“Open banking” is an increasingly familiar term in major global markets but has yet to break any real ground in Brazil. This, however, could be about to change. Last week, the Central Bank issued a list of guidelines to implement an open banking system in Brazil, which could spell good news for the country’s consumers.

The concept of “open banking” is built upon the use of open application programming interfaces (APIs) containing customers’ banking data, which can then be used by third-party developers to create platforms to help manage finances or carry out specific services.

Currently, in Brazil, citizens may have open accounts in multiple banks and use individual mobile applications to manage each one. With the introduction of open banking, all of this data could be accessed and organized by one third-party application, which could, in theory, provide assistance in budgeting, paying bills, or making investments.

Worldwide, one of the best examples of an open banking application is Intuit's Mint, which allows its customers in the United States to consolidate all of their banking data into one platform, drawing up personalized budgets and checking their credit score.

Similar initiatives have popped up in Brazil, showing there is a demand for open banking services. Guia Bolso was set up in 2014, proposing a similar model to Mint, where customers could organize their finances in one place and draw up personal budgets.

While working in practically the same terms, Guia Bolso is not strictly an open banking application, as it requires the customer to provide their login details and authorize the app to read their bank statements. Due to a lack of regulation on the matter, banks have no obligation to allow applications to access customer's account information, and major Brazilian bank Bradesco even took Guia Bolso to court last year on this subject.

Under the rules of open banking, customers would not need to provide their passwords or additional security information, simply giving their permission to access account balances would suffice.

More transparency, more competition

Besides the argument of providing new facilities to customers, proponents of open banking also claim its implementation will increase competition in the banking sector and lead to better conditions for clients.

The basic principle of open banking dictates that customers' information belongs to the customers themselves, and not banks. This empowers clients and puts the onus on financial institutions to provide attractive and innovative services, in an environment where customers are free to come and go as they please.

Brazil's current banking ecosystem is anything but open or free. Among the developed economies, only the Netherlands has a more concentrated banking system than Brazil. Central Bank data shows that 82 percent of the market is controlled by only a handful of financial institutions: Caixa, Banco do Brasil, Itaú Unibanco, Bradesco, and Santander. This concentration has increased in recent years, with Itaú and Bradesco pulling off high-profile takeovers of Citibank and HSBC Brazil.

A lack of competition results in poor conditions for clients, reflected largely in Brazil's huge interest rates. The idea is that in an open banking system, customers will find it much easier to shop around financial institutions for more advantageous rates.

The data protection issue

There is still one major question hanging over the implementation of open banking in Brazil, and it concerns the Data Protection Law enacted last year. First of all, third-party applications must obtain the "prior, express, and specific" authorization to have access to customer data, making it explicitly clear that the service would be granted permission to use client's banking information. Customers can also revoke this permission at any time, resulting in the termination of data collection and the deletion of previously held data.

High amounts of information being stored could also make companies targets for hackers, looking to gain access to banking data. While this implies the design of sophisticated protection systems, companies are also forced to immediately report data breaches if they do take place, a process which may be easier said than done.

