Security with bank connectors: what does PSD2 mean for your data?

Sharing your banking data with a third party feels nerve-racking. And rightly so. Read which security standards PSD2 requires and what you need to watch out for.

Veiligheid bij PSD2 bankkoppelingen

"Do I have to share my bank details with a third party?" That is the question we hear most often. Understandable. Transaction data and balances are sensitive, often a business secret. And the idea that an external company is looking over your shoulder feels uncomfortable, even when you know it is secure.

That is why we wrote this article. No vague promises, just a clear overview of how PSD2 protects your data, what a bank connector provider may and may not do, and what you should watch out for yourself.

PSD2: security as the foundation

PSD2 is not only a technical standard for bank data. It is a security framework. The European legislator took security as a starting point, not as an afterthought.

The three pillars:

Strong Customer Authentication (SCA). Every authorisation requires at least two authentication factors. Something you know (PIN code), something you have (phone) and something you are (fingerprint). The same security your bank uses for online banking.

Explicit consent. No third party gains access without you actively giving permission through your own banking environment. You see exactly which accounts you share and for what purpose.

Read-only access. An AISP (Account Information Service Provider) may only view transactions. No making payments, no moving money, no opening accounts. Purely reading.

What may a provider do and not do?

This is where it gets concrete. A certified bank connector provider such as iWebDevelopment operates within strict limits.

Allowed:

  • Retrieving transaction data (date, amount, counterparty account, description)
  • Requesting account information (account number, balance)
  • Forwarding data to your accounting

Not allowed:

  • Executing or initiating payments
  • Storing or requesting login credentials
  • Sharing data with third parties without permission
  • Retrieving more data than needed for the service
  • Retaining access after permission is withdrawn

A provider that operates outside these limits loses its licence. The Dutch Authority for the Financial Markets (AFM) and De Nederlandsche Bank (DNB) actively supervise this.

Verification of Payee: extra protection since October 2025

From 2025 onwards, Verification of Payee (VoP) becomes mandatory in the EU under the Instant Payment Regulation. This is a name-IBAN check: before a payment is executed, the bank checks whether the name of the recipient matches the IBAN number.

What does this mean for bank connectors? Directly, not much. VoP is about payments, not about reading transactions. But indirectly it strengthens trust in the entire ecosystem. Fraud with false IBAN numbers becomes harder. And every security layer that makes bank transactions more reliable also makes sharing transaction data safer.

Data minimisation: only what is necessary

PSD2 applies the principle of data minimisation. A provider may only request the data that is strictly necessary for the service. For a bank connector to your accounting, that means transaction data. Nothing more.

No savings account balances. No investment portfolio. No mortgage details. No business or personal data beyond what is necessary to identify transactions.

At iWebDevelopment we apply this principle consistently. We only request transaction data and forward it to your accounting package. We do not store any financial data on our servers. After transfer, the data is not retained.

ISO 27001: more than a logo

ISO 27001 is the international standard for information security. The certificate covers not only technical measures, but also processes, organisation and risk management.

We are ISO 27001 certified. That means:

  • Annual external audits by an independent certification body
  • Documented information security policy
  • Risk assessment and treatment
  • Incident response procedures
  • Access control and authorisation management
  • Encryption of data in transit and at rest

In addition, we have our infrastructure independently pentested. Not because we have to, but because we want to know where any weak spots are before someone else finds them.

PSD3: raising the bar

The European Union is working on PSD3, the successor to PSD2. In November 2025 a political agreement was reached. The expectation is that the PSD3 regulation will be adopted in Q3 this year and will therefore take effect in 2028.

The main security improvements:

Data parity. Banks must offer the same quality and availability through their APIs as through their own channels. No more stripped-down or delayed APIs. This directly improves the reliability of bank connectors.

Stricter enforcement. National supervisors gain more powers. Banks that neglect their APIs or make access difficult can be tackled more effectively.

FIDA, Financial Data Access. The Open Banking principle is extended to other financial products: insurance, pensions, investments. With the same security standards as PSD2.

Anti-fraud measures. New obligations around spoofing prevention and social engineering. Banks and providers gain a shared responsibility to prevent fraud.

We think PSD3 is a positive development for everyone who works with bank connectors. Every tightening of the standards makes the ecosystem more reliable.

Practical security checklist for choosing a provider

Not all providers are equal. Use this checklist when making your choice:

Licence and registration. Is the provider (or its aggregator) registered as an AISP with a European supervisor? Check the register of the AFM or the relevant national authority.

Certification. ISO 27001 is the minimum standard. Also ask about SOC 2 Type II or comparable audits.

Pentesting. Does the provider have independent pentests carried out? Ask about the frequency and whether results are available.

Data storage. Where is your data stored? Are transactions kept on the provider's servers, or only forwarded to your accounting? Less storage means less risk.

Encryption. TLS 1.2 or higher for data in transit. AES-256 or comparable for data at rest. This is non-negotiable.

Consent management. Can you see through your bank which parties have access? Can you withdraw permission directly? A good provider makes this transparent.

Incident response. Does the provider have a documented process for security incidents? How quickly are you informed of a data breach?

Sub-processors. Does the provider use aggregators or other third parties? If so, are they subject to the same security standards?

What you can do yourself

Security is a shared responsibility. Besides choosing a reliable provider, you can do the following yourself:

Check your authorisations regularly. Log in to your bank and review which parties have access to your account. Do you not recognise a party? Withdraw the permission.

Renew consent consciously. PSD2 requires you to give permission again every 90 days. Do not see this as a burden, but as a security moment. It forces you to think about which connectors you actively use.

Use strong authentication. Make sure your banking app is up to date and that your SCA methods (fingerprint, Face ID, SMS code) are active.

Report anomalies. Do you see transactions you do not recognise in your bank connector? Report it to your provider and your bank. Acting quickly limits any damage.

The bottom line

Bank connectors via PSD2 are safer than any predecessor. No shared passwords, no screen scraping, no uncontrolled data access. Instead: EU-regulated, encrypted, explicitly authorised read-only access.

That does not change the fact that you should be critical in your choice of provider. Certification, data storage, transparency. It matters. We invest continuously in security because we know that trust is the foundation of everything we do.

From 7.50 euro per month. ISO 27001 certified. No financial data on our servers. Operational within a day.

Want to try it yourself? View our bank connector →