Businessbusiness

UK Open Banking Mandates Bank Data Sharing

Open banking uses APIs to share customer data from banks with third parties. Learn how UK and EU regulation drove adoption, what services it enables, and where it is headed globally.
what-is-open-banking-financial-revolution

Open banking is a regulatory and technology framework that compels banks to share permissioned data with licensed third parties through standardised application programming interfaces (APIs). It is not an industry initiative. It is a legal mandate. The UK's Competition and Markets Authority forced the nine largest UK banks to adopt open banking in 2016, with a compliance deadline of January 2018. The European Union's revised Payment Services Directive (PSD2) came into force the same month, requiring banks across the EU to open payment accounts to licensed third parties. Together, these two rules created a market that did not previously exist.

Before these mandates, an individual's financial data sat locked inside their bank. A fintech company could not view transaction history, check a balance, or initiate a payment on someone's behalf unless that person handed over their login credentials. That approach was insecure, inconsistent, and impossible to scale. Open banking replaced it with a permissioned API layer. A user can now authorise a third party to access specific data for a specific purpose and revoke that permission at any time. The data moves through a standardised interface that both the bank and the third party have built to the same specification.

As of June 2023, the UK counted over 7 million active users of open banking services. That figure does not measure consumer enthusiasm. It measures how many people have used an app or service that runs on the API infrastructure the CMA compelled the banks to construct.

Open Banking API diagram
Mliu92, Wikimedia Commons, CC BY-SA 3.0

The UK and EU as the Primary Catalysts

Two Regulators, Two Philosophies

The UK and the EU took different regulatory routes to the same destination. The CMA acted on competition grounds. It concluded that the nine largest UK banks faced too little competitive pressure from smaller rivals and new entrants. By forcing those institutions to share data, the CMA aimed to lower the barrier for consumers to compare products, switch providers, or use a non-bank service. The Open Banking Implementation Entity (OBIE) was established in 2016 to oversee the creation of the API standards that enabled that data sharing. The OBIE set the technical specifications, security standards, and governance rules the nine banks had to follow.

PSD2 took a different path. It was a payments directive, not a competition remedy. It required banks across the European Union to give licensed third parties access to payment accounts. The directive created two new categories of regulated entity: account information service providers (AISPs), which can read transaction data, and payment initiation service providers (PISPs), which can initiate payments. Both must be authorised by a national regulator. The overlap between the CMA order and PSD2 meant that UK banks had to comply with both sets of rules. After Brexit, the UK retained its own framework, now independent of the EU regime.

Prescription Versus Principles

The distinction matters. The UK model is prescriptive. The CMA specified exactly which data sets had to be shared, on what timetable, and to what standard. The EU model is principles-based. PSD2 set the outcome and left implementation to national authorities and industry bodies. The UK approach produced a single, consistent API standard. The EU approach produced a patchwork of national implementations that vary in quality and scope.

What Open Banking Actually Enables

Account Aggregation

The practical services that open banking supports fall into three categories: account aggregation, credit decisioning, and payment initiation. Aggregation lets a consumer see balances and transaction history from multiple banks in a single app. That sounds simple, but before open banking it required screen scraping, which was brittle and often broke when a bank changed its website. Aggregation remains the most common use case and the one that drives the user figures cited above.

Credit Decisioning

Credit decisioning is where the economic value sits. A lender can ask a borrower to share three months of bank transaction data. The lender then analyses income, spending patterns, and recurring commitments to assess affordability. This is faster than requesting payslips and bank statements, and it is harder to fabricate. Some lenders use the data to extend loans to people who would be rejected by a credit bureau score because they have a thin credit file. The mechanism replaces an adjective like 'innovative' with a concrete change: the lender sees actual cash flow rather than a proxy for it.

Payment Initiation

Payment initiation is less visible to consumers but more consequential for the payments industry. A PISP can instruct a bank to move money directly from a consumer's account to a merchant, bypassing the card network. The merchant pays a lower fee. The payer never enters a card number. The transaction settles in real time. As of October 2023, payment initiation accounted for a small share of open banking traffic, but it is the use case that threatens the economics of the card schemes.

Consent, Security, and the Limits of the Model

How Permission Works

Open banking data sharing is governed by a consent model more explicit than most consumers realise. A user must authorise each data access request separately. The authorisation covers a specific purpose, a specific data set, and a specific time period. The user can revoke it at any point through their bank's interface. The third party never holds the bank login credentials. It holds a token that the bank issues after the user authenticates directly with the bank. This mechanism replaces the old practice of handing over a username and password.

Where the Risk Actually Sits

The protection architecture has held up well. No documented major data breach is specifically and solely attributable to open banking APIs. That does not make the system risk-free. The burden shifts to the third party, which must hold the token securely, use it only for the authorised purpose, and delete the data when consent expires. Regulators in the UK and EU audit firms for compliance. The threat is not that a bank leaks records. It is that a fintech with weak safeguards is compromised and the token is used to pull data the user did not authorise.

The Consent Fatigue Problem

Consent fatigue is a real but underdiscussed problem. A consumer who uses five open banking services grants five separate authorisations, each with different terms. That person may not remember which services still have access to their details or how to revoke them. The OBIE and its successor, the Joint Regulatory Oversight Committee, have proposed dashboard tools to give consumers a single view of all active permissions. Those tools were not widely available as of October 2023.

The Global Landscape and the Path to Open Finance

Australia and Brazil Move Faster

The UK and EU led on open banking, but other jurisdictions have moved faster in some respects. Australia's Consumer Data Right (CDR) legislation passed in 2019 and applied open banking principles to the banking sector first, in July 2020. The CDR is designed as a sector-by-sector rollout: banking first, then energy, then telecommunications. That is a broader scope than the UK's banking-only mandate. Brazil's central bank implemented its open banking initiative in phases starting in February 2021. Brazil's model is notable because it includes not just data sharing but also the sharing of product offerings, so a consumer can compare loans, credit cards, and accounts from multiple institutions in a single place.

The US Market-Driven Path

The United States has taken a market-driven approach. There is no federal mandate equivalent to the CMA order or PSD2. Instead, the Consumer Financial Protection Bureau (CFPB) proposed a personal financial data rights rule in October 2023 that would require banks to make consumer data available to third parties at the consumer's request. The proposed rule is less prescriptive than the UK model. It establishes the right to data access and leaves the technical implementation to the market. Whether the rule is finalised and how it survives legal challenge was not established as of October 2023.

From Open Banking to Open Finance

The logical next step is open finance, which extends the data-sharing principle beyond bank accounts to mortgages, pensions, insurance policies, and investment holdings. The UK government has consulted on an open finance framework. Australia's CDR already covers more than banking. Brazil's phased approach includes insurance and investments. The technical and regulatory infrastructure built for open banking is the foundation for that expansion. The same API standards, consent mechanisms, and protection protocols apply. The difference is the scope of data and the number of institutions that must participate.

About the author

, Editor

Kenneth Ma is the editor of LeadMonitor.ai, covering the companies, deals and policy decisions shaping business and technology markets.

View all 427 articles by Kenneth Ma  ·  Our editorial policy

Recent Stories

How to make money selling Canva templates

How to highlight text in Canva

How to print from Canva without quality loss

How to check if Canva is down right now

How to group and ungroup elements in Canva

How to stretch an image in Canva

How to make a QR code in Canva

Convert Canva to PowerPoint and Google Slides