The Credit QuestionBorrowing, scored and explained

Protection

Revoking Access You Gave To A Financial App

Sharing bank data through an app grants a permission that keeps running until it is withdrawn or expires, and revoking it is done at the bank as well as the app.

Person using a smartphone and credit card for online shopping or payment.
Photograph by Tima Miroshnichenko via Pexels
General information. This is journalism, not personalised financial advice. Figures, rates and rules change and vary by country — check current terms before acting. How we work.

Connecting a bank account to a budgeting, lending or accounting app grants a standing permission to read data. The permission persists after the app stops being useful, and ending it takes a deliberate step.

A connection is a consent with a scope

When an account is linked, the customer authenticates at their bank and approves a defined scope: which accounts, which data, and for how long.

The app then holds a token that lets it retrieve that data without the customer being present. Nothing is stored of the banking password itself in properly built implementations.

Because the token is the access, deleting the app from a phone does not end the connection. The permission continues to sit at the bank.

Consents expire, but not immediately

Access permissions are generally time-limited, with a maximum duration set by local rules, after which the customer must reauthenticate for data sharing to continue.

Those durations differ by market and have been revised as the frameworks have developed, so an old connection may run considerably longer than a new one would.

Expiry is a backstop rather than a control. Between renewals the app can retrieve data at whatever frequency the permission allows.

Revocation happens in two places

Most banks list active data-sharing connections in their app or online service, with an option to withdraw each one. Withdrawing there stops access at source immediately.

Doing it inside the app instead asks the provider to end the connection, which usually works but depends on the provider acting rather than on the bank enforcing it.

Where a connection matters, revoking at the bank is the step that is verifiable, because the bank's list is the record of what can currently be read.

Ending access does not delete history

Data already retrieved remains with the provider, subject to its own retention policy and to any legal obligations it has, such as records supporting a lending decision.

Deletion is therefore a separate request from revocation, and the provider may be entitled to keep some categories regardless of what the customer asks.

Rights to erasure, the exemptions that apply and the mechanism for exercising them differ between jurisdictions, and firms answer according to where they are established.

Onward sharing is the part to check

Some providers act as intermediaries, passing retrieved data to third parties such as lenders or advisers. That onward flow is governed by the consent given at the outset.

Revoking the bank connection stops new data being collected but does not necessarily unwind arrangements with parties who already received it.

Reading what the permission covered, rather than only how to switch it off, is what makes the eventual revocation meaningful.

Questions readers ask

Does a credit freeze stop card fraud?

No. It blocks new applications in your name. Fraud on an existing card or an account takeover is unaffected, and needs account security measures instead.

Do I need to freeze with every agency?

Yes, where a freeze is available. Each agency is separate, and a lender consulting an unfrozen agency will proceed normally.

Protectionfreezesfile locksfraud preventionidentity
Nadine Okoro
Editor, The Credit Question

Nadine edits The Credit Question after nine years assessing consumer lending applications.

Also by Nadine Okoro