This guide examines how open banking regulation operates across the UK and the EU in 2026. It contrasts regulatory foundations, current statutory updates, compliance mandates, data access protocols, payment initiation rules, and security standards across both jurisdictions. Businesses, financial technology providers, payment service providers, and commercial banks can evaluate operational differences as the UK advances its Smart Data framework and the EU transitions towards PSD3 and the Payment Services Regulation.
Open banking regulation in the UK and EU has the same broad objective: give customers greater control over financial data and allow authorised third parties to access accounts or initiate payments with consent. Regulatory paths are now diverging. The UK is building a long-term framework around FCA oversight and Smart Data legislation, while the EU prepares PSD3 and Payment Services Regulation. For businesses, the distinction affects authorisation, technical access and compliance planning.
What are the current open banking regulations in the UK?
UK open banking operates through multiple distinct regulatory layers as opposed to a single unified rulebook. Core rules stem from the Payment Services Regulations 2017, requirements derived from PSD2, the Retail Banking Market Investigation Order issued by the Competition and Markets Authority, supervision by the Financial Conduct Authority, oversight by the Payment Systems Regulator, and technical specifications set by the Open Banking Standard.
The original mandate focused on Nine major retail banks, designated as the CMA9. The Competition and Markets Authority confirmed the complete implementation of the CMA9 roadmap in September 2024. Statutory attention has moved towards constructing a permanent long-term structure. The Data (Use and Access) Act 2025 provides the primary legal foundation for Smart Data expansion, granting explicit statutory powers to regulatory authorities over financial services interfaces and future operational arrangements.
The UK regulatory system remains in an active transitional phase. In June 2026, the Financial Conduct Authority published a formal update stating its plan to consult on the long-term regulatory structure by the end of 2026, subject to parliamentary legislation granting necessary powers. According to an ecosystem report from the Open Banking Limited May 2026 update, active user connections surpassed 17 million alongside 2 billion monthly API requests. These statistics reflect active connections and API volume rather than unique individual account holders. Operational details and statutory oversight continue under FCA open banking framework guidance.
Q&A: Who regulates open banking in the UK?
Statutory responsibilities sit across four bodies. The Financial Conduct Authority supervises firm conduct, the Payment Systems Regulator oversees payment infrastructure, the Competition and Markets Authority maintains historical market remedies, and HM Treasury establishes overall legislative policy.
| UK regulatory layer | Main role |
| Payment Services Regulations 2017 | Core payment services requirements and rights |
| FCA | Authorisation and supervision of payment service providers |
| PSR | Oversight of payment systems and competition-related issues |
| CMA Order | Original open banking obligations for the CMA9 |
| Data (Use and Access) Act 2025 | Legal foundation for Smart Data and the future framework |
| Open Banking Standard | Technical and operational standards for participants |
How does EU open banking regulation differ from the UK?
EU open banking relies on the established PSD2 framework, while PSD3 and the Payment Services Regulation represent agreed future updates that remain outside full legal enforcement. The structural division between a directive and a regulation marks a significant operational distinction in European law; PSD3 requires transposition into national law by member states, whereas the Payment Services Regulation applies directly across all European Union jurisdictions without national variations.
The European framework regulates Account Information Service Providers that retrieve financial statements, Payment Initiation Service Providers that execute direct account transfers, and Account Servicing Payment Service Providers such as credit institutions. Following political agreement reached on 27 November 2025, legislative developments in 2026 focus on formal adoption. Reports from the European Parliament legislative timeline confirm that approved texts must undergo final publication before enforcement deadlines begin. Until that process finishes, PSD2 remains the active law.
Key updates agreed under the future European package include:
- Direct data access pathways for accredited third-party firms without unjustifiable technical barriers;
- Strict prohibitions against discriminatory treatment of third-party traffic by account-servicing banks;
- Standardised rules removing artificial obstacles placed on automated data collection;
- Dedicated permission dashboards allowing consumers to view and withdraw data consent;
- Heightened fraud prevention requirements and fraud-monitoring obligations for payment handlers.
Q&A: Is PSD3 already law in the EU?
No. Political consensus was achieved in late 2025, but formal text adoption, official publication, and transposition grace periods must complete before the rules become legally enforceable.
| Area | UK | EU |
| Current core framework | Payment Services Regulations 2017 + CMA Order + FCA/PSR oversight | PSD2 + national implementation |
| Next regulatory stage | Long-term FCA-led framework under Smart Data legislation | PSD3 + Payment Services Regulation |
| Open banking model | CMA-originated ecosystem moving to statutory oversight | EU-wide legislative framework |
| Key 2026 development | FCA preparing long-term regulatory framework | Political agreement reached; formal adoption pending |
| Technical standards | Open Banking Standard | EU technical standards and regulatory requirements |
What do UK and EU open banking rules mean for fintechs?
Fintechs must determine their precise legal classification prior to product deployment, as regulatory expectations vary considerably between payment initiation providers, account information aggregators, core credit institutions, and software vendors. A commercial firm connecting to a bank interface does not automatically require a dedicated open banking licence if it operates purely as an un-regulated intermediary or technical provider.
Authorisation requirements depend on whether a platform handles funds or processes personal ledger records directly. Companies handling account data must obtain explicit customer consent and maintain strict data protections under UK GDPR or EU GDPR alongside payment-specific rules. Technical systems must incorporate Strong Customer Authentication to verify transaction requests. Following Brexit, companies operating in both markets must satisfy separate regulatory filings, as UK permissions offer no passporting rights into the European Single Market.
Practical compliance considerations for operating fintechs:
- Regulatory perimeter: Scope depends on direct handling of account data or transaction execution.
- Interface access and consent: Banks must provide dedicated API access following explicit user approval.
- Authentication standards: Multi-factor security protocols apply to account access and payment execution.
- Data privacy and fraud prevention: Data protection laws demand explicit consent management and active fraud prevention tools.
- Operational resiliency: Systems must maintain high availability metrics and report technical outages to supervisors.
Q&A: Do UK and EU open banking rules apply in the same way to fintech?
No. Licensing rules, supervisory oversight, technical standards, and legal boundaries depend on firm location and the specific payment services provided.
How can Wallester White-Label fit alongside open banking requirements?
Financial technology companies, payment institutions, and commercial banks often combine distinct infrastructure components to build financial products. Wallester White-Label supplies card issuing infrastructure that enables organisations to launch Visa card programmes, manage physical or virtual card issuing, and configure spending controls. Open banking protocols and card issuing infrastructure handle separate layers of a modern financial service stack.
A business might implement open banking APIs to gather account data or initiate account-to-account payments, while deploying a card issuing system to handle credit or debit card transactions. Regulatory compliance follows these functional divisions. Open banking standards govern account access and direct payment transfers, while card programmes operate under card scheme regulations, issuing rules, and transaction compliance standards. Companies seeking to launch a regulated card offering can evaluate how Wallester White-Label supports card issuing infrastructure and technical integration requirements.


