When you open a business account or order a card, you hand over a lot of personal information: names, addresses, ID documents, company details and a running record of transactions. That data is valuable and sensitive, which is precisely why the EU's General Data Protection Regulation (GDPR) sets firm rules on how fintechs may collect, use and protect it. Knowing those rules helps you judge whether a provider treats your information responsibly.
2card is a marketing partner of myTU, an EU-licensed Electronic Money Institution supervised by the Bank of Lithuania. Because the account, IBAN and Visa cards are provided by myTU, the regulated handling of your financial data sits with an EU entity operating fully inside the GDPR framework.
Why financial data gets extra attention
GDPR protects all personal data, but financial information deserves particular care because it reveals so much: where you shop, who you pay, how a business operates. On top of GDPR, fintechs must satisfy anti-money-laundering and Know-Your-Business obligations, which means they are legally required to collect and retain certain identity data. Good providers are transparent about this dual reality: some data is kept because the law on financial crime demands it, and all of it is handled under GDPR's principles.
If you are weighing up how a regulated EMI differs from a bank in how it operates and what it must do, our EMI vs bank explained guide gives useful background on the licensing and supervision that sit behind the data handling.
The GDPR principles, applied to fintech
GDPR is built on a handful of principles. Translated into how a fintech should behave, they look like this:
- Lawfulness and a clear basis. Every use of your data needs a legal basis, such as performing your contract, complying with a legal obligation (for example AML checks), or a legitimate interest that is properly balanced against your rights.
- Purpose limitation. Data collected to run your account and meet compliance duties should not be quietly repurposed for unrelated uses.
- Data minimisation. A provider should ask only for what it genuinely needs, not hoard information "just in case".
- Accuracy. You should be able to correct details that are wrong or out of date.
- Storage limitation. Data should not be kept forever; retention should be tied to genuine need and legal requirements.
- Integrity and confidentiality. Strong security must protect data against loss, theft or unauthorised access.
A trustworthy fintech reflects all of these in a readable privacy notice that explains, in plain terms, what it collects, why, how long it keeps it and who it shares it with.
Your data rights, and how to use them
GDPR gives you concrete, enforceable rights over your own data. With an EU fintech you can expect to exercise:
- The right of access — ask what personal data the provider holds about you and receive a copy.
- The right to rectification — have inaccurate or incomplete data corrected.
- The right to erasure — request deletion of your data, subject to legal limits (a provider may, for example, be obliged to retain certain records for anti-money-laundering purposes for a defined period).
- The right to data portability — receive data you provided in a structured, commonly used, machine-readable format, and have it transferred where feasible.
- The right to object and to restrict — push back on certain processing, particularly anything based on legitimate interests or used for marketing.
The practical test of a good provider is how easy it is to use these rights. Look for a clearly named contact or Data Protection Officer, a stated response timeframe, and no hoops that exist purely to discourage you.
Erasure is a real right, but it is not absolute: a regulated fintech may have to keep some identity and transaction records to satisfy anti-money-laundering law. Good providers explain exactly which data this affects and why.
Security expectations you should hold a fintech to
GDPR requires "appropriate technical and organisational measures" to keep data safe. In a fintech context, the baseline you should expect includes:
- Encryption of data in transit and at rest.
- Strong authentication for account access, including measures aligned with EU payment-security rules.
- Tight internal access controls, so only staff who need data can see it.
- A breach-response process and the legal duty to notify the regulator (and you, where the risk is high) when a serious data breach occurs.
You can judge a provider partly by its track record and partly by its transparency: clear documentation, sensible defaults and a willingness to explain how data is protected are all good signs.
What good handling looks like in practice
Put together, responsible data handling at an EU fintech is recognisable. The privacy notice is readable rather than a wall of legalese. Data collection is proportionate to opening and running an account. Your rights are easy to exercise. Security is taken seriously and explained. And where data is shared with processors (for card networks, identity verification or cloud hosting), those relationships are governed by proper contracts and kept inside the GDPR framework, including the rules on any transfers outside the EEA.
For 2card, this matters at the very first touchpoint. When you submit your details on the 2card site to request early access, that information feeds a regulated onboarding process run through myTU, an EU EMI operating under GDPR. The standard is simple to state and worth insisting on from any provider: collect only what is needed, protect it properly, be transparent about it, and respect your rights without friction.