Following a number of changes to the law and regulation you can now give certain permitted companies (third party providers or TPPs) access to some of your accounts, so they can provide you with services such as:
- Account aggregation: so you can see your accounts with different providers all in one place in a mobile app or online. Banks, building societies and price comparison websites will be some of the companies providing this type of service.
- Payment initiation: so online payments can be made on your behalf, as an alternative to using your debit or credit card.
Some online retailers will be providing this service.
TPPs can only access your information and provide these type of services if you’re registered for Online Banking and give your consent (if you share your Online Banking details the TPP will be able to see information about your other accounts accessible in your Online Banking).
Before you give consent for any third party provider (TPP) to access your accounts, it’s important that you understand the services they’re providing and how they’ll use your information, including if they’ll be sharing it with anyone. You should also take reasonable steps to ensure that the company is legitimate.
To obtain your consent to access your accounts, TPPs can:
- Redirect you to Santander, where we’ll take you through a detailed online authorisation process. If you are familiar with the way to log on to our Online Banking, then this process will be very similar. A One Time Passcode (OTP) will be required to complete the consent process. This will be sent to the OTP mobile number registered with us. Remember you should never share any OTP with anyone, not even Santander staff. Learn more about OTPs
- Some TPPs may not be able to access your accounts this way, so they may ask you to share your Online Banking log on details with them. Please note, that even if you share your Online Banking log on details with these particular TPPs, you should never share any OTP with anyone, not even Santander staff.
Before sharing your details with a TPP you should take reasonable steps to check the TPP is legitimate. In all cases, be vigilant and check the transactions on your account regularly. Once the TPP has your consent and has obtained access to your information, we can’t control how it will be used. See the ‘Be safe’ tab for more information.
For payment initiation services, you’ll need to give your consent every time a TPP initiates a payment on your behalf. The payments will normally come out of your account straight away, although they can take longer (up to 90 days). Once you’ve authorised a payment, we won’t be able to stop it. The payments initiated by these companies are Faster Payments linked to your current account. Any cashback benefits associated with your cards, including Retailer Offers, won’t apply.
The TPP should make it clear how long the consent you’re giving is valid for when you agree to share your account information with them. In some instances it may be limited to 90 days.
Remember you can withdraw and manage your account information consents at any time in Online Banking. Simply log on, choose ‘Account Services’ then click on ‘Third party providers’ from the menu. If you’ve provided any of your log on details to a TPP see the ‘Be safe’ section for information about withdrawing your consent.
You can also call us on 0800 9 123 123 Our lines are open 7am to 9pm Monday to Saturday and 9am to 9pm on Sunday. If you’re a business customer, you can call us on 0800 731 6666 8am to 9pm Monday to Friday and 8am to 2pm on Saturday.
Know your rights
- Third party providers (TPPs) can only provide these services if you agree and they can only access the accounts you have given your consent for.
- TPPs have to provide key information about their services. This should include what data they will have access to and how they will use it or share it. They will also have to tell you what to do if you’re not happy with the service.
- You can withdraw and manage your consents at any time in Online Banking. Simply log on, choose ‘Account Services’ then click on ‘Third party providers’ from the menu. You can also call us on 0800 9 123 123 Our lines are open 7am to 9pm Monday to Saturday and 9am to 9pm on Sunday. If you’re a business customer, you can call us on 0800 731 6666 8am to 9pm Monday to Friday and 8am to 2pm on Saturday.
- If you’ve provided any of your log on details to a TPP you’ll need to tell them to stop using them to access your information. You may want to order new details to be confident that they can’t be used by anyone you don’t want to access your information.
- We may refuse to give access to a TPP, for example, if we believe there is a risk of fraud.
- Take reasonable steps to check a TPP is legitimate. Ask them for more details, for example who they are regulated by. UK based TPPs must be registered with the Financial Conduct Authority (FCA), with the exception of those who started operating before 12 January 2016. You can check the FCA register at: register.fca.org.uk/
- Be alert. You should be vigilant to fraud when using these services. If there is a reason to suspect that the TPP is not who they claim to be, don’t disclose any information. A genuine bank or organisation will never contact you out of the blue to ask for your PIN, full password or to move money to another account. Don’t give out personal or financial details unless it is to use a service that you have signed up to, and you’re sure that the request for your information is directly related.
- Understand what you are agreeing to, by making sure you read the terms and conditions of the TPP carefully.
- Regularly check your accounts and if you notice any activity you don’t recognise, talk to us. To help you stay up to date with your accounts you can set up alerts. If you’re a business customer you can also use the alerts service
- If you notice a transaction that you didn’t authorise, or think you have been a victim or fraud you should let us know immediately by calling us on 0800 9 123 123 or 0800 731 6666 if you’re a business customer. Lines are open 24 hours a day, 7 days a week.
- For more information about your responsibilities and keeping your account safe take a look at your product terms which you can find on your product page, or find out more on our spotting fraud or scams page.
Understand the consequences
- Once the TPP has your consent and has obtained your information, they’ll be responsible for the security of that data. We can’t control how it will be used.
- Once you have authorised a TPP to make a payment, you may not be able to stop it.
Keep safe from fraud
- Never share a Santander One Time Passcode (OTP) with anyone, not even with a Santander employee.
- Never download software or let anyone log on to your computer or devices remotely during or after a cold call.
- Never enter your Online Banking details after clicking on a link in an email or text message.
- For more information on how to protect yourself see our spotting fraud or scams page.
Open Banking is the name used by the financial industry when referring to new services allowing current account holders to share their financial information with, and make payments to, banks and other authorised organisations. This change was led by the UK’s Competition and Markets Authority (CMA) to bring more competition and innovation to the financial services industry.
Open Banking uses a secure system which allows you to tell your bank directly that you’re agreeing to use a TPP. When you’re registering with the TPP you’ll be directed to your account provider to give your agreement and you don’t need to share your Online Banking details with the TPP.
The important aspect of Open Banking is that it's up to you if you want to share your data. Open Banking gives the opportunity to share your information, but only if you expressly give your permission.
Payment Services Directive
The Payment Service Directive (PSD) is European law, which is translated into UK law as the Payment Services Regulation. This law tells banks and other providers how they have to process payments and other services linked to providing payment services. The PSD was updated, and one of the changes introduced similar services to those contained in the UK’s Open Banking rules.
The PSD changes mean that TPPs can (with your express permission) access information about accounts and make payments on your behalf. The accounts include any payment account customers can access online (such as current accounts, credit cards and some savings accounts). Some of these accounts can’t yet be accessed using the method introduced for Open Banking and so to access information some TPPs may ask for your Online Banking details.
For more information you may want to visit:
To see what these changes to the law and regulation mean for your accounts, go to the ‘Third party providers’ section on these pages: