A separate regulation - the GDPR - would cover that but raising a complaint is very difficult and a complaint would involve the subject being aware of their data being misused; you can't complain about something you don't see.
My worry about Open Banking is that it makes it much easier for companies to collect a lot more data and would normalize the practice even more.
Currently there's already no reason for a credit check to be required for a lot of services such as internet or phone service (those aren't lending any money and can cut off the service in case of non-payment), but at least a credit check gives them very little personal data compared to Open Banking - I'd rather not have to give them even more data.