Most banks can honestly say they do not sell your data, and the same institution will share it extensively. Both statements fit in the same privacy notice because sharing and selling are separate legal categories, and the distinction is doing a lot of work.
Sharing, selling, and joint marketing
- Selling generally means transferring data for money to an unrelated company. This is what privacy notices deny, usually accurately.
- Affiliate sharing means passing data to companies under the same corporate ownership. Large banking groups contain retail banking, credit cards, insurance, wealth management, and more. In the United States, the Gramm-Leach-Bliley Act permits this, and consumer control over it is narrow.
- Joint marketing agreements allow a bank to share customer data with an unrelated company for jointly offered products. No money changes hands for the data itself, so it is not a sale, and your information still arrives at a company you never chose.
- Service provider transfers move data to processors, fraud vendors, and analytics providers acting on the bank's behalf. This is genuinely necessary for the account to function, and it still multiplies the number of organisations holding the record.
The practical consequence is that asking whether your bank sells your data is the wrong question. Ask how many organisations hold a copy, because that number is what determines your exposure.
The aggregator layer
When you link your bank account to a budgeting app, a payment service, or a lender, the connection usually runs through an intermediary. Plaid, Yodlee, MX, and Finicity dominate this layer.
These companies obtain your transaction history in order to pass it to the app you authorised, and their own retention and secondary use terms are separate from that app's. Yodlee has faced repeated scrutiny from United States legislators over the resale of transaction data derived from these connections.
Two further details matter. Older integrations worked by screen scraping, which required your actual online banking credentials and stored them. And authorisations persist. The app you tried once in 2021 and deleted may still hold a live connection, because deleting an app does not revoke the data access you granted through it.
Card networks and merchant analytics
Your bank sees the accounts it holds. The card networks see activity across every issuer on their network, which is a wider view than any single bank has, and both networks operate data and analytics businesses built on aggregated transaction information sold to merchants and advertisers.
These products are typically aggregated and de-identified. Treat de-identified as a description of intent rather than a guarantee, because transaction data is unusually easy to re-identify. A small number of known purchases, with dates, is often enough to isolate one person in a large dataset.
Government access
Lawful requests are routine and generally arrive without notice to you. Separately, some reporting is automatic and requires no request: large cash transactions generate reports by law, and suspicious activity reports are filed at the bank's discretion under an obligation you are prohibited from being told about.
The opt outs that actually exist
- United States. The annual GLBA privacy notice lists the sharing categories and which of them you can limit. Sharing with non-affiliated third parties for marketing generally carries an opt out. Limiting affiliate sharing for marketing purposes comes through the Fair Credit Reporting Act. Both usually require you to act, and neither is retroactive.
- California and similar state laws. The CCPA and CPRA create rights to opt out of sale and sharing, with one large caveat. Data covered by GLBA is exempt, which excludes most of what your bank holds. The rights are more useful against fintech apps than against banks.
- EU and UK. GDPR gives you access to the data held about you, the right to object to processing for direct marketing, and the right to erasure in defined circumstances. Access requests are the most powerful of these in practice, because you cannot contest what you have not seen.
- Everywhere. Revoking aggregator connections works immediately and does not depend on your jurisdiction. It is the highest impact action available to most people.
A realistic sequence
- Review connected apps in your bank's settings and revoke everything you do not currently use.
- Check my.plaid.com for connections established through Plaid and remove the dormant ones.
- Find this year's privacy notice and exercise every opt out it offers. Most take a few minutes and stay in effect.
- Submit an access request if you are in the EU or UK, since it tells you which of the layers above actually applies to you.
- Delete dormant fintech accounts rather than leaving them idle, because each one holds a copy under its own security and its own future ownership.
Why this only goes so far
Every step reduces the number of copies of a file that already exists. The file is created by the act of transacting through an identity linked account, and no opt out changes that.
The structural alternative is a system that never collects the identity, so there is no record to share, sell, or hand over. Specter's policy is data minimisation: collect only what is operationally necessary and never sell personal information, backed by the absence of a KYC file. Related reading: data minimisation and what your bank knows about you.