For a long time there was a silent rule in banking: your bank was the sole keeper of your financial history. It knew where you shopped, how much you earned, when things got tight — and that information stayed locked inside the institution's walls. If you wanted to share it with another company, the route was to print paper statements. The question almost nobody asked was a simple one: whose data is this, anyway?
Europe answered with a directive. Directive (EU) 2015/2366 — the second Payment Services Directive, or PSD2 — was published to update the regulatory framework for payment services and to promote greater European integration in the field, as the Banco de Portugal explains [2]. Behind the technical language is a shift of principle: your bank data is yours, and you decide who you share it with. This is the story of how that happened — and of what is still changing.
Your bank data is yours: the idea behind PSD2
The European Commission is direct about the aim of PSD2: to make internet payment services easier and safer to use, and to better protect consumers against fraud, abuse and payment problems [1]. Beyond the traditional banks, the directive recognised new categories of payment service provider and opened two doors that did not exist before.
As the Banco de Portugal summarises, the legislation gave users access to two new payment services — Payment Initiation Services (PIS) and Account Information Services (AIS) [2]. The first lets you order a payment directly from your account, with no card in between. The second lets an authorised entity read — only read — your account information and present it to you in an organised way. It is this second service, AIS, that underpins much of what we now call Open Banking.
More data in motion demanded more security to protect it. So PSD2 made Strong Customer Authentication (SCA) mandatory — the two-or-more-factor confirmation you now recognise from the code on your phone or from biometrics. The requirement took effect on 14 September 2019 [1], backed by common technical standards (Commission Delegated Regulation (EU) 2018/389) designed to strengthen consumer protection, foster innovation and improve the security of payment services across the European Union [1].
In Portugal, PSD2 was transposed by Decree-Law no. 91/2018 of 12 November, which, as the Banco de Portugal notes, significantly changes the way payment service providers make their services available and how customers carry out their payment operations [2]. The supervisor is the Banco de Portugal; the framework is common to the whole EU. This is not a no-man's-land — it is one of the most heavily regulated environments in the technology sector.
How many already use Open Banking — and how many still hesitate
Adoption has stopped being a promise. According to Juniper Research, the number of Open Banking users worldwide is set to jump from 183 million in 2025 to more than 645 million in 2029 — growth of over 250% in four years [5]. On the business side, a Mastercard survey with The Harris Poll found 85% of businesses already using Open Banking and 93% expecting the sector's momentum to increase over the next five years [6].
The engine of this growth is, increasingly, its combination with artificial intelligence. As Nick Maynard, VP of Fintech Market Research at Juniper Research, notes: "Lending has embraced AI, but accessing the right data via Open Banking APIs is essential to improving efficiency." [5].
On the consumer side, the habit is already here too: 76% connect financial accounts directly to digital tools to handle their money tasks [6]. But trust is not a given. In the same study, 66% say they trust banks to share their financial data and 56% trust credit-card companies [6] — solid numbers, but far from unanimous.
And some remain wary. According to the GlobalData 2025 Financial Services Consumer Survey, more than a third of consumers stay hesitant about using Open Banking, mainly over privacy and security concerns [8]. The Mastercard report could not be clearer about what is at stake: "For the open banking ecosystem to reach its full potential, consumers need to feel confident that their data is secure […] without trust, customers and businesses will walk away and seek other financial partners." [6].
What comes next: PSD3, PSR and FIDA
PSD2 is not the end of the line. On 28 June 2023, the European Commission put forward proposals to bring payments and the wider financial sector into the digital age [3]: a new directive (PSD3) and a new regulation (PSR) to revise PSD2, plus an entirely new framework for access to financial data — FIDA.
At the time, the European Commissioner for Financial Services, Mairead McGuinness, framed the logic: "In the EU's growing data economy, every interaction in finance creates new data. It is therefore vital that European consumers remain the ones in control of their payments and they decide with whom to share this data so that they can avail of new and innovative products." [3].
The process took a leap on 27 November 2025, when the Council and the European Parliament reached a provisional political agreement on the PSR and PSD3 [4]. The aim, according to the Council, is to better combat payment fraud, increase transparency on fees and strengthen consumer protection [4] — including an anti-fraud framework against spoofing schemes (where fraudsters impersonate your payment provider) and a check that the name and IBAN match before a transfer. In the words of Morten Bødskov, the Danish minister speaking for the Council Presidency: "Today's agreement marks a major step in the fight against payment fraud in the EU. And by enhancing consumer protection, improving transparency, and fostering innovation, we are paving the way for a more secure, efficient, and consumer-friendly payment landscape for all Europeans." [4].
The most ambitious piece is still missing. FIDA (the Framework for Financial Data Access) aims to extend the logic of Open Banking beyond payment accounts — investments, insurance, pensions, credit — with full control for the customer over who accesses their data and for what purposes [7]. Unlike PSD3 and the PSR, which already have political agreement, FIDA remains under negotiation in 2026 [7]. The direction, though, is unmistakable: less friction, more competition and the user in charge.
What this changes in your everyday tools
All this regulatory engineering lands in a very concrete place: the tools you use to look at your money. Before PSD2, a personal finance app relied on manual imports — PDFs, CSV files, data ageing between exports. With Open Banking, it can work with real, up-to-date, complete transactions, with your authorisation and under European supervision.
This is exactly where AtivaMoney connects to your bank. The connection uses European Open Banking (PSD2) through GoCardless, a regulated provider licensed for the purpose. In practice, it works like the "Sign in with Google" you already know — an OAuth-style flow in which you authorise access without ever handing over your credentials. When you connect your bank, three steps happen:
- You choose your bank from the list of available institutions. The connection is brokered by GoCardless, one of the largest Open Banking providers in Europe, regulated to deliver this service.
- You are redirected to your bank's secure environment — not to an AtivaMoney page, but to the institution's official interface. You authenticate there, with SCA, and the bank asks you exactly what you are authorising (for example, reading the last 90 days of transactions).
- The bank issues a read-only access token, shared with GoCardless, which delivers the transactions to AtivaMoney. At no point does AtivaMoney see or store your banking credentials.
Why it is safer than it looks
The hesitation is legitimate — we saw that more than a third of people still feel it [8]. But it is worth looking closely at the facts of the model:
- Your credentials never leave the bank. AtivaMoney never sees your username or your password. What it receives is a read token, with limited scope.
- Access is read-only. The token lets it view transactions, but not initiate payments or touch anything. It is like letting someone see your statement without giving them the keys to the house.
- You can revoke it whenever you want. You withdraw the authorisation in your bank account settings (or within AtivaMoney) and access is cut off immediately, with no password change.
- It is regulated by the European Union. Open Banking providers are licensed and supervised by the financial authorities — in Portugal, under the eye of the Banco de Portugal [2].
Checklist: before you connect your bank
Keep these questions for any finance app you consider — not just AtivaMoney:
- Does the bank connection use a regulated Open Banking provider (PSD2), or does it ask you for your credentials directly? If it asks for credentials, be suspicious.
- Is access read-only, or can it also move money? To aggregate finances, reading is enough.
- Do you authenticate in your bank's own environment, with SCA — and not on a page belonging to the app?
- Can you view and revoke the authorisation at any time?
- Does the app tell you where your data lives and who its subprocessors are? Transparency is halfway to trust.
Open Banking handed you back a simple thing that had gone missing: ownership of your own financial data. European regulation gave you the keys — the right tools help you use them.
References
- European Commission (DG FISMA) — Payment services (PSD2); see also the European Banking Authority (EBA) on the technical standards for strong customer authentication.
- Banco de Portugal — Payment services under the PSD2 (includes the transposition by Decree-Law no. 91/2018 of 12 November).
- European Commission — Modernising payment services and opening financial services data, 28 June 2023 (with the Mairead McGuinness quote).
- Council of the European Union — Payment services: Council and Parliament agree to step up the fight against fraud and increase transparency, 27 November 2025.
- Juniper Research — Open Banking User Numbers to Surge by Over 250% by 2029, 2025.
- Mastercard Europe — Building trust in the age of open banking (Mastercard + The Harris Poll survey), 2025.
- European Commission (DG FISMA) — Framework for Financial Data Access (FIDA).
- Retail Banker International / GlobalData — Open banking: moving from compliance to cashflows (GlobalData 2025 Financial Services Consumer Survey), 2025.