Security with bank connectors: what does PSD2 mean for your data?
Sharing your banking data with a third party feels nerve-racking. But is that justified? Read which security standards PSD2 requires and what you should watch out for.
"Do I have to share my bank details with a third party?" It's a question we hear often. And that's understandable. Transaction data and balances are sensitive, often confidential business information. The idea of an external company looking in feels uncomfortable, even when you know it's safe.
That's why we wrote this article. No vague promises, but a clear overview of how PSD2 protects your data, what a bank connector provider is and isn't allowed to do, and what you should watch out for yourself.
PSD2: security as a foundation
PSD2 is not just a technical standard for bank data, it is also a security framework. The European legislator made security a starting point, not an afterthought.
PSD2 security rests on three pillars:
Strong Customer Authentication (SCA). Every authorisation requires at least two authentication factors. Something you know (PIN code), something you have (phone) and something you are (fingerprint). The same security your bank uses for online banking.
Explicit consent. No third party gets access without you actively giving permission through your own banking environment. You see exactly which accounts you share and for what purpose.
Read-only access. An AISP (Account Information Service Provider) may only view transactions. It cannot make payments, open accounts or view connected banking products.
What is a provider allowed and not allowed to do?
A certified bank connector provider such as iWebDevelopment operates within strict boundaries. In concrete terms, it comes down to this:
What is allowed:
- Retrieving transaction data (date, amount, counterparty account, description)
- Requesting account information (account number, balance)
- Forwarding data to your accounting
What is not allowed:
- Making or initiating payments
- Storing or requesting login details
- Sharing data with third parties without consent
- Retrieving more data than needed for the service
- Keeping access after consent is withdrawn
A provider that operates outside these boundaries loses its licence. The Netherlands Authority for the Financial Markets (AFM) and De Nederlandsche Bank (DNB) actively supervise this.
Verification of Payee
Since 2025, Verification of Payee (VoP) has become mandatory in the EU under the Instant Payment Regulation. This is a name-IBAN check: before a payment is executed, the bank checks whether the recipient's name matches the IBAN number.
What does this mean for bank connectors? Directly, not much. VoP is about payments, not about reading transactions. But indirectly it strengthens trust in the entire ecosystem. Fraud with false IBAN numbers becomes harder. And every security layer that makes banking traffic more reliable also makes sharing transaction data safer.
Data minimisation
PSD2 applies the principle of data minimisation. A provider may only request the data that is strictly necessary for the service. For a bank connector to your accounting, that means transaction data, nothing more.
Only the transaction and balance data of the connected accounts can be retrieved, not that of other products linked to these accounts. So no information about an investment portfolio or mortgage details. No company or personal data is retrieved either beyond what is necessary to identify transactions.
At iWebDevelopment we apply this principle consistently. We only request transaction data and forward it to your accounting package. We do not store financial data on our servers. After transmission the data is not retained.
ISO 27001 certification
ISO 27001 is the international standard for information security. The certificate covers not only technical measures, but also processes, organisation and risk management.
We are ISO 27001 certified. That means:
- Annual external audits by an independent certification body
- Documented information security policy
- Risk assessment and treatment
- Incident response procedures
- Access control and authorisation management
- Encryption of data in transit and at rest
In addition, we have our infrastructure independently pentested. Not because we have to, but because we want to know where any weak spots are before someone else finds them.
PSD3: the bar is raised
The European Union is working on PSD3, the successor to PSD2. A political agreement was reached in November 2025. PSD3 regulation is expected to be adopted in Q3 this year and to take effect in 2028.
The most important security improvements:
Data parity: Banks must offer the same quality and availability through their APIs as through their own channels. No more stripped-down or delayed APIs. This directly improves the reliability of bank connectors.
Stricter enforcement: National supervisors gain more powers. Banks that neglect their APIs or make access difficult can be dealt with more effectively.
FIDA (Financial Data Access): The Open Banking principle is extended to other financial products: insurance, pensions, investments. With the same security standards as PSD2.
Anti-fraud measures: New obligations around spoofing prevention and social engineering. Banks and providers gain a shared responsibility to prevent fraud.
We believe PSD3 is a positive development for everyone who works with bank connectors. Every tightening of the standards makes the ecosystem more reliable.
Practical security checklist for choosing a provider
Despite uniform regulation, not all providers offer the same services and security level. Use this checklist when choosing a provider that meets your standard:
Licence and registration: Is the provider (or its aggregator) registered as an AISP with a European supervisor? Check the register of the AFM or the relevant national authority.
Certification: ISO 27001 is the minimum standard. Also ask about SOC 2 Type II or comparable audits.
Pentesting: Does the provider carry out independent pentests? Ask about the frequency and whether results are available.
Data storage: Where is your data stored? Are transactions kept on the provider's servers, or only passed through to your accounting? Less storage means less risk.
Encryption: TLS 1.2 or higher for data in transit. AES-256 or comparable for data at rest.
Consent management: Can you see through your bank which parties have access? Can you withdraw consent directly? A good provider makes this transparent.
Incident response: Does the provider have a documented process for security incidents? How quickly are you informed of a data breach?
Sub-processors: Does the provider use aggregators or other third parties? If so, do they fall under the same security standards?
What you can do yourself
Security is a shared responsibility. Besides choosing a reliable provider, you can do the following yourself:
Check your authorisations regularly: Log in at your bank and see which parties have access to your account. Do you not recognise a party? Withdraw the consent.
Renew consent consciously: PSD2 requires you to grant consent again every 90 days. Do not see this as a burden, but as a security moment. It forces you to think about which connectors you actively use.
Use strong authentication: Make sure your banking app is up to date and that your SCA methods (fingerprint, face ID, SMS code) are active.
Report anomalies: Do you see transactions you do not recognise in your bank connector? Report it to your provider and your bank. Acting quickly limits any damage.
In summary
Bank connectors via PSD2 are safer than all their old predecessors. No shared passwords, screen scraping or downloads with uncontrolled data access. Instead, you get EU-wide uniform, regulated and encrypted access to your confidential transaction data.
That does not mean you should be any less critical in your choice of provider. The presence of certification, the way data is stored and transparency about this make the difference. We invest continuously in security because we know that trust is the basis of everything we do.
From 7.50 euros per month we offer a bank connector, ISO 27001 certified and without financial data storage on our servers. The connector is operational within a few minutes.
Do you want to try it yourself? View our bank connector →