Your Bank's AI Has a File on You. Here's How to Read It.
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team
There is a version of you inside your bank's systems that you have never met. It is not your name, your address and your balance. It is a behavioural profile: a running statistical description of how you earn, spend, move and log in, assembled automatically from ordinary use and consulted every time the institution has to decide something about you.
You may have picked your app from our best AI banking apps comparison partly because of what its models can do for you. This is the other half of that arrangement — what the same models are recording, which decisions they feed, and the specific written requests that oblige an EU or UK institution to show you part of it.
What the profile is actually made of
None of this is exotic. It is exhaust from normal use of the app:
- Transaction sequence and timing — not only what you spend, but the shape of the month: when income lands, which payments are fixed, how the balance curves between them.
- Merchant and category enrichment — every card payment is matched to a merchant record and a spending category, frequently by a third-party enrichment provider rather than by the bank itself.
- Counterparties — who pays you, who you pay, how often, and how regularly.
- Device and session signals — the handset, the operating system version, the network you connect from, how you interact with the screen during login.
- Geography — where the card is used and where the app is opened, which is why the first tap in a new country behaves differently from the hundredth.
- Onboarding and verification data — the identity documents, the liveness check, the screening result, and how old all of that now is.
- Your corrections — every time you recategorise a transaction or dismiss an alert, you are labelling training data.
That last one is worth sitting with. The friendly, helpful surface of the app is also the collection mechanism. Nothing sinister is implied by that. It is simply the deal.
The four decisions the profile feeds
| Decision | What the model is doing | How visible it is to you |
|---|---|---|
| Fraud and financial-crime monitoring | Scoring each transaction against your own pattern and against patterns learned across the whole book | Invisible until it fires, then extremely visible |
| Access to your funds | How quickly a large incoming payment is released, whether an outgoing transfer is held for review | Usually unexplained |
| Pricing and limits | Overdraft availability, credit limits, which upgrade prompts you are shown | Presented as an offer, never as a score |
| Content and product targeting | Which nudges, tiers and partner products appear in your feed | Looks like the app, not like advertising |
If you want the same machinery described from the bank's side, layer by layer, that is what your bank's algorithm actually does. This piece is about the file it keeps on you, and how to ask for it.
The rights that exist, quoted exactly
Where your provider is established in the EU or the UK — or offers services to people there — two articles of the General Data Protection Regulation do most of the work. We are quoting rather than summarising, because the exact wording is what you will be citing back at them.
The right of access. Article 15(1)(h) obliges the controller to tell you about:
the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
The right not to be decided about by machine alone. Article 22(1):
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
Read that on its own and it sounds enormous. It is not, because Article 22(2) disapplies it where the decision is necessary for entering into or performing a contract, is authorised by Union or Member State law, or is based on your explicit consent — between them, most of retail banking. The part that survives the exceptions is Article 22(3), and it is the genuinely useful one. In the contract and consent cases the controller must implement safeguards including:
the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
The clock. Article 12(3) sets the deadline. Information on action taken must be provided "without undue delay and in any event within one month of receipt of the request". That period "may be extended by two further months where necessary, taking into account the complexity and number of the requests", and the controller must tell you about the extension, with reasons, inside the first month.
Text of Articles 12, 15 and 22 checked at gdpr-info.eu on 5 September 2026 and quoted verbatim above.
How to actually make the request
- Put it in writing — the app's secure message channel, or the published data-protection address. Not by phone. You want a timestamp and a record.
- Name the article. "I am making a request under Article 15 of the GDPR" is routed to a different queue from "can I see my data please".
- Ask narrow questions, not for everything. A bulk request returns a bulk export of the transactions you already have. The interesting material is the profiling answer.
- Ask for human intervention separately if a specific decision has gone against you — that is Article 22(3), not Article 15, and it is a different request.
- Diarise one month from the date you sent it, and note that an extension notice must itself arrive within that month.
- If nothing arrives, escalate to the firm's formal complaints process first and get a reference, then to your national data-protection authority.
What you will not get, and why
This is the part most articles on the subject leave out, and it is the part that stops you wasting three months.
- Not the model. No weights, no feature importances, no thresholds. "Meaningful information about the logic involved" has never been read as a right to the source code, and firms cite commercial confidentiality and the rights of others.
- Not the fraud rules. Publishing the tripwires to customers publishes them to fraudsters. Expect a refusal here and expect it to be upheld.
- Nothing touching a suspicious-activity report. If a review was triggered by suspected financial crime, disclosure rules cut across your access right entirely. That is the same wall described in when the algorithm says no.
- Not a single tidy score. There is rarely one number. There are several models, run at different moments, on overlapping inputs.
What you can get is real, though: confirmation that profiling happens, the categories of data involved, the broad purpose and consequences, the third parties involved, and — crucially — a human being attached to a specific decision that went wrong.
If you are not in the EU or the UK
The profile exists regardless of where you live; only the lever differs. Comparable access and correction rights have been adopted in many jurisdictions under their own data-protection statutes, with different names, different deadlines and different regulators, so look up your own country's law rather than assuming the GDPR wording applies to you.
Two things work almost everywhere even without a statute: asking in writing for a formal complaint reference, which in most regulated markets starts a defined internal process, and asking for the decision to be reviewed by a person. Neither depends on the acronym.
The honest counter-argument
The profile is also what protects you. The same behavioural model that quietly influences your overdraft limit is the one that spots the card-testing charge at four in the morning, and most people would not trade the second to be rid of the first. Detailed profiling is not a bug that crept into banking; it is the product, and the alternative — a slower, blunter, more paperwork-heavy bank — is not obviously better for the average customer.
The reasonable position is not to demand the file be deleted. It is to know it exists, to know which decisions it touches, and to know that when it gets you wrong there is a documented route to a person. Most customers discover all three in the worst week of their financial year. Doing it now costs an evening.
What to check on your own provider this week
FAQ
Will asking put a flag on my account? Making a lawful data request is not a risk signal, and the teams that handle it are usually separate from the ones that make risk decisions. What genuinely does change behaviour is a sudden, unexplained change in how you use the account.
Can I ask them to stop profiling me altogether? Generally no, not for fraud and financial-crime monitoring, which is a regulatory obligation rather than a preference. Marketing and product-targeting profiling is a different matter and is far more often switchable.
Does this apply to an e-money provider rather than a bank? The data rights follow the establishment and the offering of services, not the licence type. The deposit protection, however, does not — which is a separate and more consequential question, covered in who actually holds your money.
What if the answer is obviously a template? Reply once, quoting Article 15(1)(h) and asking specifically for the automated-decision-making answer. Templates usually address Article 15 generally and skip point (h) entirely.
Sources
- GDPR Article 12 — Transparent information, communication and modalities: gdpr-info.eu/art-12-gdpr (checked 5 September 2026)
- GDPR Article 15 — Right of access by the data subject: gdpr-info.eu/art-15-gdpr (checked 5 September 2026)
- GDPR Article 22 — Automated individual decision-making, including profiling: gdpr-info.eu/art-22-gdpr (checked 5 September 2026)
Disclaimer: BestAiGlobalBank is an independent comparison site published by NorwegianSpark SA. This is general information about data rights, not legal or financial advice, and data-protection law differs by country. Verify the position for your own jurisdiction and provider before acting.