How to understand what financial data is shared, for how long and with whom.
Consent should be specific
A useful consent screen identifies the accounts, data types, purpose and duration of access. Broad language makes it difficult to judge whether sharing is proportionate. Customers should be able to decline optional permissions without losing unrelated functions.
Access needs an understandable chain
The service requesting data may use infrastructure providers or other processors. Review who receives information, whether payment initiation is included and how frequently data is refreshed. Businesses integrating open banking should document this chain for support and incident response.
Revocation must work in practice
People need a clear way to review and withdraw access from both the third-party service and their bank. Revocation should stop future collection without making past records mysterious. Periodic consent review is especially important when a service is no longer actively used.
