GDPR for fintech: handling customer data the right way
By SendPay Business · · 2 min read
The General Data Protection Regulation (GDPR) sets the rules for handling personal data in the EU, and the UK has its own version, UK GDPR, alongside the Data Protection Act 2018. Fintechs handle a lot of sensitive data, so getting this right matters.
Key principles
- Have a lawful reason for each use of personal data.
- Collect only what you need and keep it accurate.
- Keep data only as long as necessary, then delete it.
- Protect it with suitable security and be open with customers about how it's used.
GDPR and KYC work together
Anti-money laundering rules require firms to collect ID and keep records for set periods. GDPR allows this because it's a legal obligation, but the data should only be used for that purpose and kept no longer than the law requires.
Breaches and customer rights
Serious personal data breaches must usually be reported to the regulator within 72 hours, which is the ICO in the UK. Customers can ask to see their data, correct it and, in some cases, have it deleted. Fines for serious failures can reach €20 million or 4% of worldwide annual turnover, whichever is higher, with equivalent sterling limits in the UK.
Where SendPay fits
SendPay lets you launch your own branded platform with GBP, EUR and USD accounts, transfers and branded Visa cards, powered by licensed partners.
Build it
Create your own financial platform.
Pick a template, name it, brand it, preview every page before you pay. Your brand, your users, your fees.
Build my platform →Questions people ask
Read next
This guide is general information, not legal or financial advice. SendPay Business is a technology company, not a bank, and does not take deposits; regulated services on the platforms are provided by licensed partners. PayPal, Patreon and Substack are named as reference points only and are not affiliated with SendPay Business.