Third Party Providers (TPP)
Discussion
My bank has just emailed me, saying my account will change to allow TPPs to contact me and ask for pretty full access to my bank account.
Who are TPPs and just why would I want to allow them access? My inbuilt paranoia says this has potential for a multitude of scams, as it appears I won't have the option of saying 'don't even ask.'
Anyone shed any light on this ?
Who are TPPs and just why would I want to allow them access? My inbuilt paranoia says this has potential for a multitude of scams, as it appears I won't have the option of saying 'don't even ask.'
Anyone shed any light on this ?
Mr Pointy said:
Ah, thanks for the pointer, appreciated.You will only see more of this as banks get ready for the onset of the EU General Data Protection Regulation that launches in May 2018. There will be a lot of focus on consent to use data, on conditions for processing and on data privacy notices. In essence If the bank collects your data it can use it in relation to the reason why it collected it. So you apply for a mortgage it can use it to process the application as it would be necessary for contract. What it can’t then do without your consent for instance is to use that data to try and sell you insurance. Banks share data with third parties all the time. Think about if you buy an insurance product from the bank it’s likely to be actually a Aviva product so they would have to share the data. What you are seeing is the pre-collection of consent for them to use your data in such a way. With GDPR you can remove this consent at any time and even ask to be forgotten unless the collection of data was under the condition for processing of necessary for contract or legal obligation in which case they can refuse to forget you. That means you can’t take out a mortgage and then write to them and demand to be forgotten to avoid paying 

craigjm said:
You will only see more of this as banks get ready for the onset of the EU General Data Protection Regulation that launches in May 2018. There will be a lot of focus on consent to use data, on conditions for processing and on data privacy notices. In essence If the bank collects your data it can use it in relation to the reason why it collected it. So you apply for a mortgage it can use it to process the application as it would be necessary for contract. What it can’t then do without your consent for instance is to use that data to try and sell you insurance. Banks share data with third parties all the time. Think about if you buy an insurance product from the bank it’s likely to be actually a Aviva product so they would have to share the data. What you are seeing is the pre-collection of consent for them to use your data in such a way. With GDPR you can remove this consent at any time and even ask to be forgotten unless the collection of data was under the condition for processing of necessary for contract or legal obligation in which case they can refuse to forget you. That means you can’t take out a mortgage and then write to them and demand to be forgotten to avoid paying 
How will the ability to switch accounts, or close one and open another effect things?
Do they really need the ability of take money/set up direct debits etc?
Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?
eldar said:
How will the ability to switch accounts, or close one and open another effect things?
Do they really need the ability of take money/set up direct debits etc?
Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?
They will ask for your consent every time they do something like set up a new account and close an old one etc.Do they really need the ability of take money/set up direct debits etc?
Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?
Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
craigjm said:
They will ask for your consent every time they do something like set up a new account and close an old one etc.
Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
Sounds reasonable, put like thatBanks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
I'll fold my tin foil hat up and put it away.Not sure how it will bring benefits to the customer, sounds more like more data collection for the big corporations, who never, ever lose control of that data...
craigjm said:
eldar said:
How will the ability to switch accounts, or close one and open another effect things?
Do they really need the ability of take money/set up direct debits etc?
Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?
They will ask for your consent every time they do something like set up a new account and close an old one etc.Do they really need the ability of take money/set up direct debits etc?
Who will be responsible if a fraudulent organisation is set up, approved, and vanishes with the money?
Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
Mr Pointy said:
I don't believe that is correct. Open banking is about enabling third parties (like Aviva) to have control over my account: they can transfer funds in & out for instance. Barclays specifically say that they are not responsible for the actions of Third Parties & that they are not responsible for correcting any errors made. If it happens it's up to the account holder to sort it out with the Third Party. This is a huge change from the current situation.
Note I said operate with you as if they were the bank. craigjm said:
They will ask for your consent every time they do something like set up a new account and close an old one etc.
Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
Will the hackers ask for my consent too?Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway. The open banking stuff is about a third party like say Aviva who might be providing insurance on behalf of the bank to be able to contact you and operate with you as a customer as if they were the bank itself to provide a seamless service for you as a customer.
Edited by hyphen on Wednesday 8th November 18:52
hyphen said:
Will the hackers ask for my consent too?
That’s the whole point of GDPR though isn’t it? It’s about ensuring that companies (not just banks) have sufficient safeguards in place against that and, should a leak happen, know immediately who has been impacted and remediate that impact. If they are not able to do that then the fines are massive and rightly so. Edited by hyphen on Wednesday 8th November 18:52
craigjm said:
Mr Pointy said:
I don't believe that is correct. Open banking is about enabling third parties (like Aviva) to have control over my account: they can transfer funds in & out for instance. Barclays specifically say that they are not responsible for the actions of Third Parties & that they are not responsible for correcting any errors made. If it happens it's up to the account holder to sort it out with the Third Party. This is a huge change from the current situation.
Note I said operate with you as if they were the bank. craigjm said:
(edited quote) Banks third party on boarding processes are very stringent and include privacy risk assessments so the chances of them partnering with and fraudulent organisation is non existent but if they did and your money was impacted then it is protected anyway.
I don't believe this is correct given the information I have from Barclays. The exact wording is (referring to TPPs):"You should check they are genuine and can be trusted before you share anything as we are not responsible if something goes wrong"
Gassing Station | Finance | Top of Page | What's New | My Stuff


