The parameters around how consumer financial information should be shared with third-party apps and platforms was the subject of debate at an industry forum organized by the Consumer Financial Protection Bureau in Washington, D.C., on Wednesday.
While data aggregators and bankers participating in the forum agreed on the principle that consumers should have the right to consent to share their data with third-party platforms through aggregators, and know how their account information is being used, participants disagreed on implementation.
The core of the conversation focused on the viability of “screen scraping,” a practice whereby a third-party app, through aggregators, logs into a banking application as if it were the customer, ‘scrapes’ their financial data and pastes it into their own platform. The method has been critiqued for its security vulnerabilities.
Despite moves toward more secure forms of credential sharing, there was acknowledgement that the practice is still widespread. To bankers participating in the panel, screen scraping is dangerous and ought to be replaced by API-based data access, along the lines of recent agreements Wells Fargo and JPMorgan Chase have signed with various data aggregators.
“We need to see the end date [to screen scraping],” said Natalie Talpas, senior vice president and product group manager for digital at PNC Bank. “Screen scraping enables all of the data to be collected that a customer would access because they’re having to turn over their user ID and password to these financial applications to collect information today, and we have a lot of concerns with that.”
The risks of screen scraping include the possibility data could be shared beyond aggregators in various platforms’ quest to create unique customer experiences.
To ensure clarity of expectations between banks and third parties, PNC pointed to the The Clearing House‘s Model Agreement, which sets forth parameters for data sharing between banks and third parties. Aggregators, however, counter that the Model Agreement restricts consumer choices by giving banks the ability to block third-party apps.
“The risk is that, if every player is independently deciding which app is okay for their customers to use, they may override consumers already making the [choice],” said John Pitts, policy lead at Plaid.
See also: Plaid, Kabbage: Clearing House Model Agreement creates ‘uneven playing field’
Meanwhile, aggregator Finicity highlighted the ongoing work of banks and aggregators to determine standards for API-based data access through the Financial Data Exchange. Nick Thomas, Finicity’s co-founder and chief technology officer, argued that credential sharing is the riskiest part of screen scraping, one the ecosystem should work to eliminate.
“Screen scraping is not evil; it’s actually authentication, authorization and data access,” Thomas said. “The use of credentials is something that we really want to get away from and move to tokenized access, a near term future where you’ve fixed the problem of authentication and authorization, but maybe screen scraping is the only way to actually get the data; that’s not a bad place.”
Capital One however, highlighted concerns it had with what it called a dangerous practice.
“With the proliferation of the number of aggregators and fintechs, people are starting to wake up to the fact that this is happening, [and] they have no control over what’s being taken,” said Becky Heironimus, managing vice president of customer platforms at Capital One. “Mistakes are made, and that is full access to your account.”
Heironimus noted that sensitive data, particularly account numbers and personally-identifiable information, should be closely safeguarded by institutions in data-sharing efforts, and may merit additional consent when necessary.
While banks may want to impose additional controls, ostensibly to protect customer data, data security and continued innovation should happen in lock step and not at cross purposes, Thomas expressed.
“Hiding all the information so that that can’t be seen in the ecosystem or used the way that it’s used today, it actually creates a dangerous, dangerous tipping point,” Thomas said. “All kinds of innovation has happened because of the availability of that account number and routing number. The idea that that information shouldn’t be shared, or it shouldn’t be tokenized, I think introduces additional innovation risk.”
Banking Automation Summit, which takes place from June 1-2 in Miami, is a unique opportunity to share insights, trends, strategies and best practices on back-office automation in financial services with the industry’s leading practitioners. Register here.






