Mastercard OB Services UK Limited (“MCOBS UK”, “us” or “we”) provides 'account information services' ("AIS" or "Data") and payment initiation services ("PIS" or "Pay") referred to collectively as “Open Banking Solutions”. This Open Banking Privacy Notice (“Notice”) describes how MCOBS UK processes Personal Information in connection with our Open Banking Solutions in the UK.
This Privacy Notice describes our processing of Personal Information as a data controller for our Open Banking Solutions:
We engage Mastercard OB Services Europe A/S (MCOBS EU), a Mastercard group company, to provide services which enable us to deliver our AIS and PIS, and work with MCOBS EUin connection with the delivery of our Open Banking Solutions. We therefore share your Personal Information with MCOBS EU for the purposes set out in this Notice. For more information about our engagement of MCOBS EU, please see section 3 below.
This Privacy Notice does not cover the processing of Personal Information in connection with our Spiir product. Please consult the MCOBS UK Privacy Notice (Spiir) for more information.
This Privacy Notice also does not cover the processing of Personal Information when we act under the instructions of our customers (i.e. as a “data processor”). Examples include data processing on behalf of providers such as banks using our Data product and with whom you share your account information; and merchants that you pay using our Pay product. Please refer to the relevant provider or merchant's privacy notices for more information regarding the processing of your Personal Information.
For the purpose of this Notice, “Personal Information” means any information relating to an identified or identifiable individual. We collect the following types of Personal Information:
MCOBS UK Data
In connection with the provision of our AIS Open Banking Solutions, we obtain Personal Information relating to you from the various sources described below.
a. Personal Information Provided by You
b. Personal Information provided by third parties
c. Personal Information automatically obtained from your interaction with the Open Banking Solutions
MCOBS UK Pay
In connection with the provision of our PIS Open Banking Solutions, we obtain Personal Information relating to you from the various sources described below.
a. Personal Information Provided by You
b. Personal Information provided by third parties
c. Personal Information automatically obtained from your interaction with the Open Banking Solutions
We May Use Your Personal Information to:
Where required under applicable law, we will only use your Personal Information as necessary to provide you with our Open Banking Solutions; with your consent; to comply with a legal obligation; or when there is a legitimate and overriding interest that necessitates the use. We have carried out balancing tests for the data processing based on this basis to ensure that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms.
We may use Personal Information we obtain about you for the purposes set out below. We will only process your Personal Information when we have a legal basis for the processing as identified in the table below.
|
|
|
Provide and operate our Open Banking Solutions and related services. This includes creating and managing your profile, enabling the sharing of your Financial Information with third parties on your instruction, and remembering your Credentials and preferred settings within the Open Banking Solutions. For Pay, it also includes facilitating direct and account-to-account payments from your linked payment account. For Data, it includes providing you with a consolidated view of your various bank accounts (including spending and income) and enabling spending categorisation. |
We rely on the “performance of a contract” legal ground to provide our Open Banking Solutions to you. |
|
Troubleshoot our Open Banking Solutions and provide customer support. This includes our ticketing system where you contact us for assistance when you are experiencing a technical issue as well as analysis to ensure quality control. |
We rely on the “performance of a contract” legal ground to provide these services to you. Where required under applicable laws, we obtain your prior consent to access Financial Information and Transaction Information for these purposes. |
|
Monitor and understand IT performance. |
We rely on the "performance of a contract" legal ground for stability, improvement and ensuring the integrity of our Solutions. |
|
Market, promote and advertise our Open Banking Solutions. |
We have a legitimate interest in promoting our business. Where required under applicable laws, we will obtain your prior consent to send you electronic direct marketing communications. |
|
Comply with legal obligations, and to establish, exercise, or defend against legal claims. |
Compliance with a legal obligation (e.g., to respond to law enforcement requests). We, or a third party, have a legitimate interest in protecting against legal claims. |
|
Generate anonymised and/or aggregated statistics for internal business purposes. This includes analysing the performance of and improving upon our Open Banking Solutions and preparing insights regarding spending patterns, financial crime, and other trends. |
We have a legitimate interest in anonymising Personal Information and analysing it for internal business purposes. Where required under applicable law, we obtain your prior consent to process your Financial Information and Transaction Information for this purpose. |
|
Detect, investigate, and prevent possible financial crime. This includes tracking and hindering any possible illegal activities and abuse of our Open Banking Solutions. |
We have a legitimate interest in detecting, investigating, and preventing financial crime, such as illegal activities or abuse of our Open Banking Solutions, or we must do so to comply with legal obligations (e.g., under anti-money laundering laws). |
|
To manage our customer and vendor relationships. |
We rely on the "performance of a contract" legal ground to manage our customer and vendor relationships and operate our Open Banking Solutions. |
|
We may share Personal Information with the following third parties:
You have the right or choice to:
You can exercise your rights by submitting a request as described in the 'How to Contact Us' section below.
You have certain rights regarding the Personal Information we maintain about you and certain choices about what Personal Information we collect from you, how we use it, and how we communicate with you.
In some instances, we may not be able to provide you with the service that you request if you choose to exercise certain rights.
You can choose:
You have the right to:
To update your preferences, ask us to remove your information from our mailing lists or submit a request to exercise your rights, contact us as specified in the "How To Contact Us” section below.
If we fall short of your expectations in processing your Personal Information or you wish to make a complaint about our privacy practices, please tell us because it gives us an opportunity to fix the problem. To assist us in responding to your request, please give full details of the issue. We attempt to review and respond to all complaints within a reasonable time and as required under applicable law.
The Services are not intended for use by children under the age of 16 years old. We do not knowingly collect information from children under the age of 16.
Our Services are not directed to, or intended for, children under the age of 16. If you learn that a child has provided us with Personal Information in violation of this Notice, please alert us using the contact details below.
We may transfer your Personal Information to third parties situated in other countries which may not have the same data protection laws as the country in which you initially provided the information, but we will protect your Personal Information in accordance with this Notice, or as otherwise disclosed to you.
We comply with applicable legal requirements when transferring Personal Information to countries other than the country where you are located.
UK data protection law specifies that all countries within the European Economic Area (EEA) are regarded as providing an adequate level of data protection. If personal data is transferred to a country outside the UK or EEA, the privacy protections afforded by the destination country and/or the recipients of the data are assessed to ensure that sufficient safeguards are in place.
MCOBS UK is part of the Mastercard group, which is a global business. We may transfer the Personal Information we collect about you to third party recipients which are situated in countries other than your country. These countries may not have the same data protection laws as the country in which you initially provided the information. When we transfer your Personal Information to other countries, we will protect that information as described in this Privacy Notice, as disclosed to you at the time of data collection or as described in our programme-specific privacy notice.
Regulations under section 17A of the UK’s Data Protection Act 2018 specify that all countries within the EEA are regarded as providing an adequate level of data protection. A list of EEA member countries can be found on the UK Government website here. If personal data are transferred to a country outside the UK or EEA, the adequacy of that country and the organisations and systems processing the data are assessed to ensure appropriate safeguards are in place. This is in accordance with UK data protection law and may be by an adequacy decision issued by the UK Government, Binding Corporate Rules, standard contractual clauses, standard data transfer agreements or other transfer mechanisms as permitted by law. We have established and implemented Binding Corporate Rules (“BCRs”) that have been recognised by the UK Information Commissioner’s Office as providing an adequate level of protection to the Personal Information we process globally. A copy of our UK BCRs is available here, and which apply to our transfers to MCOBS EU . We equally rely on EEA BCRs to transfer Personal Information outside of the EEA. A copy of our EEA BCRs is available here.
You may contact us as specified in the “How To Contact Us” section below to obtain a copy of the safeguards we use to transfer Personal Information outside of your jurisdiction.
We maintain appropriate security safeguards to protect your Personal Information and only retain it for a limited period of time.
The security of your Personal Information is important to MCOBS UK. We are committed to protecting the information we collect. We maintain reasonable administrative, technical and physical safeguards designed to protect the Personal Information you provide or we collect against accidental, unlawful or unauthorised destruction, loss, alteration, access, disclosure or use. We use SSL encryption on a number of our websites from which we transfer certain Personal Information.
We also take measures to delete your Personal Information or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the type of products and services requested by or provided to you, the nature and length of our relationship with you, possible re-enrolment with our products or services, the impact on the services we provide to you if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations.
Our websites may include links to other third party websites, social media tools, widgets or plug-ins, permitting sharing web content including IP address, with third parties and social media providers. These social media providers may learn of your visit even if you are not logged in to your social media account or if you do not have an account with them. To the extent any linked websites or features you visit or use are not owned or controlled by MCOBS UK, please review their own privacy notices or policies.
Our websites may provide links to other websites for your convenience and information. Our website may also contain certain features for which we partner with other entities. These entities may learn of your visit regardless of whether you use these features. These websites and features, which may include social networking and geo-location tools, operate independently from MCOBS UK, and are clearly identified as such. To the extent any linked websites or features you visit or use are not owned or controlled by MCOBS UK, please review the privacy practices of the websites.
You may also choose to use certain features on our websites that can be accessed through, or for which we partner with, other entities that are not otherwise affiliated with MCOBS UK. These features, including geo-location tools, are operated by third parties and are clearly identified as such. Social media providers such as Facebook and Twitter, and these other third parties, are independent from MCOBS UK and do not necessarily share the same policy as MCOBS UK regarding the protection of privacy. Please verify their privacy notices if you decide to use their services and consult your social media account settings if you want to deactivate certain features.
The entity responsible for the processing of your Personal Information (or data controller) is Mastercard OB Services UK Limited. You may contact our global privacy office at privacyanddataprotection@mastercard.com, or write to us at:
Mastercard OB Services UK Limited
1 Angel Lane
EC4R 3AB
London, UK
Some MCOBS UK Open Banking Solutions have their specific privacy notices, such as Spiir. Please consult them for more information.