To understand whether open banking is secure or not, we first need to delve into the concept of the Application Programming Interface (API), the secure intermediary that facilitates the implementation of open banking.
API, which stands for Application Programming Interface, is a software that acts as a bridge between two applications. Its operation is rooted entirely in security principles. By keeping codes and user information confidential, it allows third-party service providers to utilize the necessary data in another application.
Open Banking and Personal Data Protection
Under the Second Version of the Payment Services Directive (PSD2), which encompasses European Union member countries and sets the boundaries for open banking services, various security measures are stipulated for service providers.
In this context:
-
Service providers are prohibited from accessing user information, such as usernames and passwords, that would allow them to log into the relevant bank's system. They are also mandated to ensure secure communication with all parties.
-
Before providing the service, service providers are obligated to obtain explicit consent from the customer. Just as in Turkish law, customers have the right to withdraw or limit this consent at any time.
-
Payment Initiation Service Providers (PISPs) must inform the customer about each transaction. Account Information Service Providers (AISPs), on the other hand, can only access the information provided to them by the bank. From a responsibility standpoint, PISPs share the obligation with the bank where the customer's account is held to ensure payments are made in full and on time.
To elaborate on the topic from the perspective of AISP (Account Information Service Providers) applications:
The service provider offers customers the ability to access their bank accounts and transactions through various applications. These services are executed in a manner that is compliant with end-to-end regulations and laws between the bank, the service provider, and the customer.
For the integration of online account movements to be realized, the customer provides instructions to the branch customer representatives of the banks they work with to create integration user definitions distinct from internet banking and devoid of "money transfer authority." This user information is directly sent by the bank to the email address specified by the customer in the instruction. The customer or their authorized representative then sets up the relevant definitions through the service provider's application. Notably, the application does not store passwords.
Unless specified by the customer as a user, no one can access the customer's accounts.