in force 2025-01-17
02014R0600-20241204 → 02014R0600-20250117
Amended by Regulation (EU) 2022/2554 32022R2554
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (Text with EEA relevance)
detected 2026-08-13
3 provisions touched — 3 substantive, 0 date-only, 1 disputed · 1 change without an explanation
Emendrix checks every change against three independent sources. Where they disagree it says so rather than picking a winner.
MODIFIED +420 −324 Art. 27g Organisational requirements for APAs§
applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)
dates added to the text: 2022-12-14
Paragraph 4 no longer sets out its own security-mechanism, resource, and back-up-facility requirements for an APA, and instead states that an APA shall comply with the network and information systems security requirements set out in Regulation (EU) 2022/2554.
In paragraph 8(c), the reference to the organisational requirements laid down in paragraphs 3, 4 and 5 has been changed to a reference to paragraphs 3 and 5 only, dropping the mention of paragraph 4.
Cited: Art. 27g, v2
text before / after
02014R0600-20241204 → 02014R0600-20250117
Article 27g
Organisational requirements for APAs
1. An APA shall have adequate policies and arrangements in place to make public the information required under Articles 20 and 21 as close to real time as is technically possible, on a reasonable commercial basis. The information shall be made available free of charge 15 minutes after the APA has published it. The APA shall efficiently and consistently disseminate such information in a way that ensures fast access to the information, on a non-discriminatory basis and in a format that facilitates the consolidation of the information with similar data from other sources.
2. The information made public by an APA in accordance with paragraph 1 shall include, at least, the following details:
(a) the identifier of the financial instrument;
(b) the price at which the transaction was concluded;
(c) the volume of the transaction;
(d) the time of the transaction;
(e) the time the transaction was reported;
(f) the price notation of the transaction;
(g) the code for the trading venue the transaction was executed on, or where the transaction was executed via a systematic internaliser the code SI or otherwise the code OTC;
(h) if applicable, an indicator that the transaction was subject to specific conditions.
3. An APA shall operate and maintain effective administrative arrangements designed to prevent conflicts of interest with its clients. In particular, an APA who is also a market operator or investment firm shall treat all information collected in a non-discriminatory way and shall operate and maintain appropriate arrangements to separate different business functions.
4. An APA shall have sound security mechanisms in place designed to guarantee comply with the requirements concerning the security of network and information systems set out in Regulation (EU) 2022/2554 of the means European Parliament and of transfer the CouncilRegulation (EU) 2022/2554 of information, minimise the risk European Parliament and of data corruption the Council of 14 December 2022 on digital operational resilience for the financial sector and unauthorised access amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and to prevent information leakage before publication. The APA shall maintain adequate resources and have back-up facilities in place in order to offer and maintain its services at all times. (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1)..
4a. An APA shall have objective, non-discriminatory and publicly disclosed requirements for access to its services by undertakings that are subject to the transparency requirements laid down in Article 20(1) and Article 21(1).
An APA shall publicly disclose the prices and fees associated with the data reporting services provided pursuant to this Regulation. It shall disclose separately the prices and fees of each service provided, including discounts and rebates and the conditions for benefiting from them. It shall allow reporting entities to access specific services separately.
4b. An APA shall keep records relating to its business at the disposal of the relevant competent authority or ESMA for at least five years.
5. The APA shall have systems in place that can effectively check trade reports for completeness, identify omissions and obvious errors, and request re-transmission of any such erroneous reports.
6. ESMA shall develop draft regulatory technical standards to determine common formats, data standards and technical arrangements facilitating the consolidation of information as referred to in paragraph 1.
Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1095/2010.
7. The Commission is empowered to adopt delegated acts in accordance with Article 50 in order to supplement this Regulation by specifying what constitutes a reasonable commercial basis to make information public as referred to in paragraph 1 of this Article.
8. ESMA shall develop draft regulatory technical standards specifying:
(a) the means by which an APA may comply with the information obligation referred to in paragraph 1;
(b) the content of the information published under paragraph 1, including at least the information referred to in paragraph 2 in such a way as to enable the publication of information required under this Article;
(c) the concrete organisational requirements laid down in paragraphs 3, 4 3 and 5.
Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1095/2010.
MODIFIED ±0 Art. 27h§
applies from: unknown
Sources disagree — the EU's own amendment metadata and the amending act's instructions found this change; the text comparison finds no difference in the provision's text. All are shown; none is overruled.
No explanation shipped — the structural diff did not see this change, so it carries no text; another signal named the unit and the disagreement ships as `disputed`.
text before / after
No text on either side: this unit was named by a signal that carries no text, and only the structural diff carries any.
MODIFIED +93 −398 Art. 27i Organisational requirements for ARMs§
applies from: unchanged
Paragraph 3 previously set out detailed security mechanism and resource/back-up requirements for ARMs, but now instead states that an ARM shall comply with the network and information system security requirements set out in Regulation (EU) 2022/2554.
Correspondingly, the list of paragraphs referenced in paragraph 5(b) as containing the concrete organisational requirements for regulatory technical standards was changed from paragraphs 2, 3 and 4 to paragraphs 2 and 4, dropping the reference to paragraph 3.
Cited: Art. 27i, v1 · Art. 27i, v2
text before / after
02014R0600-20241204 → 02014R0600-20250117
Article 27i
Organisational requirements for ARMs
1. An ARM shall have adequate policies and arrangements in place to report the information required under Article 26 as quickly as possible, and no later than the close of the working day following the day upon which the transaction took place.
2. The ARM shall operate and maintain effective administrative arrangements designed to prevent conflicts of interest with its clients. In particular, an ARM that is also a market operator or investment firm shall treat all information collected in a non-discriminatory fashion and shall operate and maintain appropriate arrangements to separate different business functions.
3. The An ARM shall have sound security mechanisms in place designed to guarantee comply with the requirements concerning the security of network and authentication of the means of transfer of information, minimise the risk of data corruption and unauthorised access and to prevent information leakage, maintaining the confidentiality of the data at all times. The ARM shall maintain adequate resources and have back-up facilities systems set out in place in order to offer and maintain its services at all times. Regulation (EU) 2022/2554.
4. The ARM shall have systems in place that can effectively check transaction reports for completeness, identify omissions and obvious errors caused by the investment firm, and where such error or omission occurs, to communicate details of the error or omission to the investment firm and request re-transmission of any such erroneous reports.
The ARM shall have systems in place to enable the ARM to detect errors or omissions caused by the ARM itself and to enable the ARM to correct and transmit, or re-transmit as the case may be, correct and complete transaction reports to the competent authority.
4a. An ARM shall have objective, non-discriminatory and publicly disclosed requirements for access to its services by undertakings that are subject to the reporting obligation laid down in Article 26.
An ARM shall publicly disclose the prices and fees associated with the data reporting services provided pursuant to this Regulation. It shall disclose separately the prices and fees of each service provided, including discounts and rebates and the conditions for benefiting from them. It shall allow reporting entities to access specific services separately. The prices and fees charged by an ARM shall be cost-related.
4b. An ARM shall keep records relating to its business at the disposal of the relevant competent authority or ESMA for at least five years.
5. ESMA shall develop draft regulatory technical standards specifying:
(a) the means by which the ARM may comply with the information obligation referred to in paragraph 1; and
(b) the concrete organisational requirements laid down in paragraphs 2, 3 2 and 4.
Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1095/2010.
The full entry, with the citation mapping v1 = 02014R0600-20241204, v2 = 02014R0600-20250117, is committed at eu/32014R0600/CHANGELOG.md.