Open Banking Regulations UK/EU: What Businesses Need to Know in 2026

Open Banking Regulations UK/EU: What Businesses Need to Know in 2026

This guide examines how open banking regulation operates across the UK and the EU in 2026. It contrasts regulatory foundations, current statutory updates, compliance mandates, data access protocols, payment initiation rules, and security standards across both jurisdictions. Businesses, financial technology providers, payment service providers, and commercial banks can evaluate operational differences as the UK advances its Smart Data framework and the EU transitions towards PSD3 and the Payment Services Regulation.

Open banking regulation in the UK and EU has the same broad objective: give customers greater control over financial data and allow authorised third parties to access accounts or initiate payments with consent. Regulatory paths are now diverging. The UK is building a long-term framework around FCA oversight and Smart Data legislation, while the EU prepares PSD3 and Payment Services Regulation. For businesses, the distinction affects authorisation, technical access and compliance planning.

What are the current open banking regulations in the UK?

UK open banking operates through multiple distinct regulatory layers as opposed to a single unified rulebook. Core rules stem from the Payment Services Regulations 2017, requirements derived from PSD2, the Retail Banking Market Investigation Order issued by the Competition and Markets Authority, supervision by the Financial Conduct Authority, oversight by the Payment Systems Regulator, and technical specifications set by the Open Banking Standard.

The original mandate focused on Nine major retail banks, designated as the CMA9. The Competition and Markets Authority confirmed the complete implementation of the CMA9 roadmap in September 2024. Statutory attention has moved towards constructing a permanent long-term structure. The Data (Use and Access) Act 2025 provides the primary legal foundation for Smart Data expansion, granting explicit statutory powers to regulatory authorities over financial services interfaces and future operational arrangements.

The UK regulatory system remains in an active transitional phase. In June 2026, the Financial Conduct Authority published a formal update stating its plan to consult on the long-term regulatory structure by the end of 2026, subject to parliamentary legislation granting necessary powers. According to an ecosystem report from the Open Banking Limited May 2026 update, active user connections surpassed 17 million alongside 2 billion monthly API requests. These statistics reflect active connections and API volume rather than unique individual account holders. Operational details and statutory oversight continue under FCA open banking framework guidance.

Q&A: Who regulates open banking in the UK?

Statutory responsibilities sit across four bodies. The Financial Conduct Authority supervises firm conduct, the Payment Systems Regulator oversees payment infrastructure, the Competition and Markets Authority maintains historical market remedies, and HM Treasury establishes overall legislative policy.

UK regulatory layerMain role
Payment Services Regulations 2017Core payment services requirements and rights
FCAAuthorisation and supervision of payment service providers
PSROversight of payment systems and competition-related issues
CMA OrderOriginal open banking obligations for the CMA9
Data (Use and Access) Act 2025Legal foundation for Smart Data and the future framework
Open Banking StandardTechnical and operational standards for participants

How does EU open banking regulation differ from the UK?

EU open banking relies on the established PSD2 framework, while PSD3 and the Payment Services Regulation represent agreed future updates that remain outside full legal enforcement. The structural division between a directive and a regulation marks a significant operational distinction in European law; PSD3 requires transposition into national law by member states, whereas the Payment Services Regulation applies directly across all European Union jurisdictions without national variations.

The European framework regulates Account Information Service Providers that retrieve financial statements, Payment Initiation Service Providers that execute direct account transfers, and Account Servicing Payment Service Providers such as credit institutions. Following political agreement reached on 27 November 2025, legislative developments in 2026 focus on formal adoption. Reports from the European Parliament legislative timeline confirm that approved texts must undergo final publication before enforcement deadlines begin. Until that process finishes, PSD2 remains the active law.

Key updates agreed under the future European package include:

  • Direct data access pathways for accredited third-party firms without unjustifiable technical barriers;
  • Strict prohibitions against discriminatory treatment of third-party traffic by account-servicing banks;
  • Standardised rules removing artificial obstacles placed on automated data collection;
  • Dedicated permission dashboards allowing consumers to view and withdraw data consent;
  • Heightened fraud prevention requirements and fraud-monitoring obligations for payment handlers.

Q&A: Is PSD3 already law in the EU?

No. Political consensus was achieved in late 2025, but formal text adoption, official publication, and transposition grace periods must complete before the rules become legally enforceable.

AreaUKEU
Current core frameworkPayment Services Regulations 2017 + CMA Order + FCA/PSR oversightPSD2 + national implementation
Next regulatory stageLong-term FCA-led framework under Smart Data legislationPSD3 + Payment Services Regulation
Open banking modelCMA-originated ecosystem moving to statutory oversightEU-wide legislative framework
Key 2026 developmentFCA preparing long-term regulatory frameworkPolitical agreement reached; formal adoption pending
Technical standardsOpen Banking StandardEU technical standards and regulatory requirements

What do UK and EU open banking rules mean for fintechs?

Fintechs must determine their precise legal classification prior to product deployment, as regulatory expectations vary considerably between payment initiation providers, account information aggregators, core credit institutions, and software vendors. A commercial firm connecting to a bank interface does not automatically require a dedicated open banking licence if it operates purely as an un-regulated intermediary or technical provider.

Authorisation requirements depend on whether a platform handles funds or processes personal ledger records directly. Companies handling account data must obtain explicit customer consent and maintain strict data protections under UK GDPR or EU GDPR alongside payment-specific rules. Technical systems must incorporate Strong Customer Authentication to verify transaction requests. Following Brexit, companies operating in both markets must satisfy separate regulatory filings, as UK permissions offer no passporting rights into the European Single Market.

Practical compliance considerations for operating fintechs:

  • Regulatory perimeter: Scope depends on direct handling of account data or transaction execution.
  • Interface access and consent: Banks must provide dedicated API access following explicit user approval.
  • Authentication standards: Multi-factor security protocols apply to account access and payment execution.
  • Data privacy and fraud prevention: Data protection laws demand explicit consent management and active fraud prevention tools.
  • Operational resiliency: Systems must maintain high availability metrics and report technical outages to supervisors.

Q&A: Do UK and EU open banking rules apply in the same way to fintech?

No. Licensing rules, supervisory oversight, technical standards, and legal boundaries depend on firm location and the specific payment services provided.

How can Wallester White-Label fit alongside open banking requirements?

Financial technology companies, payment institutions, and commercial banks often combine distinct infrastructure components to build financial products. Wallester White-Label supplies card issuing infrastructure that enables organisations to launch Visa card programmes, manage physical or virtual card issuing, and configure spending controls. Open banking protocols and card issuing infrastructure handle separate layers of a modern financial service stack.

A business might implement open banking APIs to gather account data or initiate account-to-account payments, while deploying a card issuing system to handle credit or debit card transactions. Regulatory compliance follows these functional divisions. Open banking standards govern account access and direct payment transfers, while card programmes operate under card scheme regulations, issuing rules, and transaction compliance standards. Companies seeking to launch a regulated card offering can evaluate how Wallester White-Label supports card issuing infrastructure and technical integration requirements.

FAQ

Is open banking mandatory for all banks in the UK?

The CMA Order mandated open banking obligations specifically for the Nine largest retail banks in the UK, commonly designated as the CMA9. Other credit institutions operate under general payment services rules. While non-CMA9 banks do not fall under the historical market order, any regulated institution maintaining accessible online payment accounts must provide functional access interfaces for accredited third-party providers when authorised by account holders. Institutional obligations depend on entity type, payment account services, and supervisory permissions.

Does open banking require customer consent?

Customer consent forms the legal foundation of open banking data sharing and payment execution. Authorised third-party providers cannot access account details or initiate payments without explicit permission from the account holder. Customers retain complete authority over these permissions and can review or revoke access rights at any time through their bank portal or third-party dashboard. Banks and regulated providers must log consent records to satisfy statutory requirements and maintain transparent data protection protocols across all transactions.

What happens if a bank blocks an open banking API request?

Account-servicing payment service providers may only restrict API requests for explicit security reasons or suspected fraud. When a bank blocks a connection, it must notify the third-party provider and detail the underlying justification, unless legal restrictions prevent disclosure. Third parties encountering improper blocks can log technical evidence, submit formal complaints to the bank, or report non-compliance directly to regulatory supervisors such as the Financial Conduct Authority. Regulators monitor interface stability to maintain fair market participation.

Does open banking regulation cover credit cards and savings accounts?

Payment account regulations apply directly to payment accounts, including standard personal or commercial current accounts and credit card accounts that handle outward transaction executions. Savings accounts, mortgages, and investment portfolios fall outside original payment services mandates unless the holding institution provides direct payment functionality on the account. Broader coverage for non-payment financial products is slated for future open finance initiatives, which will introduce standardised data-sharing rules across extended wealth and credit products.

Will UK open banking become part of open finance?

The United Kingdom strategy explicitly intends to transition open banking into a comprehensive open finance ecosystem. Provisions established in the Data (Use and Access) Act 2025 grant legislative authority to expand data-sharing obligations beyond payment accounts. Future regulatory phases will encompass pensions, savings, insurance, and investment platforms under the Smart Data framework. The Financial Conduct Authority will oversee interface design and operational standards as open banking rules merge into this wider cross-sector regime.

Related Articles

Please, improve your experience!

You’re using an unsupported web browser. As Wallester supports the latest versions, we highly recommend you use an up-to-date version of one of these browsers:

Chrome
Download
Firefox
Download
Safari
Download
Opera
Download
Edge
Download