Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Cross-Border Financial Data Sharing in Fintech: Legal and Operational Challenges

Racheal B Akinloye

Abstract

In the globalized financial sector, fintech companies routinely collect and transfer data across international borders. However, these activities face significant legal challenges, particularly regarding data privacy and security. A key issue is the fragmentation of regulatory frameworks worldwide. For example, U.S. regulations—including the Patriot Act, Consumer Financial Protection Act (CFPA), the Gramm-Leach-Bliley Act (GLBA), the Bank Secrecy Act (BSA) with Anti-Money Laundering (AML) requirements, and the California Consumer Privacy Act (CCPA)—contrast significantly with international standards like the European Union's General Data Protection Regulation (GDPR). Additionally, operational challenges such as cybersecurity risks, cross-jurisdictional licensing, compliance issues, and technological incompatibilities further hinder data sharing. Specific U.S. regulations around data localization and international data flows create unique obstacles for fintech firms. This paper also explores how technological advancements, such as blockchain, are fueling the demand for secure, efficient, and seamless cross-border data exchange in the fintech sector. To address these issues, the paper proposes several solutions, including global regulatory harmonization, the adoption of advanced technologies to bolster data protection, and the establishment of robust compliance frameworks for AML and Know Your Customer (KYC) processes.

Keywords

Cross-borderFinancial data sharingFinTech.

References

BOOKS ? Casalini F, González JL, Trade and Cross-border Data Flows (OECD 2019). ? John W. Rittinghouse and James F Ransome, Cloud Computing: Implementation, Management, and Security (CRC Press, 2017) ? Solove DJ & Schwartz PM, Information Privacy Law (8th Ed., Aspen Publishing, 2023). ? Spiezia V, and Tscheke J, International Agreements on Cross-border Data Flows and International Trade: A Statistical Analysis (OECD 2020). ? Voigt P, and Bussche AV, The EU General Data Protection Regulation (GDPR): A Practical Guide, 1st edn (Springer International Publishing 2017). CHAPTER IN BOOKS ? Dlodlo N, ‘Legal, Privacy, Security, Access and Regulatory Issues in Cloud Computing’ in Proceedings of the European Conference on Information Management & Evaluation (2011) 161-168. ? Wali G, and Bulla C, ‘Suspicious Activity Detection Model in Bank Transactions Using Deep Learning with Fog Computing Infrastructure’ in International Conference on Computational Innovations and Emerging Trends (ICCIET-2024) (2024) 292-302. JOURNAL ARTICLES ? Aaronson SA, ‘Data Is Different, and That’s Why the World Needs a New Approach to Governing Cross-border Data Flows’ (2019) 21(5) Digital Policy, Regulation and Governance 441-460 ? Abdullah Al Mamun, M Kabir Hassan, and Van Son Lai, ‘The Impact of the Gramm- Leach-Bliley Act on the Financial Service Industry, September (2004) 28(3), Journal of Economics and Finance, 333-347 ? Addae JH, Brown M, Sun X, Towey D, and Radenkovic M, ‘Measuring Attitude Towards Personal Data for Adaptive Cybersecurity’ (2017) 25(5) Information & Computer Security 560–579. ? Aidonojie P, Majekodunmi T, & Adeyemi-Balogun O, ‘The Legal Issues Concerning the Operation of Fin-Tech in Nigeria’, (2003) 30(2) Jurnal Media Hukum, 78. ? Bakare SS, and others, ‘Data Privacy Laws and Compliance: A Comparative Review of the EU GDPR and USA Regulations’ (2024) 5(3) Computer Science & IT Research Journal 528. ? Balakrishnan A, Jain V, Chintale P, Gadiparthi S, Najana M, ‘Blockchain Empowerment in Sanctions and AML Compliance: A Transparent Approach’ (2024) International Journal of Computer Trends and Technology ? Balkin JM, ‘The Fiduciary Model of Privacy’ (2020) 134 Harvard Law Review Forum 11 ? Bohmecke-Schwafert m, “The role of blockchain for trade in global value chains: A systematic literature review and guidance for future research” (2024) 48(9) Telecommunications Policy 1. ? Bradford L, Aboy M, Liddell K, ‘Standard Contractual Clauses for Cross-border Transfers of Health Data After Schrems II’ (2021) 8(1) Journal of Law and the Biosciences lsab007 ? Brkan M, ‘Data Protection and Conflict-of-Laws: A Challenging Relationship’ (2016) 2 European Data Protection Law Review 324 ? Bryssinck J, Jacobs T, Simini F, Doddasomayajula R, Koder M, Curbera F, Vishwanath V, Neti C, ‘Harnessing Synthetic Data to Address Fraud in Cross-Border Payments’ (2024) 18 Journal of Payments Strategy & Systems 261-275 ? Bygrave LA, ‘Privacy and Data Protection in an International Perspective’ (2010) 56(8) Scandinavian Studies in Law 165-200 ? Chankil P, Choi Y, Lee C, ‘Secure Multi-Party Computation of Technology Fin-tech’ (2019) 15 Journal of Korea Society of Digital Industry and Information Management 61- 66 ? Chia-Hung L, Guan X-Q, Cheng J-H, Yuan S-M, ‘Blockchain-Based Identity Management and Access Control Framework for Open Banking Ecosystem’ (2022) 135 Future Generation Computer Systems 450-466 ? Christopher L Peterson, Consumer Financial Protection Bureau Law Enforcement: An Empirical Review, 90 (2016) 1057 Tulane Law Review, (2016) 1. ? Clare S, ‘EU GDPR or APEC CBPR? A Comparative Analysis of the Approach of the EU and APEC to Cross Border Data Transfers and Protection of Personal Data in the IoT Era’ (2019) 35(4) Computer Law & Security Review 380-397 ? David Nkang Odu, ‘Impact of AML/CFT regulations on digital disruptions (FinTech) and financial inclusion in Sub-Saharan Africa,’ (2020) 44(2) Bullion, 1. ? Del Alamo JM, Guamán DS, Caiza JC, ‘GDPR Compliance Assessment for Cross-border Personal Data Transfers in Android Apps’ (2021) 9 IEEE Access 15961-15982 ? Dirk A Zetzsche, Anker-Sørensen L, Passador ML, Wehrli A, ‘DLT-Based Enhancement of Cross-Border Payment Efficiency: A Legal and Regulatory Perspective’ (2021) 15 Law and Financial Markets Review 70-115 ? FDIC, ‘Bank Secrecy Act / Anti-Money Laundering (BSA/AML)’ (2024). Retrieved from <https://www.fdic.gov/banker-resource-center/bank-secrecy-act-anti-money-laundering- bsaaml> accessed 21 October, 2024. ? Feyen R and others, ‘Fintech and the digital transformation of financial services: implications for market structure and public policy’ (Bank for International Settlements and the World Bank Group 2021) ? Foad Nahai, 'General Data Protection Regulation (GDPR) and Data Breaches: What You Should Know' (2019) 39(2) Aesthetic Surgery Journal 238-240 ? Gehan Gunasekara, ‘The “Final” Privacy Frontier? Regulating Trans-border Data Flows’ (2009) 17(2) International Journal of Law and Information Technology 147-179 ? Gu Zheng, 'Trilemma and Tripartition: The Regulatory Paradigms of Cross-border Personal Data Transfer in the EU, the US and China' (2021) 43 Computer Law & Security Review 105610 ? He, ‘Fintech and Cross-Border Payments’ (2017) International Monetary Fund ? Hoofnagle CJ, B van der Sloot, & Borgesius FZ, ‘The European Union general data protection regulation: what it is and what it means’ (2019) 28(1) Information & Communications Technology Law, 65. ? Kamaal Zaidi, ‘Harmonizing US-EU Online Privacy Laws: Toward a US Comprehensive Regime for the Protection of Personal Data’ (2003) 12 Michigan State University Journal of International Law 169 ? Keyani C, ‘Lawfare and US Economic Supremacy: The Bank Secrecy Act, FCPA, USA PATRIOT Act, and OFAC Sanctions’ (2023) 1(1) Ohio Northern University International Law Journal 3 ? Klar M, ‘Binding Effects of the European General Data Protection Regulation (GDPR) on US Companies’ (2020) 11 Hastings Science & Technology Law Journal 101 ? Kong L, 'Data Protection and Transborder Data Flow in the European and Global Context' (2010) 21(2) European Journal of International Law 441-456 ? Liao C-H, Guan X-Q, Cheng J-H, Yuan S-M, ‘Blockchain-Based Identity Management and Access Control Framework for Open Banking Ecosystem’ (2022) 135 Future Generation Computer Systems 450-466 ? Lingjie Kong, 'Data Protection and Transborder Data Flow in the European and Global Context' (2010) 21(2) European Journal of International Law 441-456 ? Manuel Klar, ‘Binding Effects of the European General Data Protection Regulation (GDPR) on US Companies’ (2020) 11 Hastings Science & Technology Law Journal 101 ? Matthiesen S, Bjørn P, ‘Why Replacing Legacy Systems Is So Hard in Global Software Development: An Information Infrastructure Perspective’ (2015) Proceedings of the 18th ACM Conference on Computer Supported Cooperative Work & Social Computing 876- 890 ? Meltzer JP, ‘The Internet, Cross?Border Data Flows and International Trade’ (2015) 2(1) Asia & the Pacific Policy Studies 90-102 ? Mitchell AD and Mishra N, Cross-Border Data Regulatory Frameworks: Opportunities, Challenges, and a Future- Forward Agenda, (2024) 34(4) Fordham Intell. Prop. Media & Ent. L.J. 842 ? Mitchell AD, Hepburn J, 'Don't Fence Me In: Reforming Trade and Investment Law to Better Facilitate Cross-border Data Transfer' (2017) 19 Yale Journal of Law & Technology 182 ? Mitchell AD, Mishra N, 'Regulating Cross-border Data Flows in a Data-driven World: How WTO Law Can Contribute' (2019) 22(3) Journal of International Economic Law 389- 416 ? Moslemzadeh Tehrani P, Sabaruddin JH, Ramanathan DAP, ‘Cross Border Data Transfer: Complexity of Adequate Protection and Its Exceptions’ (2018) 34(3) Computer Law & Security Revie

More Articles from IIARD INTERNATIONAL JOURNAL OF BANKING AND FINANCE RESEARCH

Effect of Monetary Policy on Profitability of Deposit Money Banks in Nigeria

Author: Stephanie Nguhemen Gbande, Mike T. Soomiyol, Timothy Tyona, Gaius Msendoo Asombo

Cognitive Diversity and Performance of Deposit Money Banks in Nigeria

Author: 1Nwangwu, Okwudiri Iheanyi, 2 Pepple, Grace Jamie PhD

Banking Innovations and Industrial Sector Performance in Nigeria: Evidence from ARDL Model

Author: Peter Ngbede Ajam, Abiodun Edward Adelegan, Benson Emmanuel

Environmental Sustainability and Entrepreneurial Performance in Nigeria: A Case Study of Enugu State

Author: i, Azolike Nkiru Nkechi, ii, Okwor Emmanuel Ejimnkonye, iii, Eneaniofu Daniel Mmaduakonam