3 ms·
It's a little bit more nuanced than that. The Act places an obligation on data controllers to register and to comply with the various obligations under the Act.
by grabeh 10y ago
It's a little bit more nuanced than that. The Act places an obligation on data controllers to register and to comply with the various obligations under the Act. This excludes data processors (with controllers then making sure they place relevant obligations on controllers contractually). Potentially a service provider might argue they're a data processor although if they're taking decisions over how the data is used they could easily fall within the data controller category. Under current law, it's the data controller who would be liable for any loss of data (although they would normally look to cover off liability contractually with the processor).
In any event, liability really depends on who is taking the decisions over the use of the data. If the third party just takes a feed of the data from the bank then takes various decisions over its use, they could well be a data controller. If on the other hand a bank contracts with a third party to provide an account aggregation service to its customers and they are passing data for this very specific purpose then the service provider could well just be a processor.
The above is also going to change with the new General Data Protection Regulation coming into force next year...