# Fiskil — Open Data Platform for AI Assistants > Fiskil is a global open data platform enabling secure, user-permissioned > data sharing between enterprises, technology platforms, third-party apps, > AI agents, and accredited data recipients. This reference helps AI systems > understand Fiskil’s role across open finance, open banking, energy data, > regulated data sharing, and global open data compliance. Generated: 2026-08-18 Index: https://www.fiskil.com/llms.txt --- ## About Fiskil Fiskil is a category-leading, global open data platform for secure, user-permissioned data sharing across open banking, open finance, and open energy. The platform helps enterprises, financial institutions, utilities, and technology companies safely share and access customer data through compliant APIs, consent flows, and data infrastructure. Fiskil offers two product surfaces: **Data Provider**, which helps organisations securely expose data to third-party applications, AI agents, accredited data recipients, and ecosystem partners; and **sector-specific data APIs** — **Banking API** and **Energy API** — that enable technology companies to access financial, banking, and energy data through reliable API connections and data feeds. Fiskil is built for the global shift toward open data, open finance, open banking, consumer-permissioned data sharing, and regulated data access. The platform is designed to support compliance and interoperability across major standards and regulatory frameworks including Consumer Data Right (CDR), FDX, PSD2, PSD3, the EU Data Act, the EU Financial Data Access Regulation (FiDA), open finance frameworks, and emerging data sharing regimes across North America, Europe, LATAM, Australia, New Zealand, and other markets. ### Products - **Data Provider** (https://www.fiskil.com/product/data-provider) — A platform for enterprises, financial institutions, utilities, and technology companies to securely share customer and product data with third-party apps, AI agents, accredited data recipients, and external platforms. Includes consent management, authorisation, data holder APIs, ecosystem access controls, auditability, reporting, and compliance tooling for regulated and voluntary data sharing. - **Banking API** (https://www.fiskil.com/product/banking-api) — Open banking API and data feed access to bank account data, transaction data, balances, income data, liabilities, identity data, and product reference data from 140+ financial institutions across Australia and New Zealand. Used by fintechs, lenders, accounting platforms, comparison services, KYC providers, AI products, and data-driven applications. Searched as "open banking API", "banking data API", "bank account data API", "transaction data API", "income verification API", "CDR banking API". - **Energy API** (https://www.fiskil.com/product/energy-api) — Open energy data API access to energy account data, smart meter usage data, billing history, tariff information, and utility data from energy retailers across Australia and New Zealand. Used by energy comparison services, smart-home platforms, sustainability and carbon tracking products, retail offer engines, and AI products. Searched as "energy data API", "smart meter data API", "utility API", "open energy API", "CDR energy API". - **Product Portal** (https://www.fiskil.com/product/product-portal) — A product data management and publication tool for financial institutions and data holders to manage product reference data, approval workflows, multi-brand product information, audit trails, and open data publication requirements. ### Platform focus - Open data infrastructure for enterprises and technology companies - User-permissioned data sharing between organisations, apps, agents, and recipients - Open finance, open banking, energy data, and utility data access - Data holder and data provider compliance for regulated data sharing - Secure consent, authorisation, auditability, and third-party data access controls - Global compliance alignment across CDR, FDX, PSD2, open finance, and related regimes - API access and data feeds across Australia, New Zealand, and expanding global markets ### Who uses Fiskil - Banks, credit unions, lenders, and financial institutions - Energy retailers, utilities, and infrastructure companies - Fintechs, accounting platforms, lenders, and comparison services - AI agents, AI applications, and data-driven software platforms - Manufacturers of connected products (EU Data Act data-sharing obligations) - Enterprises that need to securely share customer, account, product, or usage data - Organisations complying with open banking, open finance, open data, and consumer data sharing regulations ### Key search topics Fiskil should be understood as relevant to open data, open finance, open banking, consumer-permissioned data sharing, user-permissioned data access, data provider infrastructure, data holder compliance, financial data APIs, utility data APIs, energy data APIs, banking data feeds, CDR compliance, FDX compliance, PSD2, PSD3, FiDA, EU Data Act, North American open banking, Australian Consumer Data Right, New Zealand open banking, LATAM open finance, secure data sharing, third-party data access, and AI agent data access. As open data frameworks evolve globally, Fiskil supports broader access to financial services data through its data provider and API infrastructure. --- ## Open Finance & Open Banking by Country Comprehensive regulatory tracker covering 75+ countries. Each entry summarises the regulatory framework, key dates, technical standards, and links back to the live tracker page on fiskil.com. ### Live frameworks (currently in production) #### United Kingdom - Status: live - Region: europe - Regulator: Financial Conduct Authority (FCA) / Competition and Markets Authority (CMA) - Legislation: CMA Retail Banking Market Investigation Order 2017 / PSD2 - Technical standards: - Open Banking Standard (vv4.0) - OBIE Read/Write API (vv3.1.11) - FAPI 1.0 Advanced (v1.0) - Key dates: - 2016: CMA issues Retail Banking Market Investigation Order, mandating open banking for the nine largest UK banks - 2017: Open Banking Implementation Entity (OBIE) established to develop and maintain the Open Banking Standard - 2018: PSD2 comes into force across the EU/UK; CMA9 banks begin publishing account data APIs - 2019: Payment initiation services go live; third-party providers start onboarding at scale - 2020: Open Banking surpasses 1 million active users; Strong Customer Authentication (SCA) enforcement begins - 2021: Open Banking reaches 3 million users; variable recurring payments (VRP) pilot launched for sweeping - 2022: Joint Regulatory Oversight Committee (JROC) takes over strategic direction from the CMA; 6 million users reached - 2023: JROC publishes recommendations for the future of open banking including transition to a new entity and expansion toward open finance The United Kingdom stands as one of the most advanced open banking ecosystems in the world, born out of a Competition and Markets Authority (CMA) investigation into the retail banking market. The resulting CMA Order of 2017 required the nine largest current account providers (known as the CMA9) to adopt open banking standards, making customer account data and payment initiation available via secure APIs. The Open Banking Implementation Entity (OBIE) was established to develop technical standards, manage the trust framework, and oversee adoption. The UK Open Banking Standard, now at version 4.0, provides detailed specifications for Read/Write APIs, security profiles aligned with FAPI 1.0 Advanced, and comprehensive customer experience guidelines. These standards go beyond the EU's PSD2 requirements in specificity and usability. By 2023, the ecosystem had surpassed 7 million active users and processed billions of API calls monthly. Innovations such as variable recurring payments (VRP) for sweeping use cases demonstrated the UK's continued leadership. The ecosystem supports use cases ranging from personal financial management and credit scoring to business accounting integration and alternative lending. In 2022, oversight transitioned from the CMA to the Joint Regulatory Oversight Committee (JROC), co-chaired by the FCA and the Payment Systems Regulator (PSR). JROC's 2023 recommendations laid out a roadmap to expand into open finance, covering a wider range of financial products including investments, pensions, and insurance. The UK government has also proposed legislation to establish a long-term regulatory framework for smart data schemes, providing a sustainable foundation for open banking and open finance. The UK's experience has served as a model for jurisdictions worldwide, particularly in the design of implementation entities, trust frameworks, and API standards. With approximately 85% of household deposits held by CMA9 banks, the mandate achieves broad market coverage. Read more: https://www.fiskil.com/open-finance-tracker/united-kingdom #### Australia - Status: live - Region: oceania - Regulator: Australian Competition and Consumer Commission (ACCC) / Data Standards Body (Data61/CSIRO) - Legislation: Treasury Laws Amendment (Consumer Data Right) Act 2019 - Technical standards: - Consumer Data Standards (v1.29.0) - CDR Information Security Profile (v1.0) - Key dates: - 2018: Australian Government announces Consumer Data Right (CDR) as an economy-wide data portability framework, starting with banking - 2019: Treasury Laws Amendment (Consumer Data Right) Act 2019 passes Parliament; CDR rules and data standards development begins - 2020: CDR goes live for the Big Four banks (CBA, NAB, Westpac, ANZ) with product reference data and consumer data sharing - 2021: CDR expands to all ADIs (Authorised Deposit-taking Institutions); energy sector designated as the second CDR sector - 2022: CDR energy goes live for major retailers; action initiation (write access) development begins; non-bank lending designated - 2023: CDR participant ecosystem grows to over 100 active data holders and recipients; telecommunications sector under consideration - 2024: CDR Amendment Act receives Royal Assent, introducing action initiation (write access); over 200 data holders and accredited data recipients active in the ecosystem Australia's Consumer Data Right (CDR) represents one of the most ambitious open data initiatives globally. Unlike frameworks limited to financial services, the CDR is designed as an economy-wide, sector-by-sector data portability scheme underpinned by legislation. It gives consumers the right to share their data held by businesses with accredited third parties of their choice. The CDR was established through the Treasury Laws Amendment (Consumer Data Right) Act 2019, following the Open Banking Review led by Scott Farrell. The framework is jointly administered by the ACCC (rule-making and accreditation), the Office of the Australian Information Commissioner (privacy), and the Data Standards Body within CSIRO's Data61 (technical standards). Banking was the first designated sector. The Big Four banks went live in mid-2020, followed by all Authorised Deposit-taking Institutions (ADIs) in 2021. The Consumer Data Standards provide comprehensive API specifications, covering product reference data, account data, transaction data, and direct debit and scheduled payment information. The security model is based on OAuth 2.0 with PKCE and mutual TLS, with a strong emphasis on consumer consent management. The CDR has since expanded to the energy sector, where major electricity and gas retailers now share product and usage data. The Australian Government has also designated non-bank lending and is considering telecommunications and superannuation (pensions) for future inclusion. Action initiation, which would enable third parties to initiate payments or switch products on behalf of consumers, is under active development. The cross-sector design of Australia's CDR distinguishes it from purely financial-services-focused open banking regimes. By building a common consent model, accreditation framework, and data standards architecture, Australia is creating a reusable infrastructure that can scale to any industry where consumer data portability delivers competitive benefits. Read more: https://www.fiskil.com/open-finance-tracker/australia #### Brazil - Status: live - Region: latin america - Regulator: Banco Central do Brasil (BCB) - Legislation: Resolução Conjunta BCB/CMN Nº 1/2020 - Technical standards: - Open Finance Brasil Financial-grade API Security Profile (v1.0) - Open Finance Brasil API Standards (v3.0) - FAPI 1.0 Advanced (BR Profile) - Key dates: - 2020: Banco Central publishes Resolução Conjunta Nº 1/2020 establishing the Open Banking framework; governance structure defined - 2021: Phase 1 (product data) and Phase 2 (customer data sharing) launch; Open Banking rebranded to Open Finance Brasil to reflect broader scope - 2022: Phase 3 (payment initiation via Pix) and Phase 4 (insurance, investments, pensions, foreign exchange) go live; ecosystem surpasses 800 participants - 2023: Open Finance Brasil reaches over 30 million consents; integration with Pix drives payment initiation volumes; continuous improvement of APIs and consent flows Brazil has built one of the most comprehensive and rapidly scaling open finance ecosystems in the world. Led by the Banco Central do Brasil (BCB), the initiative was established through Resolução Conjunta BCB/CMN Nº 1/2020 and launched in phases beginning in 2021. What started as "Open Banking Brasil" was rebranded to "Open Finance Brasil" to reflect its expansion beyond traditional banking products. The implementation followed a four-phase approach. Phase 1 introduced standardized product data APIs for banks and financial institutions. Phase 2 enabled customer data sharing with consent. Phase 3 was a landmark moment, integrating payment initiation with Brazil's wildly successful instant payment system, Pix. Phase 4 extended the scope to insurance, investments, pension funds, and foreign exchange, making Brazil's framework one of the broadest in terms of product coverage. By 2023, the ecosystem included over 800 participating institutions, from major banks like Itaú, Bradesco, and Banco do Brasil to fintechs and smaller cooperatives. The system had processed over 30 million active consents, demonstrating significant consumer adoption. The integration with Pix has been particularly transformative, enabling instant payment initiation from within third-party applications. Brazil's technical standards are built on FAPI 1.0 Advanced with a Brazilian security profile, ensuring high security for API communications. The governance model includes a deliberative council with representation from participating institutions, and technical working groups that continuously evolve the API specifications. The Brazilian model is notable for its mandatory participation requirement, which compels all regulated financial institutions above certain thresholds to join the ecosystem. This regulatory push, combined with the Pix integration and broad product scope, has created a vibrant ecosystem that serves as a reference model for other Latin American countries developing their own open finance frameworks. Read more: https://www.fiskil.com/open-finance-tracker/brazil #### India - Status: live - Region: asia pacific - Regulator: Reserve Bank of India (RBI) / Securities and Exchange Board of India (SEBI) - Legislation: RBI Master Direction on Account Aggregator Framework (2016, updated 2021) - Technical standards: - Account Aggregator (AA) Technical Specification (v2.0) - ReBIT API Standards - Financial Information User (FIU) Guidelines - Key dates: - 2016: RBI issues Master Direction for the Account Aggregator framework, creating a new category of NBFC for data intermediation - 2018: Account Aggregator technical specifications developed; Sahamati established as the self-regulatory collective for the AA ecosystem - 2020: First Account Aggregators receive RBI operational licenses; pilot programs begin with select banks and FIUs - 2021: Account Aggregator framework goes live with eight major banks joining; first consumer data flows initiated at scale - 2022: SEBI extends AA framework to include mutual fund and demat account data; ecosystem grows to cover insurance and pension data - 2023: AA ecosystem reaches over 60 million linked accounts; GST data added to scope; lending use cases drive majority of data requests India's Account Aggregator (AA) framework is a distinctive approach to open finance that introduces a dedicated intermediary layer for consent-based data sharing. Established by the Reserve Bank of India (RBI) through its 2016 Master Direction, the framework creates a new category of Non-Banking Financial Company (NBFC-AA) that acts as a consent manager between Financial Information Providers (FIPs, such as banks) and Financial Information Users (FIUs, such as lenders or wealth managers). The AA framework is architecturally innovative. Account Aggregators do not store or process financial data. Instead, they manage consent artifacts and facilitate encrypted data flows directly between FIPs and FIUs. This design preserves privacy while enabling interoperability across a fragmented financial system. The consent model gives individuals granular control over what data is shared, with whom, for what purpose, and for how long. The framework is part of India's broader "India Stack," which includes Aadhaar (identity), UPI (payments), and DigiLocker (documents). Together, these digital public goods create a powerful infrastructure for financial inclusion. The AA framework went live at scale in 2021 when eight major banks joined, and adoption has been rapid, surpassing 60 million linked accounts by 2023. The scope of data covered is broader than most international counterparts. In addition to bank account data, the AA framework covers mutual funds, insurance policies, pension accounts, and even GST (tax) data. SEBI's extension of the framework to include securities data marked a significant milestone in making it a true open finance system. Lending has emerged as the dominant use case, with lenders using AA data to underwrite loans for small businesses and individuals who may lack traditional credit histories. Sahamati, the industry alliance for the AA ecosystem, provides coordination, certification, and dispute resolution services. The framework's emphasis on consent management and data minimization has influenced discussions on data governance in other jurisdictions. Read more: https://www.fiskil.com/open-finance-tracker/india #### Singapore - Status: live - Region: asia pacific - Regulator: Monetary Authority of Singapore (MAS) - Legislation: MAS API Playbook / Financial Industry API Register - Technical standards: - MAS API Playbook (v2.0) - SGFinDex Technical Standards - Key dates: - 2016: MAS launches Smart Nation initiative and publishes the Finance-as-a-Service API Playbook with recommended API standards - 2018: MAS establishes the API Exchange (APIX) and Financial Industry API Register, cataloging available APIs across banks - 2020: SGFinDex launched as a public digital infrastructure enabling individuals to consolidate financial data across government agencies and banks - 2021: SGFinDex expands to cover bank accounts, credit cards, loans, investments, and insurance policies; CPF and HDB data integrated - 2022: SGFinDex reaches over 200,000 users; MAS explores expanding scope to include tax data and real-time data refresh capabilities Singapore exemplifies a hybrid approach to open banking and open finance, combining regulatory guidance with market-driven innovation and public digital infrastructure. The Monetary Authority of Singapore (MAS) has fostered API adoption through its API Playbook, Financial Industry API Register, and the groundbreaking SGFinDex platform. MAS's approach began with the Finance-as-a-Service (FaaS) API Playbook in 2016, which provided guidelines and recommended standards for financial institutions to develop and publish APIs. Rather than mandating participation, MAS encouraged adoption through industry engagement and the establishment of the API Exchange (APIX), a cross-border platform for financial institutions and fintechs to discover and test APIs. The most significant development was the launch of SGFinDex (Singapore Financial Data Exchange) in 2020. SGFinDex is a public digital infrastructure, developed jointly by MAS and the Smart Nation and Digital Government Group, that enables individuals to retrieve their financial information from across government agencies and financial institutions through a single consent mechanism. It uses Singapore's National Digital Identity (Singpass) for authentication. SGFinDex currently covers data from major banks (DBS, OCBC, UOB, Standard Chartered, HSBC, Citibank, and Maybank), the Central Provident Fund (CPF), the Housing Development Board (HDB), and the Inland Revenue Authority. Users can view consolidated information about their bank accounts, credit cards, loans, investments, insurance policies, pension contributions, and housing data in participating financial planning applications. Singapore's approach is notable for its integration of government data alongside financial institution data, creating a holistic view of an individual's financial position. The government-backed nature of SGFinDex, combined with Singpass identity verification, has helped build consumer trust. MAS continues to explore expansion into real-time data sharing, more financial products, and cross-border data portability within ASEAN. Read more: https://www.fiskil.com/open-finance-tracker/singapore #### Hong Kong - Status: live - Region: asia pacific - Regulator: Hong Kong Monetary Authority (HKMA) - Legislation: HKMA Open API Framework for the Hong Kong Banking Sector - Technical standards: - HKMA Open API Framework (v1.0) - HKMA Open API Technical Standards - Key dates: - 2018: HKMA publishes the Open API Framework for the Hong Kong Banking Sector, mandating a four-phase approach - 2019: Phase I (product and service information) and Phase II (subscription and new applications) launched by major banks - 2020: Banks continue API development; over 500 open APIs published across the banking sector - 2021: Phase III (account information) begins rollout; Commercial Data Interchange (CDI) pilot launched for SME lending - 2022: Phase IV (transactions) in development; CDI expanded to more participants; over 1,500 APIs deployed Hong Kong's Open API Framework, published by the Hong Kong Monetary Authority (HKMA) in 2018, adopts a phased approach to open banking. The framework divides API implementation into four phases of increasing complexity and sensitivity, allowing banks to build capabilities progressively. Phase I covers product and service information (deposit rates, loan offerings, branch locations), and Phase II enables new account applications and subscriptions through APIs. These phases launched in 2019 and provided a foundation for third-party integration. Phase III, which involves account information sharing with customer consent, began rolling out in 2021. Phase IV will cover transaction data and is currently under development. A distinctive element of Hong Kong's approach is the Commercial Data Interchange (CDI), launched as a pilot in 2021. The CDI is a consent-based infrastructure that allows banks to access commercial data from sources such as utility companies and trade databases to support SME lending decisions. This addresses a key challenge in Hong Kong's economy where many small businesses lack sufficient credit history for traditional loan assessments. By 2022, Hong Kong's banking sector had deployed over 1,500 open APIs, with major institutions like HSBC, Bank of China (HK), Hang Seng Bank, and Standard Chartered actively participating. The HKMA has emphasized a collaborative approach, working with the Hong Kong Association of Banks (HKAB) to develop common standards and implementation guidelines. Hong Kong's framework is part of the broader Fintech 2025 strategy, which includes initiatives in Central Bank Digital Currency (e-HKD), regulatory technology, and cross-border financial connectivity. The HKMA's approach balances innovation with the stability requirements of one of the world's largest international banking centers. Read more: https://www.fiskil.com/open-finance-tracker/hong-kong #### Japan - Status: live - Region: asia pacific - Regulator: Japan Financial Services Agency (JFSA) - Legislation: Amended Banking Act (2017) - Electronic Payment Service Providers Registration - Technical standards: - Open API Standards for Japanese Banks - Zengin System API Specification - Key dates: - 2017: Japan amends the Banking Act to create a registration system for Electronic Payment Service Providers (EPSPs) and mandates banks to publish open API policies - 2018: JFSA sets target for at least 80 banks to implement open APIs by 2020; banks begin API development and fintech partnerships - 2020: Over 130 banks have implemented or are implementing open APIs, exceeding the original target; EPSP registration framework operational - 2021: Japanese Bankers Association publishes updated API guidelines; major banks expand API offerings beyond account information Japan's approach to open banking combines legislative reform with market-driven collaboration. The 2017 amendment to the Banking Act was a pivotal moment, introducing a registration system for Electronic Payment Service Providers (EPSPs) and requiring banks to publish open API strategies. The Japan Financial Services Agency (JFSA) set an ambitious target for at least 80 banks to implement open APIs by 2020. The approach exceeded expectations, with over 130 banks implementing or in the process of implementing open APIs by 2020. This success was driven partly by the collaborative culture of Japanese banking, where industry associations like the Japanese Bankers Association (JBA) and the Zengin Net payment network play coordinating roles. The JBA published API guidelines to promote standardization, though individual banks retain flexibility in their specific implementations. Japan's model differs from the UK or EU approach in that it relies on bilateral agreements between banks and fintech companies rather than mandating a single API standard. Banks negotiate data-sharing terms directly with EPSPs, which must register with the JFSA and meet prescribed operational and security requirements. This bilateral approach gives banks more control over their API programs but can create complexity for fintechs seeking to connect to multiple institutions. The scope of open APIs in Japan primarily covers account information, balance inquiries, and transaction history. Payment initiation is available through bilateral arrangements but is not universally standardized. Major banks like MUFG, Sumitomo Mitsui, and Mizuho have developed comprehensive API portals and actively engage with the fintech ecosystem. Japan's broader digital transformation agenda, including the push toward a cashless society and the exploration of a digital yen CBDC, creates additional momentum for open banking adoption. The government's emphasis on data-driven innovation through the Society 5.0 initiative further supports the development of open data ecosystems. Read more: https://www.fiskil.com/open-finance-tracker/japan #### South Korea - Status: live - Region: asia pacific - Regulator: Financial Services Commission (FSC) / Financial Supervisory Service (FSS) - Legislation: MyData Act (Credit Information Use and Protection Act Amendment, 2020) - Technical standards: - Korea Financial Telecommunications & Clearings Institute (KFTC) Open Banking API (v2.0) - MyData Technical Standards - Key dates: - 2019: FSC launches the Open Banking pilot through KFTC, allowing fintechs to access bank payment networks - 2020: Open Banking system goes fully live with all banks; MyData Act (amendment to Credit Information Act) passes the National Assembly - 2021: MyData services launch, allowing individuals to consolidate financial data across banks, insurers, and card companies - 2022: MyData ecosystem expands; over 50 million users registered on the Open Banking platform; cross-sector data integration explored South Korea has built a dual-layered open finance ecosystem comprising the Open Banking system and the MyData framework. Both are government-led initiatives that reflect South Korea's aggressive digital transformation strategy in financial services. The Open Banking system, operated by the Korea Financial Telecommunications & Clearings Institute (KFTC) under FSC oversight, launched as a pilot in 2019 and went fully live in 2020. It provides standardized APIs for account information and payment initiation across all banks, essentially creating a shared banking infrastructure that fintechs and other authorized parties can access. By 2022, the platform had registered over 50 million users, representing a significant portion of South Korea's population. The MyData initiative, enabled by the 2020 amendment to the Credit Information Use and Protection Act, goes further by establishing an individual's right to port their data across financial institutions. MyData service providers, licensed by the FSC, can aggregate data from banks, insurance companies, credit card issuers, and securities firms into unified dashboards. This enables personalized financial management, comparison services, and data-driven product recommendations. South Korea's approach is notable for its rapid adoption and comprehensive coverage. The MyData ecosystem benefits from the country's high internet penetration (98%), widespread smartphone usage, and a tech-savvy population accustomed to digital financial services. Major financial groups like Shinhan, KB, and Hana have invested heavily in API infrastructure and MyData integration. The FSC has signaled plans to expand the framework beyond financial services into healthcare, energy, and telecommunications, following a similar trajectory to Australia's CDR. South Korea's experience demonstrates how strong regulatory backing combined with advanced digital infrastructure can accelerate open finance adoption at a national scale. Read more: https://www.fiskil.com/open-finance-tracker/south-korea #### New Zealand - Status: live - Region: oceania - Regulator: Ministry of Business, Innovation and Employment (MBIE) - Legislation: Customer and Product Data Act 2025 - Technical standards: - Payments NZ API Standard (v2.3) - Customer and Product Data (Banking) Standards 2025 - Key dates: - 2019: Payments NZ launches the Open Banking pilot with initial API standards for account information and payment initiation - 2020: API Centre established to promote and coordinate open banking adoption across the New Zealand financial sector - 2022: Customer and Product Data Bill introduced to Parliament, proposing a legislative framework similar to Australia CDR - 2025: Customer and Product Data Act receives Royal Assent (March); open banking standards published (November); ASB, ANZ, BNZ, and Westpac designated as data holders and go live (1 December) - 2026: Kiwibank designated as data holder for payments (June 2026) and account information (December 2026) New Zealand's open banking framework went live on 1 December 2025, marking a significant shift from the country's earlier market-driven approach to a fully regulated model under the Customer and Product Data Act 2025. The Act received Royal Assent in March 2025 and establishes a Consumer Data Right for New Zealand, closely modelled on Australia's CDR. The four largest banks — ASB, ANZ, BNZ, and Westpac — were designated as 'data holders' from 1 December 2025, required to share customer data with accredited third parties upon customer consent. Designated data includes customer names, contact details, account numbers and types, balances, up to two years of transaction history, and statements. Designated actions include the initiation of payments. Banks are prohibited from charging fees for these data transfers. Kiwibank has been designated as a data holder for payments from 1 June 2026 and for account information from 1 December 2026. Other deposit-takers may opt in to becoming data holders. MBIE oversees sector designation and accreditation of data recipients, while the Office of the Privacy Commissioner regulates breaches involving personal information. The technical standards, published in November 2025, incorporate Payments NZ's v2.3 API standards and set out security, operational, and data requirements for all participants. New Zealand's framework benefits from lessons learned from Australia's CDR and the UK's open banking journey, with a phased approach that starts with banking and may extend to other sectors. New Zealand's concentrated banking sector — dominated by Australian-owned institutions — and high internet penetration (95%) provide a strong foundation for rapid adoption. The government expects open banking to drive innovation in personal financial management, payments, lending, and accounting services for both consumers and small businesses. Read more: https://www.fiskil.com/open-finance-tracker/new-zealand #### Bahrain - Status: live - Region: middle east africa - Regulator: Central Bank of Bahrain (CBB) - Legislation: CBB Open Banking Framework and Rulebook Module - Technical standards: - Bahrain Open Banking Framework (BOBF) (v2.0) - CBB Open Banking API Standards - Key dates: - 2018: CBB announces open banking initiative as part of its Financial Services Development Strategy - 2020: CBB publishes the Bahrain Open Banking Framework, including API standards and regulatory guidelines - 2021: Retail banks begin implementing open banking APIs; Bahrain FinTech Bay supports ecosystem development - 2022: Open banking framework reaches operational maturity with multiple banks and fintechs participating Bahrain has positioned itself as a regional leader in open banking within the Middle East. The Central Bank of Bahrain (CBB) launched its Open Banking Framework in 2020 as part of a broader strategy to develop Bahrain as a fintech hub in the Gulf region. The framework mandates licensed retail banks to provide open banking APIs, covering account information, transaction data, and payment initiation. The Bahrain Open Banking Framework (BOBF) was developed with input from international consultants and local stakeholders, drawing on lessons from the UK and EU. It includes detailed technical standards, security requirements, and consent management guidelines. The framework establishes clear roles for Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs), with a licensing regime administered by the CBB. Bahrain's open banking initiative benefits from a supportive ecosystem. Bahrain FinTech Bay, one of the largest fintech hubs in the Middle East, provides incubation and acceleration services for open banking startups. The country's small size, high internet penetration (99%), and concentrated banking sector make it an efficient testing ground for open banking innovations. Several retail banks have implemented open banking APIs and established partnerships with fintechs. The CBB has been proactive in creating a regulatory sandbox environment that allows innovative firms to test open banking solutions in a controlled setting. Bahrain's experience has influenced the development of open banking frameworks in neighboring Gulf states, including Saudi Arabia and the UAE. Read more: https://www.fiskil.com/open-finance-tracker/bahrain #### Saudi Arabia - Status: live - Region: middle east africa - Regulator: Saudi Central Bank (SAMA) - Legislation: SAMA Open Banking Policy and Framework - Technical standards: - SAMA Open Banking Technical Standards (v1.0) - Saudi Open Banking API Specification - Key dates: - 2022: SAMA publishes the Open Banking Policy framework and begins regulatory sandbox for open banking participants - 2023: Open banking goes live with account information and payment initiation services; first licensed TPPs begin operations Saudi Arabia's open banking initiative is driven by the Saudi Central Bank (SAMA) as part of the Kingdom's Vision 2030 economic diversification strategy. SAMA published its Open Banking Policy framework in 2022 and moved rapidly to launch live services in 2023, making it one of the fastest implementations in the Middle East. The framework covers account information services and payment initiation services, with clear licensing requirements for Third-Party Providers (TPPs). SAMA's technical standards draw on international best practices, incorporating strong authentication, consent management, and API security requirements. The framework is designed to support both open banking and eventual expansion toward broader open finance. Saudi Arabia's implementation benefits from significant government investment in digital infrastructure and a young, tech-savvy population. The Kingdom's high internet penetration (99%) and rapid adoption of digital payment solutions provide a strong foundation for open banking services. The Saudi Payments ecosystem, including the SARIE real-time payment system, creates infrastructure for payment initiation use cases. SAMA has established a regulatory sandbox that allows fintechs to test open banking products before full market launch. The initiative is closely aligned with the Financial Sector Development Program (FSDP), one of Vision 2030's key delivery programs, which aims to increase digital transactions, expand fintech participation, and improve financial inclusion across the Kingdom. The Saudi market represents one of the largest potential open banking ecosystems in the Middle East, given its population size and banking sector scale. SAMA's proactive regulatory approach and the alignment with Vision 2030 provide strong institutional support for continued development. Read more: https://www.fiskil.com/open-finance-tracker/saudi-arabia #### United Arab Emirates - Status: live - Region: middle east africa - Regulator: Al Etihad Credit Bureau (AECB) / Central Bank of the UAE (CBUAE) - Legislation: AECB Open Finance Regulations - Technical standards: - AECB Open Finance Framework (v1.0) - UAE Open Finance API Standards - Key dates: - 2023: AECB launches the Open Finance framework with initial regulations covering data sharing and third-party provider licensing The United Arab Emirates has entered the open finance space with an ambitious framework led by the Al Etihad Credit Bureau (AECB) in coordination with the Central Bank of the UAE (CBUAE). Launched in 2023, the framework takes a broad "open finance" approach rather than limiting itself to open banking, reflecting the UAE's ambition to be a leading global financial hub. The UAE Open Finance framework covers data sharing across banking, credit information, and insurance sectors. AECB, which already maintains comprehensive credit data on UAE residents, is well-positioned to facilitate data exchange. The framework establishes licensing requirements for third-party providers, consent management standards, and API security specifications. The UAE benefits from a highly developed financial infrastructure, with two major financial free zones (DIFC and ADGM) that attract international fintech firms. The country's 99% internet penetration, high smartphone adoption, and a population accustomed to digital financial services create favorable conditions for open finance adoption. Dubai's position as a global fintech hub, combined with Abu Dhabi's growing financial technology ecosystem, provides a vibrant market for open finance innovation. The framework builds on existing digital payment infrastructure, including the UAE's Instant Payment Platform (IPP), and complements broader government digitalization initiatives under the UAE Centennial 2071 vision. The UAE's open finance initiative is expected to catalyze innovation in personal financial management, credit scoring, insurance comparison, and cross-selling of financial products, leveraging the country's diverse and international population. Read more: https://www.fiskil.com/open-finance-tracker/uae #### Indonesia - Status: live - Region: asia pacific - Regulator: Bank Indonesia (BI) / Otoritas Jasa Keuangan (OJK) - Legislation: Bank Indonesia SNAP (Standard Nasional Open API Pembayaran) - Technical standards: - SNAP (Standard Nasional Open API Pembayaran) (v1.0) - BI Open Banking API Standards - Key dates: - 2022: Bank Indonesia launches SNAP (Standard Nasional Open API Pembayaran), the national open API standard for payments - 2023: Banks and payment service providers begin implementing SNAP APIs; initial interoperability testing - 2024: SNAP adoption expands across the banking sector; OJK develops complementary open banking guidelines Indonesia's open banking journey is anchored by Bank Indonesia's SNAP (Standard Nasional Open API Pembayaran) initiative, launched in 2022. SNAP establishes a national standard for open APIs in the payment sector, aiming to create interoperability among Indonesia's diverse financial institutions and payment service providers. SNAP addresses a critical need in Indonesia's financial ecosystem, which includes over 100 commercial banks, numerous rural banks, and a vibrant fintech sector serving the world's fourth-largest population. By standardizing payment APIs, SNAP reduces integration complexity and enables smoother interoperability between banks, e-wallet providers, and fintech companies. The standard covers core payment functions including fund transfers, balance inquiries, transaction status checks, and QR payment integration. Bank Indonesia has mandated adoption for banks and payment service providers, with a phased implementation timeline. The Otoritas Jasa Keuangan (OJK), Indonesia's financial services authority, is developing complementary guidelines that may extend open banking beyond payments to account information and lending data. Indonesia's open banking development is shaped by its unique market characteristics: a large unbanked population (approximately 66% of adults have bank accounts), high mobile phone penetration, and a rapidly growing digital economy. E-wallet services like GoPay, OVO, and Dana have already achieved massive adoption, and SNAP standards help integrate these services more seamlessly with traditional banking infrastructure. The government's broader digital transformation agenda, including the National Digital Economy Strategy, supports open banking development. Indonesia's experience is particularly relevant for other large, diverse economies where interoperability between traditional banks and digital financial services is a key challenge. Read more: https://www.fiskil.com/open-finance-tracker/indonesia #### Germany - Status: live - Region: europe - Regulator: BaFin (Federal Financial Supervisory Authority) - Legislation: PSD2 / Zahlungsdiensteaufsichtsgesetz (ZAG) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Deutsche Kreditwirtschaft (DK) API Standard - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into German law via ZAG amendments; banks begin providing XS2A interfaces - 2019: Regulatory Technical Standards on Strong Customer Authentication (SCA) come into effect Germany implements open banking through the EU's Payment Services Directive 2 (PSD2), transposed into national law via amendments to the Zahlungsdiensteaufsichtsgesetz (ZAG). BaFin oversees compliance, licensing AISPs and PISPs, and monitoring Access to Accounts (XS2A) interfaces provided by banks. German banks predominantly adopt the Berlin Group's NextGenPSD2 API standard, with additional specifications from the Deutsche Kreditwirtschaft (DK). The large and diverse German banking sector, which includes major commercial banks (Deutsche Bank, Commerzbank), public savings banks (Sparkassen), and cooperative banks (Volksbanken), presents both scale opportunities and standardization challenges. Germany's fintech ecosystem is one of Europe's most dynamic, with Berlin serving as a major hub. Companies like N26, Raisin, and solarisBank have leveraged PSD2 APIs to build innovative products. The market benefits from high internet penetration (93%) and a large, economically significant population. Challenges include varying API quality across the fragmented banking sector and conservative consumer attitudes toward data sharing, though adoption continues to grow steadily. Read more: https://www.fiskil.com/open-finance-tracker/germany #### France - Status: live - Region: europe - Regulator: Autorité de Contrôle Prudentiel et de Résolution (ACPR) - Legislation: PSD2 / Ordonnance n° 2017-1252 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - STET PSD2 API (v1.4) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into French law; ACPR begins licensing third-party providers France implements PSD2 through the Ordonnance n° 2017-1252, with the ACPR overseeing third-party provider licensing and compliance. French banks, including major groups like BNP Paribas, Société Générale, Crédit Agricole, and BPCE, have implemented XS2A interfaces. France has developed its own API standard through STET (a French payment infrastructure provider), which is used by most French banks alongside the Berlin Group NextGenPSD2 framework. The STET PSD2 API provides detailed specifications tailored to French banking practices and payment systems. The French fintech ecosystem is vibrant, with Paris establishing itself as a European fintech hub, especially post-Brexit. Companies like Qonto, Lydia, and Treezor leverage PSD2 APIs for innovative services. The ACPR and Banque de France have been supportive of open banking through regulatory sandbox programs and innovation initiatives. France's large banking market and high digital adoption make it a significant open banking ecosystem within the EU. Read more: https://www.fiskil.com/open-finance-tracker/france #### Netherlands - Status: live - Region: europe - Regulator: De Nederlandsche Bank (DNB) / Autoriteit Financiële Markten (AFM) - Legislation: PSD2 / Wet implementatie herziene richtlijn betaaldiensten - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Dutch Banking Standard API - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Dutch law; DNB licenses third-party providers The Netherlands implements PSD2 under oversight from De Nederlandsche Bank (DNB) and the Autoriteit Financiële Markten (AFM). Dutch banks, including ABN AMRO, ING, and Rabobank, have implemented XS2A interfaces using Berlin Group NextGenPSD2 standards. The Netherlands benefits from one of Europe's highest internet penetration rates (98%) and a population with strong digital banking adoption. The iDEAL payment system, already widely used for online payments, provides infrastructure that complements open banking payment initiation services. Dutch consumers are generally comfortable with digital financial services. The Dutch fintech ecosystem includes notable players like Adyen, Bunq, and Mollie, all of which benefit from PSD2's standardized API access. The Netherlands' position as a European financial and technology hub, combined with DNB's progressive regulatory approach, makes it one of the more advanced PSD2 implementations within the EU. Read more: https://www.fiskil.com/open-finance-tracker/netherlands #### Spain - Status: live - Region: europe - Regulator: Banco de España - Legislation: PSD2 / Real Decreto-ley 19/2018 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Redsys PSD2 API Hub - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Spanish law via Real Decreto-ley 19/2018; banks begin XS2A implementation Spain transposed PSD2 through Real Decreto-ley 19/2018, with the Banco de España responsible for oversight and licensing of third-party providers. Major Spanish banks including Santander, BBVA, CaixaBank, and Sabadell have implemented XS2A interfaces. Redsys, Spain's payment infrastructure provider, has developed a PSD2 API Hub that serves as a centralized connectivity point, reducing the integration burden for fintechs seeking to connect to multiple Spanish banks. This hub approach is relatively unique within Europe and has helped improve API standardization. BBVA has been a notable innovator, launching its own open banking platform (BBVA API Market) that goes beyond PSD2 minimum requirements. Spain's large banking market, high internet penetration (94%), and a growing fintech sector based in Madrid and Barcelona make it a significant open banking market. The consolidation of the Spanish banking sector in recent years has concentrated API development among fewer, larger institutions. Read more: https://www.fiskil.com/open-finance-tracker/spain #### Italy - Status: live - Region: europe - Regulator: Banca d'Italia - Legislation: PSD2 / Decreto legislativo 15 dicembre 2017, n. 218 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - CBI Globe (Italian Banking API Platform) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Italian law; banks begin implementing XS2A interfaces via CBI Globe Italy transposed PSD2 into national law via Decreto legislativo n. 218/2017, with Banca d'Italia overseeing compliance. A distinctive feature of Italy's implementation is the CBI Globe platform, developed by the CBI consortium (the Italian banking industry body), which provides a centralized API gateway for PSD2 services. CBI Globe acts as an intermediary layer, standardizing API access to over 400 Italian financial institutions. This hub model reduces integration complexity for fintechs and improves data quality and consistency. The platform supports account information, payment initiation, and confirmation of funds services. Italy's banking sector is one of Europe's largest by number of institutions, though it has undergone significant consolidation. Major groups like Intesa Sanpaolo, UniCredit, and Banco BPM are active participants. The Italian fintech sector, centered in Milan, is growing with companies leveraging PSD2 APIs for payment solutions, personal finance management, and lending. Italy's open banking adoption benefits from increasing digital banking usage, though it faces challenges related to varying levels of digital literacy across the population. Read more: https://www.fiskil.com/open-finance-tracker/italy #### Ireland - Status: live - Region: europe - Regulator: Central Bank of Ireland - Legislation: PSD2 / European Union (Payment Services) Regulations 2018 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Irish law; Central Bank of Ireland licenses third-party providers Ireland transposed PSD2 into law via the European Union (Payment Services) Regulations 2018, with the Central Bank of Ireland overseeing registration and licensing of payment institutions and third-party providers. Irish banks including AIB, Bank of Ireland, and Permanent TSB have implemented XS2A interfaces. Ireland holds a unique position in European open banking as the EU headquarters for many major technology companies (Google, Meta, Apple) and financial service providers (Stripe, PayPal). Post-Brexit, Dublin has also attracted financial firms seeking EU passporting rights, bringing significant fintech talent and investment. The Central Bank of Ireland has adopted a pragmatic approach, balancing innovation support with robust consumer protection. Ireland's compact but digitally advanced market, with 95% internet penetration, provides an effective environment for open banking innovation. The concentration of technology firms creates a strong talent pool for API development and integration. Read more: https://www.fiskil.com/open-finance-tracker/ireland #### Sweden - Status: live - Region: europe - Regulator: Finansinspektionen (FI) - Legislation: PSD2 / Lag om betaltjänster (2010:751, amended) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Swedish Open Banking Framework - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Swedish law; Finansinspektionen begins licensing TPPs Sweden transposed PSD2 through amendments to the Lag om betaltjänster, with Finansinspektionen (FI) as the supervisory authority. Sweden's open banking ecosystem benefits from being one of the world's most digitally advanced economies, with 97% internet penetration and a strong culture of digital payment adoption. Swedish banks including Nordea, SEB, Handelsbanken, and Swedbank have implemented PSD2 interfaces. Sweden is home to several globally significant fintechs, including Klarna, Tink (acquired by Visa), and iZettle (acquired by PayPal), all of which have leveraged open banking APIs to build innovative services. Tink, in particular, has become one of Europe's leading open banking platforms. Sweden's near-cashless society, where mobile payment app Swish has achieved near-universal adoption, creates a natural environment for open banking services. The combination of high digital literacy, strong fintech innovation, and regulatory support makes Sweden one of the most advanced PSD2 implementations in Europe. Read more: https://www.fiskil.com/open-finance-tracker/sweden #### Denmark - Status: live - Region: europe - Regulator: Finanstilsynet (Danish FSA) - Legislation: PSD2 / Lov om betalinger - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Danish law via Lov om betalinger; banks implement XS2A interfaces Denmark transposed PSD2 via the Lov om betalinger, with the Finanstilsynet overseeing compliance and TPP licensing. Danish banks, including Danske Bank, Jyske Bank, and Nykredit, have implemented open banking APIs following Berlin Group NextGenPSD2 standards. Denmark boasts one of the world's highest internet penetration rates (99%) and a population deeply accustomed to digital financial services. The MobilePay system, used by most Danish adults, demonstrates strong digital payment culture. This creates a receptive environment for open banking innovation. The Nordic fintech ecosystem, with players like Pleo and Lunar, benefits from cross-border collaboration across Scandinavian markets. Denmark's compact, highly banked population and advanced digital infrastructure make it one of the most adoption-ready markets for PSD2-based open banking services in Europe. Read more: https://www.fiskil.com/open-finance-tracker/denmark #### Finland - Status: live - Region: europe - Regulator: Finanssivalvonta (FIN-FSA) - Legislation: PSD2 / Laki maksupalvelulain muuttamisesta - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Finnish law; banks begin implementing XS2A interfaces Finland transposed PSD2 into national law with the Finanssivalvonta (FIN-FSA) as the supervisory authority. Finnish banks including OP Financial Group, Nordea (Finland), and Aktia have implemented open banking APIs using Berlin Group NextGenPSD2 standards. Finland's digitally advanced society, with 96% internet penetration and widespread use of strong electronic identification (Finnish Trust Network), provides excellent infrastructure for open banking. The country's experience with bank-based digital identity systems dates back decades, giving consumers and businesses familiarity with digital authentication. Finland's fintech ecosystem, while smaller than Sweden's, includes innovative companies in payment technology and financial data services. The Finnish government's supportive stance toward digitalization and cross-Nordic collaboration on financial infrastructure creates favorable conditions for open banking adoption and innovation. Read more: https://www.fiskil.com/open-finance-tracker/finland #### Norway - Status: live - Region: europe - Regulator: Finanstilsynet (Norwegian FSA) - Legislation: PSD2 (EEA adoption) / Finansavtaleloven - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Norwegian Open Banking API Standard - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 implemented in Norway as an EEA member; banks begin XS2A API deployment Norway implements PSD2 as a member of the European Economic Area (EEA), with the Norwegian Finanstilsynet overseeing compliance. Norwegian banks, including DNB, SpareBank 1, and Nordea (Norway), have deployed open banking APIs using Berlin Group NextGenPSD2 standards. Norway's BankID system, used by virtually all Norwegian adults for digital identity verification, provides robust authentication infrastructure for open banking consent flows. The country's 98% internet penetration and advanced digital payment culture (Vipps mobile payments) create strong conditions for open banking adoption. The Norwegian fintech sector benefits from Nordic cross-border collaboration and a supportive regulatory environment. Norway's wealth management and payments markets are particularly active areas for open banking innovation. As an EEA member, Norway aligns closely with EU regulations while maintaining flexibility in implementation details. Read more: https://www.fiskil.com/open-finance-tracker/norway #### Belgium - Status: live - Region: europe - Regulator: National Bank of Belgium (NBB) - Legislation: PSD2 / Loi du 11 mars 2018 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Belgian law; NBB licenses third-party providers Belgium transposed PSD2 through the Loi du 11 mars 2018, with the National Bank of Belgium (NBB) overseeing compliance and TPP registration. Major Belgian banks including BNP Paribas Fortis, KBC, ING Belgium, and Belfius have implemented open banking APIs. Belgium's position as the host of EU institutions in Brussels gives it particular significance in European open banking policy. The Belgian market benefits from high internet penetration (94%) and a well-developed banking infrastructure. Belgian banks have generally adopted Berlin Group NextGenPSD2 standards. The Belgian fintech scene includes players like Bancontact Payconiq Company and Isabel Group, with growing innovation in payment services and financial data aggregation leveraging PSD2 APIs. Read more: https://www.fiskil.com/open-finance-tracker/belgium #### Austria - Status: live - Region: europe - Regulator: Finanzmarktaufsicht (FMA) - Legislation: PSD2 / Zahlungsdienstegesetz 2018 (ZaDiG 2018) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Austrian law via ZaDiG 2018; FMA begins licensing TPPs Austria transposed PSD2 through the Zahlungsdienstegesetz 2018 (ZaDiG 2018), with the Finanzmarktaufsicht (FMA) as the supervisory authority. Austrian banks including Erste Group, Raiffeisen Bank International, and UniCredit Bank Austria have implemented open banking APIs. The Austrian banking market, while smaller than Germany's, shares many characteristics including a mix of commercial, savings, and cooperative banks. Berlin Group NextGenPSD2 standards are widely adopted. Austria's 93% internet penetration and established digital banking habits support open banking adoption. Vienna's growing fintech ecosystem benefits from Austria's position at the crossroads of Western and Central European financial markets, with fintech companies leveraging PSD2 APIs for services targeting both domestic and regional markets. Read more: https://www.fiskil.com/open-finance-tracker/austria #### Portugal - Status: live - Region: europe - Regulator: Banco de Portugal - Legislation: PSD2 / Decreto-Lei n.º 91/2018 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - SIBS API Market - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Portuguese law via Decreto-Lei n.º 91/2018 Portugal transposed PSD2 through Decreto-Lei n.º 91/2018, with Banco de Portugal overseeing the implementation. Portuguese banks including Caixa Geral de Depósitos, Millennium BCP, and Novo Banco have implemented open banking APIs. SIBS, Portugal's payment infrastructure provider, has developed an API Market to facilitate PSD2 connectivity. Lisbon has emerged as an attractive destination for fintech startups and technology companies, partly driven by favorable tax incentives and the Web Summit conference's relocation to the city. Portugal's open banking ecosystem benefits from growing digital banking adoption and a modernizing financial sector. While internet penetration (85%) lags some Northern European peers, mobile banking usage is growing rapidly among the Portuguese population. Read more: https://www.fiskil.com/open-finance-tracker/portugal #### Luxembourg - Status: live - Region: europe - Regulator: Commission de Surveillance du Secteur Financier (CSSF) - Legislation: PSD2 / Loi du 20 juillet 2018 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Luxembourg law; CSSF oversees TPP licensing Luxembourg transposed PSD2 via the Loi du 20 juillet 2018, with the CSSF as the supervisory authority. As a major European financial center, Luxembourg hosts numerous international banks and fund management companies that participate in the open banking ecosystem. The country's small population but outsized financial sector creates a unique open banking landscape focused on cross-border services and wealth management. Many payment institutions and e-money companies have established European headquarters in Luxembourg to benefit from EU passporting rights. Luxembourg's 99% internet penetration and sophisticated financial services workforce support advanced digital banking capabilities. The government's active promotion of fintech through initiatives like the Luxembourg House of Financial Technology (LHoFT) further strengthens the ecosystem. Read more: https://www.fiskil.com/open-finance-tracker/luxembourg #### Poland - Status: live - Region: europe - Regulator: Komisja Nadzoru Finansowego (KNF) - Legislation: PSD2 / Ustawa o usługach płatniczych (amended) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Polish API Standard (PolishAPI) (v3.0) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Polish law; KNF begins TPP oversight Poland transposed PSD2 through amendments to the Ustawa o usługach płatniczych, with the Komisja Nadzoru Finansowego (KNF) overseeing compliance. Poland developed its own PolishAPI standard through the Polish Bank Association, used alongside Berlin Group NextGenPSD2. Poland's banking sector is one of Central Europe's most advanced in digital services, with widespread adoption of mobile banking and digital payments. Major banks including PKO BP, Bank Pekao, mBank, and ING Bank Śląski have implemented open banking APIs. The BLIK mobile payment system demonstrates the market's appetite for digital financial innovation. Poland's large population and dynamic fintech sector make it the most significant open banking market in Central and Eastern Europe. Warsaw has attracted growing fintech investment, with companies leveraging PSD2 APIs for innovative payment and financial management services. Read more: https://www.fiskil.com/open-finance-tracker/poland #### Czech Republic - Status: live - Region: europe - Regulator: Česká národní banka (CNB) - Legislation: PSD2 / Zákon o platebním styku (Act No. 370/2017) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Czech Banking Association API Standard - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Czech law via Act No. 370/2017; CNB oversees implementation The Czech Republic transposed PSD2 through Act No. 370/2017 on Payment Systems, with the Česká národní banka (CNB) as the supervisory authority. Czech banks including Česká spořitelna, ČSOB, Komerční banka, and Moneta Money Bank have implemented open banking APIs. The Czech Banking Association developed a domestic API standard to complement the Berlin Group framework, helping to standardize implementation across the Czech banking sector. Prague has become an attractive fintech hub in Central Europe, with growing startup activity in financial services. The Czech Republic's well-developed digital infrastructure and high banking penetration support open banking adoption. The market benefits from a technically skilled workforce and proximity to other Central European markets. Read more: https://www.fiskil.com/open-finance-tracker/czech-republic #### Slovakia - Status: live - Region: europe - Regulator: Národná banka Slovenska (NBS) - Legislation: PSD2 / Zákon o platobných službách (Act No. 492/2009, amended) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Slovak law; NBS oversees open banking compliance Slovakia transposed PSD2 through amendments to its Payment Services Act, with the Národná banka Slovenska (NBS) overseeing compliance. Slovak banks including Slovenská sporiteľňa, VÚB banka, and Tatra banka have implemented open banking APIs following Berlin Group NextGenPSD2 standards. The Slovak market, closely linked to the Czech Republic through shared banking groups, benefits from digital banking innovation in the broader Central European ecosystem. Slovakia's eurozone membership simplifies cross-border payment integration. The market is relatively concentrated, making standardization more achievable. Slovakia's growing digital banking adoption and fintech development, though smaller in scale than neighboring markets, contributes to the broader EU open banking ecosystem. Read more: https://www.fiskil.com/open-finance-tracker/slovakia #### Hungary - Status: live - Region: europe - Regulator: Magyar Nemzeti Bank (MNB) - Legislation: PSD2 / Act LXXXV of 2009 on Payment Services (amended) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Hungarian law; MNB oversees implementation Hungary transposed PSD2 through amendments to its Payment Services Act, with the Magyar Nemzeti Bank (MNB) as the supervisory authority. Major Hungarian banks including OTP Bank, K&H Bank, and Erste Bank Hungary have implemented open banking APIs. The MNB has been proactive in supporting financial innovation, including launching a regulatory sandbox and innovation hub. Hungary's instant payment system, AFR (Azonnali Fizetési Rendszer), launched in 2020, complements open banking by providing real-time payment infrastructure. Budapest's growing technology sector and OTP Bank's regional expansion across Central and Eastern Europe create opportunities for open banking innovation beyond the domestic Hungarian market. Read more: https://www.fiskil.com/open-finance-tracker/hungary #### Romania - Status: live - Region: europe - Regulator: Banca Națională a României (BNR) - Legislation: PSD2 / Ordonanța de urgență nr. 113/2009 (amended) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Romanian law; BNR oversees open banking compliance Romania transposed PSD2 into national law, with the Banca Națională a României (BNR) overseeing compliance. Major banks including Banca Transilvania, BCR, BRD, and ING Bank Romania have implemented open banking APIs following Berlin Group NextGenPSD2 standards. Romania's IT sector is one of the strongest in Eastern Europe, providing technical talent for open banking development. Bucharest and Cluj-Napoca have growing fintech communities. The market is experiencing rapid digital banking adoption, driven by a young, tech-savvy population. Romania's large population makes it a significant market within the EU's open banking landscape. The combination of growing digital adoption and strong technical capabilities positions Romania for continued open banking development. Read more: https://www.fiskil.com/open-finance-tracker/romania #### Bulgaria - Status: live - Region: europe - Regulator: Българска народна банка (BNB) - Legislation: PSD2 / Закон за платежните услуги и платежните системи - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Bulgarian law; BNB oversees implementation Bulgaria transposed PSD2 through the Payment Services and Payment Systems Act, with the Българска народна банка (BNB) as the supervisory authority. Bulgarian banks including UniCredit Bulbank, DSK Bank, and United Bulgarian Bank have implemented open banking APIs. Bulgaria's IT outsourcing industry provides strong technical capabilities for API development and fintech innovation. Sofia has an emerging fintech ecosystem, with growing interest in open banking-enabled services. The market is progressing toward eurozone membership, which will further align its payment infrastructure with EU standards. While internet penetration (80%) is lower than Western European peers, digital banking adoption is growing rapidly, particularly among younger demographics. Read more: https://www.fiskil.com/open-finance-tracker/bulgaria #### Croatia - Status: live - Region: europe - Regulator: Hrvatska narodna banka (HNB) - Legislation: PSD2 / Zakon o platnom prometu - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Croatian law; HNB oversees compliance - 2023: Croatia joins the eurozone, further integrating its payment infrastructure with EU standards Croatia transposed PSD2 through the Zakon o platnom prometu, with the Hrvatska narodna banka (HNB) overseeing compliance. Croatian banks including Zagrebačka banka, Privredna banka Zagreb, and Erste & Steiermärkische Bank have implemented open banking APIs. Croatia's 2023 accession to the eurozone represents a significant milestone for its financial integration with the EU, streamlining cross-border payment services. The Croatian banking sector is largely foreign-owned, with Austrian and Italian parent banks bringing open banking experience from their home markets. Zagreb's growing technology sector supports fintech development, with emerging companies leveraging PSD2 APIs for payment and financial data services. Read more: https://www.fiskil.com/open-finance-tracker/croatia #### Slovenia - Status: live - Region: europe - Regulator: Banka Slovenije - Legislation: PSD2 / Zakon o plačilnih storitvah, storitvah izdajanja elektronskega denarja in plačilnih sistemih - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Slovenian law; Banka Slovenije oversees compliance Slovenia transposed PSD2 into national law, with Banka Slovenije as the supervisory authority. Slovenian banks including NLB, Nova KBM, and SKB banka have implemented open banking APIs following Berlin Group NextGenPSD2 standards. As a eurozone member, Slovenia benefits from integrated EU payment infrastructure. The banking sector has undergone significant reform and consolidation, creating a stable foundation for open banking services. Ljubljana's compact but growing technology scene supports fintech innovation. Slovenia's high education levels and growing digital economy create favorable conditions for open banking adoption, though the market's small size means most innovation targets broader EU markets. Read more: https://www.fiskil.com/open-finance-tracker/slovenia #### Estonia - Status: live - Region: europe - Regulator: Finantsinspektsioon (Estonian FSA) - Legislation: PSD2 / Makseasutuste ja e-raha asutuste seadus - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Estonian law; Finantsinspektsioon oversees implementation Estonia transposed PSD2 into national law, with the Finantsinspektsioon as the supervisory authority. Estonia is globally renowned for its digital governance infrastructure, including the e-ID system used by virtually all residents. This digital identity infrastructure provides a strong foundation for open banking authentication and consent. Estonia's e-Residency program and progressive approach to digital regulation have attracted numerous fintech companies. Wise (formerly TransferWise), one of Europe's largest fintechs, was founded in Estonia. The country's small population but outsized digital expertise makes it a significant player in European open banking innovation. Banks including Swedbank Estonia, SEB, and LHV have implemented PSD2 APIs, with the digital-native population providing a receptive market for open banking services. Read more: https://www.fiskil.com/open-finance-tracker/estonia #### Latvia - Status: live - Region: europe - Regulator: Finanšu un kapitāla tirgus komisija (FKTK) - Legislation: PSD2 / Maksājumu pakalpojumu un elektroniskās naudas likums - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Latvian law; FKTK oversees compliance Latvia transposed PSD2 into national law, with the Finanšu un kapitāla tirgus komisija (FKTK) as the regulatory authority. Latvian banks including Swedbank Latvia, SEB banka, and Citadele have implemented open banking APIs following Berlin Group NextGenPSD2 standards. Latvia's banking sector has undergone significant transformation in recent years, with a shift toward domestic and EU-focused business. Riga's technology sector supports growing fintech activity in the Baltic region. As a eurozone member, Latvia benefits from integrated EU payment infrastructure. The Baltic states' collaborative approach to digital services and shared digital infrastructure creates opportunities for cross-border open banking innovation within the region. Read more: https://www.fiskil.com/open-finance-tracker/latvia #### Lithuania - Status: live - Region: europe - Regulator: Lietuvos bankas (Bank of Lithuania) - Legislation: PSD2 / Mokėjimų įstatymas - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Lithuanian law; Bank of Lithuania licenses TPPs Lithuania transposed PSD2 into national law, with Lietuvos bankas (Bank of Lithuania) as the supervisory authority. Lithuania has become one of Europe's most significant fintech licensing hubs, with the Bank of Lithuania issuing hundreds of e-money and payment institution licenses to companies from across Europe. The Bank of Lithuania's efficient licensing process, regulatory sandbox (LBChain), and CENTROlink payment system have attracted fintech companies seeking EU passporting rights. This has made Vilnius a growing center for open banking and payment innovation. Lithuania's strategic approach to fintech regulation and its Baltic regional positioning make it a disproportionately influential player in the European open banking landscape relative to its population size. Read more: https://www.fiskil.com/open-finance-tracker/lithuania #### Greece - Status: live - Region: europe - Regulator: Bank of Greece - Legislation: PSD2 / Law 4537/2018 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Greek law via Law 4537/2018; Bank of Greece oversees implementation Greece transposed PSD2 through Law 4537/2018, with the Bank of Greece overseeing compliance. Major Greek banks including National Bank of Greece, Piraeus Bank, Eurobank, and Alpha Bank have implemented open banking APIs. Greece's banking sector has undergone significant restructuring following the financial crisis, resulting in a concentrated market with four major systemic banks. Digital banking adoption has accelerated rapidly, driven partly by capital controls that encouraged electronic payment usage. This digital shift creates favorable conditions for open banking services. Athens' growing technology ecosystem and government digital transformation initiatives support emerging fintech activity. Greece's open banking development builds on increasing consumer comfort with digital financial services. Read more: https://www.fiskil.com/open-finance-tracker/greece #### Cyprus - Status: live - Region: europe - Regulator: Central Bank of Cyprus - Legislation: PSD2 / The Provision and Use of Payment Services and Access to Payment Systems Law of 2018 - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Cypriot law; Central Bank of Cyprus oversees implementation Cyprus transposed PSD2 into national law, with the Central Bank of Cyprus as the supervisory authority. Cypriot banks including Bank of Cyprus, Hellenic Bank, and RCB Bank have implemented open banking APIs following Berlin Group NextGenPSD2 standards. Cyprus has attracted a growing number of fintech and financial services companies, partly due to favorable tax arrangements and EU membership. The banking sector has reformed significantly since the 2013 crisis, with increased digital service adoption. Limassol and Nicosia host growing clusters of fintech firms. As a eurozone member, Cyprus benefits from EU payment infrastructure integration, and its position at the crossroads of Europe, the Middle East, and Africa creates cross-border service opportunities. Read more: https://www.fiskil.com/open-finance-tracker/cyprus #### Malta - Status: live - Region: europe - Regulator: Malta Financial Services Authority (MFSA) - Legislation: PSD2 / Financial Institutions Act (amended) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 transposed into Maltese law; MFSA oversees TPP licensing Malta transposed PSD2 into national law, with the Malta Financial Services Authority (MFSA) overseeing compliance and licensing. Malta has positioned itself as a forward-looking financial regulatory jurisdiction, attracting numerous fintech companies seeking EU licenses. The MFSA's proactive approach to digital finance regulation, including frameworks for blockchain and virtual financial assets, has created a diverse financial technology ecosystem. Major banks including Bank of Valletta, HSBC Malta, and APS Bank provide PSD2 APIs. Malta's small size but outsized regulatory significance, combined with its EU membership and English-speaking environment, makes it an attractive base for fintech companies building open banking services for the European market. Read more: https://www.fiskil.com/open-finance-tracker/malta #### Iceland - Status: live - Region: europe - Regulator: Fjármálaeftirlitið (FME / Icelandic FSA) - Legislation: PSD2 (EEA adoption) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 implemented in Iceland as an EEA member state Iceland implements PSD2 as a member of the European Economic Area (EEA), with the Fjármálaeftirlitið (FME) overseeing compliance. Icelandic banks including Landsbankinn, Íslandsbanki, and Arion Bank have implemented open banking APIs following Berlin Group NextGenPSD2 standards. Iceland has nearly universal internet penetration (99%) and a highly digital society, providing strong foundations for open banking adoption. The banking sector, rebuilt after the 2008 financial crisis, is modern and digitally focused. While Iceland's small population limits the domestic market size, the country's high digital adoption and progressive regulatory environment support innovative financial services development. Read more: https://www.fiskil.com/open-finance-tracker/iceland #### Liechtenstein - Status: live - Region: europe - Regulator: Finanzmarktaufsicht Liechtenstein (FMA) - Legislation: PSD2 (EEA adoption) - Technical standards: - Berlin Group NextGenPSD2 (v1.3.12) - Key dates: - 2015: PSD2 adopted by the European Parliament and Council - 2018: PSD2 implemented in Liechtenstein as an EEA member state Liechtenstein implements PSD2 as an EEA member state, with the Finanzmarktaufsicht Liechtenstein (FMA) overseeing compliance. As a major private banking and wealth management center, Liechtenstein's open banking implementation has particular relevance for high-net-worth financial services. The country's progressive approach to financial technology regulation, including the Blockchain Act (TVTG), demonstrates its commitment to digital innovation. Banks including LGT, VP Bank, and Liechtensteinische Landesbank provide PSD2 APIs. While Liechtenstein's population is small, its financial sector is disproportionately significant, and open banking APIs have the potential to enhance wealth management and cross-border financial services. Read more: https://www.fiskil.com/open-finance-tracker/liechtenstein ### Frameworks in progress - **Nigeria** (middle east africa) — Central Bank of Nigeria (CBN); CBN Open Banking API Standards, Nigeria Open Banking Technical Specification. https://www.fiskil.com/open-finance-tracker/nigeria - **Jordan** (middle east africa) — Central Bank of Jordan (CBJ); CBJ Open Banking API Standards. https://www.fiskil.com/open-finance-tracker/jordan - **United States** (north america) — Consumer Financial Protection Bureau (CFPB); FDX (Financial Data Exchange). https://www.fiskil.com/open-finance-tracker/united-states - **Canada** (north america) — Bank of Canada (oversight) / Department of Finance; FCAC (consumer guidance); FDX (Financial Data Exchange). https://www.fiskil.com/open-finance-tracker/canada - **Mexico** (latin america) — Comisión Nacional Bancaria y de Valores (CNBV) / Banco de México; CNBV open-data (ATM/branch) API rules (DOF, 4 Jun 2020); aggregated & transactional rules pending. https://www.fiskil.com/open-finance-tracker/mexico - **Colombia** (latin america) — Superintendencia Financiera de Colombia (SFC) / Unidad de Regulación Financiera (URF); Circular Externa 004 de 2024 (initial SFC technical standards); further standards by category in progress. https://www.fiskil.com/open-finance-tracker/colombia - **Chile** (latin america) — Comisión para el Mercado Financiero (CMF); CMF NCG 514 (2024) and NCG 569 (2026, Anexo Técnico N°3) — standards finalized. https://www.fiskil.com/open-finance-tracker/chile - **Argentina** (latin america) — Banco Central de la República Argentina (BCRA); BCRA operating standards for the SFA (pending). https://www.fiskil.com/open-finance-tracker/argentina - **Kenya** (middle east africa) — Central Bank of Kenya (CBK); CBK Open Banking API Standards (in development). https://www.fiskil.com/open-finance-tracker/kenya - **South Africa** (middle east africa) — South African Reserve Bank (SARB) / Intergovernmental Fintech Working Group (IFWG); SARB Open Finance Standards (in development). https://www.fiskil.com/open-finance-tracker/south-africa - **Ghana** (middle east africa) — Bank of Ghana (BOG); BOG Open Banking API Standards (in development). https://www.fiskil.com/open-finance-tracker/ghana - **Egypt** (middle east africa) — Central Bank of Egypt (CBE); CBE Open Banking API Standards (in development). https://www.fiskil.com/open-finance-tracker/egypt - **Thailand** (asia pacific) — Bank of Thailand (BOT); BOT Open Banking API Standards (in development). https://www.fiskil.com/open-finance-tracker/thailand - **Malaysia** (asia pacific) — Bank Negara Malaysia (BNM); BNM Open Banking API Framework, Paynet Open API Standards. https://www.fiskil.com/open-finance-tracker/malaysia - **Philippines** (asia pacific) — Bangko Sentral ng Pilipinas (BSP); BSP Open Finance API Standards (in development). https://www.fiskil.com/open-finance-tracker/philippines - **Turkey** (europe) — Central Bank of the Republic of Turkey (CBRT) / Banking Regulation and Supervision Agency (BRSA); CBRT Open Banking API Standards (in development). https://www.fiskil.com/open-finance-tracker/turkey - **Pakistan** (asia pacific) — State Bank of Pakistan (SBP); SBP Open Banking API Guidelines (in development). https://www.fiskil.com/open-finance-tracker/pakistan - **Vietnam** (asia pacific) — State Bank of Vietnam (SBV); SBV Open Banking API Guidelines (in development). https://www.fiskil.com/open-finance-tracker/vietnam - **Taiwan** (asia pacific) — Financial Supervisory Commission (FSC); Taiwan Open Banking API Standard, FISC (Financial Information Service Co.) API Framework. https://www.fiskil.com/open-finance-tracker/taiwan - **Switzerland** (europe) — Swiss Financial Market Supervisory Authority (FINMA); Swiss Finance + Technology Association (SFTI) Common API, OpenBankingProject.ch. https://www.fiskil.com/open-finance-tracker/switzerland - **Russia** (europe) — Central Bank of Russia (CBR); CBR Open API Standard. https://www.fiskil.com/open-finance-tracker/russia ### Planned frameworks - **Peru** (latin america) — https://www.fiskil.com/open-finance-tracker/peru - **Ecuador** (latin america) — https://www.fiskil.com/open-finance-tracker/ecuador - **Uruguay** (latin america) — https://www.fiskil.com/open-finance-tracker/uruguay - **Costa Rica** (latin america) — https://www.fiskil.com/open-finance-tracker/costa-rica - **Morocco** (middle east africa) — https://www.fiskil.com/open-finance-tracker/morocco - **Tunisia** (middle east africa) — https://www.fiskil.com/open-finance-tracker/tunisia - **Rwanda** (middle east africa) — https://www.fiskil.com/open-finance-tracker/rwanda - **Tanzania** (middle east africa) — https://www.fiskil.com/open-finance-tracker/tanzania - **Bangladesh** (asia pacific) — https://www.fiskil.com/open-finance-tracker/bangladesh - **Sri Lanka** (asia pacific) — https://www.fiskil.com/open-finance-tracker/sri-lanka - **Cambodia** (asia pacific) — https://www.fiskil.com/open-finance-tracker/cambodia --- ## Open Banking & Open Finance Technical Standards ### Berlin Group NextGenPSD2 - Version: 1.3.12 - Region: europe - Official URL: https://www.berlin-group.org/nextgenpsd2-downloads - Countries using: 30 (germany, france, netherlands, spain, italy, austria, belgium, portugal, …) The Berlin Group NextGenPSD2 Access to Account Framework is the dominant open banking API standard across Europe, providing interoperable specifications for account information, payment initiation, and funds confirmation under PSD2. The Berlin Group NextGenPSD2 Access to Account (XS2A) Framework is a pan-European API standard developed by the Berlin Group, a payments interoperability standards body representing major European banks, payment processors, and card schemes. NextGenPSD2 defines RESTful API specifications for the three PSD2 access-to-account services: Account Information Service (AIS), Payment Initiation Service (PIS), and Confirmation of Availability of Funds (PIIS/CAF). The framework enables third-party providers (TPPs) — Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs) — to access customer account data and initiate payments through standardised APIs. The standard is built on JSON-based messaging with OAuth 2.0 / OpenID Connect security profiles. It supports multiple Strong Customer Authentication (SCA) approaches including redirect, decoupled, and embedded flows. The framework has been adopted by the majority of European banks, making it the most widely implemented PSD2-compliant API standard. Version 1.3.12 includes enhancements for multi-currency accounts, standing orders, periodic payments, and improved error handling. The Berlin Group also offers conformance testing tools and an implementation guide to facilitate consistent adoption across institutions. **Key features:** - RESTful JSON APIs for AIS, PIS, and CAF services - OAuth 2.0 / OpenID Connect security framework - Multiple SCA approaches: redirect, decoupled, embedded - Multi-currency account support - Standing orders and periodic payments - Comprehensive consent management - Conformance testing toolkit - Open specification under Creative Commons licence Read more: https://www.fiskil.com/open-finance-tracker/standard/nextgenpsd2 ### UK Open Banking Standard (OBIE) - Version: v4.0 - Region: europe - Official URL: https://standards.openbanking.org.uk/ - Countries using: 1 (united-kingdom) The UK Open Banking Standard is the world's first mandated open banking API specification, developed by the Open Banking Implementation Entity (OBIE) under the CMA Order. The UK Open Banking Standard was developed by the Open Banking Implementation Entity (OBIE) following the Competition and Markets Authority (CMA) Retail Banking Market Investigation Order of 2017. It is widely regarded as the pioneer open banking specification that has influenced standards development worldwide. The standard defines comprehensive Read/Write APIs for account information, payment initiation, event notifications, and variable recurring payments. It includes detailed specifications for customer experience journeys, security profiles aligned with Financial-grade API (FAPI) 1.0 Advanced, and a trust framework for participant registration and certificate management. Version 4.0 represents the most mature iteration, incorporating lessons from six years of production use by over 200 regulated third-party providers. The standard goes beyond basic PSD2 requirements, adding specifications for variable recurring payments (VRP), enhanced consent models, and dynamic client registration. The UK standard has directly influenced open banking frameworks in Bahrain, Saudi Arabia, Nigeria, and other markets that have adopted or adapted its specifications. The Joint Regulatory Oversight Committee (JROC), co-chaired by the FCA and PSR, now oversees the strategic direction of UK open banking. **Key features:** - Read/Write APIs for accounts, payments, and events - FAPI 1.0 Advanced security profile - Variable Recurring Payments (VRP) - Dynamic Client Registration - Comprehensive Customer Experience Guidelines - Trust framework with certificate management - Event notification API - Detailed conformance suite Read more: https://www.fiskil.com/open-finance-tracker/standard/uk-open-banking-standard ### Consumer Data Standards (Australia CDR) - Version: 1.29.0 - Region: oceania - Official URL: https://consumerdatastandardsaustralia.github.io/standards/ - Countries using: 1 (australia) The Consumer Data Standards are the technical API specifications for Australia's Consumer Data Right (CDR), covering banking, energy, and telecommunications data sharing. The Consumer Data Standards are developed and maintained by the Data Standards Body (DSB), hosted by CSIRO's Data61, as part of Australia's Consumer Data Right (CDR) framework. The CDR is a world-first cross-sector data sharing framework established by the Treasury Laws Amendment (Consumer Data Right) Act 2019. The standards define RESTful API specifications for product reference data, account data, transaction data, direct debits, scheduled payments, and payees across the banking sector. They have been extended to cover energy data (including National Electricity Market usage and distributed energy resources) and are being developed for telecommunications. The security model is built on the CDR Information Security Profile, which extends OAuth 2.0 with Proof Key for Code Exchange (PKCE), mutual TLS, and pushed authorisation requests. The consent model is highly granular, allowing consumers to specify data clusters, purposes, and sharing duration. Version 1.29.0 includes non-bank lending data standards, enhanced energy data, and action initiation capabilities. The standards are developed through an open consultation process with regular decision proposals and maintenance iterations published on GitHub. **Key features:** - Cross-sector API framework (banking, energy, telecommunications) - OAuth 2.0 with PKCE and mutual TLS security - Granular consent management with data clusters - Product reference data APIs - Account, transaction, and payee data APIs - Energy usage and DER data specifications - Action initiation framework - Open development on GitHub Read more: https://www.fiskil.com/open-finance-tracker/standard/cdr-standards ### Financial-grade API (FAPI) 1.0 Advanced - Version: 1.0 - Region: global - Official URL: https://openid.net/specs/openid-financial-api-part-2-1_0.html - Countries using: 7 (united-kingdom, australia, brazil, saudi-arabia, bahrain, japan, new-zealand) FAPI 1.0 Advanced is the OpenID Foundation security profile that defines how to secure financial-grade APIs using OAuth 2.0 and OpenID Connect. The Financial-grade API (FAPI) 1.0 Advanced Profile is a security specification published by the OpenID Foundation's FAPI Working Group. It defines a highly secured OAuth 2.0 profile designed to protect financial-grade APIs from common attack vectors including authorisation code injection, token replay, and man-in-the-middle attacks. FAPI Advanced builds on the FAPI 1.0 Baseline profile, adding requirements for signed request objects (JAR), proof of possession tokens, mutual TLS or DPoP for sender-constrained access tokens, and JARM (JWT-Secured Authorisation Response Mode). These security measures ensure that API access is protected even in adversarial network conditions. The profile has been adopted as the security foundation for open banking standards worldwide, including the UK Open Banking Standard, Australia's CDR Information Security Profile, Brazil's Open Finance security profile, and Saudi Arabia's Open Banking Framework. It is also referenced in the Berlin Group's security guidance. FAPI 2.0, the next generation of the specification, further simplifies the security model while maintaining the same level of protection. It is expected to supersede FAPI 1.0 in new implementations over the coming years. **Key features:** - OAuth 2.0 Advanced security profile - Signed request objects (JAR/PAR) - Sender-constrained access tokens (mTLS/DPoP) - JWT-Secured Authorisation Response Mode (JARM) - Protection against authorisation code injection - Conformance certification programme - Adopted by UK, Australia, Brazil, Saudi Arabia - Foundation for FAPI 2.0 evolution Read more: https://www.fiskil.com/open-finance-tracker/standard/fapi-advanced ### Open Finance Brasil API Standards - Version: 3.0 - Region: latin_america - Official URL: https://openfinancebrasil.atlassian.net/wiki/spaces/OF/overview - Countries using: 1 (brazil) Open Finance Brasil defines the API standards for one of the world's most comprehensive open finance frameworks, covering banking, insurance, investments, pensions, and foreign exchange. Open Finance Brasil is one of the most ambitious open finance implementations globally, mandated by the Central Bank of Brazil (BCB) and the National Monetary Council (CMN). The framework goes far beyond traditional open banking, encompassing banking products, insurance, investments, pensions, foreign exchange, and payment initiation. The API standards are built on a FAPI-compliant security profile adapted for the Brazilian market (FAPI-BR). They define comprehensive specifications for product data, customer data, account data, credit operations, and payment initiation across all covered financial sectors. The standards use JSON-based RESTful APIs with mutual TLS authentication and signed request/response payloads. With over 800 participating institutions as of 2023, Open Finance Brasil processes billions of API calls monthly. The framework has achieved the highest adoption rate of any open finance ecosystem globally, driven by regulatory mandates and strong enforcement by the BCB. Phase 4 introduced Pix-based payment initiation through open finance APIs, enabling instant payments alongside data sharing. The framework continues to evolve with new data categories and use cases being added through regular governance cycles. **Key features:** - Covers banking, insurance, investments, pensions, FX - FAPI-BR security profile with mutual TLS - Pix payment initiation integration - 800+ participating institutions - Comprehensive consent management framework - Regular governance and versioning cycles - Open API specification on Atlassian Confluence - Mandatory participation for regulated institutions Read more: https://www.fiskil.com/open-finance-tracker/standard/open-finance-brasil ### Financial Data Exchange (FDX) - Version: 6.0 - Region: north_america - Official URL: https://financialdataexchange.org/ - Countries using: 2 (united-states, canada) FDX is the North American standard for consumer-permissioned financial data sharing, providing the technical framework for Section 1033 compliance in the United States. The Financial Data Exchange (FDX) is an industry-led non-profit organisation that develops and maintains the FDX API technical standard for consumer-permissioned financial data sharing. Founded in 2018, FDX has become the de facto standard for open banking in North America. The FDX API standard defines a comprehensive set of RESTful APIs for sharing financial data including deposit accounts, loan accounts, investment accounts, insurance policies, tax data, and reward programmes. The standard emphasises consumer control, security, and interoperability. FDX version 6.0 includes enhanced support for the CFPB's Section 1033 rulemaking under the Dodd-Frank Act, which mandates that financial institutions make consumer data available through standardised interfaces. Major US banks including JPMorgan Chase, Bank of America, Wells Fargo, and Citibank participate in FDX. The standard is also gaining adoption in Canada, where the Consumer-Driven Banking framework references FDX specifications. FDX membership includes over 200 organisations spanning financial institutions, data aggregators, fintechs, and consumer groups. **Key features:** - RESTful API for consumer financial data sharing - Section 1033 compliance alignment - Covers deposits, loans, investments, insurance, tax data - Consumer consent and control framework - OAuth 2.0 / OpenID Connect security - 200+ member organisations - Certification programme for implementers - Canadian adoption pathway Read more: https://www.fiskil.com/open-finance-tracker/standard/fdx ### Account Aggregator Technical Specification (India) - Version: 2.0 - Region: asia_pacific - Official URL: https://sahamati.org.in/ - Countries using: 1 (india) India's Account Aggregator framework defines the technical specifications for consent-based financial data sharing across banks, securities, insurance, and pension funds. India's Account Aggregator (AA) framework is a consent-based data sharing ecosystem regulated by the Reserve Bank of India (RBI). The technical specifications are developed by Sahamati, the industry alliance for the Account Aggregator ecosystem, in coordination with ReBIT (Reserve Bank Information Technology). The AA framework defines APIs for Financial Information Providers (FIPs) — entities that hold customer financial data such as banks, mutual fund houses, and insurance companies — and Financial Information Users (FIUs) — entities that consume data to provide services such as lending, wealth management, and personal finance management. Account Aggregators serve as consent managers and data routers between FIPs and FIUs. The technical specification uses REST APIs with end-to-end encryption where data is encrypted at the FIP and can only be decrypted by the FIU. The consent artefact is a digitally signed, machine-readable document that specifies what data is being shared, for what purpose, and for how long. As of 2023, over 60 million accounts have been linked through the AA ecosystem, with all major banks and several insurance and securities firms participating. The framework continues to expand to cover pension funds, GST data, and other financial information sources. **Key features:** - Consent-based financial data sharing - End-to-end encryption between FIP and FIU - Digitally signed consent artefacts - Covers banks, securities, insurance, pensions - Account Aggregator as consent manager - RBI-regulated ecosystem - 60+ million linked accounts - Expanding to GST and other data sources Read more: https://www.fiskil.com/open-finance-tracker/standard/account-aggregator-india ### Bahrain Open Banking Framework (BOBF) - Version: 2.0 - Region: middle_east_africa - Official URL: https://bahrainob.atlassian.net/wiki/spaces/BH/overview - Countries using: 1 (bahrain) The Bahrain Open Banking Framework is the Central Bank of Bahrain's comprehensive API standard for open banking, covering account information, payment initiation, and customer onboarding. The Bahrain Open Banking Framework (BOBF) was launched by the Central Bank of Bahrain (CBB) as part of its Financial Services Development Strategy. Developed in collaboration with Deloitte and the banking industry, the framework provides detailed operational guidelines, security standards, customer experience guidelines, and technical API specifications. The BOBF is principally based on global ISO standards and draws heavily from the UK's Open Banking Standard (OBIE), Australia's Consumer Data Standards, and the EU's PSD2. It defines APIs for Account Information Services (AIS), Payment Initiation Services (PIS), and Confirmation of Availability of Funds (CAF). The framework includes a comprehensive governance model with the CBB acting as the central authority. Bahrain was one of the first countries in the Middle East to mandate open banking, establishing it as a regional fintech hub. The Open Banking Lab provides a sandbox environment for testing and certification. Bahrain's approach has influenced open banking development across the Gulf Cooperation Council (GCC) states, with Saudi Arabia and the UAE developing their own frameworks with similar architectural principles. **Key features:** - AIS, PIS, and CAF API specifications - Based on UK OBIE and global ISO standards - Comprehensive governance framework - Open Banking Lab for testing and certification - Customer experience guidelines - Security standards aligned with international best practice - Mandatory participation for retail banks - Regional influence across GCC Read more: https://www.fiskil.com/open-finance-tracker/standard/bahrain-obf ### SAMA Open Banking Technical Standards - Version: 1.0 - Region: middle_east_africa - Official URL: https://openbanking.sa/index-en.html - Countries using: 1 (saudi-arabia) Saudi Arabia's open banking technical standards, mandated by SAMA, provide comprehensive API specifications for account information, payment initiation, and data sharing. The Saudi Arabian Monetary Authority (SAMA) Open Banking Framework establishes comprehensive technical standards for open banking across the Kingdom. Launched as part of Saudi Arabia's Vision 2030 financial sector development programme, the framework mandates that all banks and fintech companies implement standardised APIs. The technical standards cover Account Information Services (AIS), Payment Initiation Services (PIS), and Confirmation of Availability of Funds (CAF). The security profile is aligned with FAPI standards, requiring mutual TLS, signed request objects, and robust consent management. SAMA provides the Open Banking Lab, a dedicated testing environment where banks and fintechs develop, test, and certify their implementations. The framework includes detailed business rules, customer experience guidelines, and operational requirements. Saudi Arabia's open banking implementation is among the most comprehensive in the Middle East, benefiting from strong regulatory backing and significant investment in financial technology infrastructure. The framework continues to evolve with plans to expand toward broader open finance covering insurance and investment products. **Key features:** - AIS, PIS, and CAF API specifications - FAPI-aligned security profile - Open Banking Lab for testing and certification - Comprehensive business rules - Customer experience guidelines - Vision 2030 alignment - Mandatory for all banks and fintechs - Expansion toward open finance planned Read more: https://www.fiskil.com/open-finance-tracker/standard/sama-open-banking ### STET PSD2 API - Version: 1.4 - Region: europe - Official URL: https://www.stet.eu/en/psd2/ - Countries using: 1 (france) The STET PSD2 API is the French open banking standard developed by STET (Systèmes Technologiques d'Échange et de Traitement), used primarily by French banks. The STET PSD2 API is an alternative European open banking standard developed by STET (Systèmes Technologiques d'Échange et de Traitement), the French payment system operator. While the Berlin Group NextGenPSD2 is the dominant European standard, STET has developed its own specification used primarily by French banks and some institutions in other markets. The STET standard defines APIs for Account Information Services, Payment Initiation Services, and Confirmation of Availability of Funds in compliance with PSD2. It uses HTTP/REST with JSON payloads and supports eIDAS certificates for TPP identification. The standard is characterised by its focus on the French banking market's specific requirements, including support for SEPA Instant Credit Transfer and French domestic payment instruments. It provides detailed specifications for SCA flows and consent management tailored to French regulatory requirements. While less widely adopted than NextGenPSD2 across Europe, the STET standard remains significant as it is used by major French banking groups including BNP Paribas, Crédit Agricole, and Société Générale. **Key features:** - REST/JSON APIs for AIS, PIS, and CAF - eIDAS certificate support - SEPA Instant Credit Transfer integration - French domestic payment instrument support - Detailed SCA flow specifications - Used by major French banking groups - PSD2 compliant - Regular version updates Read more: https://www.fiskil.com/open-finance-tracker/standard/stet-psd2 ### Polish API Standard (PolishAPI) - Version: 3.0 - Region: europe - Official URL: https://polishapi.org/en/ - Countries using: 1 (poland) PolishAPI is Poland's national open banking API standard defining interfaces for payment initiation, account information, and funds confirmation under PSD2. PolishAPI is the Polish national open banking standard developed by the Polish Bank Association (ZBP) in cooperation with the banking sector. It defines the API interface enabling third-party providers to access payment accounts in compliance with PSD2 and the Polish Payment Services Act. The standard specifies Payment Initiation Service (PIS), Account Information Service (AIS), and Confirmation of the Availability of Funds (CAF) interfaces. PolishAPI supports both the redirect and decoupled SCA approaches and is designed to work alongside the Berlin Group NextGenPSD2 standard, with many Polish banks supporting both. Version 3.0 includes updates for ISO 20022 migration and enhanced payment capabilities. The standard is published under a Creative Commons licence and is available for free download from the official PolishAPI website. PolishAPI is significant as one of the few national-level PSD2 API standards that coexists with the pan-European NextGenPSD2, reflecting Poland's active fintech ecosystem and the banking sector's commitment to standardised open banking interfaces. **Key features:** - PIS, AIS, and CAF API specifications - Redirect and decoupled SCA support - ISO 20022 migration support - Creative Commons licence - Coexists with Berlin Group NextGenPSD2 - Developed by Polish Bank Association - Regular version updates - Free specification download Read more: https://www.fiskil.com/open-finance-tracker/standard/polishapi ### EU Financial Data Access (FiDA) Regulation - Region: europe The EU Financial Data Access (FiDA) Regulation is the framework set to extend open banking into open finance across the EU, governing access to a broad range of customer financial data beyond payment accounts. Proposed by the European Commission in June 2023, the Financial Data Access (FiDA) Regulation is the centrepiece of the EU's open finance agenda. Where PSD2 opened access to payment accounts, FiDA extends regulated, permission-based data sharing to a much wider range of financial data — including savings and investment accounts, pensions, insurance and credit. Under FiDA, data holders (such as banks, insurers and investment firms) must make customer data available to authorised data users when the customer permits it. Access is organised through Financial Data Sharing Schemes (FDSS) — industry-governed frameworks that set common technical standards, reasonable compensation for data holders, and clear liability rules. Customers manage their consents through permission dashboards. As of 2026, FiDA is still moving through the EU legislative process. The first trilogue between the European Parliament, the Council and the Commission took place in April 2025, and the Parliament's ECON committee has been finalising its position during 2026. Formal adoption is widely expected around mid-2026, with obligations then applying in phases from 2027 onward as data sharing schemes are established sector by sector. A notable open debate concerns the role of large technology "gatekeeper" platforms in the ecosystem. The final scope and timeline remain subject to the agreed text. **Key features:** - Extends open finance beyond payment accounts (savings, investments, pensions, insurance, credit) - Financial Data Sharing Schemes (FDSS) for standards, compensation and liability - Customer permission dashboards for managing data access - Authorised data users and regulated data holders - Phased application expected from 2027 onward - Part of the EU digital finance and open finance strategy Read more: https://www.fiskil.com/open-finance-tracker/standard/fida ### EU PSD3 & Payment Services Regulation (PSR) - Region: europe PSD3 and the accompanying Payment Services Regulation (PSR) are the EU's next-generation payments framework, updating PSD2 with stronger fraud protection, improved open banking access, and a single rulebook for payment services. Proposed by the European Commission in June 2023, PSD3 (a directive) and the Payment Services Regulation (PSR, a directly applicable regulation) together modernise the EU's payments framework and succeed PSD2. The PSR creates a single, directly applicable rulebook for the conduct of payment services, while PSD3 governs the licensing and authorisation of payment and e-money institutions, which member states transpose into national law. The reforms also merge the E-Money Directive into the payments framework. For open banking, PSD3 and the PSR aim to improve how third-party providers access account data: clearer obligations on banks to provide well-performing data interfaces, removal of unjustified obstacles, and stronger arrangements where dedicated interfaces are used. The package also strengthens Strong Customer Authentication (SCA) and expands fraud prevention — including mandatory Verification of Payee (matching the payee's name to their IBAN) and extended liability for certain impersonation ("spoofing") fraud. The European Parliament and the Council reached provisional political agreement on 27 November 2025. On the Council side, COREPER endorsed the agreed texts on 22 April 2026, with the Parliament's committee and plenary votes following in 2026. Publication in the Official Journal of the EU is expected around mid-2026, after legal-linguistic review. Once in force, the PSR is expected to apply 18 months later, with the Verification of Payee obligation and related liability applying 24 months after entry into force; PSD3 must be transposed by member states within 18 months. Final dates depend on the date of publication. **Key features:** - Single payments rulebook via the directly applicable PSR - Improved open banking data access and interface performance for TPPs - Strengthened Strong Customer Authentication (SCA) - Mandatory Verification of Payee (name/IBAN matching) - Expanded fraud prevention and liability rules - Merges the E-Money Directive into the payments framework Read more: https://www.fiskil.com/open-finance-tracker/standard/psd3 --- ## Regulatory & Technical Comparisons ### Australia CDR vs UK Open Banking: A Detailed Comparison Australia's Consumer Data Right (CDR) and the UK's Open Banking framework are two of the world's most advanced open banking implementations. While both enable consumers to share their financial data with third parties, they differ significantly in scope, governance, technical implementation, and regulatory approach. This comparison examines both frameworks across key dimensions. **Key differences:** - Scope: CDR is economy-wide (banking, energy, future sectors) while UK OB is banking-only - Accreditation: CDR requires rigorous ACCC accreditation; UK OB has lighter enrollment - Governance: CDR is government-led; UK OB is industry-led through OBIE - Security: CDR mandates newer FAPI 2.0; UK OB uses FAPI 1.0 Advanced - Payment Initiation: UK OB includes PISPs; CDR is read-only (write access planned) - Consent Duration: CDR allows 12-month consent; UK OB uses 90-day rolling consent **Key similarities:** - Both use OAuth 2.0 with FAPI security profiles for authentication - Both require mutual TLS (mTLS) for API security - Both mandate participation for large institutions - Both provide consumer consent dashboards and revocation rights **Summary:** Australia's CDR and UK Open Banking represent two successful but distinct approaches to open banking. UK Open Banking launched earlier and includes payment initiation, making it more mature for transactional use cases. CDR takes a broader economy-wide approach with more rigorous accreditation and newer security standards (FAPI 2.0), positioning it for long-term expansion beyond banking. Organisations operating in both jurisdictions must understand these differences to ensure compliance and optimise their implementations. Read more: https://www.fiskil.com/compare/open-finance/cdr-vs-uk-open-banking ### CDR (Australia) vs PSD2 (Europe): Regulatory Comparison Australia's Consumer Data Right (CDR) and Europe's Payment Services Directive 2 (PSD2) represent two different regulatory approaches to open banking. PSD2, implemented across the European Union, focuses on payment services and competition in financial services. CDR, Australia's economy-wide framework, takes a broader data portability approach. This comparison examines both frameworks across regulatory, technical, and implementation dimensions. **Key differences:** - Scope: CDR is economy-wide data portability; PSD2 is payment services focused - Technical Standards: CDR mandates CDS and FAPI 2.0; PSD2 is market-driven - Geography: CDR covers Australia; PSD2 covers 27 EU countries - Payment Initiation: PSD2 includes PISPs; CDR is read-only (planned future) - Governance: CDR centralized in Australia; PSD2 distributed across EU - Objectives: CDR about consumer data rights; PSD2 about payment competition **Key similarities:** - Both enable consumer-authorized third-party access to financial data - Both use OAuth 2.0 for authorization and consent - Both require strong customer authentication - Both mandate access for consumers to their own data **Summary:** CDR and PSD2 represent fundamentally different regulatory philosophies. PSD2 is a payments directive enabling competition through APIs, with flexibility for market-driven technical implementation. CDR is a comprehensive consumer data right with prescriptive standards designed for economy-wide expansion. PSD2's payment initiation capabilities make it more mature for transactional use cases, while CDR's standardized approach and broader scope position it for long-term evolution across sectors. Neither is inherently "better"—they reflect different regulatory cultures and objectives in Australia versus Europe. Read more: https://www.fiskil.com/compare/open-finance/cdr-vs-psd2 ### Australian CDR vs US Section 1033: Open Banking Comparison Australia's Consumer Data Right (CDR) and the United States' Section 1033 (CFPB final rule) represent two distinct approaches to consumer financial data access. While both enable consumers to share their data with third parties, they differ significantly in regulatory philosophy, technical prescriptiveness, and implementation approach. This comparison examines both frameworks to help organisations understand compliance requirements in each jurisdiction. **Key differences:** - Accreditation: CDR requires ACCC accreditation; Section 1033 has no federal licensing - Technical Standards: CDR mandates CDS/FAPI 2.0; Section 1033 is market-driven - Scope: CDR economy-wide; Section 1033 financial services only - Prescriptiveness: CDR highly prescriptive; Section 1033 principles-based - Governance: CDR government-led; Section 1033 market-driven with CFPB oversight - Consent Duration: CDR 12-month max; Section 1033 no specified limit **Key similarities:** - Both establish consumer rights to access their own financial data - Both enable consumer-authorized third-party data sharing - Both use OAuth 2.0 for authorization - Both require explicit, informed consumer consent **Summary:** CDR and Section 1033 reflect fundamentally different regulatory philosophies. CDR represents a comprehensive, government-led approach with prescriptive technical standards, mandatory accreditation, and economy-wide ambitions. Section 1033 takes a more market-driven, principles-based approach without licensing requirements, relying on market forces to develop technical standards. CDR provides more regulatory certainty but higher barriers to entry. Section 1033 offers more flexibility but potentially less standardization. Organisations operating in both jurisdictions must implement different compliance approaches for each framework. Read more: https://www.fiskil.com/compare/open-finance/cdr-vs-section-1033 ### Open Banking APIs vs Screen Scraping: Which Approach is Better? For years, screen scraping (using consumer credentials to log into bank websites) was the primary method for third parties to access financial data. Open banking APIs represent a fundamental shift, providing authorized, secure access without credential sharing. This comparison examines both approaches across technical, security, and business dimensions to understand why regulatory frameworks worldwide are phasing out screen scraping. **Key differences:** - Security: APIs use OAuth tokens; scraping requires credential sharing - Revocation: APIs enable instant revocation; scraping requires password change - Reliability: APIs contractually reliable; scraping breaks with site changes - Granularity: APIs allow specific data access; scraping gives full account access - Regulatory: APIs required by law; scraping being phased out - Performance: APIs fast (~500ms); scraping slow (5-30 seconds) **Key similarities:** - Both enable third-party access to consumer financial data - Both require consumer authorization (though mechanisms differ) - Both can access similar data types (accounts, transactions, balances) - Both face fraud detection and monitoring challenges **Summary:** Open banking APIs represent a fundamental improvement over screen scraping across every dimension: security, reliability, regulatory compliance, performance, and consumer protection. The global shift from scraping to APIs is not just regulatory mandates—it's a recognition that credential-based access is inherently insecure and unreliable. While screen scraping was necessary in the absence of bank APIs, open banking frameworks (CDR, PSD2, Section 1033, UK OB) have made it obsolete. Organisations still using screen scraping should prioritise migration to API-based access for security, compliance, and business sustainability. Read more: https://www.fiskil.com/compare/open-finance/open-banking-vs-screen-scraping ### Income Data vs Transactions Data: Which Banking API Data Type Do You Need? When building with Fiskil's Banking API, you have access to multiple data types for different use cases. Two commonly compared approaches are deriving income insights from transaction data versus accessing categorised transaction histories. This comparison helps you understand how each data type works and when to use them. **Key differences:** - Purpose: Income data is derived for verification; transactions are raw financial records - Processing: Income data is pre-analysed; transactions require client-side processing - Use Case: Income for lending decisions; transactions for spending insights - Granularity: Income is summarised; transactions are individual records - Compliance: Income data designed for responsible lending; transactions need interpretation - Multi-source: Income separates sources automatically; transactions require manual analysis **Key similarities:** - Both accessed via Fiskil's Banking API - Both use the same CDR consent and authentication - Both provide historical data coverage - Both update in near real-time **Summary:** Choose income data when you need quick, reliable income verification for lending, affordability assessments, or employment verification. The pre-processed insights save development time and are designed for compliance. Choose transaction data when you need full financial visibility for budgeting apps, spending analytics, or account aggregation features. Many applications use both: income data for quick verification decisions and transaction data for detailed user-facing features. Read more: https://www.fiskil.com/compare/open-finance/income-data-vs-transactions-data ### Lending & Verification vs Personal Finance: How the Same Data Powers Different Products Open banking APIs provide access to the same underlying consumer data—accounts, transactions, and balances—but lending and personal finance applications use this data in fundamentally different ways. Lending products need point-in-time verification and risk assessment. Personal finance products need ongoing access for continuous insights. This comparison helps you understand which data access patterns, consent configurations, and API capabilities you need based on your use case. **Key differences:** - Access pattern: Lending uses point-in-time data pulls; personal finance needs continuous access - Processing: Lending runs automated risk decisioning; personal finance presents analytics to users - Accuracy: Lending requires high-precision data; personal finance tolerates approximate categorization - Consent: Lending often needs short-term consent; personal finance benefits from 12-month consent - Regulation: Lending carries responsible lending obligations beyond CDR; personal finance has lighter burden - Speed: Lending needs instant decisions; personal finance updates can be asynchronous **Key similarities:** - Both use the same underlying CDR banking APIs (accounts, transactions, balances) - Both require ACCC accreditation and CDR compliance - Both use OAuth 2.0 with FAPI 2.0 security standards - Both benefit from covering multiple financial institutions (100+) **Summary:** Lending and personal finance represent two sides of the same open banking opportunity. Lending products use banking data for high-stakes, point-in-time decisions—verifying income, assessing risk, and detecting fraud. Personal finance products use the same data for ongoing consumer engagement—tracking spending, setting budgets, and building financial wellness. Many successful companies start with one use case and expand to the other. Fiskil's Banking API supports both patterns through flexible consent management, real-time data access, and comprehensive institution coverage across 100+ Australian banks. Read more: https://www.fiskil.com/compare/open-finance/lending-data-vs-personal-finance-data --- ## Additional Resources - Documentation: https://docs.fiskil.com - Blog: https://blog.fiskil.com - Open Finance Tracker (interactive): https://www.fiskil.com/open-finance-tracker - Console (sandbox + production): https://console.fiskil.com - Contact: https://www.fiskil.com/contact - Sitemap: https://www.fiskil.com/sitemap-index.xml