Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Banking
    3. >Battling Regulations – How Banks can Navigate PSD2 and GDPR
    Banking

    Battling Regulations – How Banks Can Navigate PSD2 and Gdpr

    Published by Gbaf News

    Posted on July 4, 2018

    10 min read

    Last updated: January 21, 2026

    Add as preferred source on Google
    The image illustrates the aftermath of Russian attacks on Ukrainian energy infrastructure, crucial to Kyiv's military capabilities. This highlights the intensifying conflict and its implications for global finance and security.
    Russian military operations targeting Ukrainian energy facilities amid ongoing conflict - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Satya SwarupDas, Senior Solution Architect, Virtusa

    Benjamin Franklin once said, ‘when you’re finished changing, you’re finished’ and nowhere is it truer than in the commercial banking sector. The industry has been beset by numerous new opportunities and challenges in recent years that it’s sometimes tough to keep track.

    Many banks still recovering from the impact of digital disruption, yet now are having to contend with two new game-changing regulations in the shape of Open Banking/Payment Services Directive-Revised(PSD2)in January 2018 and General Data Protection Regulation(GDPR) in May 2018.

    The challenge to adapt to both and still maintain a profitable business can be overwhelming at the onset, especially when the two seem to contradict one another.The good part is that the power balance will shift towards customers as both legislations are likely to give them greater control over their personal data and, if handled appropriately, also help banks build stronger relationships with customers.

    Navigating the battle of regulations

    At first blush, the goals of Open Banking –gives better service options to customers through sharing of data by banks to Third Party Providers (TPP) – is the exact opposite of GDPR that aims to help consumers limit how and where their personal data is used as they will have the chance to know, understand, and consent to the data collected about them. While the former is trying to provide customers with greater choice, better products and better service when it comes to banking, the latter represents a substantial check on how that data can be used by companies. This has left many businesses confused about how to ensure they are compliant with both simultaneously.

    To make matters worse, the issue is further muddied by numerous grey areas in both legislations. Now, there are several key questions we don’t have a definite answer to. For example, since Open Banking will allow TPPs to access data and use it for customer servicing, if there is a breach of GDPR rules by a third-party provider, where does the culpability lie – with the bank or the TPP? And who does the customer take its grievances to? Can the same definition of ‘consent’ be used for both regulations? These issues, along with many others, need to be clarified by the regulators. In the meantime, it can be challenging to know the best way to stay compliant to both. Given that GDPR allows regulators to levy fines up to 4% of the annual global turnover, it may well be the case that banks are more focused on GDPR compliance than Open Banking. If so, regulators will need to pitch in so that the concerns of both banks and consumers can be reconciled.

    All in the data

    However, despite the prima facie contradictions between GDPR and Open Banking, the end goal for both is to give consumers greater control over their data, and at the same time, banks to gain visibility and control of the customer data they have. As of May 25th, 2018, customers can demand that banks share their data with a TPP or delete it under GDPR – either way, unless the bank knows where all the relevant customer data is held, it will not be able to meet these requests and will end up falling foul of the regulations.

    The first step in gaining this level of control is to break down all the internal data silos so that a comprehensive profile can be built for every customer. This will guarantee that no data is missed or overlooked. Once these silos are broken down, banks will review all internal data-handling processes to see if they are still fit for purpose. Chances are that in many cases they won’t be and banks will have to strategically consider how to best redesign them to ensure that the requirements of both regulations are met.

    The Customer Perspective

    As per Veritas GDPR Consumer Research, 2018 some interesting facts come into notice. As per this survey, 71% customers state that they will exercise their right to be forgotten under the new GDPR regulations which means they will ask their banks to delete their personal data. 56% of customers surveyed want to clearly understand how the data companies utilize their data. 79% believe that organizations will not be able to find and/or delete all of the personal data that they hold on them. These figures apply to all other industry sectors. But given the finding that 56% (Highest among all industry segments) feel the hardest sector to be hit by the regulation is Financial Services, the concern applies most to banks and financial institutions.

    The above findings indicate that there is a lot of ground to cover to strike the right balance. There are some intrinsic cushions for banks within both the regulations.  e.g. PSD2 has Strong Customer Authentication (SCA), Secure Communication (SC) and Regulatory Technical Standard (RTS) aspects to take care of checks and also does not allow to share “sensitive payment data”. Similarly, GDPR defines “personal data” by taking appropriate stand on security majors and keeping banks’ interest intact.

    Into the future

    Alone, either GDPR or Open Banking will present a huge challenge for the banking industry. Taken together, the effect is seismic, pulling major global institutions in a dozen different ways at once, especially given that input and clarification is urgently needed from regulators on a host of issues. However, it’s important for the industry not to be reactive and wait for these clarifications.

    Open Banking and GDPR represent a fantastic opportunity for banks to reshape the way they interact with customers, provided they can get full control and visibility of the data they hold. Many banks – particularly the more established ones – have huge amounts of legacy infrastructure problems that have resulted in data being stored in different places. If GDPR and Open Banking provide the final push to address that problem then everyone, from banks to consumers, will benefit.

    Satya SwarupDas, Senior Solution Architect, Virtusa

    Benjamin Franklin once said, ‘when you’re finished changing, you’re finished’ and nowhere is it truer than in the commercial banking sector. The industry has been beset by numerous new opportunities and challenges in recent years that it’s sometimes tough to keep track.

    Many banks still recovering from the impact of digital disruption, yet now are having to contend with two new game-changing regulations in the shape of Open Banking/Payment Services Directive-Revised(PSD2)in January 2018 and General Data Protection Regulation(GDPR) in May 2018.

    The challenge to adapt to both and still maintain a profitable business can be overwhelming at the onset, especially when the two seem to contradict one another.The good part is that the power balance will shift towards customers as both legislations are likely to give them greater control over their personal data and, if handled appropriately, also help banks build stronger relationships with customers.

    Navigating the battle of regulations

    At first blush, the goals of Open Banking –gives better service options to customers through sharing of data by banks to Third Party Providers (TPP) – is the exact opposite of GDPR that aims to help consumers limit how and where their personal data is used as they will have the chance to know, understand, and consent to the data collected about them. While the former is trying to provide customers with greater choice, better products and better service when it comes to banking, the latter represents a substantial check on how that data can be used by companies. This has left many businesses confused about how to ensure they are compliant with both simultaneously.

    To make matters worse, the issue is further muddied by numerous grey areas in both legislations. Now, there are several key questions we don’t have a definite answer to. For example, since Open Banking will allow TPPs to access data and use it for customer servicing, if there is a breach of GDPR rules by a third-party provider, where does the culpability lie – with the bank or the TPP? And who does the customer take its grievances to? Can the same definition of ‘consent’ be used for both regulations? These issues, along with many others, need to be clarified by the regulators. In the meantime, it can be challenging to know the best way to stay compliant to both. Given that GDPR allows regulators to levy fines up to 4% of the annual global turnover, it may well be the case that banks are more focused on GDPR compliance than Open Banking. If so, regulators will need to pitch in so that the concerns of both banks and consumers can be reconciled.

    All in the data

    However, despite the prima facie contradictions between GDPR and Open Banking, the end goal for both is to give consumers greater control over their data, and at the same time, banks to gain visibility and control of the customer data they have. As of May 25th, 2018, customers can demand that banks share their data with a TPP or delete it under GDPR – either way, unless the bank knows where all the relevant customer data is held, it will not be able to meet these requests and will end up falling foul of the regulations.

    The first step in gaining this level of control is to break down all the internal data silos so that a comprehensive profile can be built for every customer. This will guarantee that no data is missed or overlooked. Once these silos are broken down, banks will review all internal data-handling processes to see if they are still fit for purpose. Chances are that in many cases they won’t be and banks will have to strategically consider how to best redesign them to ensure that the requirements of both regulations are met.

    The Customer Perspective

    As per Veritas GDPR Consumer Research, 2018 some interesting facts come into notice. As per this survey, 71% customers state that they will exercise their right to be forgotten under the new GDPR regulations which means they will ask their banks to delete their personal data. 56% of customers surveyed want to clearly understand how the data companies utilize their data. 79% believe that organizations will not be able to find and/or delete all of the personal data that they hold on them. These figures apply to all other industry sectors. But given the finding that 56% (Highest among all industry segments) feel the hardest sector to be hit by the regulation is Financial Services, the concern applies most to banks and financial institutions.

    The above findings indicate that there is a lot of ground to cover to strike the right balance. There are some intrinsic cushions for banks within both the regulations.  e.g. PSD2 has Strong Customer Authentication (SCA), Secure Communication (SC) and Regulatory Technical Standard (RTS) aspects to take care of checks and also does not allow to share “sensitive payment data”. Similarly, GDPR defines “personal data” by taking appropriate stand on security majors and keeping banks’ interest intact.

    Into the future

    Alone, either GDPR or Open Banking will present a huge challenge for the banking industry. Taken together, the effect is seismic, pulling major global institutions in a dozen different ways at once, especially given that input and clarification is urgently needed from regulators on a host of issues. However, it’s important for the industry not to be reactive and wait for these clarifications.

    Open Banking and GDPR represent a fantastic opportunity for banks to reshape the way they interact with customers, provided they can get full control and visibility of the data they hold. Many banks – particularly the more established ones – have huge amounts of legacy infrastructure problems that have resulted in data being stored in different places. If GDPR and Open Banking provide the final push to address that problem then everyone, from banks to consumers, will benefit.

    More from Banking

    Explore more articles in the Banking category

    Image for Nominate Today for the Leadership Awards 2026
    Nominate Today for the Leadership Awards 2026
    Image for Submit Your Entries for Insurance & Takaful Awards 2026
    Submit Your Entries for Insurance & Takaful Awards 2026
    Image for Calling for Entries: ESG & Sustainability Awards 2026
    Calling for Entries: ESG & Sustainability Awards 2026
    Image for Call for Entries: Deal of the Year Awards 2026
    Call for Entries: Deal of the Year Awards 2026
    Image for Submit Your Entry Today for Customer Service Awards 2026
    Submit Your Entry Today for Customer Service Awards 2026
    Image for Submit Your Entry Today for CSR Awards 2026
    Submit Your Entry Today for CSR Awards 2026
    Image for Submit Your Entry Today for Retail Banking Awards 2026
    Submit Your Entry Today for Retail Banking Awards 2026
    Image for Nominations Open for Islamic Banking Awards 2026
    Nominations Open for Islamic Banking Awards 2026
    Image for Submit Your Entry Today for Fund & Asset Management Awards 2026
    Submit Your Entry Today for Fund & Asset Management Awards 2026
    Image for Entries Open for Forex Banking Awards 2026
    Entries Open for Forex Banking Awards 2026
    Image for Call for Entries for Brand of the Year Awards 2026
    Call for Entries for Brand of the Year Awards 2026
    Image for Nominations Open for Corporate Banking Awards 2026
    Nominations Open for Corporate Banking Awards 2026
    View All Banking Posts
    Previous Banking PostCrypto and Blockchain Integration in Established Banks
    Next Banking PostCareer Opportunities in Banking: Where Are We Now and What Is the Future?