Skip to Content

Effective Date: August 2024

Mastercard OB Services UK Limited (“MCOBS UK”, “us” or “we”) provides 'account information services' ("AIS" or "Data") and payment initiation services ("PIS" or "Pay") referred to collectively as “Open Banking Solutions”. This Open Banking Privacy Notice (“Notice”) describes how MCOBS UK processes Personal Information in connection with our Open Banking Solutions in the UK.

This Privacy Notice describes our processing of Personal Information as a data controller for our Open Banking Solutions:

  • Account Information Services (AIS) or “Data”: Our Data AIS product allows you to retrieve, view and store information from your payment accounts and to share that information with third party service providers.
  • Payment Initiation Services (PIS) or “Pay”: Our Pay PIS product allows you to initiate online payments directly from your bank account to a payee merchant.

We engage Mastercard OB Services Europe A/S (MCOBS EU), a Mastercard group company, to provide services which enable us to deliver our AIS and PIS, and work with MCOBS EUin connection with the delivery of our Open Banking Solutions. We therefore share your Personal Information with MCOBS EU for the purposes set out in this Notice. For more information about our engagement of MCOBS EU, please see section 3 below.

This Privacy Notice does not cover the processing of Personal Information in connection with our Spiir product. Please consult the MCOBS UK Privacy Notice (Spiir) for more information.

This Privacy Notice also does not cover the processing of Personal Information when we act under the instructions of our customers (i.e. as a “data processor”). Examples include data processing on behalf of providers such as banks using our Data product and with whom you share your account information; and merchants that you pay using our Pay product. Please refer to the relevant provider or merchant's privacy notices for more information regarding the processing of your Personal Information.

 

 

1. Personal Information We May Collect

For the purpose of this Notice, “Personal Information” means any information relating to an identified or identifiable individual. We collect the following types of Personal Information:

  • Personal and/or Business Contact Information and Credentials.
  • User Open Banking Hub Profile Information.
  • Financial Information.
  • Authorisations.
  • Request Information.
  • Transaction Information.
  • Device-related Information.
  • Financial Crime Prevention Information.
  • General Communication Information.
  • Logs of your use of the Open Banking Solutions.

MCOBS UK Data

In connection with the provision of our AIS Open Banking Solutions, we obtain Personal Information relating to you from the various sources described below.

    a. Personal Information Provided by You

  • Personal and/or Business Contact Information and Credentials, being: name, user ID, email address and phone number.
  • User Open Banking Hub Profile Information, being: email address;, and depending on the Open Banking Solution, any other information that you add to your profile, such as name and bank account detail.
  • Authorisations that you grant us to manage your Personal Information in specific ways (e.g., to access, retrieve and display your financial information or transaction information through our Open Banking Solutions, to update your profile based on recent transactions or to transfer financial information to third party service providers of your choice).
  • General Communication Information which we may receive when you contact us (e.g. via email, phone, or online web forms), such as your first and last name, phone number, email address, physical address, as well as any other content that you provide. If you do not provide such information, we may not be able to answer your requests or queries.

    b. Personal Information provided by third parties

  • Financial Information, being: information relating to a bank account that is enrolled in one of the Open Banking Solutions (e.g., account name or reference, unique account reference ID, balance, and transactions), refund account details (account number, sort code and financial institution servicing the refund account), payment receipts, payment card details and billing address.
  • Transaction Information, being: your account provider and account number, date / time of payment, payment recipient and data needed for communication with your account provider, information about disputed transactions, financial crime related information (e.g., failed logins).

    c. Personal Information automatically obtained from your interaction with the Open Banking Solutions

  • Device-related Information, being: information which we obtain by automated means such as cookies, web beacons, and embedded scripts. This may include information from a web browser (such as browser type and browser language), an IP address, device identifier numbers, and the actions taken on a website (such as how a visitor interacts with the web pages and the links clicked, mouse location and keystroke timing). For detailed information about the use of cookies and similar technologies, please see the cookie notices and consent tools that are provided in our Open Banking Solutions.
  • Logs of your use of the Open Banking Solutions, which comprise information on which profile is logged into or whether it concerns a one-time user, the IP address used, the time and date, which action has been performed and device information i.e. information on operating system, browser information and settings. Further, whenever a third party service accesses the Open Banking Solutions, a similar log is created.

MCOBS UK Pay

In connection with the provision of our PIS Open Banking Solutions, we obtain Personal Information relating to you from the various sources described below.

    a. Personal Information Provided by You

  • Personal and/or Business Contact Information and Credentials, being: name, user ID, email address and phone number.
  • Authorisations that you grant us to manage your Personal Information (e.g., to transfer financial information to third party service providers of your choice).
  • Information relating to your account(s) such as bank account numbers and bank card details.
  • General Communication Information which we may receive when you contact us (e.g., via email, phone, or online web forms), such as your first and last name, phone number, email address, physical address, as well as any other content that you provide. If you do not provide such information, we may not be able to answer your requests or queries.

    b. Personal Information provided by third parties

  • Financial Information, being: information relating to a bank account that is enrolled in one of the Open Banking Solutions (e.g., account name or reference, unique account reference ID), refund account details (account number, sort code and financial institution servicing the refund account), payment receipts, payment card details and billing address.
  • Request Information, being: payment initiation service requests, request reference number, and response status.
  • Transaction Information, being: your account provider and account number, date/time of payment, payment recipient and data needed for communication with your account provider, information about disputed transactions, financial crime-related information (e.g., failed logins).

    c. Personal Information automatically obtained from your interaction with the Open Banking Solutions

  • Device-related Information, being: information which we obtain by automated means such as cookies, web beacons, and embedded scripts. This may include information from a web browser (such as browser type and browser language), an IP address, device identifier numbers, and the actions taken on a website (such as how a visitor interacts with the web pages and the links clicked, mouse location and keystroke timing). For detailed information about the use of cookies and similar technologies, please see the cookie notices and consent tools that are provided in our Open Banking Solutions.
  • Financial Crime Prevention Information that we need to collect when you use the Open Banking Solutions to initiate payments (e.g., to comply with anti-money laundering legislation). This includes account holder name, address, and date of birth, account number, sort code; and name, address, and date of birth of the beneficial owners, senior management, or authorised signatories, including copies of documents, if necessary, as well as device-related information and logs of your use of the Open Banking Solutions.
  • Logs of your use of the Open Banking Solutions, which comprise information on which profile is logged into or whether it concerns a one-time user, the IP address used, the time and date, which action has been performed and device information, i.e., information on operating system, browser information and settings. Further, whenever a third party service accesses the Open Banking Solutions, a similar log is created. We also monitor payments initiations for anomalies such as unusually high frequency of failed initiations, unusually high frequency of successful initiations, unusually high value of initiated payments or if payments are initiated from an unusual geographical location.

View summary

2. How We May Use Your Personal Information

We May Use Your Personal Information to:

  • Provide our Open Banking Solutions and related services.
  • Diagnose, troubleshoot, and fix issues with the Open Banking Solutions, including customer support and quality control.
  • Monitor and understand IT performance.
  • Market, promote and advertise our Open Banking Solutions.
  • Enforce compliance with our terms (e.g., helping to resolve disputes about Open Banking transactions), comply with legal obligations, and to establish, exercise, or defend against legal claims.
  • Generate aggregated or anonymised statistics for internal business purposes.
  • Monitor, detect and investigate possible financial crime.
  • Manage our customer, vendor, and partner relationships.

Where required under applicable law, we will only use your Personal Information as necessary to provide you with our Open Banking Solutions; with your consent; to comply with a legal obligation; or when there is a legitimate and overriding interest that necessitates the use. We have carried out balancing tests for the data processing based on this basis to ensure that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms.

We may use Personal Information we obtain about you for the purposes set out below. We will only process your Personal Information when we have a legal basis for the processing as identified in the table below.

    Processing purposes

Legal basis

Categories of Personal Information

    Provide and operate our Open Banking Solutions and related services.

    This includes creating and managing your profile, enabling the sharing of your Financial Information with third parties on your instruction, and remembering your Credentials and preferred settings within the Open Banking Solutions.

    For Pay, it also includes facilitating direct and account-to-account payments from your linked payment account.

    For Data, it includes providing you with a consolidated view of your various bank accounts (including spending and income) and enabling spending categorisation.

    We rely on the “performance of a contract” legal ground to provide our Open Banking Solutions to you.

  • Personal and/or Business Contact Information and Credentials.
  • User Profile Information.
  • Financial Information.
  • Authorisations.
  • Request Information.

    Troubleshoot our Open Banking Solutions and provide customer support.

    This includes our ticketing system where you contact us for assistance when you are experiencing a technical issue as well as analysis to ensure quality control.

    We rely on the “performance of a contract” legal ground to provide these services to you.

    Where required under applicable laws, we obtain your prior consent to access Financial Information and Transaction Information for these purposes.

  • User Profile Information.
  • Financial Information.
  • Authorisations.
  • TPP Request Information.
  • Transaction Information.
  • Logs of your use of the Open Banking Solutions.
  • Device-related Information.

    Monitor and understand IT performance.

    We rely on the "performance of a contract" legal ground for stability, improvement and ensuring the integrity of our Solutions.

  • Logs of your use of the Open Banking Solutions.
  • Device-related Information.

    Market, promote and advertise our Open Banking Solutions.

    We have a legitimate interest in promoting our business.

    Where required under applicable laws, we will obtain your prior consent to send you electronic direct marketing communications.

  • User Profile Information.
  • Personal and/or Business Contact Information and Credentials.

    Comply with legal obligations, and to establish, exercise, or defend against legal claims.

    Compliance with a legal obligation (e.g., to respond to law enforcement requests).

    We, or a third party, have a legitimate interest in protecting against legal claims.

  • Personal and/or Business Contact Information and Credentials.
  • User Profile Information.
  • Financial Information.
  • Authorisations.
  • TPP Request Information.
  • Transaction Information.
  • Device-related Information.
  • Financial Crime Prevention Information.
  • General Communication Information.
  • Logs of your use of the Open Banking Solutions.

    Generate anonymised and/or aggregated statistics for internal business purposes.

    This includes analysing the performance of and improving upon our Open Banking Solutions and preparing insights regarding spending patterns, financial crime, and other trends.

    We have a legitimate interest in anonymising Personal Information and analysing it for internal business purposes.

    Where required under applicable law, we obtain your prior consent to process your Financial Information and Transaction Information for this purpose.

  • User Profile Information.
  • Financial Information.
  • TPP Request Information.
  • Transaction Information.
  • Device-related Information.

    Detect, investigate, and prevent possible financial crime.

    This includes tracking and hindering any possible illegal activities and abuse of our Open Banking Solutions.

    We have a legitimate interest in detecting, investigating, and preventing financial crime, such as illegal activities or abuse of our Open Banking Solutions, or we must do so to comply with legal obligations (e.g., under anti-money laundering laws).

  • Device-related Information.
  • Financial crime Prevention Information.
  • General Communication Information.
  • Logs of your use of the Open Banking Solutions.

    To manage our customer and vendor relationships.

    We rely on the "performance of a contract" legal ground to manage our customer and vendor relationships and operate our Open Banking Solutions.

  • Personal and/or Business Contact Information and Credentials.

View summary

3. How We Share Your Personal Information

We may share Personal Information with the following third parties:

  • Financial institutions, business customers, partners, and service providers acting on our behalf.
  • Public authorities.
  • Potential transactional partners.
  • Mastercard’s affiliates, and other entities within Mastercard’s group of companies.

We may disclose Personal Information we collect about you to the following third parties, for the purposes described below:

    a. Other permitted users

You may allow other users to access and view your Personal Information in the Open Banking Solutions. This applies to our Data services only. If you choose to do this, you agree that MCOBS UK, in order to comply with this agreement with you, will disclose your Personal Information to the person who you have allowed access. You can revoke this access at any time in the Open Banking Solutions’ settings.

    b. Mastercard Group

We share the Personal Information we collect with Mastercard’s affiliates and other entities within the Mastercard group of companies, for the purposes described in this Notice. Please see the “Data Transfers” section below to understand how we comply with applicable cross-border data transfer rules.

MCOBS EU is part of the Mastercard group. We work with MCOBS EU to provide services which enable us to deliver our account information services (Data) and payment initiation services (Pay). We therefore share your Personal Information with MCOBS EU which is a Controller for this purpose. If you have any questions regarding the services of MCOBS EU, please contact us.

    c. Financial institutions, business customers, partners and service providers acting on our behalf

For the purpose of providing our Open Banking Services, we also share the Personal Information we collect with financial institutions, business customers (where you permit us to do so) and partners. For Pay, this can mean disclosing Transaction Information to a third party provider to enable the payment transaction. For Data, this means sharing your Personal Information with your Bank. Additionally, we use service providers acting on our behalf, such as hosting and infrastructure providers; and providers for monitoring, security, and IT support services.

    d. Public authorities

YIn some circumstances we share the Personal Information we collect with public authorities. This includes (i) if we are required to do so by law or legal process, (ii) in response to a request from a court, law enforcement authorities, or government officials, or (iii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity.

    e. Potential transactional partners

We may share the Personal Information we collect with potential transactional partners or other third parties in the event of a sale or transfer of our business or assets.

View summary

4. Your Rights and Choices

You have the right or choice to:

  • Opt out of some collection or uses of your Personal Information, including the use of cookies and similar technologies, the use of your Personal Information for marketing purposes, and the anonymisation of your Personal Information for data analyses.
  • Access your Personal Information, obtain a copy of it, rectify it, restrict or object to its processing, or request its deletion, destruction or anonymisation.
  • Receive the Personal Information you provided us with to transmit to another company.
  • Withdraw any consent provided.
  • Where applicable, lodge a complaint with your supervisory authority.

You can exercise your rights by submitting a request as described in the 'How to Contact Us' section below.

You have certain rights regarding the Personal Information we maintain about you and certain choices about what Personal Information we collect from you, how we use it, and how we communicate with you.

In some instances, we may not be able to provide you with the service that you request if you choose to exercise certain rights.

You can choose:

  • Not to provide Personal Information to MCOBS UK by refraining from conducting payment transactions using Pay, obtaining and sharing payment account information using Data or from submitting Personal Information directly to us. When we collect Personal Information from you, we indicate whether and why it is necessary to provide it to us, as well as the consequences of failing to do so. If you do not provide Personal Information, you may not be able to benefit from the MCOBS UK services if that information is necessary to provide you with them, or if we are legally required to collect it in relation to the provision of such service. Please note that Personal Information shared with your service provider prior to removal of your authorisation may still be retained and processed by them; for further information, please refer to their privacy notice.
  • To opt out of the collection and use of certain information, which we collect about you by automated means, when you visit our websites or use our apps. You can exercise your choice regarding the use of cookies and similar technologies by clicking on the “Manage cookies” banner displayed in the bottom right corner of MCOBS UK websites. Your browser may tell you how to be notified of and opt out of having certain types of cookies placed on your device. Note that without certain cookies you may not be able to use all the features of our websites, apps or online services.
  • To opt out of certain uses of information, which we collect about you by automated means when you visit third party websites and interact with our ads. We may use service providers to serve ads on those third-party websites. These ads may be customised and served based on the use of data we and our partners have collected on our websites and apps. In addition, some of our service providers and partners may collect information about your online activities over time and across third party websites to customise and serve these ads. MCOBS UK ads are sometimes delivered with icons that help consumers (i) learn more about how their data is being used and (ii) exercise choices they may have regarding the use of their data. Please click, where applicable, on the icon in our targeted ads to learn about your ability to opt out or limit the use of your browsing behaviour for advertising purposes. You may also exercise your choice regarding the use of cookies and similar technologies by clicking on the “Manage cookies” banner displayed in the bottom right corner of our websites.
  • To tell us not to send you marketing emails by clicking on the unsubscribe link within the marketing emails you receive from us or by contacting us as indicated below.
  • To opt out of the anonymisation of your Personal Information to perform data analyses by clicking https://www.mastercard.co.uk/en-gb/vision/terms-of-use/commitment-to-privacy/privacy/data-analytics-opt-out.html.

You have the right to:

  • Request access to and receive information about the Personal Information we maintain about you, to update and correct inaccuracies in your Personal Information, to restrict or to object to the processing of your Personal Information, to have the information anonymised destroyed or deleted, as appropriate, or to exercise your right to data portability to easily transfer your Personal Information to another company. In addition, you may also have the right to lodge a complaint with a supervisory authority, including in your country of residence, place of work or where an incident took place.
  • Withdraw any consent you previously provided to us regarding the processing of your Personal Information, at any time and free of charge. We will apply your preferences going forward and this will not affect the lawfulness of the processing before your consent withdrawal.

To update your preferences, ask us to remove your information from our mailing lists or submit a request to exercise your rights, contact us as specified in the "How To Contact Us” section below.

If we fall short of your expectations in processing your Personal Information or you wish to make a complaint about our privacy practices, please tell us because it gives us an opportunity to fix the problem. To assist us in responding to your request, please give full details of the issue. We attempt to review and respond to all complaints within a reasonable time and as required under applicable law.

View summary

5. Children’s Privacy

The Services are not intended for use by children under the age of 16 years old. We do not knowingly collect information from children under the age of 16.

Our Services are not directed to, or intended for, children under the age of 16. If you learn that a child has provided us with Personal Information in violation of this Notice, please alert us using the contact details below.

View summary

6. Data Transfers

We may transfer your Personal Information to third parties situated in other countries which may not have the same data protection laws as the country in which you initially provided the information, but we will protect your Personal Information in accordance with this Notice, or as otherwise disclosed to you.

We comply with applicable legal requirements when transferring Personal Information to countries other than the country where you are located.

UK data protection law specifies that all countries within the European Economic Area (EEA) are regarded as providing an adequate level of data protection. If personal data is transferred to a country outside the UK or EEA, the privacy protections afforded by the destination country and/or the recipients of the data are assessed to ensure that sufficient safeguards are in place.

MCOBS UK is part of the Mastercard group, which is a global business. We may transfer the Personal Information we collect about you to third party recipients which are situated in countries other than your country. These countries may not have the same data protection laws as the country in which you initially provided the information. When we transfer your Personal Information to other countries, we will protect that information as described in this Privacy Notice, as disclosed to you at the time of data collection or as described in our programme-specific privacy notice.

Regulations under section 17A of the UK’s Data Protection Act 2018 specify that all countries within the EEA are regarded as providing an adequate level of data protection. A list of EEA member countries can be found on the UK Government website here. If personal data are transferred to a country outside the UK or EEA, the adequacy of that country and the organisations and systems processing the data are assessed to ensure appropriate safeguards are in place. This is in accordance with UK data protection law and may be by an adequacy decision issued by the UK Government, Binding Corporate Rules, standard contractual clauses, standard data transfer agreements or other transfer mechanisms as permitted by law. We have established and implemented Binding Corporate Rules (“BCRs”) that have been recognised by the UK Information Commissioner’s Office as providing an adequate level of protection to the Personal Information we process globally. A copy of our UK BCRs is available here, and which apply to our transfers to MCOBS EU . We equally rely on EEA BCRs to transfer Personal Information outside of the EEA. A copy of our EEA BCRs is available here.

You may contact us as specified in the “How To Contact Us” section below to obtain a copy of the safeguards we use to transfer Personal Information outside of your jurisdiction.

View summary

7. How We Protect Your Personal Information

We maintain appropriate security safeguards to protect your Personal Information and only retain it for a limited period of time.

The security of your Personal Information is important to MCOBS UK. We are committed to protecting the information we collect. We maintain reasonable administrative, technical and physical safeguards designed to protect the Personal Information you provide or we collect against accidental, unlawful or unauthorised destruction, loss, alteration, access, disclosure or use. We use SSL encryption on a number of our websites from which we transfer certain Personal Information.

We also take measures to delete your Personal Information or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it, unless we are required by law to keep this information for a longer period. When determining the retention period, we take into account various criteria, such as the type of products and services requested by or provided to you, the nature and length of our relationship with you, possible re-enrolment with our products or services, the impact on the services we provide to you if we delete some information from or about you, mandatory retention periods provided by law and the statute of limitations.

View summary

8. Features and Links to Other Websites

Our websites may include links to other third party websites, social media tools, widgets or plug-ins, permitting sharing web content including IP address, with third parties and social media providers. These social media providers may learn of your visit even if you are not logged in to your social media account or if you do not have an account with them. To the extent any linked websites or features you visit or use are not owned or controlled by MCOBS UK, please review their own privacy notices or policies.

Our websites may provide links to other websites for your convenience and information. Our website may also contain certain features for which we partner with other entities. These entities may learn of your visit regardless of whether you use these features. These websites and features, which may include social networking and geo-location tools, operate independently from MCOBS UK, and are clearly identified as such. To the extent any linked websites or features you visit or use are not owned or controlled by MCOBS UK, please review the privacy practices of the websites.

You may also choose to use certain features on our websites that can be accessed through, or for which we partner with, other entities that are not otherwise affiliated with MCOBS UK. These features, including geo-location tools, are operated by third parties and are clearly identified as such. Social media providers such as Facebook and Twitter, and these other third parties, are independent from MCOBS UK and do not necessarily share the same policy as MCOBS UK regarding the protection of privacy. Please verify their privacy notices if you decide to use their services and consult your social media account settings if you want to deactivate certain features.

View summary

9. How to Contact Us and Additional Information About Out Practices

The entity responsible for the processing of your Personal Information (or data controller) is Mastercard OB Services UK Limited. You may contact our global privacy office at privacyanddataprotection@mastercard.com, or write to us at:

Mastercard OB Services UK Limited
1 Angel Lane
EC4R 3AB
London, UK

Some MCOBS UK Open Banking Solutions have their specific privacy notices, such as Spiir. Please consult them for more information.

View summary