Consumer Insights

Open Banking Personalisation: Decisions, Use Cases and Guardrails

Responsible ways to use open-banking data for personalisation, with practical safeguards for privacy, vulnerability, fairness and customer control.

Open Banking Personalisation: Decisions, Use Cases and Guardrails

For about ten years I sat on the account side of a personalisation platform, and the campaign a brand asked for was rarely the campaign that would earn it the most money. It was usually the one that would present best inside its own organisation. Personalised homepage sliders. Social proof widgets. Messages injected into the browser tab title when somebody clicked away. These arrive with a story attached and they market extremely well to a room of executives, which is a different thing from working.

One of those tab-title tests produced a headline conversion uplift I was formally entitled to report and never once believed. The homepage-slider work was not broken at all, but the hours both teams poured into it left the cost-benefit somewhere at or below an ordinary campaign. In neither case was anybody acting in bad faith. The request had simply been shaped by what was visible internally rather than by a decision anyone had specified.

Open-banking data makes that failure mode more expensive, because the raw material is more intimate. A transaction signal can be useful for one decision and unacceptable for another. The same recurring-payment pattern might support an optional budgeting view, justify suppressing a badly timed promotion, or become an intrusive basis for targeting somebody who appears financially stretched. Relevance is not permission.

Responsible design therefore starts with a customer decision, not with a dataset, a model or a campaign idea.

Before using any transaction-derived signal, define:

  • the customer need;
  • the exact decision being changed;
  • whether the decision is a service function, service communication, marketing personalisation, direct marketing, financial-wellbeing support, eligibility assessment, pricing decision or credit decision;
  • why open-banking data is necessary and proportionate;
  • what the customer was told and can control;
  • what benefit and harm will be measured;
  • who owns approval, monitoring and escalation.

For the upstream methodology, meaning what the data contains, how enrichment and categorisation work, and why transaction patterns do not prove motivation, see how open-banking consumer insights are produced.

A note on the evidence below. This article draws on two kinds of support and keeps them apart. Claims marked with a superscript number, such as [1], come from published regulatory, academic or standards sources, all listed in full at the end. Passages headed “From the account side” are my own first-hand observations from client work. They are one practitioner’s experience rather than research, the organisations are described rather than named, and they carry no citation number.

Start with the customer decision, not the data

A usable decision statement has this form:

For customers who have chosen service X, use signal Y to change decision Z, because it addresses need N. Do not use the signal for purposes P or Q. Measure benefit B and harm H. Escalate exceptions to owner O.

Compare two proposals.

Data-first proposal: “Use transaction data to target customers with relevant financial products.”

This is too broad. It does not identify the decision, the purpose, the risk, the customer’s control or the prohibited uses. It cannot be reviewed, because there is nothing specific enough to disagree with.

Decision-first proposal: “For customers who have enabled a budgeting assistant, use high-confidence recurring-payment series to show an editable forecast of expected bills. Do not use the series to increase prices, infer a sensitive condition or trigger third-party advertising. Measure correction rate, forecast usefulness and complaints.”

The second proposal can be reviewed, tested and stopped.

From the account side. In fashion, making it quicker to add an item to the basket, or sending people from an advert straight to a category page, generally worked. We tried the same treatment for a car manufacturer and bounce rates went slightly up instead of down. We stopped the campaign and spent the time making the product detail pages easier to read, which improved both bounce and overall engagement. Someone buying a jumper wants speed. Someone buying a car wants to read and compare, and hurrying them along removes the thing they came for. The tactic was not wrong in the abstract. It was wrong for that decision, and no amount of extra data about those customers would have revealed that in advance. Specifying the decision would have.

Classify the decision before assessing it

“Personalisation” is not one legal or ethical category. Separate at least the following:

Decision classExamplePrimary concern
Service personalisationOrdering an optional cash-flow dashboardAccuracy, usefulness, control
Service communicationWarning that a customer-selected bill may fall before expected incomeAccuracy, timing, undue alarm
Marketing personalisationChoosing which educational product content to displayExpectations, fairness, sensitive inference
Direct marketingSending an individually directed promotional emailData protection, PECR, right to object, frequency
Financial-wellbeing supportOffering neutral help or signposting after customer-declared difficultyVulnerability, dignity, non-exploitation
Offer suppressionWithholding credit or urgency-led promotion when harm risk is elevatedFalse positives, missed benefit, review
Product eligibilityDetermining whether a customer can access a productApplicable product and sector rules, evidence quality
Affordability or credit decisionAssessing risk that repayment may adversely affect the customerRegulated assessment, complete context, explainability
PricingVarying a price using inferred willingness or financial pressureFair value, discrimination, exploitation, trust

A marketing team should not quietly repurpose a signal created for budgeting into eligibility, pricing or credit. Purpose changes require a fresh assessment and, where relevant, specialist legal, compliance and risk approval.

Which personalisation decisions might be appropriate?

The most defensible uses are normally customer-initiated, easy to understand, reversible and low consequence. They use the least sensitive signal needed and give the customer a correction or opt-out route.

Potentially appropriate examples include:

  • an optional recurring-payment view;
  • customer-controlled cash-flow reminders;
  • adapting the order or depth of educational content;
  • suppressing irrelevant or potentially harmful promotions;
  • routing a customer to appropriate service support;
  • pre-filling a non-consequential service field that the customer confirms;
  • adjusting communication frequency within stated preferences.

Appropriateness still depends on the actual purpose, data, population and safeguards. “Helpful” is not a substitute for evidence.

Which decisions require greater caution or should be prohibited?

Usually require specialist review

  • financial-service eligibility;
  • affordability or creditworthiness assessment;
  • fraud or financial-crime controls;
  • differential pricing;
  • decisions with legal or similarly significant effects;
  • decisions based on vulnerability indicators;
  • inferences that may reveal special-category data;
  • modelled household circumstances;
  • automated suppression that could deny a beneficial service;
  • third-party audience creation from transaction data.

Strong candidates for prohibition

  • targeting a higher-priced product because a customer appears urgent or financially constrained;
  • promoting more credit after signals of debt stress or problem gambling;
  • inferring pregnancy, disability, health, religion or political belief for promotional targeting;
  • using salary timing to create pressure or countdown messaging;
  • treating a proxy as a protected characteristic while claiming the model is demographic-free;
  • presenting an inferred life event as known fact;
  • selling or exporting transaction-derived sensitive audiences to unrelated advertisers;
  • using an unexplained score as the sole basis for a consequential decision;
  • using open-banking data for a materially different purpose from the one the customer reasonably understood.

ICO guidance notes that profiling for direct marketing can itself involve special-category data when an organisation draws inferences about race, political opinions or health from other information [1]. Financial data is not automatically special-category data under UK GDPR, but its use can create highly sensitive inferences and must still be fair [2].

Declared, transaction and existing first-party data

Choose data by fitness for the decision, not by novelty.

Declared information

Best suited to goals, preferences, accessibility needs, household context and customer confirmation. It may be incomplete or change over time, but it gives the customer a direct voice in the decision.

Transaction-derived information

Best suited to recorded amounts, timing, recurrence and observed account activity within the authorised coverage. Merchant, category, income and vulnerability labels may be derived, and derived labels carry uncertainty.

Existing first-party information

Product holdings, service interactions, complaint history, stated communication preferences and previous outcomes may answer the question without processing more granular financial data at all.

A proportionate design uses the least intrusive source that can reliably support the customer need. It should not prefer transaction data merely because it feels behavioural or objective. What the data actually reflects is a combination of payment systems, account coverage, merchant labels, household arrangements and modelling choices.

Service personalisation versus promotional targeting

The same visual surface can carry different decisions, and the customer cannot always tell them apart.

A dashboard tile showing a customer’s own upcoming direct debits is a service function. A tile that uses those same direct debits to recommend a product the organisation sells is promotional targeting, even if the design language is identical. The second one attracts a different set of rules, a different consent position and a different expectation of restraint.

Practical separation means:

  • labelling promotional content as promotional;
  • keeping mandatory service messages outside marketing suppression logic;
  • preventing a service feature from becoming a distribution channel by default;
  • recording which team owns each surface and for what purpose;
  • resisting the drift that follows when a service feature starts being measured on revenue.

Use case: optional cash-flow and recurring-payment support

Customer need: Understand upcoming regular commitments and reduce avoidable surprises.

Data signal: High-confidence recurring debit series, expected date range and observed balance pattern.

Proposed decision: Show an editable forecast or optional reminder inside a service the customer has chosen.

Expected benefit: Better visibility and planning, with lower effort than manual entry.

Legal and ethical risk: An incorrect reminder may alarm the customer, granular financial data may be retained longer than needed, and the service may drift into promotion.

Inappropriate inference risk: Assuming a recurring merchant proves a continuing contract, a household need or a sensitive circumstance.

Customer control: Allow the customer to hide, rename, correct and disable series and reminders.

Measurement method: Forecast precision by series type, correction rate, opt-out rate, customer-reported usefulness, complaints, and support contacts caused by false alerts.

Harm guardrail: Do not use low-confidence series, avoid alarming language, prevent the feature from triggering promotional urgency, and stop or review if false-alert or complaint thresholds are exceeded.

When not to use it: When data coverage is too short, the account is multi-user without suitable context, or the series is sensitive and the customer has not explicitly chosen the feature.

Use case: relevant content and product education

Customer need: Find clear information relevant to a self-identified goal without navigating an entire product library.

Data signal: Prefer declared goal and product relationship, and use broad, high-confidence transaction patterns only where necessary.

Proposed decision: Reorder neutral educational content or explain product features. Do not determine eligibility or present an offer as approved.

Expected benefit: Reduced search effort and improved understanding.

Legal and ethical risk: Educational content can become disguised promotion, and signal selection can exclude or stereotype groups.

Inappropriate inference risk: Translating spending into a life-stage claim, such as assuming a home move, pregnancy, illness or retirement plan.

Customer control: Let customers choose topics, reset personalisation and reach the full unpersonalised content library.

Measurement method: Comprehension, task completion, voluntary content selection and downstream complaints, not only clicks.

Harm guardrail: Compare outcomes across relevant groups, audit content omissions, prohibit sensitive life-event labels, and do not escalate message urgency from financial-pressure signals.

When not to use it: When the content could materially influence a regulated decision, when a declared preference is already available, or when the signal depends on a sensitive inference.

Use case: offer suppression and contact restraint

Customer need: Avoid irrelevant, repetitive or potentially harmful promotions.

Data signal: Existing opt-outs, recent product holdings, complaint or contact history, declared difficulty and carefully approved risk indicators.

Proposed decision: Suppress a promotion, reduce frequency or replace it with neutral service information.

Expected benefit: Less nuisance, reduced pressure and lower risk of exploiting vulnerability.

Legal and ethical risk: A false positive may prevent a customer seeing a genuinely useful offer, and silent suppression may hide inconsistent treatment.

Inappropriate inference risk: Labelling a customer vulnerable, or a problem gambler, from a merchant category without any context.

Customer control: Honour marketing objections, provide channel and frequency preferences, and allow customers to request information directly even when outbound promotion is suppressed.

Measurement method: Complaint rate, opt-out rate, repeat-contact burden, customer-reported pressure and differential access, not merely lost or preserved conversion.

Harm guardrail: Use suppression as a restraint, never as a hidden basis for worse service or a worse price. Maintain review routes, and test false-positive rates and group differences.

When not to use it: When suppression would remove a mandatory service message, emergency information or a benefit to which the customer is entitled.

The FCA defines a vulnerable customer as someone especially susceptible to harm because of personal circumstances, particularly when a firm does not act with appropriate care [3]. Its guidance asks firms to consider both positive and negative product impacts, support the disclosure of needs and monitor outcomes [3]. Identifying possible vulnerability does not create permission to sell more.

Use case: payment and account-support experiences

Customer need: Resolve a payment problem or understand an account event with less repetition.

Data signal: The specific transaction in dispute, its status, date, amount, reference and the context the customer supplies.

Proposed decision: Route the customer to relevant support, pre-populate the transaction reference, or explain the next service step.

Expected benefit: Faster resolution and reduced effort.

Legal and ethical risk: Revealing sensitive transaction details to the wrong user, or allowing automated routing to block access to a person.

Inappropriate inference risk: Assuming the merchant label explains the customer’s problem, or that a declined or missing payment reveals financial distress.

Customer control: Confirm the transaction, offer a general support route and provide access to a human where appropriate.

Measurement method: Resolution rate, repeat contacts, time to resolution, accessibility outcomes and incorrect-routing rate.

Harm guardrail: Strong authentication and access controls, no sensitive merchant detail in exposed notifications, human override, and audit trails.

When not to use it: When account ownership is ambiguous, the data may expose another household member, or the issue requires regulated complaint handling or specialist support.

Use case: financial-wellbeing support

Customer need: Obtain neutral, practical support after expressing difficulty or choosing a wellbeing service.

Data signal: Customer-declared need should lead. Transaction patterns may support a customer-controlled view of commitments or cash flow, but should not silently diagnose vulnerability.

Proposed decision: Offer support options, flexible service channels, budgeting tools or signposting. Keep this separate from promotional product recommendations.

Expected benefit: Earlier, lower-friction access to suitable help.

Legal and ethical risk: Stigma, unwanted surveillance, inappropriate disclosure, excessive retention and commercial exploitation.

Inappropriate inference risk: Concluding that debt, gambling, health-related spending or a low balance proves a particular condition or its cause.

Customer control: Explain why support is being offered, and let the customer correct the context, choose a channel and decline without losing ordinary service.

Measurement method: Successful support access, resolution, repeat effort, customer-reported dignity, and outcomes for customers in vulnerable circumstances.

Harm guardrail: No cross-selling from a vulnerability flag, restricted access, defined deletion or review dates, and monitoring of whether flagged customers receive systematically poorer outcomes.

When not to use it: When the organisation cannot separate support from sales incentives, cannot protect the signal, or lacks trained escalation routes.

The FCA’s Consumer Duty expects firms to deliver good outcomes for all customers, including those in vulnerable circumstances, and to identify groups receiving systematically poorer outcomes [4][5].

Affordability and eligibility boundaries

Open-banking data may contribute evidence to a regulated process, but a transaction-derived score should not be presented as proof of affordability or eligibility.

The FCA’s consumer-credit rules distinguish:

  • credit risk: the risk to the firm that repayments will not be made; and
  • affordability risk: the risk to the customer of not being able to make repayments without adverse consequences.

The rules require proportionate steps to determine or reasonably estimate current non-discretionary expenditure, and define this to include priority debts, essential living expenses and other hard-to-reduce obligations [6]. They also recognise household obligations and cases where statistical estimates are not representative [6].

A connected-account view may miss:

  • income paid elsewhere;
  • cash expenditure;
  • shared obligations;
  • future changes;
  • debt held with another provider;
  • support received from or provided to another person;
  • annual or irregular essential costs.

Therefore:

  • do not let marketing teams define affordability logic;
  • do not reuse a budgeting estimate as a credit decision without a separate approved process;
  • keep product education distinct from an eligibility representation;
  • state when customer confirmation or additional evidence is required;
  • provide meaningful review and correction where the decision warrants it;
  • document the applicable product, regulatory and legal requirements.

Vulnerability and sensitive inference

Transaction data can expose or suggest circumstances that customers reasonably regard as private. Examples include:

  • debt and arrears;
  • gambling-related payments;
  • disability-related purchases;
  • health services or medicines;
  • religious or political donations;
  • salary and benefit timing;
  • fertility, pregnancy or family-status signals;
  • domestic or household financial arrangements;
  • possible bereavement;
  • sudden income loss;
  • susceptibility to urgency or scarcity messaging.

Some signals may amount to or generate special-category data, depending on what the organisation infers and how it intends to use the inference [1][2]. Even where a signal is not legally special-category data, it may still be intensely private and capable of causing discrimination or distress.

From the account side. What tends to unsettle ordinary shoppers is not the idea that a brand knows what they bought. Most people assume that already, and have done for years. It is what gets predicted from it. Roughly when their salary lands. How many people they appear to be shopping for. Which triggers reliably move them towards a decision. I watched companies derive all three from shopping behaviour across a decade of client work, and the uncomfortable part was never that it worked badly. It was that it worked well enough to act on while the customer had no idea it was happening. That gap between what an organisation can infer and what a customer would expect it to infer is the whole reason a sensitive-inference rule has to exist, because capability arrives long before anybody stops to ask whether it should be used.

Use a sensitive-inference rule:

  1. Is the inference necessary for a specific customer benefit?
  2. Is the customer likely to expect it?
  3. Is a less intrusive signal available?
  4. Could the output reveal health, disability, religion, politics, sexuality, pregnancy or another protected or vulnerable circumstance?
  5. Is the output used for support, suppression, eligibility, price or promotion?
  6. Can the customer see, correct and contest it?
  7. Would the organisation be comfortable explaining the decision plainly to the affected customer?

Where the answer is uncertain, do not operationalise the inference until privacy, compliance, fairness and customer-outcome owners have reviewed it.

Fairness and proxy discrimination

Removing explicit demographic fields does not remove discrimination risk. Merchant patterns, location fragments, income cadence, benefit payments, donation patterns and spending categories may all correlate with protected characteristics or vulnerability.

Proxy discrimination occurs when an apparently neutral feature functions as a stand-in for a protected trait and influences an outcome [7]. The practical risk is wider than model intent, because a system can create group disadvantage even when no developer ever included a protected field.

A fairness assessment should include:

  • a clear definition of the benefit and the burden created by the decision;
  • performance and outcome analysis across relevant groups where lawful and appropriate;
  • false-positive and false-negative costs;
  • tests for features that act as sensitive proxies;
  • comparison with a less intrusive baseline;
  • analysis of who is excluded because data is missing or an account is not connected;
  • review of interaction effects, not only single features;
  • documented choices about fairness measures and their limits;
  • qualitative research with affected customers;
  • a process for complaints, correction and human review.

The ICO distinguishes dataset, design, outcome and implementation fairness [8]. That distinction is useful, because a statistically balanced model can still be unfair if the purpose, the interface, the escalation path or the real-world outcome is harmful.

Explainability and customer control

Explainability should be designed before deployment, not retrofitted after a complaint.

For a customer-facing use, be able to state:

  • what feature is being personalised;
  • which broad data was used;
  • whether the signal was observed, derived or declared;
  • the main reason for the decision;
  • what the decision does and does not mean;
  • how the customer can change preferences or correct data;
  • how to request human review where relevant;
  • who is responsible.

Do not expose raw sensitive transactions unnecessarily. Explanations can describe categories and reasons while protecting other account users and counterparties.

The EDPB’s endorsed profiling guidance addresses automated individual decision-making and profiling under data-protection law [9]. ICO and Alan Turing Institute guidance likewise treats explanation as an organisational responsibility, covering rationale, data, fairness, impact and responsibility [10].

Customer control should be proportionate to the decision:

  • view and edit for service labels;
  • reset for recommendation preferences;
  • opt out or object for direct marketing;
  • contest and human review for consequential decisions;
  • deletion or disconnection controls where applicable;
  • an unpersonalised route that does not degrade essential service.

Frequency, suppression and contextual harm

A message can be entirely accurate and still be harmful because of its timing, its repetition or its context.

Examples include:

  • a credit promotion arriving immediately after salary lands;
  • repeated messages following debt-related transactions;
  • urgency language during a low-balance period;
  • a maternity-themed message based on an ambiguous merchant;
  • a gambling-related support prompt displayed where another household member can see it;
  • repeated offers of help that begin to feel like surveillance.

Set frequency and context controls across channels, not within each campaign alone. Include:

  • global contact limits;
  • cooling-off periods after complaints or declared difficulty;
  • sensitive-context suppression;
  • channel-specific privacy checks;
  • separation of mandatory service messages from marketing;
  • precedence rules for when several models compete for the same surface;
  • monitoring of cumulative exposure.

ICO direct-marketing guidance specifically identifies contact frequency and potential harm as factors in the balancing exercise [1].

Human review and escalation

Human involvement is not meaningful merely because an employee can see the model output. The reviewer needs authority, context, time and a genuine ability to change the result.

Define escalation for:

  • low-confidence data;
  • sensitive inference;
  • joint or multi-user ambiguity;
  • customer correction;
  • adverse or consequential outcomes;
  • group-level fairness alerts;
  • complaints suggesting distress or surprise;
  • model or provider drift;
  • conflict between commercial targets and customer outcomes.

Reviewers should see the source and the uncertainty, not only a risk label. Record the reason for every override and feed those reasons back into monitoring.

Measurement and customer-harm guardrails

A personalisation experiment that optimises only for clicks, conversion or revenue will eventually tell you something false, and the reporting will look excellent the whole time it does so.

Benefit measures

Choose measures linked to the customer need, such as comprehension, task completion, reduced effort, successful support access or corrected cash-flow forecasts.

Harm measures

Include complaints, opt-outs, correction rates, false alerts, pressure or distress reports, differential outcomes, service exclusion, repeat contacts and inappropriate disclosure.

Experiment design

  • pre-register the decision, population and primary measures;
  • use a suitable control or less-personalised baseline;
  • separate service and promotional outcomes;
  • evaluate by relevant group and data-coverage level;
  • set stopping thresholds for harm;
  • measure beyond the immediate click or sale;
  • retain an audit trail of eligibility and suppression;
  • do not enrol high-risk populations by default merely to improve statistical power;
  • re-run the test rather than treating a past result as permanent, because customer behaviour and audience composition both move.

From the account side. A beauty retail chain in France ran an email automation that gave its loyal segment a discount thirty days after purchase. For five months the reporting looked excellent, with healthy opens, healthy clicks and healthy conversions. Then we split the audience and held a group back with no discount at all. Opens came out similar, clicks were actually lower among the discounted group, and conversion differed by roughly two percentage points. The programme had been paying people who were going to buy anyway. Nothing in the reporting had been false, and nobody had manipulated anything. There was simply no control group, so there was nothing for any of those numbers to mean anything against. Open-banking signals make this trap easier to fall into rather than harder, because a highly relevant offer aimed at somebody already committed to the purchase will look like the best-performing campaign the team has ever run.

For broader evaluation methods, see Herm.io’s guide to measuring personalisation effectiveness and personalisation KPI reference. For measurement architecture, use first-party data measurement in the post-cookie era.

Decision register

Maintain one record for every open-banking personalisation decision.

FieldRequired entry
Decision namePlain-language description
Customer needEvidence that the need exists
Decision classService, communication, marketing, direct marketing, support, eligibility, affordability, pricing or credit
PopulationIncluded and excluded customers
Input dataDeclared, first-party and transaction-derived fields
ProvenanceSource, provider, transformation and version
NecessityWhy less intrusive data is insufficient
Output or actionExact customer-facing change
Prohibited reusePurposes for which the signal cannot be used
Customer explanationWhat will be shown or made available
Control and reviewCorrection, opt-out, contest and human-review route
Fairness testsGroups, metrics, thresholds and limitations
Benefit metricsCustomer and service outcomes
Harm metricsComplaints, errors, pressure, exclusion and other risks
Stop conditionsThresholds that pause or end the decision
OwnersProduct, data, privacy, compliance, risk and customer-outcome owners
Review dateRevalidation cadence and trigger events

Governance checklist

Do not launch until the team can answer yes to all of the following:

  • The exact decision and decision class are documented.
  • The customer need is supported by research rather than assumed from transactions.
  • The least intrusive adequate data source has been chosen.
  • Observed, declared and derived fields are separated.
  • The insight method and its limitations are documented.
  • Sensitive inferences and proxy features have been reviewed.
  • Marketing, support, eligibility, affordability, pricing and credit purposes are not blurred.
  • Customer explanation and control are usable in practice, not only present in principle.
  • Human review is meaningful for consequential or high-risk decisions.
  • Fairness is assessed across data, design, outcomes and implementation.
  • Experiments measure benefit and harm.
  • Contact frequency and contextual suppression operate across channels.
  • A named decision owner can pause the system.
  • Data retention and access are proportionate.
  • Complaints, corrections, overrides and drift feed back into review.
  • Commercial incentives cannot override harm thresholds without independent approval.

Frequently Asked Questions

Can open-banking data be used for marketing personalisation?

Potentially, but only for a defined purpose with an appropriate data-protection and communications assessment, data that is accurate enough for the decision, reasonable customer expectations, meaningful control and safeguards against sensitive or unfair targeting. A customer's permission to connect an account for one service should never be treated as unlimited permission for marketing.

Is service personalisation the same as direct marketing?

No. An optional budgeting view, a required service notice and a promotional email are three different decisions, even when they appear on the same screen and look identical to the customer. Classify the purpose and the channel before deciding which rules and controls apply.

Can transaction data identify financially vulnerable customers?

It may reveal patterns that warrant caution or an offer of support, but it rarely establishes vulnerability or its cause by itself. Use declared needs and service context, avoid stigmatising labels, and never convert a possible vulnerability signal into a sales opportunity.

Can transaction data prove affordability?

No single transaction-derived signal should be described as proof of affordability. The relevant assessment may require income, non-discretionary expenditure, foreseeable changes, household obligations and other information that sits well beyond connected-account history.

Is it safe to remove demographic data and target only on behaviour?

No. Behavioural variables can act as proxies for protected characteristics or for vulnerability, so a model with no demographic fields can still produce group disadvantage. Assess the purpose, the features, the errors and the outcomes rather than assuming behavioural targeting is neutral by construction.

Should personalisation use inferred life events?

Generally not for promotional targeting, particularly where the event is sensitive or the signal is ambiguous. A transaction pattern may generate a research question, but it does not prove pregnancy, illness, bereavement, unemployment, faith, politics or a change in household composition.

What should be measured besides conversion?

Measure the intended customer benefit and the possible harm: comprehension, effort, correction rates, complaints, opt-outs, reported pressure, false alerts, exclusion, differences between groups and longer-term outcomes. A campaign can win every dashboard metric while delivering nothing incremental, which is why a control group matters more than a good-looking report.

Conclusion

Open-banking personalisation should make a specific customer decision better. Making targeting more precise is not the same achievement, and the two get confused constantly because precision is easy to demonstrate in a meeting and improvement is not.

The safest starting points are optional service features, customer-controlled support and deliberate restraint. The riskiest are sensitive inference, vulnerability-led selling, behavioural pricing, urgency built on financial pressure, and consequential decisions taken from an incomplete view of somebody’s accounts.

Keep the analytical and decision layers apart. First establish the limits of transaction-data inference. Then ask whether the output is necessary for the customer need, explainable, fair, controllable and measurable for harm. Where those conditions cannot all be met, the responsible form of personalisation may be suppression, or no decision at all. In my experience the hardest part of this work is not building any of it. It is being willing to switch something off while the dashboard still says it is winning.

For open-banking market context, see the rise of open banking and its opportunities for marketers. For adoption and connection journeys, use open-banking opportunities for enhanced consumer engagement. For implementation architecture, use enhancing marketing strategies with open-banking data. For the wider ethical framework, use ethical use of consumer data in marketing.

Sources

  1. Information Commissioner’s Office. “Plan direct marketing.” Direct Marketing Guidance. Current page accessed 28 July 2026. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/direct-marketing-guidance/plan-direct-marketing/ Classification: Official regulator guidance. Interest disclosure: The ICO is the UK data-protection regulator. The page is authoritative guidance, but it is not a substitute for case-specific legal advice.
  1. Information Commissioner’s Office. “What is special category data?” UK GDPR Guidance and Resources. Updated 9 April 2024, accessed 28 July 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/lawful-basis/special-category-data/what-is-special-category-data/ Classification: Official regulator guidance. Interest disclosure: Same regulatory interest and limitation as above. The page also clarifies that financial data is not automatically special-category data.
  1. Financial Conduct Authority. FG21/1: Guidance for firms on the fair treatment of vulnerable customers. Finalised Guidance FG21/1. Published 23 February 2021, page updated 22 July 2026. https://www.fca.org.uk/publication/finalised-guidance/fg21-1.pdf Classification: Official regulator finalised guidance. Interest disclosure: The FCA is the UK conduct regulator. The guidance is authoritative for FCA expectations, but its application depends on the firm and the activity.
  1. Financial Conduct Authority. FG22/5: Final non-Handbook Guidance for firms on the Consumer Duty. Finalised Guidance FG22/5. Published 27 July 2022. https://www.fca.org.uk/publication/finalised-guidance/fg22-5.pdf Classification: Official regulator finalised guidance. Interest disclosure: Same regulatory interest and limitation as above.
  1. Financial Conduct Authority. “Delivering good outcomes for customers in vulnerable circumstances: good practice and areas for improvement.” Published 7 March 2025. https://www.fca.org.uk/publications/good-and-poor-practice/delivering-vulnerable-customers Classification: Official regulator review and good-practice publication. Interest disclosure: FCA supervisory findings are not a controlled causal study, but they are directly relevant to current regulatory expectations.
  1. Financial Conduct Authority. “CONC 5.2A Creditworthiness assessment.” FCA Handbook, Consumer Credit Sourcebook. Rules effective from 1 November 2018, current page accessed 28 July 2026. Official identifier: CONC 5.2A. https://handbook.fca.org.uk/handbook/conc5/conc5s6 Classification: Official regulator rulebook. Interest disclosure: Authoritative for the cited FCA provisions. It does not determine any given organisation’s obligations without context.
  1. Prince, Anya E. R. and Daniel Schwarcz. “Proxy Discrimination in the Age of Artificial Intelligence and Big Data.” Iowa Law Review 105, no. 3 (2020): 1257 to 1318. https://ilr.law.uiowa.edu/print/volume-105-issue-3/proxy-discrimination-in-the-age-of-artificial-intelligence-and-big-data Classification: Academic legal scholarship. Interest disclosure: Normative and doctrinal scholarship rather than an empirical benchmark. No commercial interest was identified.
  1. Information Commissioner’s Office. “How do we ensure fairness in AI?” Guidance on AI and Data Protection. Current page accessed 28 July 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-fairness-in-ai/ Classification: Official regulator guidance. Interest disclosure: ICO guidance sits under an evolving legal framework and should be checked for updates before implementation.
  1. European Data Protection Board. “Automated decision-making and profiling.” Endorsed WP29 Guidelines WP251 rev.01. Endorsed 25 May 2018. https://www.edpb.europa.eu/documents/guideline/automated-decision-making-and-profiling_en Classification: Official EU data-protection guidance. Interest disclosure: The EDPB is an EU supervisory body. UK and EU applicability must be assessed for the specific organisation and processing at issue.
  1. Information Commissioner’s Office and The Alan Turing Institute. “Explaining decisions made with AI.” Practical guidance, current page accessed 28 July 2026 and marked under review following legal change. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/explaining-decisions-made-with-artificial-intelligence/ Classification: Regulator and research-institute practical guidance. Interest disclosure: Co-produced guidance, currently under review. It provides a framework, not certification that any given decision is lawful or fair.
◍ herm · cite this

Use this guide as a source

If it settled an argument in your reporting, cite it, and add Herm as a preferred source so the next answer you get from search or a model comes from work with its definitions attached.

└ Erul, İ. (2026) Open Banking Personalisation: Decisions, Use Cases and Guardrails. Herm. www.herm.io/blog/maximizing-consumer-insights-the-intersection-of-personalization-and-open-banking/
İlkem Erul
Written by

İlkem Erul

Contributor

I have over nine years of experience in digital marketing, account management, and B2C loyalty. I've helped global brands grow, and now, as a co-founder of Herm.io, I work on smarter, safer shopping experiences for consumers.

More from İlkem →

Related reading

All in this category →

More in Consumer Insights and Behavior

01 Competitive Advantage through Consumer Insights

Get the next guide

Readiness

Attribution you can't defend is one symptom. See how five AI models currently describe, price and recommend your brand.

Get your score