Memo № 03

Guide · 2026.05.20 · 3 min read

Open Banking Explained: What Your Bank Actually Shares When You Connect It

What PSD2 read-only access is, what a licensed provider can and cannot see, why consent expires every 90 days, and what happens to your credentials.

The stone facade and columns of a bank building
The door PSD2 made every European bank build. · Photo: Unsplash

"Connect your bank" is the button people hesitate over most, and rightly so. Here is what happens behind it in Europe, in plain terms.

PSD2 in one paragraph

The second Payment Services Directive obliges every bank in the European Economic Area to expose a regulated interface through which a licensed third party, with your explicit consent, can read your accounts. The license is issued by a national regulator; the third party is audited; the bank sees who is asking. This is not screen scraping with your password. It is a door the bank built on purpose, and you hold the key.

Read-only means read-only

There are two kinds of PSD2 access: account information (reading balances and transactions) and payment initiation (moving money). Lait uses only the first. The provider Lait connects through, Enable Banking, is licensed for account information. There is no code path in Lait that can initiate a transfer, and no consent screen ever asks you for one.

What your bank shares

  • Account identifiers: IBAN, name, currency.
  • Balances: booked and available.
  • Transactions: date, amount, counterparty text, sometimes a merchant category, typically 90 days to two years of history depending on the bank.

What it does not share: your login credentials, your card number, your other products at that bank, or anything about accounts you did not tick in the consent screen.

Why you re-consent every 90 days

The regulation caps a consent at 90 days (some banks now allow 180). After that, access stops until you renew it at the bank. This is a feature: a connection you forgot cannot quietly keep reading you forever. Lait warns you a week before expiry and again when it lapses, and keeps your history either way.

Where your credentials go

Nowhere. You authenticate at the bank, on the bank's page or app, with the bank's own two-factor. Lait receives a session token scoped to the accounts you approved. The token is stored encrypted; your password never leaves the bank.

What Lait does with the data

Balances become part of your net worth, in EUR, with non-EUR pockets (a Revolut USD account, say) converted at the ECB rate and shown with their native amount too. Transactions are categorised, first by rules, then by a model for the ones rules cannot match, and only the description leaves for the model: IBANs, emails and phone numbers are stripped before anything is sent. Nothing you share is used to train a model.

Coverage and honesty about it

Lait is built on this and is opening it to members soon; until then, bank data arrives as a CSV or Excel statement. 2,500+ banks across the EEA are reachable through the provider. Coverage is good for the large retail banks and the neobanks, patchier for small regional ones. Where a bank is not connected yet, Lait accepts its CSV export: 40+ formats are recognised automatically, which is the fallback most people end up using for at least one account.

If you are outside the EEA, PSD2 does not apply to you: US and UK banks are handled by CSV, and everything else in Lait works the same.

Try it

Lait puts your crypto, stocks, banks, property and debt on one screen, in EUR or USD. Request an invitation.

No card needed. Basic access is free. Built in Barcelona.

← All memosLait / Barcelona
LaitLive Asset Intelligence
Barcelona