FinanceGadget
Guide

What Happens to Your Data When a Fintech Shuts Down?

The short answer

When a financial technology company shuts down, liquidates, or enters insolvency, customer data does not automatically vanish. While bank tokens (OAuth access permissions) expire or can be revoked, raw transaction history, account details, identity verification (KYC) documents, and analytics logs remain stored on cloud servers and database backups.

In insolvency proceedings, customer data databases are frequently treated as corporate assets that can be acquired by buyers, subject to GDPR constraints and statutory record-retention laws.

What Happens to Your Data: The 4 Phases

Phase 1: Open Banking API Tokens Are Terminated

If the app connected to your bank via PSD2 Open Banking APIs:

  • Access tokens expire automatically (typically within 90 to 180 days).
  • You can immediately terminate the token from your online banking security portal, severing the app’s ability to read new transactions. Read our guide on what you agree to when an app connects to your bank.

Phase 2: KYC Data Must Be Retained by Law

Anti-Money Laundering (AML) and Counter-Terrorist Financing (CTF) laws require financial institutions and payment providers to retain customer identity verification data (passport scans, addresses, transaction records) for a mandatory statutory period—typically 5 to 10 years following the closure of an account—regardless of whether the company shuts down.

Phase 3: Non-Essential Data Must Be Purged (GDPR Article 17)

Under GDPR Article 17 (Right to Erasure), non-statutory data—such as user preferences, budget categories, marketing profiles, and app usage logs—must be securely erased when no longer necessary for the original purpose.

Phase 4: Data Assets in Insolvency Sales

In insolvency or bankruptcy proceedings, liquidators seek to sell company assets to pay creditors. Customer databases can be sold to acquirers, provided:

  • The acquirer uses the data for substantially similar purposes.
  • Users are notified of the change in data controller.
  • Users are granted the right to object or request erasure where statutory retention does not apply.

Risk Breakdown During Fintech Liquidation

Data CategoryRetention RealityCan You Request Erasure?Risk Level
Bank OAuth TokensRevoked / Expired immediatelyYes (Revoke at bank)Low
KYC Identity ScansRetained 5–10 years by AML lawNo (Statutory obligation)High (Data breach risk)
Transaction HistoryRetained 5–10 years by tax/financial lawNo (Statutory obligation)Medium
App Preferences & LogsMust be deleted upon winding downYes (Submit GDPR erasure)Low

The other half: what happens to your money

Data is one exposure. If the provider held a balance, that is a separate process with a separate timeline, and the two run in parallel.

Money held by an e-money or payment institution is not covered by a deposit guarantee scheme. It is protected by safeguarding — the requirement to keep customer funds segregated from the firm’s own, so that on insolvency they form a pool belonging to customers rather than to general creditors. That protection is real and it works differently from deposit insurance in ways that matter during exactly this event: there is no state backstop covering a shortfall, no statutory payout deadline, and the distribution is run by an insolvency practitioner rather than a compensation scheme.

The practical consequence is that your balance is frozen while it happens, and “eventually recovered in full” and “available on Thursday” are very different things when rent is due. What a payment institution licence actually protects covers the mechanics and how to check which licence a provider holds before you need to know.

Security degrades before the shutdown is announced

This is the part that receives the least attention and creates the most risk.

A company heading into insolvency loses staff first, and security and engineering teams are rarely the last to go. In the months before a public announcement, the same infrastructure holding your KYC documents is typically being maintained by fewer people, with patching deferred, monitoring alerts unattended, and offboarding of departed employees done inconsistently.

The data is at its most exposed precisely when the organisation is least capable of protecting it — and this window opens well before customers are told anything. It is the strongest practical argument for acting on early warning signs rather than waiting for the announcement.

The signs worth noticing: support response times collapsing, the app going months without updates, unexplained changes to fee structures or limits, senior departures visible on LinkedIn, features being quietly withdrawn, or a regulator publishing a notice against the entity.

What an administrator actually does with the database

Once an insolvency practitioner is appointed, they owe duties to creditors, and the customer database is an asset on the balance sheet.

In practice one of three things happens. The book is sold to a competitor as a going concern, in which case the data transfers with it and you should receive a controller-change notification. The assets are sold piecemeal, where the database may go to a buyer with no interest in continuing the service. Or nothing sells, and the data sits in whatever cloud environment the administrator can afford to keep running until statutory retention lapses — which is the worst outcome, since nobody is actively responsible for it and there is no budget for security.

Your rights survive all three. The controller changes; the obligations do not. But exercising a right against a company in administration is slow, and against one that has been fully dissolved it may be practically impossible — there is no DPO, no support desk, and no entity to complain about.

That asymmetry is the reason the actions below are time-sensitive rather than merely advisable.

Practical Actions to Protect Yourself

If a fintech app you use announces a shutdown or suspension of operations:

  1. Revoke Bank Access Immediately: Log into your bank’s web portal or mobile app and revoke the app’s Open Banking token under “Connected Apps”. Do this at the bank rather than in the app — the bank’s revocation is authoritative and works even if the app’s own systems have stopped responding.
  2. Move any balance out first, before anything else: If the provider still processes withdrawals, this is the action with a closing window. Everything else on this list can be done later; this one cannot.
  3. Export Your Financial Data: Download your transaction history and account records before the app servers go offline permanently. Take statements in a durable format, not screenshots — you may need them for tax records or to prove a claim in the administration.
  4. Submit a Formal GDPR Erasure Request: Send an email to the company’s designated Data Protection Officer (DPO) requesting the deletion of all non-statutory personal data. Ask them to state specifically which records they are retaining, under which obligation, and for how long — that forces a distinction between data they must keep and data they merely have.
  5. Monitor for Acquisition Announcements: Pay attention to emails regarding the transfer of user databases to successor companies, and exercise your right to object if you do not trust the buyer.
  6. Register as a creditor if you are owed money: The administrator will publish a process and a deadline. Missing it can forfeit the claim, and nobody will chase you.
  7. Treat your identity documents as exposed: KYC scans are retained by law, in an environment nobody is now funding properly. If the provider held passport or ID images, watch for identity fraud and consider a credit freeze — the document cannot be rotated the way a password can.

The lesson that transfers to every other provider

The failure of any single company is not predictable. What is predictable is that this sequence — degraded security, frozen funds, data that outlives the organisation — is the same every time.

Two habits follow. Do not hold a balance at a non-bank provider that you could not afford to lose access to for several weeks; these products are excellent at moving money and merely adequate at storing it. And keep the number of providers holding a copy of your identity documents deliberately small, because that is the data you can never rotate, and every provider that holds it will eventually either be breached, acquired, or wound up.

Related: how to audit which apps can reach your money covers finding the connections you have forgotten, and what happens to your data after you revoke consent covers the erasure request in detail.