Kennedys: FiDA and its impact on MGAs and the insurance sector
11th August 2026

By Dr. Nathalie Moreno, Partner, Kennedys Law LLP
1. What is FiDA and why should MGAs and the insurance sector act before the regulation is finalised?
FiDA, the EU’s proposed Financial Data Access Regulation, is intended to create a framework for open finance. It would allow customers to instruct firms holding their financial data to share specified information with authorised third parties. It builds on Open Banking but extends the concept into wider financial services, including certain insurance data.
The proposal remains under negotiation, so it’s final scope is not settled. If adopted broadly, insurers, reinsurers, brokers, MGAs, TPAs and other intermediaries acting as data holders may need to make relevant customer data available to customers or authorised data users, including FISPs. The proposal currently covers non-life insurance, while sickness and health insurance are excluded. The Council position also excludes personal injury data.
For MGAs and insurers, the immediate task is to understand which products and datasets may be affected. Mixed products, particularly travel insurance, may combine in-scope non-life benefits with excluded medical or personal-injury elements. Product scoping, data mapping and governance work can take time, so early preparation remains sensible.

2. Will FiDA disrupt insurance as Open Banking disrupted banking, and where will the impact be felt first?
FiDA could materially affect insurance, but disruption is unlikely to mirror Open Banking exactly. One difference is the commercial model: data holders could claim reasonable compensation from data users for making customer data available, helping offset the cost of building and maintaining APIs.
Insurance data is also more complex and less standardised than banking data. It can connect to underwriting, pricing, claims, assistance, delegated authority and distribution. FiDA would not require every item in an insurer’s systems to be shared. Trade secrets, intellectual property, confidential business information and internally enriched data are protected or limited under current negotiating positions. The boundary between raw customer data and proprietary analysis will therefore be important.
Early impact is likely in digital markets where verified policy information can reduce friction, such as comparison, switching, renewals, proof-of-cover checks, dashboards, embedded insurance and tailored recommendations. Travel insurance may be affected early because the customer journey is already digital and often linked to another purchase, such as a flight or holiday. Firms may, however, need to separate in-scope non-life data from excluded health, sickness or personal-injury information.
3. How could FiDA change insurance data-sharing and enable more personalised customer experiences?
FiDA could make insurance data-sharing more consistent and structured. Today, data often moves through bespoke broker platforms, bordereaux, delegated authority arrangements, claims systems, assistance networks and customer portals. FiDA would add a regulated route for customer-permitted sharing using standardised APIs.
Customers would also need permission dashboards, showing which organisations can access their data, for what purpose and for how long. Even so, FiDA would not remove the need for contracts, supplier controls, liability arrangements, data protection provisions and clear responsibilities for quality and security.
Insurers, MGAs and intermediaries may act as both data holders and data users. A firm may have to share information for one product while using data from elsewhere to improve distribution, servicing or renewals. For travel insurance, benefits could include fewer repeated questions, pre-populated applications, quicker cover checks, clearer policy information and more relevant product recommendations.
Personalisation would still be constrained by GDPR, insurance conduct obligations and confidentiality duties. FiDA permission would not remove the need for a valid legal basis to process personal data, and special-category data such as health information would require additional safeguards. Mixed products will therefore require careful data separation.
4. What practical steps should MGAs and the insurance sector take now to prepare for FiDA?
Preparation should begin with product scope, not technology. Firms should identify which EU products may fall within FiDA, which are excluded and which need deeper analysis because they combine different covers. Travel insurance should be reviewed benefit by benefit, with the legal analysis following the underlying data rather than the product label.
The next priority is data mapping and classification. Firms need to know what customer data they hold, where it is stored, whether it is structured, whether it includes personal or sensitive information and whether it is raw customer data or internally generated analysis. Pricing models, underwriting judgements, fraud indicators, claims strategies and proprietary analytics should not automatically be treated as portable customer data.
Firms should then assess operational and technology readiness, including permission dashboards, secure APIs, authentication, audit trails, withdrawal of consent, supplier controls, liability frameworks and participation in financial data-sharing schemes. New interfaces should also sit within existing cybersecurity, operational-resilience and third-party risk frameworks, including DORA where relevant.
A practical response is to establish a cross-functional compliance-by-design programme. Even before final rules are agreed, firms can address fragmented systems, poor data visibility, unclear ownership and weak permission controls. This no-regrets work will make implementation easier once final requirements are known.
5. Will incumbents or technology-led entrants benefit most from FiDA, and what will determine success?
The market is unlikely to divide neatly between incumbents and technology-led entrants. Established insurers have advantages in regulatory permissions, capital, underwriting expertise, data and customer relationships. However, those strengths will only matter if they can identify, manage, share and use customer data effectively.
Technology-led entrants may move faster because their systems are often built around APIs, customer permissions and interoperability. The bigger risk for incumbents is not necessarily replacement as risk carriers, but losing the primary customer relationship to aggregators, comparison services, embedded platforms or other digital intermediaries.
The winners will treat FiDA as a new commercial environment, not just a compliance project. They will understand where they act as data holders, where they want to act as data users and which customer problems data access can solve. Success will depend on regulatory understanding, modern data architecture, permission management, strong partnerships, early engagement in data-sharing schemes and protection of proprietary information.
Find Out More: mgaa.co.uk/members/kennedys-law-llp
Dr. Nathalie Moreno
Partner Kennedys Law LLP
We think you also might like …
LexisNexis® Insurance Demand Meter U.K. Reveals Lowest Motor Insurance Switching Levels Since 2023 as Vehicle Values Continue to Fall
LexisNexis® Insurance Demand Meter U.K. Reveals Lowest Motor Insurance Switching Levels Since 2023 as Vehicle Values Continue to Fall
11th August 2026
Intersys: AI Is Changing the Rules. Governance Must Keep Up
Artificial intelligence has arrived in the MGA market with remarkable speed. From underwriting and claims to document handling and customer communications, generative AI is already transforming the way many businesses operate. For a sector that has always embraced innovation, the appeal is obvious: greater efficiency, faster decision-making, and the ability to eliminate time-consuming administrative tasks.
10th August 2026
CyberOne: When Attacks Move at Machine Speed, Can Your Incident Response Keep Up?
In Q2 2026, 2,279 ransomware victims were publicly reported, up 7% from the previous quarter and 43% year on year. With more than 90 active ransomware groups operating globally, cybercrime has become a highly organised and fast-moving industry.
10th August 2026