PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Access to Bank Data by Fintechs May Be Coming under Greater Restrictions

By Tim Sloane
February 26, 2020
in Analysts Coverage, APIs, Emerging Payments, Fintech
0
0
SHARES
0
VIEWS
Share on LinkedIn
APIs Payments Industry access controls

The Importance of APIs in the Payments Industry

As open banking and fintech services have expanded, the way financial data is shared has become a critical issue for banks, technology providers, and consumers. For years, many fintech applications relied on screen scraping to access customer account information, allowing budgeting apps, personal finance tools, and digital wealth management platforms to gather data directly from online banking portals. While effective, this approach often provided broad access to customer information and raised concerns about privacy, security, and data governance.

These concerns have accelerated the shift toward API access control, which allows financial institutions to grant consumers more precise control over what information is shared and with whom. JPMorgan’s move to phase out screen scraping in favor of API-based data sharing reflects a broader industry effort to strengthen data protection while supporting innovation in financial services. By limiting access to only the information explicitly authorized by consumers, APIs offer a more secure and transparent framework for managing financial data.

Screen scraping is the process of extracting data from a website that is not intended to be accessed or parsed by automated means. It is often used to bank data, such as account balances and transactions, from websites that do not provide an API or other means of automated access. Screen scraping can be performed manually, by writing code to parse the relevant data from the HTML source of a web page, or it can be performed using a screen scraper, a tool that automates the process of extracting data from web pages. How can we protect data with access control technology?

The other day, The Clearing House and 11 banks invested in access protection firm Akoya. Now, JPMorgan tells Fintechs they have until the end of July to wean themselves off of screen scraping and move to a more restricted access control technology implemented in APIs.

In the past, screen scrapers, once permissioned by the user, could poke around and collect a wealth of data on an individual perhaps unassociated with what that individual gave permission for, such as other accounts and their balances. It is expected the API will prevent such meandering:

“The deadline is the latest move in the bank’s effort to transition fintechs and data aggregators to what it has said is a more secure way of accessing customer data.

Fintech startups, such as those that offer budgeting apps or digital wealth management, usually connect to a user’s bank account to gather the necessary data to provide their services. Some gather the data through aggregators such as Yodlee and Plaid, which is in the process of being acquired by Visa Inc (V.N), while others request that customers provide their password.

Through JPMorgan’s new method, fintechs will not be able to use customers’ passwords to access their entire financial data, but will instead connect to a set of bank programming code known as an API, that grants access only to limited account information authorized by the consumer.

The transition comes as large banks and fintech companies globally tussle over data-sharing. Banks have said their wariness to grant access to third parties stems from a need to protect highly sensitive information, such as transaction history and income.

Fintechs have been skeptical, arguing that it should be up to consumers, not banks, to decide what companies can look at that information.

JPMorgan said earlier this year that it was preparing to crack down on the use of customer passwords for data-sharing purposes, and had been discussing another method to access information since 2016.

However, some startups said they were surprised by the stringent requirements and strict deadline in the letter, according to one fintech source.

“We’ve been working on this with aggregators and fintechs since 2016 because our secure API is the best way to help our customers make smart money decisions more easily and safely,” Paul LaRusso, managing director of digital platforms at Chase, said in a written statement to Reuters.

The bank said companies that have agreed to JPM’s terms would be able to continue accessing customer data using existing tools, provided they have a concrete plan in place to move to the new method and are making progress toward that goal.”

The transition from screen scraping to API access control represents an important evolution in financial data sharing. While screen scraping enabled many fintech innovations, it also created security and privacy challenges by granting broader access than was often necessary. API-based solutions help address these concerns by providing controlled, permission-based access to consumer data.

As banks, fintechs, and data aggregators continue to modernize their data-sharing frameworks, access control technology will play a central role in balancing innovation with security. The future of open banking will increasingly depend on secure APIs that protect consumer information while still enabling the digital financial services that customers expect.

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: APIAPI enablementData ManagementFintechsJPMorgan ChaseScreen ScrapingSecurityTechnologyThe Clearing House

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    real-time payment fraud prevention

    How Innovation Is Transforming Payment Fraud Prevention

    August 13, 2026
    phygital payments

    Why People Still Want Physical Things in a Digital World

    August 12, 2026
    AI debt collection, Apple Pay transaction growth

    How AI Makes Collections More Human—and More Effective

    August 11, 2026
    FedNow Service

    The Use Cases Propelling the FedNow® Service’s Growth—and Shaping Its Future

    August 10, 2026
    merchant debit fee

    Culture Clash: How Banks Are Adapting to Embedded AI Experts

    August 7, 2026
    programmatic payments

    The Rise of Programmatic Payments and the New Compliance Challenge

    August 6, 2026
    stablecoin compliance

    The Death of the Payment Router: Why “Compliance as an OS” is the Only Way Forward for 2026

    August 5, 2026
    payment choice

    Why Payment Choice Still Matters in a Digital-First Economy

    August 4, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result