
When open banking was first proposed in the UK through PSD2 in 2015, it was pitched as a way to rebalance power in finance. For decades, banks had held customers’ data in closed vaults. With regulators’ intervention, consumers were promised greater choice, competition, and ultimately better services by allowing third parties (fintechs, lenders, budgeting apps) to access account data with their consent.
The model spread quickly. Australia and Canada built consumer data rights frameworks. Brazil and India leapfrogged ahead, embedding open finance as a cornerstone of digital inclusion. Today, the UK is moving toward an Open Finance regime, while the EU is drafting PSD3 to expand the scope.
Yet the pure concept of open banking still raises uncomfortable questions. No other industry asks consumers to hand over their most intimate financial details so freely.
Giving an app or lender access to transaction-level history is far more revealing than any credit report. It tells a story about spending patterns, personal habits, even relationships. For affordability checks in lending or gambling, perhaps this level of access has justification. But outside of those high-risk contexts, does sharing one’s entire financial diary really feel proportionate?
The industry often glosses over this moral dimension. The rhetoric is about empowerment, but the reality can feel like exposure. Consumers rarely think in terms of APIs or consent dashboards; they experience the moment of clicking “agree” with limited understanding of how far their data will travel, or for how long.
And yet, dismissing open banking as an overreach would be a mistake. Properly governed, it remains one of the most significant consumer innovations in modern finance. It offers alternatives to entrenched monopolies, drives down costs, and enables tailored services that traditional banks rarely provided. The rise of variable recurring payments in the UK, or instant loan approvals in Brazil, are proof that the model can work to the customer’s advantage.
The challenge is ensuring that empowerment is not confused with exploitation. That means stronger guardrails: clear consent journeys, limited data-sharing where possible, and redress mechanisms when things go wrong. It also means asking whether regulators should draw sharper boundaries between legitimate use cases (like affordability checks) and more speculative ones, where access to transaction data is less justifiable.
The industry has already learned from past excesses in data collection. Just as GDPR forced companies to rethink their treatment of personal information, open banking needs its own cultural shift; one that treats financial data not as a free commodity, but as an asset loaned by consumers under trust.
In my mind, the prize is worth the discomfort. If we can reconcile the moral unease with the practical benefits, open banking can remain a cornerstone of fairer finance. But if the industry continues to ignore the ethical debate, it risks undermining the very trust on which its future depends.