Your Bank Knows Where You Buy Your Coffee and They Call it "Transparency"
Open a bank's privacy notice and you'll find a document that reads like it was written to be skimmed, not read. Somewhere in the middle, in the same flat tone used to describe cheque clearing times, you'll find a sentence granting the bank the right to build a behavioural profile of you, feed your spending history into AI models, some run by the bank, some run by third parties it won't always name and then use the result to "understand your needs" and shape what gets marketed at you. You agreed to this. You almost certainly didn't read it.
That's not a hypothetical. It's the current state of UK retail banking, and it's worth being precise about what's going on, because the industry has become very good at describing surveillance in the language of customer service.
The Legal Cover Story
Start with what's unavoidable: banks are legally required to run automated monitoring over every transaction you make, to catch fraud and money laundering. That's fine. Nobody sensible objects to that, and it works in your favour. The problem is that this legal requirement has become the cover story for something much broader. Once a bank has built the infrastructure and secured the legal basis to run algorithms over your transaction data for fraud, it's a short internal hop to running algorithms over the same data for marketing, product cross-selling, and "personalised insights" and that expansion doesn't require a new law, just a line added to a privacy notice that nobody is going to challenge.
Case Study: Lloyds Banking Group
Look at what Lloyds Banking Group (Lloyds, Halifax, and Bank of Scotland, one balance sheet wearing three high-street logos) has been doing, because it's a useful case study in how this unfolds.
Moneyhub and the Affordability-Assessment Pipeline
It has taken on a third-party AI vendor, Moneyhub, to categorise and enrich customer transaction data not just for "spending insights" but explicitly to feed affordability assessments and other financial-wellness products.
The AI Assistant Built to act Across your Accounts
It has launched its own AI-powered financial assistant, built to act across your accounts.
Selling Anonymised Data, and the March 2026 Data Leak
And reporting from the Financial Times, via Computer Weekly, describes a plan to sell more anonymised customer data to third parties as part of a wider cost-cutting drive; a plan the group's own public statement about "accelerating our data and technology capabilities" conspicuously didn't mention by name. Then, in March 2026, a technical fault let Lloyds, Halifax, and Bank of Scotland app users briefly see other customers' transactions such as shop names, wage references, sort codes and school fee payments which was a small accidental preview of just how much granular data these systems now hold on ordinary current-account customers, and how easily it can end up somewhere it shouldn't. None of this is a rogue actor. It's the industry's direction of travel, executed by one of its biggest players, in full public view, because none of it currently requires it to slow down.
The opt-out that isn't
And the "you can always opt out" defence doesn't hold up under scrutiny. Every bank will point you to a marketing-preferences toggle in the app and call it meaningful consent. But read closely and you'll usually find that toggle only stops direct marketing communications but the underlying profiling, the behavioural segmentation, the "categorising customers based on their interactions," continues regardless, because it's classified as a legitimate business interest rather than marketing. You can turn off the emails. You generally cannot turn off the analysis that produces them. That's not an oversight; it's a distinction banks have every incentive to keep vague, because a granular opt-out profiling off, fraud detection on — would be trivial to build and they haven't built it.
Who's Supposed to be Watching?
None of this requires a conspiracy. It requires exactly what's happened: privacy notices that get longer and vaguer with each revision, broad "AI and our partners" language that covers whatever the bank wants to do next without needing your renewed consent, and a regulatory framework namely UK GDPR, the FCA's conduct rules that in principle gives you real rights, but in practice relies on customers reading documents that are engineered not to be read. Data privacy law in the UK isn't fake. It's just optional in practice, because enforcement depends on complaints, and complaints depend on people knowing what happened to their data in the first place. Most don't, by design.
The ICO's Enforcement Actions fell 50% in a year
And the two bodies meant to police this i.e. the regulators, not just the redress route customers fall back on afterwards; are conspicuously not doing so. The ICO holds the statutory power to enforce UK GDPR against exactly this kind of behavioural profiling, and in 2025 it took enforcement action on just 31 occasions, down from 62 the year before: a 50% fall in a single year, in a year when AI-driven data processing exploded across every sector it oversees. Civil society groups and academics found that alarming enough to write to Parliament warning of what they called a "collapse" in enforcement.
The FCA's "Supercharged Sandbox" Built for Speed, not Scrutiny
The FCA, for its part, has been unusually candid about where its priorities lie: Chief Executive, Nikhil Rathi has said openly that "legislation will never keep up" with AI, and rather than tightening supervision, the FCA has built a Supercharged Sandbox, an AI Lab, and an AI Consortium infrastructure specifically designed to help firms deploy AI faster. Helping the industry move quickly and holding it to account are not the same job, and right now the regulator is doing the first one enthusiastically and the second one on a shrinking budget of attention. Call it stewardship if you like the FCA's word for it. From where the customer sits, a regulator that spends its energy accelerating the thing it's supposed to be watching, while its data-protection counterpart's enforcement activity halves in a year, isn't failing quietly, it's asleep at the wheel, and both of them are turning a blind eye in plain sight.
The Financial Ombudsman, Buckling Under Delays and new Limits
And the one place customers can turn to once the regulators have already missed it isn't picking up the slack either. The Financial Ombudsman Service isn't a regulator itself and it can't stop any of this happening, only rule on individual complaints after the fact but even that job is buckling. The press has highlighted "catastrophic" delays leaving cases unanswered for years. Reforms working through Parliament this year will make it worse, tying the Ombudsman's rulings more tightly to whether a firm technically followed FCA rules, so a bank that stayed inside a loosely drawn rulebook wins by default, however unfair the outcome looks to the person on the other end of it. Martin Lewis has warned this opens up a "protection gap" cases where, in his words, "every right-thinking, reasonable individual would say" a customer was treated unfairly, but the Ombudsman's hands are tied because the rulebook never quite forbade it. A watchdog too slow to bark, about to be muzzled is not a safety net, it's a farce.
The Real Scandal
This isn't a lawless industry. It's a well-lawyered one, operating right at the edge of what the rules technically permit, betting correctly that almost nobody including, increasingly, the regulators will look closely enough to notice where the edge is.
That's the real scandal. Not that banks are breaking the rules, but that the rules were written loosely enough so that they don't have to.