THE INDUSTRY FILES

Finance & Banking

Closing the account does not close the file: money-laundering and tax rules keep identity and transaction records for years, and “where permitted by law” covers the rest. The stickiest holds are the statutory ones no request can move.

TRACKING PRIORITY HIGH

Identity documents and full financial history under long legal holds. Track who holds them.

IF IT LEAKS SEVERE
EXPECT IT KEPT INDEFINITELY

Anti-money-laundering and tax rules keep identity and transaction records for years after you leave, by law.

IDENTITY DEMANDED FULL KYC

Full identity verification is required: passport or licence, often with a face scan.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

A finance file names what you hold, what you owe and what you move, beside the ID documents that opened the account. Leaked, it is both the means to impersonate you and the reason to pick you as a target.

What repeats in the policies

WHAT'S ON FILE

The stickiest file you'll hand over

Anti-money-laundering rules set the floor: government ID, commonly a selfie taken to match it, and your transaction history. Identity and transaction records are usually kept about five years after the account closes, and policies let the company keep them longer if it sees fit.

THE FINE PRINT

A refusal that works as a permission

"We do not share except as permitted by law" reads as a refusal and works as a permission: the permitted list covers processors, joint marketing, fraud networks and affiliates. Data labelled de-identified sits outside every other promise, and it has a documented resale market.

THE SHARED LIST

A marker travels further than you do

Every policy read hands your details to identity and fraud-prevention networks, and the pipe runs both ways for the life of the account. A marker set there is consulted by other lenders, banks and insurers, so a refusal can follow you to firms you have never dealt with. The record sits with the network, not with the company that put it there.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileIdentity DocumentsFinancialPhotos & BiometricsCriminal & Offence Records Browsing & Activity maybeMessages maybePurchases maybeLocation maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Money and net worth HIGHLY LIKELY

Balances and statements reveal it directly.

Where you go LIKELY

Card transactions map where you are and when.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

identity / anti-money-laundering records ABOUT 5 YEARS LAW SETS IT

Money-laundering rules require ID and transaction records after an account closes.

financial regulatory records AROUND 5 TO 7 YEARS LAW SETS IT

Financial regulators require advice, suitability, and transaction records.

fraud-prevention markers ABOUT 2 TO 6 YEARS THEY SET IT

To flag suspected fraud, often on a shared industry database you cannot reach through the company.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

Who wants this data

Bank-transaction data, relabelled anonymous, has been sold at scale by the services that connect apps to your account. More finance policies now reserve the right to train their own AI on customer data.

SOLD OR SHARED POSSIBLE

Regulated and less ad-driven, but transaction data still feeds credit and fraud scoring.

AI TRAINING MODERATE

Transaction patterns train fraud and credit models; a narrower training market than open web data.

Even anonymised, this can still be you

Anonymised is their word. Four card transactions identify 90% of people (de Montjoye et al., Science, 2015), and this industry keeps every one of yours next to your date of birth and address.

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces SOMETIMES

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns TYPICAL

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

How you write SOMETIMES

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Face and voice TYPICAL

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint SOMETIMES

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“we do not share your data with third parties except as permitted by law”

It sounds like a refusal, but what the law permits includes processors, affiliates, joint marketing and fraud databases.

THE MOVE An access request turns the sentence around: which of those actually got your data. Their reply goes on your record.

“we may keep your personal data longer if we cannot delete it for legal, regulatory, or technical reasons”

They can keep data even longer than the law requires, on their own call; technical inconvenience counts as a reason.

THE MOVE A retention question makes the reason specific: which one covers your data, and when it ends. Their reply goes on your record.

“develop, train, test, and deploy artificial intelligence systems”

Your account and transaction records become training material inside the company. Nothing here limits which models, or says whether one built on your data outlives your account and your deletion.

THE MOVE An objection draws the line in writing: run the account, do not train on it. Their reply goes on your record.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →