Revoke Open Banking Access UK: Do It at the Bank, Not App
To revoke open banking access UK side, cancel at your bank, not just in the app. Exact menus for NatWest, HSBC, Lloyds and Monzo, plus what data they keep.
Most people try to revoke open banking access in the UK by deleting the app, and that does almost nothing. Deleting an app removes it from your phone. The permission that lets that company keep pulling your transactions sits somewhere else entirely: it is a token held between the provider and your bank, and it survives the app being uninstalled. If you want the data flow to actually stop, you have to cancel it on the bank’s side.
This page shows you where that screen lives at the main UK banks, what order to do things in, and the part nobody mentions: revoking access stops future data sharing but does not delete the data the app already holds. That takes a separate request.
Why uninstalling the app is not enough
When you connected a budgeting app to your current account, you were bounced into your own bank’s app or website to approve it. Your bank then issued the provider an access token. Three things follow from that:
- The token lives with your bank and the provider, not on your handset.
- Removing the app from your phone does not tell either party anything.
- Closing your account with the provider should revoke it, but only if that provider actually processes the cancellation. Some do it instantly. Some queue it. Some have gone out of business and nobody is processing anything.
That last case is the reason to go bank-side first. Your bank’s cancel button does not depend on the other company still existing or still caring.
Do it in this order
- Cancel at your bank. This kills the token. Data sharing stops here, within a day at most.
- Then close or delete your account with the app. This deals with the account itself, any subscription and any stored profile.
- Then ask the provider to erase what it already holds. Under UK GDPR you have a right to erasure. Email their data protection contact and ask for deletion of your account information data; they have one month to respond. They can refuse to delete records they are legally required to keep, such as anti-money-laundering files, and they will usually say so.
Doing it in the other order is the common mistake. Delete the account first and you sometimes lose the login you needed to find the data deletion contact.
Where the cancel screen lives, bank by bank
Labels move between app releases, so treat these as the route rather than the literal pixels. The words to hunt for are connections, consents, open banking or third party access, and they are almost always filed under security or privacy rather than under the account itself.
| Bank | Where to look |
|---|---|
| NatWest and RBS | Online banking: Security tab, then the link to view or change consent preferences. App: profile icon, Settings, Manage connections. You will need your customer number. |
| HSBC | App or online banking, then Open Banking Connections, and cancel access for the relevant app or website. |
| Lloyds, Halifax, Bank of Scotland | Mobile app, connected accounts area in settings, withdraw consent from there. |
| Monzo | Settings, then the privacy and security area, where connected apps and their permissions are listed. |
| Barclays, Santander, Nationwide, Starling, Chase | No single documented path that stays put. Search your app’s own help for “open banking” from inside the app; the in-app search usually deep-links you straight to the consent list. |
NatWest’s own walkthrough is worth reading if you bank there, because the customer number step catches people out: it is on your online banking account summary, or in the app under More, then Need Help, then My customer number. See NatWest’s open banking support page and HSBC’s equivalent for the current wording.
If you genuinely cannot find the screen, phone the bank and say the words “I want to revoke an open banking consent”. That is a defined regulatory action and front-line staff can raise it.
What you will see when you get there
A good consent dashboard shows four things per connection, and it is worth reading all four before you start cancelling:
- Who. The regulated firm’s name, which is often not the brand name you know. Snoop-style consumer apps frequently sit behind a technical provider such as Yapily, TrueLayer or Tink, so you may see the plumbing company rather than the app.
- Which accounts. Some connections cover one current account, others cover every account and card you hold.
- What data. Balances only, or full transaction history including merchant names.
- When it expires. Consents have an end date. Older ones may already be dead.
That third point is the one to act on. If a savings comparison site has read access to your full transaction history two years after you used it once, cancel it.
The 90-day rule that used to clean this up for you
There used to be a natural expiry: every 90 days you had to re-authenticate with your bank for each connected app, and if you ignored the prompt the connection died. Drop-out at that 90-day mark ran high, which is exactly why the FCA scrapped the requirement in November 2021. Providers now only need you to reconfirm consent with them directly, which in practice is a tap on a notification.
The user experience got better. The hygiene got worse. Connections that would once have quietly lapsed now persist for as long as you keep tapping yes, and a lot of people tap yes without reading which app is asking. If you have not audited your consents since 2022, assume there are stale ones in there.
Revoking does not delete what they already have
This is the part the bank screens do not tell you. Cancelling a consent is a valve, not an eraser. Everything the provider pulled up to that moment stays in their systems under their own retention policy, and Open Banking Ltd’s own guidance points you back to the provider rather than the bank for deletion.
So if your concern is privacy rather than housekeeping, the bank-side cancel is step one of two. Step two is a written erasure request to the provider. Keep it short:
I am withdrawing consent for account information services and have revoked the connection at my bank. Please confirm deletion of the account and transaction data you hold about me, and tell me what you are retaining and under which legal obligation.
The last clause matters. It forces a specific answer rather than a template.
Before you connect the next one, check it is regulated
Everything above is easier to avoid than to unwind. Any firm reading your bank data must be authorised or registered with the FCA for account information services. Two free checks, thirty seconds each:
If the app is not on either, do not connect it. A polished website and an app store listing are not authorisation. This is also the single best defence against clone apps, which are built to look exactly like a brand you already trust.
If you are picking a budgeting app now, our notes on which apps actually link to UK bank accounts and whether budgeting apps are safe cover the same checks before you hand over access rather than after. Unsure what a term means, the money apps glossary has the short version.
What breaks when you revoke
Worth knowing before you start clicking, because some of these surprise people:
- Budgeting and net worth apps stop updating. Historic charts usually stay, new transactions stop arriving.
- Credit-building products that verify affordability by reading your account may pause or fail their next check.
- Some savings apps calculate round-ups or automated deposits from your transaction feed. Revoke the read access and the automation stops, though the money already saved is unaffected.
- Accounting software loses its bank feed and you are back to manual imports.
None of that touches your money. Read access cannot move funds. If you want the underlying detail on that split, are digital banks safe walks through what the permission actually covers.
Frequently asked questions
Does revoking open banking access close my bank account or affect my credit score? No to both. An open banking consent is a data permission sitting alongside your account. Cancelling it does not touch the account, does not appear on your credit file and is not a search. The only credit effect is indirect: if you were using a credit-builder product that reads your account to verify affordability, that product may stop working until you reconnect.
How long does it take to stop after I cancel? The token is invalidated at the point you confirm, so in practice it is immediate. Allow up to a day for the provider’s own systems to catch up and for any in-flight sync to finish. If an app is still showing fresh transactions a couple of days later, go back to the bank screen and check the connection really is gone rather than just greyed out.
Can I revoke access to one account but keep another connected? Usually yes, if the connection was set up that way. The consent dashboard lists accounts per connection, and many banks let you cancel the whole connection but not individual accounts within it. Where you cannot, the workaround is to cancel entirely and reconnect selecting only the accounts you want shared.
What if the app company has shut down? Cancel at the bank and the data flow stops regardless, which is the main reason to go bank-side. For deletion of data already held, an administrator or the acquiring company inherits the data protection obligations, so send the erasure request to whoever is listed on the old privacy policy or on Companies House filings for the firm.
Is there any way to see every connection across all my banks at once? Not from one screen. There is no central UK consent register for consumers, so you have to check each bank separately. If you hold accounts at four banks, that is four audits. Diarise it annually; most people find at least one connection they had forgotten about.
Should I revoke access before switching banks? Yes, tidy it up first. A current account switch moves payments and balances but not your open banking consents, and old consents on a closed account are messy to cancel afterwards because you may lose access to the banking login that controls them.