Balancing innovation and privacy: Salt Edge guide to data protection in Open Banking

Terms like General Data Protection Regulation (GDPR), personal data, PSD2, and Open Banking dominate financial technology discussions. Yet, how these regulatory frameworks interact still remains a frequent pain point for fintechs, traditional banks, and businesses.
At Salt Edge, we help businesses securely access and use financial data through open banking infrastructure. As a provider operating at the intersection of payments, data sharing, and regulation, data protection is embedded into how we design and deliver our services.
In this article, our Data Protection Officer, Valeria Ciumac-Bodnari, explains how GDPR principles apply in open banking, where responsibilities lie across the ecosystem, and how Salt Edge approaches data protection.
What falls within the scope of protected personal data
A fundamental part of data safety is understanding exactly which data triggers the GDPR strict protections. Under GDPR Article 4, data is only considered personal data if it can be traced back to an identified or identifiable living human being, known as a “data subject”.
In our ecosystem, this person is the “payment service user (PSU)”, referring strictly to an individual consumer connecting their private bank account to a financial application. This framework focuses entirely on natural persons, as corporate and commercial entities are legal structures that fall outside the GDPR scope. However, while corporate entities themselves are not protected as data subjects, business records may still contain personal data relating to identifiable individuals, such as company directors, employees, or sole proprietors.
In the regulatory landscape of Open Banking, it is rarely possible to issue a blanket statement declaring a specific piece of data as universally “personal” or “exempt”. The legal classification under the GDPR is dynamic rather than static, and it depends entirely on the specific circumstances, the operational context, and how data is combined with other direct or indirect identifiers.
While a single number or technical detail might not point to anyone on its own, things change when you start putting those pieces together. If a combination of different details, such as a transfer amount paired with a location or a date, makes it possible to identify a specific person or map out their daily habits, then the combined dataset may constitute personal data under GDPR.

It is important to mention that Salt Edge does not determine which financial data a bank makes available to a PSU. We retrieve only the data exposed by the ASPSP and authorised by the PSU, while any subsequent processing is performed strictly within the agreed contractual scope and applicable regulatory requirements.
We act strictly as a secure, technical bridge connecting three parties:
- The bank: The institution that holds the data subject’s financial records and releases them.
- The app/business: The service data subject wants to use that needs this information to help the individual.
- The data subject: The individual who starts the process and gives explicit consent to connect the two above.
How Open Finance expands the scope of data sharing
Under the standard Open Banking framework (governed by PSD2), the data scope is strictly limited to payment accounts. It typically includes checking accounts, digital wallets, and credit cards. However, the financial landscape is undergoing a major regulatory expansion.
The European Union’s upcoming frameworks–PSD3, the Payment Services Regulation (PSR), and the Financial Data Access (FiDA) framework–are legally pushing the industry forward from Open Banking to Open Finance. Once fully in force, these rules will mandate secure data portability for broader, non-payment financial assets, such as mortgages, personal loans, investment portfolios, stocks, bonds, pension plans, and insurance histories.
While regulatory bodies finalise the implementation timelines for these new rules, Salt Edge already supports parts of this broader ecosystem. We closely align with the direction of upcoming European legislation, proactively developing the necessary technology well in advance. Today, Salt Edge securely integrates Premium/Commercial APIs from participating banks and develops APIs based on the Open Finance API Framework.
This means we are already securely processing not only financial data from payment accounts but also from non-payment accounts. For businesses, this means you do not have to wait to build next-generation Open Finance tools, as Salt Edge already has the functional infrastructure and operational experience required to handle this highly diverse data. For data subjects (PSUs), any financial data shared, regardless of complexity, is safeguarded under the exact same rigorous, GDPR-compliant security and data minimisation protocols established for payment accounts.
GDPR consent and PSD2 permission are not the same thing
One of the most heavily discussed compliance topics in Open Banking is consent. A frequent point of confusion for fintechs stems from the use of the term “explicit consent” in both PSD2 and GDPR, despite carrying entirely different definitions and legal mechanisms.
GDPR consent vs. PSD2 consent
- Under the GDPR, consent is one of six valid legal grounds (Article 6) for processing personal data, requiring a freely given, specific, informed, and unambiguous indication of choice.
- Under PSD2, “explicit consent” acts as a contractual requirement. When an individual enters into an agreement with an AISP or PISP, they must be fully informed of the specific data categories required for the service and must explicitly accept those contractual terms.
From a data protection standpoint, the primary legal basis for standard Open Banking services is typically contractual necessity (Article 6(1)(b) GDPR), rather than GDPR-style consent. To eliminate this semantic confusion entirely, the European Commission’s updated Payment Services Regulation (PSR) proposal formally replaces the word “consent” with “permission” within payment services regulations. The change is welcomed since the “permission” will act as the regulatory gatekeeper to open the API doors. Another “Lawful basis” will remain the GDPR engine that will govern what to do with the data next.
What happens to financial data after a user connects their account?
A business cannot legally process data without a GDPR basis, nor can a payment system fetch it without PSD2 permission, leaving end-users trapped in a loop of confusing checkboxes.
To address this structural gap and ensure full compliance, Salt Edge developed a widget for collecting relevant consents and an End-User Dashboard that serves as a centralised hub for managing permissions.
The Dashboard lists every active financial connection a PSU has authorised. Users can view the precise categories of data accessed, see which specific business is using it, and, crucially, revoke their permission at any moment with a single click, instantly and permanently severing the API link.
This setup resolves the conflict by keeping the end-user in complete control of their GDPR rights while giving businesses a clean, fully compliant mechanism to manage active PSD2 access permissions.
Technical security & governance: Salt Edge perspective
Financial data is deeply personal. A single security flaw can expose everyday users to immediate risks like payment fraud or identity theft. Salt Edge eliminates these high-stakes risks by building a system where security is baked directly into our code, rather than added as an afterthought.
- For our business clients, this means you can launch innovative financial tools immediately, without the heavy burden of managing and maintaining complex security infrastructure yourself.
- For data subjects, it means your financial data is protected through multiple technical and organisational controls, completely isolated from prying eyes, and accessible only within the permissions and legal basis established for the service.
Salt Edge uses a multi-layered security setup to protect the information. The moment an end-user connects their bank account, the system converts that connection into an encrypted digital token using industry-standard 2048-bit RSA encryption keys. Even in the unlikely event of a network interception, the data remains encrypted and unusable without the appropriate key.
Salt Edge’s internal controls, day-to-day operations, and data privacy habits are constantly verified and backed by an active, third-party-audited SOC 2 Type II report alongside our ISO 27001 certification. This continuous testing means our digital defences are always sharp and ready to block both internal and external threats.
We build privacy into our platforms from day one. For businesses that integrate our pre-built dashboards or payment widgets, “privacy by default” means that any optional data-sharing checkboxes, marketing toggles, or tracking tools are turned off out of the box. End-users must actively opt in before optional data sharing is enabled.
Enforcing rights: Empowering users and safeguarding businesses
The ultimate goal of the GDPR is to give data subjects absolute ownership over their digital footprint.

Salt Edge does not view data subject rights as a bureaucratic hurdle. We’ve implemented strict internal policies and operational processes that enable data subjects to exercise their rights effectively, safely, and rapidly at any time, without disrupting business continuity, while fully supporting and ensuring our clients’ compliance with the GDPR.
Profiling and automated decisions: Where Open Banking meets high legal risks
Open Banking data can support a wide range of financial decisions. Today, many financial apps use it to automatically evaluate a user’s financial life, whether for credit scoring, loan approvals, fraud checks, or customer profiling. However, using algorithms or AI to make these calls triggers some of the strictest rules under Article 22 of the GDPR, because automated decisions can have a significant impact on a person’s life.
The risks and legal obligations under GDPR
When a financial app handles data this way, significant compliance risks emerge. The GDPR mandates strict safeguards to protect users from unfair algorithmic treatment:
- The risk of “black box” decisions: If an app uses automated processing to deny someone a credit card or a loan, it cannot be a total mystery. The provider must be completely transparent and provide meaningful information about the basic logic involved, as well as the significance and envisioned consequences of the processing (Articles 13(2)(f) and 14(2)(g) GDPR).
- The right to know and object: Even if a decision isn’t fully automated, users have the right to request information from the data controller about whether profiling is taking place (Article 15 GDPR) and a clear right to object to such profiling (Article 21 GDPR).
- The right to human intervention: If an algorithmic decision produces legal effects or similarly significantly affects a user (such as an automatic loan refusal), the user has the explicit right to demand human intervention (Article 22(2) GDPR). They cannot be left trapped in a purely automated loop.
- The right to contest: If an algorithm denies an application or incorrectly flags a user, that user has the explicit right to voice their point of view and formally challenge the automated decision (Article 22(2) GDPR).
Because these high-stakes risks exist across the fintech ecosystem, Salt Edge has taken a clear approach and does not use open banking data to make automated decisions about individuals, such as approving or rejecting credit applications, determining creditworthiness, or making other decisions that produce legal or similarly significant effects on a person. Where Salt Edge provides data enrichment, analytics, or insights capabilities, these tools are designed to support business clients in their own decision-making processes and remain subject to the client’s governance, regulatory obligations, and applicable data protection laws.
Trust as a core asset
Data protection has become a competitive factor businesses consider when choosing financial technology providers. By shifting the heavy regulatory and technical compliance burden onto Salt Edge, businesses can navigate the transition to Open Finance and innovate with absolute peace of mind, knowing they are fully backed by industry-standard SOC 2 Type II auditing and rigorous data filtering. Concurrently, payment service users can confidently engage with modern fintech tools, secure in the knowledge that their sensitive financial data is entirely under their own control.




