# FinTech Privacy: PSD2, Open Banking & GDPR
**Date:** April 18, 2026
**Author:** Thomas Mueller, Legal Analyst
**Category:** Industry Guide
**Reading Time:** 15 min
---
Money requires trust. In FinTech, trust is built on data security.
The intersection of **PSD2** (Payment Services Directive 2), **Open Banking**, and **GDPR** creates a complex web of obligations for modern financial apps. You must open your data APIs (PSD2) while locking down user privacy (GDPR).
## The Conflict: Access vs. Privacy
* **PSD2** says: "You must share customer data with Third Party Providers (TPPs) if the customer asks."
* **GDPR** says: "You must ensure data is secure and minimized."
**The Solution:** Strong Customer Authentication (SCA) and explicit consent management.
## Cookie Consent in FinTech
Financial sites have a unique category of cookies: **Fraud Prevention**.
* **Essential Cookies:** Cookies used to detect botnets, fingerprint devices for security, or maintain secure sessions are "Strictly Necessary."
* **Consent:** You do **not** need user consent for fraud prevention cookies (Recital 29 of GDPR).
* **Implementation:** Configure GetCookies to classify your fraud tools (e.g., Sift, Seon) as "Essential." Do not let users toggle them off.
## Marketing in Banking
While fraud cookies are essential, retargeting pixels are not.
**The Risk:** Using transaction data for marketing.
* If a user pays for a subscription to a cancer support group via your banking app, you cannot use that data to target them with life insurance ads unless you have explicit, specific consent for that processing.
## Data Localization (GLBA / SOX / GDPR)
FinTechs often face strict data residency rules.
* **US:** GLBA requires safeguarding financial info.
* **EU:** GDPR + Local banking secrecy laws (e.g., Swiss Banking Secrecy).
* **Strategy:** Ensure your CMP and analytics stack supports **Data Residency**. Do not send German banking logs to a US analytics server.
## Checklist for FinTech CPOs
1. **Audit Essential Cookies:** Verify that cookies marked "Essential" are *actually* for security/auth, not analytics.
2. **Consent Receipt:** Log every consent event with a timestamp and IP. In finance, you need an audit trail for everything.
3. **Vendor Risk:** Your marketing team wants to add a new "Growth Hack" tool. Vetting it is your job. If it scrapes screen data (session replay), it might capture IBANs. Block it.
## Conclusion
FinTech privacy is high-stakes. A breach isn't just embarrassing; it's expensive and regulated. Use your CMP as a gatekeeper to ensure only approved, compliant vendors ever touch your user's browser.
Tilbake til bloggen
Industry Guide
FinTech Privacy: PSD2, Open Banking & GDPR
Thomas Mueller, Legal AnalystApril 18, 202615 min lesing
FinTechPSD2BankingGDPR
T
Thomas Mueller, Legal Analyst
Skribent hos GetCookies, spesialisert på personvernsamsvar, samtykkeadministrasjon og optimalisering av digital markedsføring.
Klar til å forenkle informasjonskapselsamtykke?
GetCookies gjør GDPR, CCPA og globalt personvernsamsvar uanstrengt. Kom i gang i dag.