What can a budgeting app actually see? PSD2 in plain words
Mihkel Vetemaa
Founder & CEO · · Updated
Facts last verified:
A budgeting app connected under PSD2 can see transaction, balance, and basic account details for the accounts you approved — and nothing else. It cannot see your bank password, cannot move money, and the access expires unless you renew it. Those limits are not the app being polite. They are EU law. Here is what the law actually says, in plain words.
What PSD2 is
PSD2 (the second Payment Services Directive) is the EU law that lets you share your bank account data with a licensed third party, with your explicit consent. It is Directive (EU) 2015/2366, applied since January 2018, and the sharing happens under the supervision of financial regulators.
Before PSD2, your transaction history was locked inside your bank. PSD2 created regulated access to eligible payment-account data when you consent, and required banks across the EU/EEA to build a secure channel for it. This is the framework that lets an app like Bilance, made for European banks, sync and categorise your accounts automatically without ever touching your bank credentials.
The permission model: two very different licences
PSD2 defines two separate kinds of third-party access:
- Account information (AISP — account information service provider): permission to read account data. This is what budgeting apps use.
- Payment initiation (PISP — payment initiation service provider): permission to start a payment, approved by you one payment at a time. Budgeting apps that only track your money do not have or need this.
The two cannot blur into each other. Read access can never be escalated into payments; they are different licences, granted separately by the regulator and approved separately by you at your bank. Every AISP must be registered with a national financial supervisor and appears in public registers. Bilance’s connections run through two named, regulated providers: GoCardless (supervised by France’s ACPR) and Enable Banking (supervised by the Finnish FIN-FSA), both listed in our privacy policy.
What data actually flows
With account-information access, the app receives, for the accounts you approved:
- the list of transactions (date, amount, counterparty, reference text),
- current balances,
- the account’s name, type, and identifier (such as its IBAN).
What never flows: your login credentials, your card PINs, and anything on accounts you did not approve. You authenticate at your own bank, and the bank passes the app a limited-time token instead of anything you could log in with. The step-by-step of what this looks like in practice is in how bank sync works.
The time limits
PSD2 access is not permanent. Your bank will periodically ask you to authenticate again; under the current EU technical standards (updated in 2023) this must happen when more than 180 days have passed. Some banks and providers use shorter periods. If you do nothing, the access simply lapses. You also do not have to wait for that: in Bilance you can stop the syncing or delete a bank connection at any moment, and the data sharing stops with it.
Why the EU frame matters
PSD2 makes these protections legal requirements rather than optional promises. Banks must offer the secure channel, providers are supervised, and consent must be explicit and renewable. You still need to trust the app and its providers to implement the requirements correctly and to protect the data after it arrives. GDPR then covers everything the app does with the data afterwards, including your right to have it erased.
The one thing PSD2 does not decide is what a company does with your data once it has it. That is a business-model question, and we have answered it honestly for ourselves in how Bilance makes money. Bilance uses this framework to connect 2,300+ banks across Europe — check if yours is covered.
Try Bilance
Connect your bank accounts and let Bilance do the categorising — set up in about 2 minutes.