2c2card
Compliance

GDPR & Your Financial Data: What EU Fintechs Must Do

By the 2card team··8 min read

When you open a business account or order a card, you hand over a lot of personal information: names, addresses, ID documents, company details and a running record of transactions. That data is valuable and sensitive, which is precisely why the EU's General Data Protection Regulation (GDPR) sets firm rules on how fintechs may collect, use and protect it. Knowing those rules helps you judge whether a provider treats your information responsibly.

2card is a marketing partner of myTU, an EU-licensed Electronic Money Institution supervised by the Bank of Lithuania. Because the account, IBAN and Visa cards are provided by myTU, the regulated handling of your financial data sits with an EU entity operating fully inside the GDPR framework.

Why financial data gets extra attention

GDPR protects all personal data, but financial information deserves particular care because it reveals so much: where you shop, who you pay, how a business operates. On top of GDPR, fintechs must satisfy anti-money-laundering and Know-Your-Business obligations, which means they are legally required to collect and retain certain identity data. Good providers are transparent about this dual reality: some data is kept because the law on financial crime demands it, and all of it is handled under GDPR's principles.

If you are weighing up how a regulated EMI differs from a bank in how it operates and what it must do, our EMI vs bank explained guide gives useful background on the licensing and supervision that sit behind the data handling.

The GDPR principles, applied to fintech

GDPR is built on a handful of principles. Translated into how a fintech should behave, they look like this:

A trustworthy fintech reflects all of these in a readable privacy notice that explains, in plain terms, what it collects, why, how long it keeps it and who it shares it with.

Your data rights, and how to use them

GDPR gives you concrete, enforceable rights over your own data. With an EU fintech you can expect to exercise:

The practical test of a good provider is how easy it is to use these rights. Look for a clearly named contact or Data Protection Officer, a stated response timeframe, and no hoops that exist purely to discourage you.

Erasure is a real right, but it is not absolute: a regulated fintech may have to keep some identity and transaction records to satisfy anti-money-laundering law. Good providers explain exactly which data this affects and why.

Security expectations you should hold a fintech to

GDPR requires "appropriate technical and organisational measures" to keep data safe. In a fintech context, the baseline you should expect includes:

You can judge a provider partly by its track record and partly by its transparency: clear documentation, sensible defaults and a willingness to explain how data is protected are all good signs.

What good handling looks like in practice

Put together, responsible data handling at an EU fintech is recognisable. The privacy notice is readable rather than a wall of legalese. Data collection is proportionate to opening and running an account. Your rights are easy to exercise. Security is taken seriously and explained. And where data is shared with processors (for card networks, identity verification or cloud hosting), those relationships are governed by proper contracts and kept inside the GDPR framework, including the rules on any transfers outside the EEA.

For 2card, this matters at the very first touchpoint. When you submit your details on the 2card site to request early access, that information feeds a regulated onboarding process run through myTU, an EU EMI operating under GDPR. The standard is simple to state and worth insisting on from any provider: collect only what is needed, protect it properly, be transparent about it, and respect your rights without friction.

One EU IBAN. Three kinds of cards.

Early access is open. Get a card and limit setup tailored to your spend profile — KYB by myTU is fully online.

Get early access

Frequently asked questions

Can I ask an EU fintech to delete all my data?+

You can request erasure, but it is not absolute. A regulated fintech often must retain certain identity and transaction records to meet anti-money-laundering and other legal obligations for a defined period. Outside those requirements, data should be deleted on request under GDPR.

What financial data does a fintech collect and why?+

Typically identity details, company information, ID documents and transaction records. Some is needed to provide and run the account under your contract, and some is required by anti-money-laundering and Know-Your-Business law. A good provider explains each purpose clearly in its privacy notice.

Does GDPR apply to 2card and myTU?+

Yes. Both operate within the EU GDPR framework. The account, IBAN and Visa cards are provided by myTU, an EU-licensed EMI supervised by the Bank of Lithuania, so your financial data is handled under GDPR's principles and your data rights apply.

← Back to all articles