Do GDPR and PSD2 contradict each other?

To comply to both regulations and satisfy their customers, companies need a granular view of their customer data and use this data according to their customers’ needs.
Since GDPR came into force, businesses are still making mistakes and learning to navigate the EU regulatory waters. PSD2 asks banks to openly share consumer data with their consent, while GDPR requires that consumer data remains private and secure. How can businesses possibly juggle the two seemingly contradictory regulations?
Ultimately, this remains a data issue and relates to how well companies can visualise and use their data. To comply to both regulations and satisfy their customers, companies need a granular view of their customer data and use this data according to their customers’ needs. However, how can businesses accomplish that without a complete IT overhaul with potentially disastrous results?
Not as easy as it seems for Financial Services organisations
Financial Services organisations will need to be able to easily access, share and protect data - a challenge indeed! FinTech competition will not miss the opportunity the new regulations present to punish the old guard and poach the customers from the unprepared organisations.
Sharing customer data with third parties, as directed by PSD2, is a great idea but difficult to carry out for banks. Banks are challenged by legacy systems, operating in silos and current IT practices, which do not facilitate data management. EU GDPR only adds further complexity to data management processes because banks have to know the source of every single bit of data they hold in their systems.
In addition, the right to erasure (article 17 of GDPR) means enterprises are required to have a good handle on customer data in order to be able to delete specific information on request. The right to data portability (article 20 of GDPR) presents the challenge for businesses to move, copy or transfer data easily from one database, storage or IT environment to another.
All Financial Services organisations will need to be able to access and analyse the data of any transaction at any time. As part of regulatory audits, banks will need to be able to summon up specific customer data very quickly and they will have to understand what that data means in the broader context of their payment history.
Data protection and privacy will be particularly difficult for unprepared companies ahead of GDPR. At worse, it could mean an overhaul of the entire IT system. Businesses will have to detect and report data breaches within 72 hours once the breach is found to avoid being fined. This could mean working on weekends for some banks if they detect the breach on a Friday.
These challenges will require some help from technology. Banks and other Financial Services organisations will have to demonstrate true digitalisation. These organisations need to provide context-specific offers to the customer, which is helped further by Open Banking, as they will be able to track data from other banks catering to the customer.
However, this type of opportunity will only be seized by organisations capable of customer-centricity and building their own marketplace economy.
Looking beyond rules towards customer-centricity
Should they want to thrive, banks cannot have a narrow view and see regulations as checkpoints to be ticked off in order to be compliant, neglecting the wider picture.
GDPR and PSD2 do not contradict themselves; they both have the exact same objective. Both regulations want to push organisations towards customer-centricity in order for business to adapt to faster to the digital age and the rise of the platform economy. In the post-GDPR era, efficient data management will be critical in order to provide services as close as possible to their customers’ need.
This requires a system or platform flexible enough to dissect very specific data that is within the scope of client consent, while restricting conditional elements from being shared. This granular level of data management would truly push them toward customer-centricity.
This is crucial, as going beyond simple compliance and handling customer data with efficiency and transparency will go a long way to rebuild customer trust. The benefits of GDPR can be seized when financial organisations can convince not only regulators, but also customers, that their data is in a safe pair of hands. A greater understanding of who the customer is, what the product is and the price point will require better management of tangible and intangible data in order to better meet expectations in a post-GDPR world.
Reviewing data management processes to make them more efficient can directly lead to enhanced customer loyalty, which will come about by creating better deals for customers through the use of all the data held by a bank. This data can help create unique revenue models and pricing solutions adapted to the customer’s needs and spending patterns. These value-added services are sure to generate increased customer satisfaction.
Concerning the data security element of GDPR, organisations need to go beyond simply applying a turnkey cyber security solution. Businesses will need to keep internal records of data protection and show regulators and customers alike what has been done to keep their data safe. An audit log of public, private and personal APIs being accessed will need to be kept in order to keep track of any access to customer data.
The multiplication of RegTech solutions might seem like good news for businesses looking to avoid fines and immediate consequences of non-compliance. However, it often presents a short-term solution to a long-term, more nuanced problem. Banks need to manage their data in a way that puts customers at the centre.
Being customer centric enables these organisations to reap the benefits this year’s new regulations entail.
The benefits of being customer-centricity:
-
Reputational benefits: it will ensure customers their data is well-protected and showing transparency when dealing with customer data will increase trust. Avoiding brand image disasters like Equifax and becoming an example of a company making an effort and caring about the duties that comes with the custody of data could lead to immense reputational benefits.
-
Financial benefits: being customer-centric will improve customer retention and attract new customers. Knowing and tending to the needs of your customers will increase trust and customer satisfaction: while competitors are poorly managing their data and offering customers irrelevant offers, having the reputation of being an efficient, insightful business can bring immediate financial benefits.
-
Preparation for an increasingly customer-centric economy: digital transformation is leading businesses toward an increasingly customer-centric economy. GDPR is an attempt to regulate this wave of change and make sure some businesses are not left behind. Preempting the intent of GDPR and being customer-centric ahead of the curve through impeccable data management could give businesses a competitive edge.
While GDPR and PSD2 may seem to be contradictory in their requirements, they are in fact complementary, as both regulations guide high street banks, new banks and Financial Services organisations alike toward a much needed acceleration of their digital transformation process by placing the customer in the centre.
Source: itproportal

Latest Jobs
-
- CIAM Architect Azure B2C
- N/A
- N/A
-
We are seeking a highly skilled and experienced Azure B2C CIAM Architect for a contract starting on Jan 2024. As an Azure B2C CIAM Architect, you will be responsible for designing, implementing, and deploying an new Azure B2C Solution . Responsibilities: Design and implement an Azure B2C-based CIAM solution that meets the needs of our clients organization. Maintain and support the Azure B2C-based CIAM solution. Provide training and support to our employees on the use of the CIAM solution. Background designing, implementing, and maintaining CIAM solutions. Experience with cloud-based identity and access management (IAM) solutions. Experience with OAuth, OpenID Connect,and SAML. Excellent written and verbal communication skills
-
- Senior IAM Consultant
- Germany
- Upto €110,000 depending on level of position
-
Senior IAM Consultant is needed to help lead and deploy IAM Projects for this expand IAM Consultancy The ideal candidate will have a deep understanding of IAM concepts and technologies, as well as experience in deploying and managing complex IAM solutions. Responsibilities Lead the deployment of IAM solutions for our clients Work with clients to understand their IAM requirements and design solutions that meet their needs Configure and implement IAM solutions using best practices Integrate IAM solutions with other enterprise systems Provide training and support to clients on the use of IAM solutions Stay up-to-date on the latest IAM technologies and trends We are looking for an experieneced IAM Consutlatn with: Strong understanding of IAM concepts and technologies,including identity lifecycle management,access control,and authentication Experience in deploying and managing complex IAM solutions Experience with IAM products and solutions,such as SailPoint,One Identity Manager,and Azure Active Directory Excellent communication and interpersonal skills Ability to work independently and as part of a team Fluent in German Candidates witll need to live and have the right to work within Germany to be considered.
-
- Security Architect - SOC Design - Outside IR35 London. SC / DV cleared
- London
- Outside IR35
-
Security Architect - With in-depth SOC Design experience needed for Outside IR35 London. SC / DV cleared. 6 month rolling Immediate Experience delivering technical Security Architecture design / assurance of security design with mobile network experience. HLD / LLD Current SC Clearance a must. Willingness to undertake DV. London 3 days a week Immediately interviewing.
-
- Cyber Security Risk Consultant. UK. Hybrid. Home | Work balance
- United Kingdom
- N/A
-
Cyber Security Consultancy - done the right way. Seeking a passionate Cyber Security Risk Consultant who enjoys helping clients make a different to their business. Warning- if you want a large, slow moving, high politics, high travel security consultancy that demands their a pound of flesh this is NOT for you. A successful individual will have experience working with clients to identify business cyber security risk. This is a remote first opportunity which means you will spend the majority of your time working remotely. You will however spend some time meeting clients as well as meeting up with the team on a monthly basis.. Some of the nice to have certifications. CRISC, ISO27001 Lead implementer, CISA, CISM, CISSP Along with dedicated training budgets, unlimited holiday and a structured career path, this opportunity will give a much needed work life balance. Unable to offer Visa sponsorship now or in the future. Apply and book a call in my diary with the below