Zpět na blog
Industry Guide

FinTech Privacy: PSD2, Open Banking & GDPR

Thomas Mueller, Legal AnalystApril 18, 202615 min čtení
FinTechPSD2BankingGDPR
FinTech Privacy: PSD2, Open Banking & GDPR
# FinTech Privacy: PSD2, Open Banking & GDPR **Date:** April 18, 2026 **Author:** Thomas Mueller, Legal Analyst **Category:** Industry Guide **Reading Time:** 15 min --- Money requires trust. In FinTech, trust is built on data security. The intersection of **PSD2** (Payment Services Directive 2), **Open Banking**, and **GDPR** creates a complex web of obligations for modern financial apps. You must open your data APIs (PSD2) while locking down user privacy (GDPR). ## The Conflict: Access vs. Privacy * **PSD2** says: "You must share customer data with Third Party Providers (TPPs) if the customer asks." * **GDPR** says: "You must ensure data is secure and minimized." **The Solution:** Strong Customer Authentication (SCA) and explicit consent management. ## Cookie Consent in FinTech Financial sites have a unique category of cookies: **Fraud Prevention**. * **Essential Cookies:** Cookies used to detect botnets, fingerprint devices for security, or maintain secure sessions are "Strictly Necessary." * **Consent:** You do **not** need user consent for fraud prevention cookies (Recital 29 of GDPR). * **Implementation:** Configure GetCookies to classify your fraud tools (e.g., Sift, Seon) as "Essential." Do not let users toggle them off. ## Marketing in Banking While fraud cookies are essential, retargeting pixels are not. **The Risk:** Using transaction data for marketing. * If a user pays for a subscription to a cancer support group via your banking app, you cannot use that data to target them with life insurance ads unless you have explicit, specific consent for that processing. ## Data Localization (GLBA / SOX / GDPR) FinTechs often face strict data residency rules. * **US:** GLBA requires safeguarding financial info. * **EU:** GDPR + Local banking secrecy laws (e.g., Swiss Banking Secrecy). * **Strategy:** Ensure your CMP and analytics stack supports **Data Residency**. Do not send German banking logs to a US analytics server. ## Checklist for FinTech CPOs 1. **Audit Essential Cookies:** Verify that cookies marked "Essential" are *actually* for security/auth, not analytics. 2. **Consent Receipt:** Log every consent event with a timestamp and IP. In finance, you need an audit trail for everything. 3. **Vendor Risk:** Your marketing team wants to add a new "Growth Hack" tool. Vetting it is your job. If it scrapes screen data (session replay), it might capture IBANs. Block it. ## Conclusion FinTech privacy is high-stakes. A breach isn't just embarrassing; it's expensive and regulated. Use your CMP as a gatekeeper to ensure only approved, compliant vendors ever touch your user's browser.
T

Thomas Mueller, Legal Analyst

Přispívající autor GetCookies, specializující se na compliance soukromí, správu souhlasu a optimalizaci digitálního marketingu.

Připraveni zjednodušit souhlas s cookies?

GetCookies dělá GDPR, CCPA a globální compliance soukromí snadné. Začněte ještě dnes.