Open Banking allows you to securely share information with third party providers (TPPs), who can then provide you with a range of services, like giving you budgeting tools to help you manage your money.
Account information sharing
By sharing your information securely with a TPP you could do things like connect your accounts and view all of your balances and transactions in a single place. Plus, you could use product comparison sites to check if there’s a more suitable account for your lifestyle.
Sharing your account information securely
TPPs will require your consent to access your M&S Credit Card account details; it's important you understand the services they are providing and how they will use your information.
There are two ways that a TPP could have access to your account information.
1. Application Programming Interface (API) based access: the TPP will ask you for your consent and you will be securely redirected to M&S Bank's online authentication process. This will be similar to the way you sign in to our Internet Banking service. If you're using our Mobile Banking app, you'll simply be able to use your fingerprint or face to authenticate, where available. If you have any problems authenticating, make sure you follow the process with step-by-step on-screen instructions on how to generate the security code.
Once authenticated, you can select the account you want to share. The TPP will ask for your consent for them to access your account information either as a one-off, or for a period of time. Depending on the duration of the consent you provide, they will ask for your consent every 90 days to carry on accessing your data.
2. Screen scraping access: Before a TPP can access your account, they will need to identify themselves to us. TPPs may then access your accounts by signing in using your Internet Banking security credentials. They'll need to request this information from you each time they need to access your information. The TPP will be able to access information in a similar way to when you use Internet Banking. This is commonly known as screen scraping. TPPs are only legally permitted to access screens and information for account that you have given consent to. This includes the account summary, and balance data. All TPPs that access your information must comply with data protection laws and must be registered or authorised with the Financial Conduct Authority (FCA).
If you're concerned about the data you've shared and feel it may have been used incorrectly, get in touch with us or the TPP as soon as possible. You can also cancel any consents within ‘Open Banking connections’ on digital banking.