What is open banking data?
Open banking data is the financial information that consumers and businesses can share with FCA-regulated third parties via secure APIs, with explicit consent. It typically includes bank account balances, transaction history, income credits, regular payments, and direct debits. Open banking data cannot include passwords or personal identity documents — only the transaction data visible within the accounts you choose to connect.
What categories of data can be accessed through open banking?
Under the UK open banking standards, AISPs can access: account balances and available funds, transaction history (typically up to 12 months), payee and payer details, transaction categories, and standing order or direct debit schedules. The data is automatically categorised by the AISP — for example, into salary, rent, groceries, and subscriptions — to power affordability tools, budgeting apps, and credit assessments.
How is open banking data protected in the UK?
Open banking data is protected by multiple layers of regulation. The Payment Services Regulations 2017 require providers to use Strong Customer Authentication and encrypted API connections. UK GDPR gives consumers the right to access, correct, and delete their data. The FCA’s Consumer Duty (2023) requires firms to use data in consumers’ best interests. Consent must be specific, time-limited, and revocable at any time.
Open Banking in Practice: Open banking data is distinct from credit data held by agencies such as Experian, Equifax, and TransUnion. It provides a real-time view of actual financial behaviour rather than a historical credit record. This makes it particularly valuable for lenders assessing consumers with thin credit files. The JROC’s 2023 roadmap envisages expanding open data to pensions and investments under a broader open finance framework. Read more on openfuture.world.
FAQ
Can open banking data be sold to third parties?
No — FCA-regulated providers cannot sell or share your open banking data beyond the purpose you consented to; doing so would breach FCA rules and UK GDPR.
How long is open banking data stored by providers?
Providers must state the retention period at the point of consent and delete data when it is no longer needed for the stated purpose.
Is open banking data the same as a credit check?
No — open banking data shows real-time transaction behaviour; a credit check draws on historical credit records held by credit reference agencies.