abschnitt zum weiteren Vorgehen mit der Feststellung, es habe im Europäischen Parlament seit dem zweiten Trilogtreffen im Juni 2025 keine Entwicklungen gegeben.
Zwei Wochen zuvor hatte der Ratsvorsitz einen Fragebogen an die Mitgliedstaaten verschickt, Dokument WK 4626/2026 vom 25. März 2026, mit Frist zum 10. April. Die erste Frage bittet jede Regierung, schriftlich zu bestätigen, dass bei ihr der politische Wille bestehe, konstruktiv weiterzuarbeiten, mit dem Ziel, die Trilogverhandlungen wieder aufzunehmen. Ein Vorsitz, der siebenundzwanzig Regierungen schriftlich bestätigen lassen muss, dass sie überhaupt noch verhandeln wollen, beschreibt den Zustand eines Verfahrens genauer als jeder Kommentar.
Dieselben Dokumente zeigen, was für die Wiederbelebung hergegeben wird. Das Non-Paper zählt Ausnahmen auf, die im Rat breite Zustimmung fanden: Ratingagenturen, Großunternehmen, kleine Wertpapierfirmen und Fondsverwalter, Emittenten wertreferenzierter Token und von E-Geld-Token; weitere Zustimmung gab es für die Herausnahme kleiner Versicherungsvermittler und von Kreditgenossenschaften, dazu die Bestätigung der bereits vereinbarten Herausnahme betrieblicher Altersvorsorgedaten mit nationaler Beitrittsmöglichkeit. Eine Mehrheit der Mitgliedstaaten will beendete Verträge ausnehmen. Die Begriffsbestimmung der Kundendaten wurde so verengt, dass nur Daten erfasst sind, die keine wesentliche Bearbeitung erfahren haben. Zur Frage, wie weit das Recht zurückreicht, hält das Non-Paper fest, es gebe mehr Rückhalt für einen stufenweisen Ansatz beginnend bei zwei Jahren als für eine pauschale Grenze bei sieben Jahren — dasselbe Recht an denselben Daten, mit einer Spanne von dreieinhalb zu eins, offen im April 2026. Eine so weite Spanne ist kein Befund über die richtige Antwort. Sie ist ein Eingeständnis, dass die Frage politisch entschieden wird und nicht analytisch.
Ein Punkt ist ausdrücklich ungelöst. Ob Plattformen, die nach dem Gesetz über digitale Märkte als Torwächter benannt sind, ganz oder nur teilweise ausgeschlossen werden, ist laut Non-Paper im Rat noch nicht hinreichend konvergiert. Der Fragebogen des Vorsitzes stellt den Regierungen genau diese Frage als Entweder-oder: vollständiger oder teilweiser Ausschluss.
Das Phasentor und was es mit der Durchsetzung macht
Der Mechanismus, der jetzt auf dem Tisch liegt, ist der Teil, den man genau lesen sollte. Beide Ratsdokumente beschreiben ihn. Die Pflicht der Datenhalter, Daten unmittelbar an Datennutzer herauszugeben — Artikel 5 des Vorschlags —, soll in drei Phasen gelten: die erste 24 Monate nach Inkrafttreten der Verordnung, für Daten zu Verbraucherkrediten, Konten, Sparguthaben und Kraftfahrzeugversicherungen; die zweite ab 36 Monaten, für Immobiliarkredite, Anlagen in Finanzinstrumenten, Kryptowerte und europäische Altersvorsorgeprodukte; die dritte ab 48 Monaten, für die übrigen Kreditverträge, die Kreditwürdigkeitsdaten von Unternehmen, Versicherungen außerhalb der Kraftfahrtsparte und fondsgebundene Versicherungsprodukte.
Neu ist, dass der Übergang zwischen den Phasen nicht mehr von selbst geschieht. Jede weitere Phase gilt erst, nachdem die Kommission einen Durchführungsrechtsakt erlassen hat, und erst nach einer Bewertung der vorangegangenen Phase. Der Anhang des Fragebogens zählt auf, was bewertet wird: ob Systeme entstanden und voll betriebsfähig sind, samt Verwaltung, Datensätzen, Daten- und Schnittstellenstandards und Vergütungsregeln; ob die Schnittstellen Dritter umgesetzt und voll funktionsfähig sind; und ob Datennutzer Daten abrufen und dafür bezahlen.
Eine Unterscheidung hält das Non-Paper dabei ausdrücklich fest: Nur Artikel 5 soll in Phasen kommen. Das Recht des Kunden auf Zugang zu seinen eigenen Daten nach Artikel 4 soll dem ursprünglich von der Kommission vorgeschlagenen Zeitplan folgen. Das ist sauber gedacht und zugleich der Punkt, an dem das Vorhaben seinen Zweck verlöre: Ein Kunde, der seine Versicherungsdaten selbst abrufen darf, sie aber nicht von einem Anbieter zu einem anderen bewegen lassen kann, hat kein Recht auf Datenübertragbarkeit, sondern einen Datenauszug. Genau der Unterschied zwischen diesen beiden Dingen ist der Grund, warum die Verordnung überhaupt geschrieben wurde.
Man sollte das als Durchsetzungsentwurf lesen, nicht als Zeitplan. Die Frage, die der Zahlungsrahmen nie beantworten konnte — taugt die Schnittstelle etwas? —, entscheidet nun darüber, ob der nächste Teil des Gesetzes überhaupt gilt. Lautet die Antwort Nein, trägt die Folge, wer auf den nächsten Datensatz gewartet hat, und der Kunde, der ihn hätte mitnehmen können. Der Datenhalter, dessen Schnittstelle nicht funktionierte, wird dadurch nicht dazu gebracht, sie zu reparieren. Der Druck läuft die Kette hinunter in die falsche Richtung.
Der Einwand dagegen ist ernst zu nehmen: Die Befugnis aus Artikel 11 besteht daneben fort, und die Kommission sagt, sie könne genutzt werden, um Modalitäten zu berichtigen, die nicht funktioniert haben. Nur sind die beiden Instrumente nicht gleich teuer. Eine Phase nicht zu aktivieren, ist ein Unterlassen, als Vorsicht darstellbar, ohne Textarbeit und ohne Auseinandersetzung mit einem Datenhalter. Modalitäten per delegiertem Rechtsakt vorzugeben, ist eine Handlung, angreifbar, und sie macht die Kommission zur Urheberin eines technischen Standards, den sie danach pflegen muss. Wo eine Behörde eine billige und eine teure Möglichkeit hat, wird in diesem Feld erfahrungsgemäß die billige genutzt — das ist die Lehre aus den beiden EBA-Stellungnahmen: Auf dem Papier standen Geldbußen und der Entzug von Ausnahmen zur Verfügung, herausgegeben wurde eine zweite Stellungnahme.
Die Rechnung
Diese Summe hat niemand veröffentlicht, deshalb hier mit benannten Eingangsgrößen. Die Phasenfristen stammen aus den Anhängen der beiden Ratsdokumente. Das Inkrafttreten liegt nach der üblichen Formel zwanzig Tage nach der Veröffentlichung im Amtsblatt. Alles Übrige ist Annahme.
Nehmen wir großzügig an, der Trilog kommt wieder in Gang und führt 2026 zu einer politischen Einigung, und der Text erscheint 2027 im Amtsblatt — ungefähr der Abstand, den das Zahlungspaket von der vorläufigen Einigung im November 2025 bis zur Billigung im April 2026 gebraucht hat, zuzüglich Rechts- und Sprachprüfung und zweier förmlicher Abstimmungen. Dann gilt Phase 1 des unmittelbaren Datenzugangs 2029. Phase 2 nicht vor 2030, Phase 3 nicht vor 2031, und keine der beiden von selbst. Zahlungskontodaten sind zugelassenen Dritten seit Januar 2018 zugänglich. Unter diesen Annahmen liegen zwischen den beiden Hälften des finanziellen Lebens eines Kunden — dem Zahlungskonto und allem anderen — rund dreizehn Jahre.
Das ist eine Rechnung auf einem veröffentlichten Zeitplan, keine Vorhersage, und der Mechanismus ist benannt statt unterstellt: Die Fristen von 24, 36 und 48 Monaten stehen im Anhang des Rates, und die beiden Tore dazwischen sind der Gegenstand des Fragebogens, den die Regierungen im April 2026 beantwortet haben.
Sicherheitsgrade
Fest vertreten: Der Gütemaßstab für die Schnittstelle steht nicht in der Verordnung, und das Verfahren bewegte sich zwischen Juni 2025 und April 2026 im Parlament nicht. Beides steht in Dokumenten, welche die Institutionen selbst geschrieben haben.
Mit vernünftiger Sicherheit: Das Phasentor verschiebt die Kosten einer schlechten Schnittstelle von demjenigen, der sie gebaut hat, auf diejenigen, die auf sie warten. Das folgt aus der Beschreibung des Mechanismus, nicht aus Beobachtung — denn er hat noch nie gewirkt.
Vorsichtig: dass die Befugnis aus Artikel 11 seltener genutzt wird als das Phasentor. Das ist ein Schluss aus dem Umgang mit einer vergleichbaren Eskalation im Zahlungsrahmen, und ein einziger erlassener delegierter Rechtsakt würde ihn deutlich schwächen.
Was daraus nicht folgt
Es folgt nichts über den endgültigen Text, denn einen endgültigen Text gibt es nicht. Alles hier zum Phasentor stammt aus einem Fragebogen des Vorsitzes und einem Non-Paper der Kommission, beide als LIMITE gekennzeichnet, beide ausdrücklich Optionen und keine beschlossenen Positionen — das Non-Paper trägt den Hinweis, es sei von der Kommission weder angenommen noch gebilligt worden. Die Haltung des Parlaments zur Phasenbildung kommt in keinem der beiden Dokumente vor, und das Parlament ist einer der beiden Gesetzgeber.
Es folgt auch nicht, dass die Übertragung an Marktsysteme schlechte Schnittstellen erzeugt. Es folgt, dass der Zahlungsrahmen, der weniger übertrug und weniger vorschrieb, Schnittstellen hervorbrachte, über die die Aufsicht zweimal schreiben musste. Ob die Vergütung genügt, dieses Verhalten zu ändern, ist eine empirische Frage, die heute niemand beantworten kann — und sie ist der wahrscheinlichste Weg, auf dem die These dieses Beitrags falsch sein könnte.
Und es folgt nichts über den Stand von heute. Diese Recherche hat keinen Beleg für eine politische Einigung gefunden, und die jüngsten aufgefundenen Primärdokumente stammen aus März und April 2026. Eine Lücke in einer Suche ist kein Beweis für eine Lücke in Brüssel.
Was der Fall lehrt
Das Muster ist nicht auf Finanzdaten beschränkt. Ein Gesetzgeber, der sich auf ein Recht einigen kann, aber nicht auf den Maßstab, der dieses Recht brauchbar macht, überträgt den Maßstab — an eine Aufsicht, an ein Normungsgremium, an ein Marktsystem oder an sich selbst in Gestalt eines späteren Rechtsakts. Die Übertragung ist stets sachlich verteidigbar und wird gewöhnlich mit Flexibilität und Technikneutralität begründet. Sie kehrt Jahre später als Grund dafür wieder, dass das Recht nicht funktioniert hat, und die Korrektur kostet eine Gesetzgebungsperiode.
Dieselbe Form ist im europäischen Zahlungsrecht mehrfach zu sehen. Die starke Kundenauthentifizierung wurde in technischen Regulierungsstandards festgelegt und nicht in der Richtlinie, und der Betrug, den sie verdrängte, tauchte in den Kategorien wieder auf, die der Standard nicht erfasste. Der Abgleich des Empfängernamens wurde vorgeschrieben, ohne den Schaden neu zuzuordnen — die Warnung erscheint nun, und die Haftung liegt, wo sie immer lag. Jedes Mal wurde das Instrument geschrieben und die Folge der Entdeckung überlassen.
Bemerkenswert am Verfahren zum Zugang zu Finanzdaten ist, dass diese Entdeckung erstmals in das Gesetz hineingebaut wird. Das Phasentor ist ein ehrliches Eingeständnis, dass niemand weiß, ob die Schnittstellen funktionieren werden, und ein ehrlicher Versuch, eine Pflicht nicht in einen Markt hinein auszudehnen, der sie nicht trägt. Es ist, als Anreiz gelesen, zugleich ein Versprechen an den zögernden Datenhalter, dass eine schwache Schnittstelle keine Folge hat außer einer kleineren Pflicht zu einem späteren Zeitpunkt. Beide Lesarten stimmen. Welche das Ergebnis beschreibt, hängt allein daran, ob die Kommission bereit ist, die härtere ihrer beiden Befugnisse zu gebrauchen — und das kann kein Text entscheiden, weil eine Ermessensbefugnis genau so viel wert ist, wie ihr Inhaber bereit ist, für sie auszugeben.