
INNOVATE THIS 2025 Unwrapped
INNOVATE THIS 2025 Unwrapped INNOVATE THIS 2025 Unwrapped recaps on all the conference sessions – with key take-aways for all the panel sessions, fireside chats
1. What is FiDA and why should insurers act before the regulation is finalised?
FiDA – the EU’s proposed Financial Data Access Regulation – is intended to create a framework for open finance. In simple terms, it would allow customers to instruct a firm holding their financial data to share specified information with another authorised provider. It builds on the principles of Open Banking but extends them beyond payment-account data into other areas of financial services, including certain insurance data.
The proposal remains under negotiation, so its final scope and requirements have not yet been settled. However, if adopted broadly in its current form, it could require insurers, reinsurers and insurance intermediaries acting as ‘data holders’ – including, where they act as intermediaries, brokers, MGAs and TPAs, as well as ancillary insurance intermediaries such as non-insurance businesses that distribute insurance – to make certain customer data available either directly to the customer or to authorised third parties known as ‘data users’. These could include licensed financial information service providers, or ‘FISPs’.
For insurers, one of the most important questions is which products and data will fall within scope. The proposal currently covers non-life insurance but excludes sickness and health insurance. The Council’s negotiating position also excludes data relating to personal injury.
That distinction is particularly important for travel insurance. A single policy may combine cancellation, baggage, assistance and emergency medical benefits, meaning some elements of the product – and the data associated with them – could be treated differently from others.
Insurers and their partners therefore need to understand which parts of their products may be affected, what relevant customer data they hold, and where that data sits within their systems.
Although the final wording may change, the operational questions will not disappear. Product scoping, data mapping and changes to systems and governance can take considerable time. Firms that begin this work now will be better placed to respond once the final requirements are settled – particularly if the eventual implementation timeline is as tight as anticipated.
2. Will FiDA disrupt insurance as Open Banking disrupted banking, and where will the impact be felt first?
FiDA could ultimately have a significant impact on insurance, but the disruption is unlikely to happen in exactly the same way – or at the same pace – as it did in banking.
One important difference is the commercial model. Unlike the Open Banking framework under PSD2, FiDA would allow data holders to claim reasonable compensation from data users for making customer data available. This is intended to help firms recover some of the cost of developing and maintaining the necessary technical interfaces – namely, APIs. Where the data user is a qualifying SME, the compensation would be limited to the direct costs associated with providing the requested data.
Insurance data is also more complex and less standardised than bank account data. It can be closely connected to underwriting, pricing, claims, delegated authority, assistance services and distribution. Some of that information belongs clearly to the customer, while other data reflects an insurer’s own analysis, risk assessment or commercial expertise.
FiDA does not mean that everything held within an insurer’s systems would have to be shared. The proposal protects trade secrets and intellectual property, while the Council’s negotiating position limits the definition of customer data to raw data and excludes information that has been enriched internally by the data holder. Deciding where customer data ends and proprietary analysis begins is likely to be one of the most contested aspects of implementation.
The effects are likely to be felt first in highly digital areas of the market where faster access to verified policy information could remove paperwork and administrative friction. Potential applications include product comparison and switching, renewals, proof-of-cover checks, customer dashboards, embedded insurance and more tailored product recommendations.
Travel insurance is likely to be among the earlier markets affected because the customer journey is already highly digital, transactional and frequently connected to another purchase, such as a flight or holiday. Data sharing could support pre-populated applications, quicker cover checks, simpler renewals and a clearer view of the protection a customer already has.
Its mixed-benefit structure will, however, make implementation more complex. Firms may need to separate data relating to in-scope non-life benefits from excluded sickness, health and personal-injury information.
The position for health insurance and international private medical insurance is more nuanced. Sickness and health insurance products are currently excluded from FiDA’s scope, but the sector may still feel an indirect impact through adjacent data, mixed products, administration, wider customer journeys and future guidance on how in-scope financial data may be used for risk assessment and pricing.
3. How could FiDA change insurance data-sharing and enable more personalised customer experiences?
FiDA could make data sharing across the insurance market more consistent and structured, reducing some of the industry’s reliance on bespoke arrangements and custom-built IT connections.
Today, the way data moves between insurers, MGAs, brokers, claims providers and assistance companies often depends on the particular distribution model. Information may be exchanged through broker platforms, bordereaux, delegated authority arrangements, claims systems, assistance networks and customer portals. FiDA would add a regulated route through which specified customer data could be shared when the customer grants permission.
Data holders would also be required to provide permission dashboards, allowing customers to see and manage which organisations can access their data, for what purpose and for how long. The framework envisages that customer data would be made available securely and in real time using standardised APIs.
However, FiDA would not remove the need for commercial contracts and operational controls. Firms would still require scheme rules, delegated authority agreements, supplier terms, data protection provisions, liability arrangements and clear responsibilities for data quality and security.
Insurers, MGAs and intermediaries may also find themselves acting in two different capacities. A firm could be a data holder, required to make information available in relation to one product, while also acting as a data user, accessing information held elsewhere to improve distribution, servicing or renewal journeys. To access data through the framework, an organisation would need to be an eligible regulated financial institution or be authorised as a FISP.
For travel insurance, the opportunities are concrete. Customers could be asked fewer repetitive questions, applications could be pre-populated, and insurers could provide faster cover checks, clearer policy information, more relevant renewal prompts and a better view of protection the customer already holds. In time, access to reliable policy information could also support more appropriate product recommendations and more efficient claims and assistance journeys.

But more personalised does not mean unrestricted. FiDA would operate alongside GDPR, insurance conduct requirements and duties of confidentiality. Customer permission under FiDA would not remove the need for a valid legal basis to process personal data. Where health or other special-category data is involved, the additional requirements of Article 9 GDPR would also have to be satisfied. Transfers of personal data outside the EEA would remain subject to the GDPR’s international-transfer rules.
This is particularly important for travel or other mixed products that combine in-scope non-life benefits with excluded medical or health elements. Firms may need to separate those datasets carefully so that medical information is not shared simply because permission has been granted for other policy data.
The Council’s negotiating position anticipates EIOPA guidance on the use of FiDA data in insurance risk assessment and pricing. That guidance would be expected to address the risk of overly granular personalisation undermining the principle of pooling risk, or making insurance harder for some customers to access.
4. What practical steps should insurers take now to prepare for FiDA?
Preparation should begin with product scope, rather than technology.
Insurers and intermediaries first need to identify which of their EU products may fall within FiDA’s current proposed scope, which are excluded and which require closer analysis because they combine different types of cover. Mixed products such as travel insurance will need to be assessed cover by cover, with the legal analysis following the underlying data rather than simply the name given to the product.
Firms should also assess how their products could fit within the phased implementation timetable currently proposed by the Council. Under that negotiating position, motor insurance data would enter the framework 24 months after the Regulation comes into force, while other non-life insurance data and insurance-based investment products would follow at 48 months. However, this remains a negotiating position rather than final law.
The next priority is data mapping and classification. Firms need to understand what customer data they hold, where it is stored, whether it is structured and readily accessible, and whether it includes personal or sensitive information. They must also distinguish data supplied by or generated through the customer relationship from internally created analysis.
Not everything held within an insurer’s systems should be treated as portable customer data. Pricing models, underwriting judgements, fraud indicators, claims strategies, proprietary analytics, confidential business information and trade secrets should not automatically be treated as shareable. The Council text limits customer data to raw data and excludes internally enriched data, confidential business information and trade secrets, but firms will still need to apply that analysis carefully to each dataset.
Firms should then assess their operational and technology readiness. This includes considering permission dashboards, secure data-sharing interfaces, customer authentication, audit trails, the withdrawal of permissions, third-party supplier controls, liability arrangements and participation in financial data-sharing schemes.
Any new APIs and external connection points will also need to be incorporated into firms’ existing cybersecurity, operational-resilience and third-party risk frameworks. For businesses subject to the Digital Operational Resilience Act, or DORA, FiDA implementation should therefore form part of their wider ICT risk-management programme rather than being developed as a standalone project.
The most sensible approach is therefore to establish a cross-functional, ‘compliance by design’ programme now. Firms do not need to commit to a final technical architecture while the legislation is still being negotiated, but they can begin removing existing obstacles such as fragmented systems, poor data visibility, unclear data ownership and weak permission controls. This no-regrets work will make implementation considerably easier once the final scope, standards and timetable are known.
5. Will incumbents or technology-led entrants benefit most from FiDA, and what will determine success?
The market is unlikely to divide neatly along incumbent-versus-entrant lines.
Established insurers have significant advantages. They already possess regulatory permissions, capital, underwriting expertise, extensive data and established customer relationships. However, those strengths will not be enough if they cannot identify, manage, share and use customer data effectively.
Technology-led entrants may have an advantage in speed. Businesses built around APIs, customer permissions and interoperable systems from the outset may be able to create simpler journeys and launch new services more quickly than firms working with fragmented legacy infrastructure.
The risk for established insurers is not necessarily that new entrants will replace them as risk carriers. It is that aggregators, comparison services, embedded insurance platforms and other digital intermediaries could take control of the primary customer relationship. Incumbents could then become increasingly dependent on third-party platforms for access to customers and distribution.
That risk is especially relevant in travel insurance, where cover is frequently purchased digitally and alongside another product or service. The organisations that can use shared data to give customers a clearer view of their existing protection, reduce repeated questions and make purchasing or renewing cover easier may be best placed to retain the customer interface.
The winners will understand that FiDA is not simply a data-sharing obligation but a new commercial environment. They will know where they act as data holders, where they want to act as data users and which customer problems they want access to data to solve.
Early involvement in the proposed financial data-sharing schemes could also be strategically important. These schemes would establish key rules covering data and interface standards, compensation, liability, security, governance and dispute resolution. Firms that engage early may have a greater opportunity to help shape arrangements that are workable for their products and customers.
Ultimately, the organisations that thrive will combine regulatory understanding with clear customer use cases, modern data architecture, strong permission management, effective partnerships and appropriate protection for proprietary information. Those that treat FiDA solely as a compliance project – or wait until every detail is final before addressing fragmented systems and unclear data ownership – are more likely to struggle.
Share this article

INNOVATE THIS 2025 Unwrapped INNOVATE THIS 2025 Unwrapped recaps on all the conference sessions – with key take-aways for all the panel sessions, fireside chats

5 Questions with Katya Skorik, Global Head of Travel Business Line & Chief Commercial Officer, Europ Assistance Could you briefly introduce Europ Assistance to our
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields
"*" indicates required fields