Quentin CasaresData and AI leadership for regulated growth
Insights

2026-09-14 / 7 min

Smart data stops being voluntary

On 8 July 2026 the Department for Business and Trade opened a call for evidence on smart data schemes in five more sectors, closing on 1 October. The underlying power lets ministers compel firms to share customer and commercial data.

In brief: the Data (Use and Access) Act 2025 gives ministers a general power to require firms to hand over customer data and commercial data such as pricing, enforced by designated authorities with powers of entry, inspection and unlimited fines. On 8 July 2026 the Department for Business and Trade opened a multi-sector call for evidence to decide where that power is used next, and it closes at 11:59pm on 1 October 2026. Boards in the ten named sectors have about three weeks to shape the design rather than absorb it.

Most boards filed open banking under fintech and moved on. That was a reasonable reading of a scheme imposed on nine banks by a competition remedy. It is no longer the right reading, because Parliament has since converted that one-off intervention into a standing power that reaches ten sectors of the economy, and the government has started deciding where to point it.

Part 1 of the Data (Use and Access) Act 2025 lets the Secretary of State or the Treasury make regulations requiring a data holder to provide customer data to a customer or to an authorised third party, and to provide business data to anyone the regulations specify. On 26 March 2026 the Department for Business and Trade published Smart Data 2035, committing at least £36 million over four years and setting a target of five or more active schemes by 2030 and twenty or more by 2035, across banking, finance, energy, road fuels, property, retail, digital markets, transport, telecoms and agrifood. On 8 July 2026 the same department opened a call for evidence covering agri-food, property, retail, trade and transport, asking about use cases, scheme design and cross-sector governance. It closes on 1 October 2026.

The power is broader than the open banking precedent suggests

The Act separates two things that most data strategies treat as one. Section 1 defines customer data as information relating to a customer of a trader, including information about the goods, services and digital content supplied to that customer. It defines business data separately as information about the goods, services and digital content a trader supplies, including their terms, usage, performance and the feedback on them. Customer data moves on a customer's authority. Business data does not need one.

ProvisionWhat it allowsWhat a data holder should expect
Sections 2 and 3Regulations requiring provision of customer data to customers or authorised third parties, and requiring that data to be produced, collected, retained and rectifiedAn obligation to create and correct records, not merely to release records that already exist
Sections 4 and 5Regulations requiring provision of business data, including terms, usage and performance informationPricing and product data leaving the firm on a standardised schedule, without a customer permission step
Section 7Designation of interface bodies to set technical standards and interfacesThe format, latency and availability of the feed decided by a third party, not by the firm's architects
Sections 8 and 10Designation of an enforcer with powers to require documents and information, to require attendance to answer questions, and of entry, inspection, search and seizure, plus financial penalties and offences carrying an unlimited fineSupervised data supply, with false or misleading information a sanctionable act

Sections 14 to 17 carve out the financial services sector specifically, which is how open banking is expected to move from a competition remedy onto a statutory footing. The point for a board outside financial services is that the same machinery now exists for its own sector, and the sector order is being set this autumn.

Business data is the part nobody has costed

Customer data sharing has a decade of precedent and a familiar control set: consent capture, authentication, revocation, dispute handling. Business data sharing has almost none. A price transparency scheme requires standardised commercial data rather than customer data, needs no consumer consent, and mandates participation by the firms in scope. That is a different proposition entirely. It means a competitor, a comparison service or an aggregator receives your pricing and performance data on a defined cadence, in a defined shape, because a statutory instrument says so.

Three consequences follow that rarely appear in a data strategy paper. First, the commercial model changes: if list price, availability and service performance become a published feed, the margin that depended on search friction goes with it. Second, the data quality exposure inverts. Internally, a wrong figure costs a correction. In a supervised feed, section 8 makes providing false or misleading information a sanctionable act, so the firm needs the same evidence of accuracy on the way out that it has learned to hold for regulatory returns. Third, the obligation is to produce and retain, not only to disclose, which means datasets a firm chose not to hold can become ones it is required to hold.

The controls already exist under different names

None of this needs a new framework, which is the useful part. A firm that has done Critical Data Elements work already knows how to name a small set of fields, assign an accountable owner and set a quality threshold. A firm with maintained data lineage can already show which source systems feed each published field and what breaks when one of them changes. The shift is scope: the outbound feed is a new class of critical data element, and it is the first one whose consumers are outside the firm and whose accuracy is enforceable by an authority with powers of entry.

Regulated firms should read across further. A smart data feed that misprices a product is a Consumer Duty question about the outcome a customer received, and the operation of a mandated interface is the kind of material activity that belongs in a named individual's statement of responsibilities under SM&CR. Deciding that after the regulations are made is more expensive than deciding it now.

SectorPosition as of September 2026Next fixed point
Banking and financeFCA open finance roadmap published 14 April 2026, prioritising SME credit and mortgage accessFCA consultation on the long-term open banking framework by the end of 2026
EnergyDetailed scheme proposals in developmentConsultation during 2026, regulations expected 2027 or 2028
PropertyRoadmap due in 2026Covered by the call for evidence closing 1 October 2026
Retail, transport, agri-food and tradeEvidence gathering only, with no scheme designedCall for evidence closing 1 October 2026, then feasibility work
All sectorsNo cross-economy standard yetCross-sector Smart Data Guidebook due early 2027

The open finance numbers show why the government is pressing. The FCA counts roughly 17 million open banking users in the UK, close to one adult in three, and puts the potential combined economic impact of open finance at £7.4 billion a year within five years. Smart Data 2035 is an attempt to reproduce that in nine more sectors on a single legal footing.

Four questions before the next board meeting

  1. Which of our data holdings would fall inside a smart data scheme for our sector, and has anyone written that list down?
  2. If pricing, terms and service performance became a standardised outbound feed, which parts of our commercial model depend on them not being one?
  3. Who would own the accuracy of that feed, and can we evidence the accuracy of those fields today without rebuilding them by hand?
  4. Are we responding to the call for evidence before 1 October 2026, and if not, who decided that our sector's scheme should be designed without us?

Every firm in the ten named sectors will eventually be a data holder under this regime; the only open question is whether it helped write the specification or received it.

Sources

Related service: Advisory

Executive Data Briefing

A low-volume note for data and AI decisions with consequence.

Consent-based and double opt-in. Governance patterns, board-level data trust, and decision infrastructure - not generic AI commentary.