SlideShare a Scribd company logo
Accelerating the Future of Work
The Law Society of Hong Kong
Hong Kong Academy of Law
Fintech Workshop
Who are we
•Xccelerate is a HK based training
institute with focus in Technology
•Xccelerate has developed and
provides courses in AI, Data Science,
Software Engineering, UX Design and
Fintech
•Xccelerate also manages a tech
community and a hiring network
•Henrique works as Innovation Project
Manager implementing Fintech and
Blockchain Projects for the Financial
Industry
•Find me here:
linkedin.com/in/henriquecentieiro
Emil Chan
•Emil is a FinTech evangelist with over 20 years experience in managing IT and business transformation projects in international financial institutions. He had
worked for several sizeable international banks including Credit Suisse and BayernLB as the roles of First Vice President, Head of IT in Asia Pacific, Project
Director and Operations Manager AP. He has extensive experience in both Business and IT consulting encompassing the design, setup, leading and managing
of cross-border projects throughout Asia. He is the adjunct professor, visiting lecturer as well as advisor of various departments of local renowned universities.
•In the past 10 years, he participated actively in voluntary community services in related to popular adoption of technology. He is a mentor of the HK Cyberport
Mentors Network, Guangzhou CP-Nest Incubator of Chinese Academy of Sciences and Chief Judge of the HK ICT Startup Award 2019. In order to unleash
Hong Kong's potential and play a new role in the Greater Bay Area, Emil also hosts seminars, delivers public speeches and publishes articles of FinTech related
topics on local newspapers and interviewed by various media from time to time.
•Tertiary Education:
City University of Hong Kong Business College - EMBA Adjunct Professor and EE Department Advisor
Hong Kong University SPACE - Part-time Lecturer
Hong Kong PolyU Institute of Entrepreneurship – Visiting Lecturer
Lingnan University Faculty of Business - MBA Adjunct Lecturer
VTC PEAK - Adjunct Lecturer
GBA Institute - Adjunct Lecturer and 1st GBA Fellow
Workshop Format
● Ask questions as we go! Type the questions
in the chat. At the end of each chapter I will
stop and reply to the questions
● We will stop a few times for polling
● We will have a coffee break!
Workshop Goals
● Understand what is Fintech and the main
technologies enabling the Fintech revolution
● The main areas being disrupted by Fintech
● Technological trends being adopted by the
corporate industry
● How to lead innovation through Agile
API and Open Banking
• Opening up the Banking System
• Unbundling banking services
• Based in Microservices concept
• Who owns the customer data
• Source of revenue for banks
• New distribution channels – BaaS for Fintech companies
• Open up the system with APIs is now a necessity
Silicon Valley is coming. Jamie Dimon, JP Morgan
Banking-as-a-Service - BaaS
Source: https://www.linkedin.com/pulse/8-biggest-fintech-trends-2019-henrique-centieiro/
Traditional banks have legacy
systems that don’t allow them to
innovate and roll out the
innovation to the entire
customer base with the same
speed Fintech startups are
doing it. At the same time,
Fintech startups need to face
regulations and heavy capital
requirements, an area where
existing banks are already
comfortable. This is where the
middleware Bank-as-a-Service
is born allowing API integration
between the Fintech which
provide the user with a better
experience and the regulated
bank providing an existing back
office
Unbundling the banking system
Source: https://www.cbinsights.com/research/disrupting-banking-fintech-startups/
API and Open Banking
• API – Application Programming Interface is a software intermediary that
allows two applications to talk to each other to perform pre-defined actions
via the internet
• A technical messenger delivers your request to the service provider that you
are requesting from (API provider) and then delivers the response back to you
• Brings efficiency, scalability, cross selling opportunities, innovation and better
time-to-market
• Used in almost all industries
API and Open Banking
Source: https://www.okta.com/blog/2019/05/how-uber-takes-advantage-of-the-api-economy//
Open Banking through APIs
• Open Banking: regulators are incentivizing banks and building societies to release their
data in a secure, standardized form, with authorized organizations though API
• To increase competition in the market by driving innovation in the quality if products and
services that customers receive
• Structured sharing of data between financial service providers, based on the needs of
and consent by the customer
• Supported by the Competition and Markets Authority – CMA – through Open Banking
Implementation Entity – OBIE – Technical standards, support, security directory,
ecosystem development, disputes, etc.
• The 3 types of financial data are: customer data, transaction data and value-added data
Open Banking through APIs
Quiz 1
API is …
• Apply Production Interface
• Application Programming Interface
• Application for Programmers International
PSD2
• PSD2 – Payment Service Directive 2 is the EU’s regulation that mandates banks to open
up access to accounts and customer data. It came in force in January 2018
• It’s a legal framework that regulates payment services through the EU and EEA –
European Economic Area. Many countries worldwide have adopted similar
regulations
• Main objectives according to the EU are:
 Contribute to a more integrated and efficient European payments market
 Improve the level of playing field for payment service providers (including new players)
 Make payments safer and more secure
 Protect consumers
 Encourage lower prices for payments
PSD2
• Participants:
 AISP - Account Information Service
Provider
 PISP - Payment Initiation Service
Provider
 PIISP - Payment Instrument Issuing
Service Provider
 ASPSP – Account Servicing Payment
Service Providers
AISP
• AISP – Account Information Service Provider
• Provides details on transactions and balances, and accesses account information only
based on the customer’s consent. It has read only access.
• A customer holding accounts in different banks across different countries can use an
AISP to get consolidated reports of these accounts. Can provide detailed analysis
• Ensure that data is not accessible to other parties and that when they are transmitted by
the AISP, that it is done through safe and efficient channels
• Identify itself at each session to the ASPSP (i.e. bank) of the customer and securely
communicate with the ASPSP and the customer
AISP
• Access only the information from the designated payment accounts and associated
payment transitions
• Not request sensitive payment data linked to the payment accounts
• No us, access or store any data for purposes other than for performing the account
information service explicitly requested by the customer, in accordance with the data
protection rules
AISP - Examples
PISP
• PISP – Payment Initiation Service Provider
• Will be able to initiate payments on behalf of a customer from the customer’s account
with a bank (the ASPSP)
• Someone making an online purchase can initiate a credit transfer via PISP instead of
using a debit or credit card
• Not hold the payer’s funds at any time, but only initiate payments in connection with the
provision of the payment initiation service
• Ensure that the personalized security credentials of the customer are not accessible to
any other parties and that they are transmitted by the PISP through safe and efficient
channels
PISP
• Ensure that any other information about the customer obtained when providing payment
initiation service, is only provided to the payee and only with the customer’s explicit
consent
• Ensure that every time a payment is initiated that communications between all parties
are conducted in a secure way
• Not store sensitive payment data of the customer and all the data must be encrypted
• Not request from the customer any data other than that which is necessary to provide
the payment initiation service
• Not use, access or store any data for purposes other than for the provision of the
payment initiation service as explicitly requested by the payer
• Not modify the amount the recipient or any other feature of the transation
PISP
PIISP
• PIISP – Payment Instrument Issuing Service Provider, is a party which issues
something that you can pay with . This instrument may be a credit card, a mobile
application, a payment watch, etc.
• Also know as CISP – Card Issuing Service Provider. CISPs can make a request to the
ASPSP (bank) of the user for the availability of funds before the execution of the card-
based payment
• The answer can only be positive or negative and the CISP will never be aware of the
account balance or record the response or use it for any other purpose other than the
execution of the card-based payment transaction
• This entity provides information about the funds availability on PSD2 payment based on
the payment cards
ASPSP
• ASPSP – Account Servicing Payment Service Providers
• Your bank (Financial Institution) is called ASPSP in
PSD2
• ASPSPs are obligated to receive and manage payment
orders initiated by its customers through PISP that are
qualified to operate
• ASPSPs are obligated to provide payment account
information upon request of their customers that are
users of those AISPs
• Banks are like a warehouse
Access to Account – XS2A
• The provision of secure access to accounts operated by
ASPSPs using APIs in order to enable TPPs (Third
Parties) to provide PISP, AISP and PIISP to customers
• It follows Strong Customer Authentication – SCA – 2
Factor Authentication (2FA or MFA)
 Something you know
 Something you have
 Something you are
• Additionally could be Multi Factor Authentication,
behavioral biometric, etc.
• Like a security guard (TPP) checking a guest list at a
public event (ASPSP)
API Banking Examples
• Siri, Cortana, Alexa – Helping in personal finance management and transactions
• Facebook messenger payment – Can transfer money to friends without leaving the
service through Stripe, PayPal, Braintree, Visa, MasterCard, American Express, and
others. Some options also available for WhatsApp in some countries
• Invoice and accounting software Wave – Uses banking APIs to connect to a user’s bank
account, empowering its clients with full control of their business finances in one place.
Connects with online lender OnDeck to offer loans through its platform
Alexa and Capital One
Alexa and Capital One
Examples of APIs by banks
• Opening up of APIs
• Started with
general services
• Gradually with
general services
• It’s an opportunity
for banks
• Reduced margins
Examples of APIs
Quiz 2
Full form of PSD2 is
• Payment Service Directive 2
• Partners and Service Distributors 2
• Payments and Securities Database 2
GDPR
• GDPR - General Data Protection Regulation came into place in May 2018 and it protects the
processing of personal information
• Designed to harmonize data privacy laws across all its member countries as well as providing greater
protection and rights to individuals
• Processing includes the collection, organization, structuring, storage, alteration, consultations, use,
communication, combination, restriction, deletion and disposal of personal data
• Applies to businesses if they:
Have business established in the EU
Offer goods or services to anyone in the EU
Collect, store, transfer or use personal information about European citizens
But most countries in the world are following similar rules
• Data breach needs to be reported within 72 hours or penalties may apply
GDPR – 7 Principles
• Lawfulness, Fairness and Transparency – Data is processed lawfully with fairness and transparency7
• Purpose limitation – Data is collected for specified, explicit and legitimate purposes
• Data minimization – Shouldn’t collect more personal information than required
• Accuracy – Accurate and kept up to date
• Integrity and confidentiality (security) – Data must be protected against unauthorized access
• Storage Limitation – Data storage time should be defined and communicated
• Accountability – Controller should be responsible for the data
Individual Rights under GDPR
• Right to be informed: inform about data collection
• Right to have access: must be able to access their data
• Right of rectification: must be able to rectify their data held with the company
• Right to be forgotten: to have the data permanently erased
• Right to restrict processing: restrict or suppress the data on request
• Right of data portability: obtain or reuse the personal data across different services
• Right to object: object to the processing of their personal data in certain circumstances
• In relation to automated decision making and profiling: applies to automated individual
decision-making and profiling
Penalties under GDPR
• Smaller offenses – Up to €10 million or 2% of the company’s global revenue
• Big breaches – Up to €20 million or 4% of the company’s global revenue
• Google was fined by the National Data Protection Commission – CNIL – for € 50 million
(approx. HKD 423 Million):
- Google didn’t provide enough information to users about how it uses the data that gets
from 20 different services; and
- Not getting proper consent for processing the user data
See more here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-
general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/
Quiz 3
GDPR stands for
• General Data Protection Regulation
• General Data Protection Risk
• Grand Data Protective Regulation
The need of PSD2 in Open Banking
• Customers wants to control their data
• Non standard systems
• Rise in Digital Economy
• Increase in cases of data breach
• Lesser innovation in financial services
• Pricing is not in line with service offering
• Not able to compare services
• Multiple sign in with no single view
• Multiple frictions in transactions
• Data sharing through physical statements
Stakeholders – Individual customers
• Removing frictions
• Best of all options
• Easy to compare benefits
• Easy to switch
• Personalized service
• Track finances
• Sharing information
• Better access to products
Stakeholders – Business and Fintechs
• More customer insight
• Digital input
• Customized products
• Funding and Capital for Businesses
(WAVE, SoFi, etc)
• Better rates
• Better risk management
• Level playing field with banks
• Better cash flow
• Robo advisors
Stakeholders – Banks
• Additional revenue model
• Better risk assessment
• Easy acquisition
• Expansion
• Customer insights
• More data
• Innovation opportunities
• Sell multiple bank services
• Reduced margins
• BaaS model
Stakeholders – Regulators
• More competition
• Increased monitoring
• Can use Regtech
• Improved transparency
• Customer protection and choice
Opportunities and Challenges
• OPPORTUNITIES
 Banks become BaaS
 Acquire new customers
 Become more relevant
 Better customer experience
 New revenue streams
 More data and insight
 Customized Offering
 Better prediction and risk management
• CHALLENGES
 Data Protection
 Too many players
 Standard APIs
 Complex system
 Reputational risk
 Regulatory/penalties risk
 Cyber security risk
Use cases of API and Open Banking
• BANKING
• Branch locator
• ATM locator
• Bank products/service information
• Digital personal assistant (Alexa for example)
• Overview of all the bank accounts and wallets
• Manage accounts, cards, wallets, digital payments, saving accounts, etc
• Checking account balances, etc
• Customer Finance, revolving credit, personal loans, etc
• Buying and selling stocks, securities, etc
Use cases of API and Open Banking
• PAYMENTS
• Online Banking: credit transfers, direct debits, immediate payments
• Recurring payments
• Mobile money transfers, P2 and mobile remittances
• In-app payments (POS, online, QR-code, NFC, etc)
• Cardless cash withdrawals at ATMs or cashback locations
Use cases of API and Open Banking
• THIRD PARTY PROVIDERS
• Receiving messages across banks
• Recurring payment management for subscriptions
• E-billing and e-invoicing across banks
• Revolving credit and installments
• Personal finance management
• Cash flow prediction based on account data across banks
• Financial advice and possible actions based on account data across banks
• Requesting loans on behalf of the customer
Quiz 4
What is BaaS in the PSD2 context
• Blockchain as a Service
• Banking as a Service
• Backup as a Service
Millions need to upgrade skills
Ant Financial Sustainability Report 2016
4
Next
Steps

More Related Content

What's hot

Open banking standards: The future of banks?
Open banking standards: The future of banks?Open banking standards: The future of banks?
Open banking standards: The future of banks?
Initio
 
Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation
WSO2
 
TOAP Annual Summit 2017
TOAP Annual Summit 2017TOAP Annual Summit 2017
TOAP Annual Summit 2017
Archana Shah
 
Wealth Management in Asia - Webinar
Wealth Management in Asia - WebinarWealth Management in Asia - Webinar
Wealth Management in Asia - Webinar
Sopra Banking Software
 
Protecting the bank
Protecting the bankProtecting the bank
Protecting the bank
CGI Suomi
 
AI in Fintech - slides for plenary panel @ IJCAI-20
AI in Fintech - slides for plenary panel @ IJCAI-20 AI in Fintech - slides for plenary panel @ IJCAI-20
AI in Fintech - slides for plenary panel @ IJCAI-20
Usama Fayyad
 
Psd2 in a nutshell
Psd2 in a nutshellPsd2 in a nutshell
Psd2 in a nutshell
Initio
 
Presentation business analytics in finance 16 9-2014
Presentation business analytics in finance 16 9-2014Presentation business analytics in finance 16 9-2014
Presentation business analytics in finance 16 9-2014
GuyVanderSande
 
PSD2: Open Banking with APIs
PSD2: Open Banking with APIsPSD2: Open Banking with APIs
PSD2: Open Banking with APIs
Jason Bloomberg
 
Branch Transformation (Presentacion)
Branch Transformation (Presentacion)Branch Transformation (Presentacion)
Branch Transformation (Presentacion)
Asociación de Marketing Bancario Argentino
 
Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...
Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...
Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...
Institute of Contemporary Sciences
 
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
WSO2
 
Trust kart
Trust kartTrust kart
Trust kart
krishn21
 
Machine Learning in Banking Sector
Machine Learning in Banking SectorMachine Learning in Banking Sector
Machine Learning in Banking Sector
Knoldus Inc.
 
Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...
Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...
Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...
lance slides
 
Ashish Baheti IIM Shillong
Ashish Baheti IIM Shillong Ashish Baheti IIM Shillong
Ashish Baheti IIM Shillong
ING Vysya Bank
 
ExB Labs - NOAH19 Berlin
ExB Labs - NOAH19 BerlinExB Labs - NOAH19 Berlin
ExB Labs - NOAH19 Berlin
NOAH Advisors
 
Boost o2c efficiency with digital assistants - Emagia Gia
Boost o2c efficiency with digital assistants - Emagia GiaBoost o2c efficiency with digital assistants - Emagia Gia
Boost o2c efficiency with digital assistants - Emagia Gia
Emagia
 
Procurement ai is artificial intelligence real in procurement
Procurement ai is artificial intelligence real in procurementProcurement ai is artificial intelligence real in procurement
Procurement ai is artificial intelligence real in procurement
Zycus
 
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
WSO2
 

What's hot (20)

Open banking standards: The future of banks?
Open banking standards: The future of banks?Open banking standards: The future of banks?
Open banking standards: The future of banks?
 
Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation
 
TOAP Annual Summit 2017
TOAP Annual Summit 2017TOAP Annual Summit 2017
TOAP Annual Summit 2017
 
Wealth Management in Asia - Webinar
Wealth Management in Asia - WebinarWealth Management in Asia - Webinar
Wealth Management in Asia - Webinar
 
Protecting the bank
Protecting the bankProtecting the bank
Protecting the bank
 
AI in Fintech - slides for plenary panel @ IJCAI-20
AI in Fintech - slides for plenary panel @ IJCAI-20 AI in Fintech - slides for plenary panel @ IJCAI-20
AI in Fintech - slides for plenary panel @ IJCAI-20
 
Psd2 in a nutshell
Psd2 in a nutshellPsd2 in a nutshell
Psd2 in a nutshell
 
Presentation business analytics in finance 16 9-2014
Presentation business analytics in finance 16 9-2014Presentation business analytics in finance 16 9-2014
Presentation business analytics in finance 16 9-2014
 
PSD2: Open Banking with APIs
PSD2: Open Banking with APIsPSD2: Open Banking with APIs
PSD2: Open Banking with APIs
 
Branch Transformation (Presentacion)
Branch Transformation (Presentacion)Branch Transformation (Presentacion)
Branch Transformation (Presentacion)
 
Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...
Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...
Trends and practical applications of AI/ML in Fin Tech industry - Milos Kosan...
 
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
 
Trust kart
Trust kartTrust kart
Trust kart
 
Machine Learning in Banking Sector
Machine Learning in Banking SectorMachine Learning in Banking Sector
Machine Learning in Banking Sector
 
Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...
Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...
Qlikview in Banking Business Intelligence - Interactive Risk Information Disc...
 
Ashish Baheti IIM Shillong
Ashish Baheti IIM Shillong Ashish Baheti IIM Shillong
Ashish Baheti IIM Shillong
 
ExB Labs - NOAH19 Berlin
ExB Labs - NOAH19 BerlinExB Labs - NOAH19 Berlin
ExB Labs - NOAH19 Berlin
 
Boost o2c efficiency with digital assistants - Emagia Gia
Boost o2c efficiency with digital assistants - Emagia GiaBoost o2c efficiency with digital assistants - Emagia Gia
Boost o2c efficiency with digital assistants - Emagia Gia
 
Procurement ai is artificial intelligence real in procurement
Procurement ai is artificial intelligence real in procurementProcurement ai is artificial intelligence real in procurement
Procurement ai is artificial intelligence real in procurement
 
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
 

Similar to Fintech workshop Part II - Law Society of Hong Kong - Xccelerate

Άσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking ForumΆσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking Forum
Starttech Ventures
 
Sibos 2016 - Access to Account
Sibos 2016 - Access to Account Sibos 2016 - Access to Account
Sibos 2016 - Access to Account
Aya El Mernissi
 
E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...
E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...
E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...
BBAsourashtracollege
 
apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...
apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...
apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...
apidays
 
SCF in India an overview and way forward
SCF in India an overview and way forwardSCF in India an overview and way forward
SCF in India an overview and way forward
goelnaveen1973
 
Organizing stakeholders and working with mobile network operators
Organizing stakeholders and working with mobile network operatorsOrganizing stakeholders and working with mobile network operators
Organizing stakeholders and working with mobile network operators
Mahesh Amarasiri
 
Computerized Banking System
Computerized Banking SystemComputerized Banking System
Computerized Banking System
Shibly Ahamed
 
apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...
apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...
apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...
apidays
 
Cashing in on Mobile Payments with a Winning Strategy
Cashing in on Mobile Payments with a Winning StrategyCashing in on Mobile Payments with a Winning Strategy
Cashing in on Mobile Payments with a Winning Strategy
Perficient, Inc.
 
Grow VC Group: Digital Hybrid Finance
Grow VC Group: Digital Hybrid FinanceGrow VC Group: Digital Hybrid Finance
Grow VC Group: Digital Hybrid Finance
Jouko Ahvenainen
 
YAR-Bank launch of IB project 2014
YAR-Bank launch of IB project 2014YAR-Bank launch of IB project 2014
YAR-Bank launch of IB project 2014
Olga Maslova
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service Directive
Lac Vuong
 
Presentation at Retail Banking Forum
Presentation at Retail Banking ForumPresentation at Retail Banking Forum
Presentation at Retail Banking Forum
Grow VC Group
 
Online Banking Management System – Its Scope and the Technology Used.
Online Banking Management System – Its Scope and the Technology Used.Online Banking Management System – Its Scope and the Technology Used.
Online Banking Management System – Its Scope and the Technology Used.
Techugo
 
Payments
PaymentsPayments
Payments
Neoworks
 
51955853 banking-system-documentation
51955853 banking-system-documentation51955853 banking-system-documentation
51955853 banking-system-documentation
Aziz Muslim
 
Unleashing the o2 o business when the local mobile payment services are takin...
Unleashing the o2 o business when the local mobile payment services are takin...Unleashing the o2 o business when the local mobile payment services are takin...
Unleashing the o2 o business when the local mobile payment services are takin...
Emil Chan
 
RFP Response for Unique Bank Technical Migration
RFP Response for Unique Bank Technical MigrationRFP Response for Unique Bank Technical Migration
RFP Response for Unique Bank Technical Migration
DEEPRAJ PATHAK
 
Hdfc case presentation
Hdfc case presentationHdfc case presentation
Hdfc case presentation
Rohit Patidar
 
Principles and Practices of Banking Module 5
Principles and Practices of Banking Module 5Principles and Practices of Banking Module 5
Principles and Practices of Banking Module 5
ARUNKUMAR7358
 

Similar to Fintech workshop Part II - Law Society of Hong Kong - Xccelerate (20)

Άσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking ForumΆσπα Παλημέρη, 5th Digital Banking Forum
Άσπα Παλημέρη, 5th Digital Banking Forum
 
Sibos 2016 - Access to Account
Sibos 2016 - Access to Account Sibos 2016 - Access to Account
Sibos 2016 - Access to Account
 
E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...
E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...
E Commerce Skill 2.pptx- by Dr.K.G.Raja Sabarish Babu, Assistant Professor, R...
 
apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...
apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...
apidays LIVE Jakarta - Connecting the digital economy in South East Asia with...
 
SCF in India an overview and way forward
SCF in India an overview and way forwardSCF in India an overview and way forward
SCF in India an overview and way forward
 
Organizing stakeholders and working with mobile network operators
Organizing stakeholders and working with mobile network operatorsOrganizing stakeholders and working with mobile network operators
Organizing stakeholders and working with mobile network operators
 
Computerized Banking System
Computerized Banking SystemComputerized Banking System
Computerized Banking System
 
apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...
apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...
apidays New York 2023 - Embedded Payments in B2B and B2C use cases, Adrita Bh...
 
Cashing in on Mobile Payments with a Winning Strategy
Cashing in on Mobile Payments with a Winning StrategyCashing in on Mobile Payments with a Winning Strategy
Cashing in on Mobile Payments with a Winning Strategy
 
Grow VC Group: Digital Hybrid Finance
Grow VC Group: Digital Hybrid FinanceGrow VC Group: Digital Hybrid Finance
Grow VC Group: Digital Hybrid Finance
 
YAR-Bank launch of IB project 2014
YAR-Bank launch of IB project 2014YAR-Bank launch of IB project 2014
YAR-Bank launch of IB project 2014
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service Directive
 
Presentation at Retail Banking Forum
Presentation at Retail Banking ForumPresentation at Retail Banking Forum
Presentation at Retail Banking Forum
 
Online Banking Management System – Its Scope and the Technology Used.
Online Banking Management System – Its Scope and the Technology Used.Online Banking Management System – Its Scope and the Technology Used.
Online Banking Management System – Its Scope and the Technology Used.
 
Payments
PaymentsPayments
Payments
 
51955853 banking-system-documentation
51955853 banking-system-documentation51955853 banking-system-documentation
51955853 banking-system-documentation
 
Unleashing the o2 o business when the local mobile payment services are takin...
Unleashing the o2 o business when the local mobile payment services are takin...Unleashing the o2 o business when the local mobile payment services are takin...
Unleashing the o2 o business when the local mobile payment services are takin...
 
RFP Response for Unique Bank Technical Migration
RFP Response for Unique Bank Technical MigrationRFP Response for Unique Bank Technical Migration
RFP Response for Unique Bank Technical Migration
 
Hdfc case presentation
Hdfc case presentationHdfc case presentation
Hdfc case presentation
 
Principles and Practices of Banking Module 5
Principles and Practices of Banking Module 5Principles and Practices of Banking Module 5
Principles and Practices of Banking Module 5
 

Recently uploaded

GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
kumardaparthi1024
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
Matthew Sinclair
 
Mariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceXMariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceX
Mariano Tinti
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
Neo4j
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
Zilliz
 
How to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptxHow to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptx
danishmna97
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
Alpen-Adria-Universität
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Safe Software
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
Daiki Mogmet Ito
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
Safe Software
 
Uni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdfUni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems S.M.S.A.
 
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy SurveyTrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
Zilliz
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
Tomaz Bratanic
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
innovationoecd
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
DianaGray10
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
Pixlogix Infotech
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
Matthew Sinclair
 

Recently uploaded (20)

GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
 
Mariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceXMariano G Tinti - Decoding SpaceX
Mariano G Tinti - Decoding SpaceX
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
 
How to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptxHow to Get CNIC Information System with Paksim Ga.pptx
How to Get CNIC Information System with Paksim Ga.pptx
 
Video Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the FutureVideo Streaming: Then, Now, and in the Future
Video Streaming: Then, Now, and in the Future
 
Driving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success StoryDriving Business Innovation: Latest Generative AI Advancements & Success Story
Driving Business Innovation: Latest Generative AI Advancements & Success Story
 
How to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For FlutterHow to use Firebase Data Connect For Flutter
How to use Firebase Data Connect For Flutter
 
Essentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FMEEssentials of Automations: The Art of Triggers and Actions in FME
Essentials of Automations: The Art of Triggers and Actions in FME
 
Uni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdfUni Systems Copilot event_05062024_C.Vlachos.pdf
Uni Systems Copilot event_05062024_C.Vlachos.pdf
 
TrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy SurveyTrustArc Webinar - 2024 Global Privacy Survey
TrustArc Webinar - 2024 Global Privacy Survey
 
Full-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalizationFull-RAG: A modern architecture for hyper-personalization
Full-RAG: A modern architecture for hyper-personalization
 
GraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracyGraphRAG for Life Science to increase LLM accuracy
GraphRAG for Life Science to increase LLM accuracy
 
Presentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of GermanyPresentation of the OECD Artificial Intelligence Review of Germany
Presentation of the OECD Artificial Intelligence Review of Germany
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
 
Best 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERPBest 20 SEO Techniques To Improve Website Visibility In SERP
Best 20 SEO Techniques To Improve Website Visibility In SERP
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
20240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 202420240607 QFM018 Elixir Reading List May 2024
20240607 QFM018 Elixir Reading List May 2024
 

Fintech workshop Part II - Law Society of Hong Kong - Xccelerate

  • 1. Accelerating the Future of Work The Law Society of Hong Kong Hong Kong Academy of Law Fintech Workshop
  • 2. Who are we •Xccelerate is a HK based training institute with focus in Technology •Xccelerate has developed and provides courses in AI, Data Science, Software Engineering, UX Design and Fintech •Xccelerate also manages a tech community and a hiring network •Henrique works as Innovation Project Manager implementing Fintech and Blockchain Projects for the Financial Industry •Find me here: linkedin.com/in/henriquecentieiro
  • 3. Emil Chan •Emil is a FinTech evangelist with over 20 years experience in managing IT and business transformation projects in international financial institutions. He had worked for several sizeable international banks including Credit Suisse and BayernLB as the roles of First Vice President, Head of IT in Asia Pacific, Project Director and Operations Manager AP. He has extensive experience in both Business and IT consulting encompassing the design, setup, leading and managing of cross-border projects throughout Asia. He is the adjunct professor, visiting lecturer as well as advisor of various departments of local renowned universities. •In the past 10 years, he participated actively in voluntary community services in related to popular adoption of technology. He is a mentor of the HK Cyberport Mentors Network, Guangzhou CP-Nest Incubator of Chinese Academy of Sciences and Chief Judge of the HK ICT Startup Award 2019. In order to unleash Hong Kong's potential and play a new role in the Greater Bay Area, Emil also hosts seminars, delivers public speeches and publishes articles of FinTech related topics on local newspapers and interviewed by various media from time to time. •Tertiary Education: City University of Hong Kong Business College - EMBA Adjunct Professor and EE Department Advisor Hong Kong University SPACE - Part-time Lecturer Hong Kong PolyU Institute of Entrepreneurship – Visiting Lecturer Lingnan University Faculty of Business - MBA Adjunct Lecturer VTC PEAK - Adjunct Lecturer GBA Institute - Adjunct Lecturer and 1st GBA Fellow
  • 4. Workshop Format ● Ask questions as we go! Type the questions in the chat. At the end of each chapter I will stop and reply to the questions ● We will stop a few times for polling ● We will have a coffee break!
  • 5. Workshop Goals ● Understand what is Fintech and the main technologies enabling the Fintech revolution ● The main areas being disrupted by Fintech ● Technological trends being adopted by the corporate industry ● How to lead innovation through Agile
  • 6. API and Open Banking • Opening up the Banking System • Unbundling banking services • Based in Microservices concept • Who owns the customer data • Source of revenue for banks • New distribution channels – BaaS for Fintech companies • Open up the system with APIs is now a necessity Silicon Valley is coming. Jamie Dimon, JP Morgan
  • 7. Banking-as-a-Service - BaaS Source: https://www.linkedin.com/pulse/8-biggest-fintech-trends-2019-henrique-centieiro/ Traditional banks have legacy systems that don’t allow them to innovate and roll out the innovation to the entire customer base with the same speed Fintech startups are doing it. At the same time, Fintech startups need to face regulations and heavy capital requirements, an area where existing banks are already comfortable. This is where the middleware Bank-as-a-Service is born allowing API integration between the Fintech which provide the user with a better experience and the regulated bank providing an existing back office
  • 8. Unbundling the banking system Source: https://www.cbinsights.com/research/disrupting-banking-fintech-startups/
  • 9. API and Open Banking • API – Application Programming Interface is a software intermediary that allows two applications to talk to each other to perform pre-defined actions via the internet • A technical messenger delivers your request to the service provider that you are requesting from (API provider) and then delivers the response back to you • Brings efficiency, scalability, cross selling opportunities, innovation and better time-to-market • Used in almost all industries
  • 10. API and Open Banking Source: https://www.okta.com/blog/2019/05/how-uber-takes-advantage-of-the-api-economy//
  • 11. Open Banking through APIs • Open Banking: regulators are incentivizing banks and building societies to release their data in a secure, standardized form, with authorized organizations though API • To increase competition in the market by driving innovation in the quality if products and services that customers receive • Structured sharing of data between financial service providers, based on the needs of and consent by the customer • Supported by the Competition and Markets Authority – CMA – through Open Banking Implementation Entity – OBIE – Technical standards, support, security directory, ecosystem development, disputes, etc. • The 3 types of financial data are: customer data, transaction data and value-added data
  • 13. Quiz 1 API is … • Apply Production Interface • Application Programming Interface • Application for Programmers International
  • 14. PSD2 • PSD2 – Payment Service Directive 2 is the EU’s regulation that mandates banks to open up access to accounts and customer data. It came in force in January 2018 • It’s a legal framework that regulates payment services through the EU and EEA – European Economic Area. Many countries worldwide have adopted similar regulations • Main objectives according to the EU are:  Contribute to a more integrated and efficient European payments market  Improve the level of playing field for payment service providers (including new players)  Make payments safer and more secure  Protect consumers  Encourage lower prices for payments
  • 15. PSD2 • Participants:  AISP - Account Information Service Provider  PISP - Payment Initiation Service Provider  PIISP - Payment Instrument Issuing Service Provider  ASPSP – Account Servicing Payment Service Providers
  • 16. AISP • AISP – Account Information Service Provider • Provides details on transactions and balances, and accesses account information only based on the customer’s consent. It has read only access. • A customer holding accounts in different banks across different countries can use an AISP to get consolidated reports of these accounts. Can provide detailed analysis • Ensure that data is not accessible to other parties and that when they are transmitted by the AISP, that it is done through safe and efficient channels • Identify itself at each session to the ASPSP (i.e. bank) of the customer and securely communicate with the ASPSP and the customer
  • 17. AISP • Access only the information from the designated payment accounts and associated payment transitions • Not request sensitive payment data linked to the payment accounts • No us, access or store any data for purposes other than for performing the account information service explicitly requested by the customer, in accordance with the data protection rules
  • 19. PISP • PISP – Payment Initiation Service Provider • Will be able to initiate payments on behalf of a customer from the customer’s account with a bank (the ASPSP) • Someone making an online purchase can initiate a credit transfer via PISP instead of using a debit or credit card • Not hold the payer’s funds at any time, but only initiate payments in connection with the provision of the payment initiation service • Ensure that the personalized security credentials of the customer are not accessible to any other parties and that they are transmitted by the PISP through safe and efficient channels
  • 20. PISP • Ensure that any other information about the customer obtained when providing payment initiation service, is only provided to the payee and only with the customer’s explicit consent • Ensure that every time a payment is initiated that communications between all parties are conducted in a secure way • Not store sensitive payment data of the customer and all the data must be encrypted • Not request from the customer any data other than that which is necessary to provide the payment initiation service • Not use, access or store any data for purposes other than for the provision of the payment initiation service as explicitly requested by the payer • Not modify the amount the recipient or any other feature of the transation
  • 21. PISP
  • 22. PIISP • PIISP – Payment Instrument Issuing Service Provider, is a party which issues something that you can pay with . This instrument may be a credit card, a mobile application, a payment watch, etc. • Also know as CISP – Card Issuing Service Provider. CISPs can make a request to the ASPSP (bank) of the user for the availability of funds before the execution of the card- based payment • The answer can only be positive or negative and the CISP will never be aware of the account balance or record the response or use it for any other purpose other than the execution of the card-based payment transaction • This entity provides information about the funds availability on PSD2 payment based on the payment cards
  • 23. ASPSP • ASPSP – Account Servicing Payment Service Providers • Your bank (Financial Institution) is called ASPSP in PSD2 • ASPSPs are obligated to receive and manage payment orders initiated by its customers through PISP that are qualified to operate • ASPSPs are obligated to provide payment account information upon request of their customers that are users of those AISPs • Banks are like a warehouse
  • 24. Access to Account – XS2A • The provision of secure access to accounts operated by ASPSPs using APIs in order to enable TPPs (Third Parties) to provide PISP, AISP and PIISP to customers • It follows Strong Customer Authentication – SCA – 2 Factor Authentication (2FA or MFA)  Something you know  Something you have  Something you are • Additionally could be Multi Factor Authentication, behavioral biometric, etc. • Like a security guard (TPP) checking a guest list at a public event (ASPSP)
  • 25. API Banking Examples • Siri, Cortana, Alexa – Helping in personal finance management and transactions • Facebook messenger payment – Can transfer money to friends without leaving the service through Stripe, PayPal, Braintree, Visa, MasterCard, American Express, and others. Some options also available for WhatsApp in some countries • Invoice and accounting software Wave – Uses banking APIs to connect to a user’s bank account, empowering its clients with full control of their business finances in one place. Connects with online lender OnDeck to offer loans through its platform
  • 28. Examples of APIs by banks • Opening up of APIs • Started with general services • Gradually with general services • It’s an opportunity for banks • Reduced margins
  • 30. Quiz 2 Full form of PSD2 is • Payment Service Directive 2 • Partners and Service Distributors 2 • Payments and Securities Database 2
  • 31. GDPR • GDPR - General Data Protection Regulation came into place in May 2018 and it protects the processing of personal information • Designed to harmonize data privacy laws across all its member countries as well as providing greater protection and rights to individuals • Processing includes the collection, organization, structuring, storage, alteration, consultations, use, communication, combination, restriction, deletion and disposal of personal data • Applies to businesses if they: Have business established in the EU Offer goods or services to anyone in the EU Collect, store, transfer or use personal information about European citizens But most countries in the world are following similar rules • Data breach needs to be reported within 72 hours or penalties may apply
  • 32. GDPR – 7 Principles • Lawfulness, Fairness and Transparency – Data is processed lawfully with fairness and transparency7 • Purpose limitation – Data is collected for specified, explicit and legitimate purposes • Data minimization – Shouldn’t collect more personal information than required • Accuracy – Accurate and kept up to date • Integrity and confidentiality (security) – Data must be protected against unauthorized access • Storage Limitation – Data storage time should be defined and communicated • Accountability – Controller should be responsible for the data
  • 33. Individual Rights under GDPR • Right to be informed: inform about data collection • Right to have access: must be able to access their data • Right of rectification: must be able to rectify their data held with the company • Right to be forgotten: to have the data permanently erased • Right to restrict processing: restrict or suppress the data on request • Right of data portability: obtain or reuse the personal data across different services • Right to object: object to the processing of their personal data in certain circumstances • In relation to automated decision making and profiling: applies to automated individual decision-making and profiling
  • 34. Penalties under GDPR • Smaller offenses – Up to €10 million or 2% of the company’s global revenue • Big breaches – Up to €20 million or 4% of the company’s global revenue • Google was fined by the National Data Protection Commission – CNIL – for € 50 million (approx. HKD 423 Million): - Google didn’t provide enough information to users about how it uses the data that gets from 20 different services; and - Not getting proper consent for processing the user data See more here: https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the- general-data-protection-regulation-gdpr/individual-rights/right-to-data-portability/
  • 35. Quiz 3 GDPR stands for • General Data Protection Regulation • General Data Protection Risk • Grand Data Protective Regulation
  • 36. The need of PSD2 in Open Banking • Customers wants to control their data • Non standard systems • Rise in Digital Economy • Increase in cases of data breach • Lesser innovation in financial services • Pricing is not in line with service offering • Not able to compare services • Multiple sign in with no single view • Multiple frictions in transactions • Data sharing through physical statements
  • 37. Stakeholders – Individual customers • Removing frictions • Best of all options • Easy to compare benefits • Easy to switch • Personalized service • Track finances • Sharing information • Better access to products
  • 38. Stakeholders – Business and Fintechs • More customer insight • Digital input • Customized products • Funding and Capital for Businesses (WAVE, SoFi, etc) • Better rates • Better risk management • Level playing field with banks • Better cash flow • Robo advisors
  • 39. Stakeholders – Banks • Additional revenue model • Better risk assessment • Easy acquisition • Expansion • Customer insights • More data • Innovation opportunities • Sell multiple bank services • Reduced margins • BaaS model
  • 40. Stakeholders – Regulators • More competition • Increased monitoring • Can use Regtech • Improved transparency • Customer protection and choice
  • 41. Opportunities and Challenges • OPPORTUNITIES  Banks become BaaS  Acquire new customers  Become more relevant  Better customer experience  New revenue streams  More data and insight  Customized Offering  Better prediction and risk management • CHALLENGES  Data Protection  Too many players  Standard APIs  Complex system  Reputational risk  Regulatory/penalties risk  Cyber security risk
  • 42. Use cases of API and Open Banking • BANKING • Branch locator • ATM locator • Bank products/service information • Digital personal assistant (Alexa for example) • Overview of all the bank accounts and wallets • Manage accounts, cards, wallets, digital payments, saving accounts, etc • Checking account balances, etc • Customer Finance, revolving credit, personal loans, etc • Buying and selling stocks, securities, etc
  • 43. Use cases of API and Open Banking • PAYMENTS • Online Banking: credit transfers, direct debits, immediate payments • Recurring payments • Mobile money transfers, P2 and mobile remittances • In-app payments (POS, online, QR-code, NFC, etc) • Cardless cash withdrawals at ATMs or cashback locations
  • 44. Use cases of API and Open Banking • THIRD PARTY PROVIDERS • Receiving messages across banks • Recurring payment management for subscriptions • E-billing and e-invoicing across banks • Revolving credit and installments • Personal finance management • Cash flow prediction based on account data across banks • Financial advice and possible actions based on account data across banks • Requesting loans on behalf of the customer
  • 45. Quiz 4 What is BaaS in the PSD2 context • Blockchain as a Service • Banking as a Service • Backup as a Service
  • 46. Millions need to upgrade skills Ant Financial Sustainability Report 2016