Third Party Providers (TPP)
Third Party Providers (TPP)
Author
Discussion

eldar

Original Poster:

25,291 posts

226 months

Tuesday 7th November 2017
quotequote all
My bank has just emailed me, saying my account will change to allow TPPs to contact me and ask for pretty full access to my bank account.

Who are TPPs and just why would I want to allow them access? My inbuilt paranoia says this has potential for a multitude of scams, as it appears I won't have the option of saying 'don't even ask.'

Anyone shed any light on this ?

Mr Pointy

13,400 posts

189 months

Tuesday 7th November 2017
quotequote all

eldar

Original Poster:

25,291 posts

226 months

Tuesday 7th November 2017
quotequote all
Mr Pointy said:
Ah, thanks for the pointer, appreciated.

Mr Pointy

13,400 posts

189 months

Tuesday 7th November 2017
quotequote all
eldar said:
Ah, thanks for the pointer, appreciated.
You're welcome & I agree with you. No-one else seems to think it's a problem.

craigjm

21,495 posts

230 months

Wednesday 8th November 2017
quotequote all
You will only see more of this as banks get ready for the onset of the EU General Data Protection Regulation that launches in May 2018. There will be a lot of focus on consent to use data, on conditions for processing and on data privacy notices. In essence If the bank collects your data it can use it in relation to the reason why it collected it. So you apply for a mortgage it can use it to process the application as it would be necessary for contract. What it can’t then do without your consent for instance is to use that data to try and sell you insurance. Banks share data with third parties all the time. Think about if you buy an insurance product from the bank it’s likely to be actually a Aviva product so they would have to share the data. What you are seeing is the pre-collection of consent for them to use your data in such a way. With GDPR you can remove this consent at any time and even ask to be forgotten unless the collection of data was under the condition for processing of necessary for contract or legal obligation in which case they can refuse to forget you. That means you can’t take out a mortgage and then write to them and demand to be forgotten to avoid paying hehe

eldar

Original Poster:

25,291 posts

226 months

Wednesday 8th November 2017
quotequote all
craigjm said:
You will only see more of this as banks get ready for the onset of the EU General Data Protection Regulation that launches in May 2018. There will be a lot of focus on consent to use data, on conditions for processing and on data privacy notices. In essence If the bank collects your data it can use it in relation to the reason why it collected it. So you apply for a mortgage it can use it to process the application as it would be necessary for contract. What it can’t then do without your consent for instance is to use that data to try and sell you insurance. Banks share data with third parties all the time. Think about if you buy an insurance product from the bank it’s likely to be actually a Aviva product so they would have to share the data. What you are seeing is the pre-collection of consent for them to use your data in such a way. With GDPR you can remove this consent at any time and even ask to be forgotten unless the collection of data was under the condition for processing of necessary for contract or legal obligation in which case they can refuse to forget you. That means you can’t take out a mortgage and then write to them and demand to be forgotten to avoid paying hehe
How will the ability to switch accounts, or close one and open another effect things?

Do they really need the ability of take money/set up direct debits etc?

Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?

craigjm

21,495 posts

230 months

Wednesday 8th November 2017
quotequote all
eldar said:
How will the ability to switch accounts, or close one and open another effect things?

Do they really need the ability of take money/set up direct debits etc?

Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?
They will ask for your consent every time they do something like set up a new account and close an old one etc.

Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.

eldar

Original Poster:

25,291 posts

226 months

Wednesday 8th November 2017
quotequote all
craigjm said:
They will ask for your consent every time they do something like set up a new account and close an old one etc.

Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
Sounds reasonable, put like thatsmile I'll fold my tin foil hat up and put it away.

Not sure how it will bring benefits to the customer, sounds more like more data collection for the big corporations, who never, ever lose control of that data...

Mr Pointy

13,400 posts

189 months

Wednesday 8th November 2017
quotequote all
craigjm said:
eldar said:
How will the ability to switch accounts, or close one and open another effect things?

Do they really need the ability of take money/set up direct debits etc?

Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?
They will ask for your consent every time they do something like set up a new account and close an old one etc.

Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
I don't believe that is correct. Open banking is about enabling third parties (like Aviva) to have control over my account: they can transfer funds in & out for instance. Barclays specifically say that they are not responsible for the actions of Third Parties & that they are not responsible for correcting any errors made. If it happens it's up to the account holder to sort it out with the Third Party. This is a huge change from the current situation.

craigjm

21,495 posts

230 months

Wednesday 8th November 2017
quotequote all
Mr Pointy said:
I don't believe that is correct. Open banking is about enabling third parties (like Aviva) to have control over my account: they can transfer funds in & out for instance. Barclays specifically say that they are not responsible for the actions of Third Parties & that they are not responsible for correcting any errors made. If it happens it's up to the account holder to sort it out with the Third Party. This is a huge change from the current situation.
Note I said operate with you as if they were the bank.

hyphen

26,262 posts

120 months

Wednesday 8th November 2017
quotequote all
craigjm said:
They will ask for your consent every time they do something like set up a new account and close an old one etc.

Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
Will the hackers ask for my consent too?

Edited by hyphen on Wednesday 8th November 18:52

craigjm

21,495 posts

230 months

Wednesday 8th November 2017
quotequote all
hyphen said:
Will the hackers ask for my consent too?

Edited by hyphen on Wednesday 8th November 18:52
That’s the whole point of GDPR though isn’t it? It’s about ensuring that companies (not just banks) have sufficient safeguards in place against that and, should a leak happen, know immediately who has been impacted and remediate that impact. If they are not able to do that then the fines are massive and rightly so.

Mr Pointy

13,400 posts

189 months

Tuesday 14th November 2017
quotequote all
craigjm said:
Mr Pointy said:
I don't believe that is correct. Open banking is about enabling third parties (like Aviva) to have control over my account: they can transfer funds in & out for instance. Barclays specifically say that they are not responsible for the actions of Third Parties & that they are not responsible for correcting any errors made. If it happens it's up to the account holder to sort it out with the Third Party. This is a huge change from the current situation.
Note I said operate with you as if they were the bank.
Well what you actually said was:

craigjm said:
(edited quote) Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway.
I don't believe this is correct given the information I have from Barclays. The exact wording is (referring to TPPs):

"You should check they are genuine and can be trusted before you share anything as we are not responsible if something goes wrong"