Open banking data sharing shown as scoped data flowing directly from a banking app

Open Banking Data Sharing: How Secure Consent Works

Open banking data sharing lets a customer grant a regulated third party read access to specific banking data, for a defined period, without ever handing over a username or password. The bank stays the login gatekeeper throughout. 

This guide walks through exactly how open banking data sharing works, what permissions are actually granted, and the privacy protections built into the model so both customers and compliance leads can see the mechanism, not just the marketing.

Key Takeaways

  • Open banking data sharing never involves handing over login credentials; the bank authenticates the customer directly, every time.
  • Consent is scoped, time-limited, and revocable from the banking app at any moment, not locked in for the life of the relationship.
  • Read access and write access are entirely separate permissions; granting one never grants the other.
  • Open Banking Limited’s Customer Experience Guidelines require AIS consent to be reconfirmed at least every 90 days, regardless of how long the underlying relationship continues.

How Does The Open Banking Data Sharing Consent Journey Actually Work?

Open banking data sharing consent journey shown broken into five sequential steps

Open banking data sharing follows a fixed sequence set by regulation, not by individual platforms. Every step below is standard across UK banks, which is part of what makes open banking data privacy predictable rather than provider-dependent.

The Consent Journey Runs Through Five Distinct Steps

A platform requests access to specific data, such as transaction history or account balances, and states the purpose. The customer is redirected to their own bank’s login page, never the platform’s, and authenticates using Strong Customer Authentication (SCA), typically a fingerprint, PIN, or banking app approval. 

This sequence is consistent whether a customer connects through a lending platform, an accounting tool, or a budgeting app; these open banking examples all follow the same underlying open banking data sharing mechanism, regulated at the bank level, not the platform level.

What Permissions Does Open Banking Data Sharing Actually Grant? 

Open banking data sharing read access shown kept fully separate from payment permissions

Permissions in open banking data sharing are scoped, meaning a platform only receives what it explicitly requested, and the customer explicitly approved. A request for balance data does not include transaction history unless separately scoped and approved.

Granting open banking data sharing permissions for account information never grants payment initiation rights. A platform with read access cannot move a single pound without a separate, distinct consent covering that specific action.

How Does Open Banking Data Privacy Work In Practice?

Open banking data privacy shown as four protections built into the consent model

Open banking data privacy is built into the consent model itself rather than added as a policy layer afterward. Four protections apply to every connection.

No Credentials Are Ever Shared With The Platform

The customer authenticates directly with their bank. The platform requesting open banking data sharing never sees, stores, or has access to banking credentials at any point in the journey.

Consent Can Be Revoked From The Banking App At Any Time

Revocation does not require contacting the platform. The customer opens their banking app, finds the connection, and ends it. Access stops immediately once revoked.

Every Consent Has A Defined Expiry

FCA Authorisation Is A Precondition, Not An Add-On

How Is This Different From Credential-Based Access?

Before regulated open banking data sharing existed, some tools asked customers for their online banking username and password directly, a method known as credential-based access or screen scraping. The table below sets out where the two approaches actually diverge.

FactorCredential-Based AccessOpen Banking Data Sharing
Login credentialsHeld by the platformNever leave the bank
Point of failurePlatform breach exposes login detailsNo credentials for a platform to lose
Liability on unauthorised accessOften unclearDefined by FCA-regulated consent
AuthenticationSimulated by the platformPerformed directly by the bank via SCA
Legal status under open banking UK rulesNot a recognised lawful methodThe only lawful method under PSD2

Regulated open banking data sharing keeps authentication with the bank throughout, which is precisely why the entire open banking API UK market moved away from credential sharing toward consent-based access.

What Should Platforms Be Responsible For?

Open banking data sharing places specific obligations on the platform requesting access, separate from the bank’s role.

Platforms must display consent clearly, showing exactly what data is being requested and why, in plain language rather than legal text. They must prompt re-authentication before consent expires rather than letting a connection silently fail. And they must state a clear purpose for every data request, since vague or bundled requests undermine the entire premise of scoped open banking data privacy.

The Open Banking Directory Confirms Whether A Provider Is Genuinely Authorised

Checking a provider against the FCA open banking directory takes under a minute, yet it remains the most reliable way to confirm a service is genuinely authorised rather than simply claiming to be. With well over a hundred regulated participants listed, the open banking directory is the practical starting point for due diligence.

How Does Finexer Support Open Banking Data Sharing And Privacy?

Finexer operates as an FCA-authorised AISP (FRN 925695), which means that open banking data sharing through the platform follows the same regulated consent model described throughout this guide, rather than a simplified or altered version of it.

  • Consent lifecycle management is handled directly, including the 90-day reconfirmation cycle required under OBL guidelines.
  • Re-authentication prompts are triggered automatically before consent lapses, so platforms using Finexer do not need to build this logic themselves.

The Bottom Line

Open banking data sharing is not a trust exercise; it is a regulated mechanism where the bank remains the authentication gatekeeper throughout. Credentials never leave the bank, permissions are scoped and time-limited, and every consent can be revoked in seconds from the banking app. For platforms operating under open banking API UK rules, open banking data privacy is not optional positioning; it is the precondition for lawful access in the first place.

Is Open Banking Data Sharing Safe For Personal Banking Details?

Yes. Open banking data privacy is protected because credentials are never shared with the platform, and every connection requires FCA-authorised access with defined scope and expiry.

Where Can I Check Which Providers Are Authorised For Open Banking UK?

The FCA’s Financial Services Register is the official open banking directory for checking whether a provider is authorised. Open Banking Limited also maintains its own open banking directory of regulated participants operating in open banking UK.

What Are Common Open Banking Examples of Data Sharing In Practice?

Common open banking examples include a budgeting app reading transaction history to categorise spending, a lender checking account balances for affordability, and an accounting platform reconciling invoices against bank data, all under the open banking API UK framework.

Can a Platform Access My Account After I Revoke Consent?

No. Once consent is revoked through the banking app, open banking data sharing for that connection ends immediately, and no further data can be retrieved.

Finexer handles the consent lifecycle, re-authentication and revocation automatically, so your platform never has to build that logic in-house.

Ready to see how consent-based data access actually works?

About the Author

Clare Pearson
Clare Pearson

Clare Pearson is a senior payments professional with extensive experience across the global financial services and payments industry. She specialises in Open Banking, payment infrastructure, and financial technology transformation, with expertise spanning product delivery, operational strategy, regulatory compliance, and large-scale payments programmes. Clare currently serves as a Non-Executive Director at Finexer and a panel member for the Payment Systems Regulator (PSR), advising on the development of payment systems policy and innovation