Introduction: the document that knows you better than your family
Imagine being asked to sum up your life in three pages. You would talk about your job, the people close to you, your tastes. Now imagine that someone took twelve months of your bank statements instead. The result would be infinitely more precise.
It would reveal the time you buy your coffee, and therefore the time you leave for work. The pharmacy you visit every three months. The medical testing lab on 14 March. The A10 motorway toll every other Friday evening — the sign of shared custody. The subscription to a union, a political party, a place of worship. The monthly transfer to a care home. The abrupt change of delivery address in June, the rent dropping from €1,100 to €650, the joint account becoming a sole account: a separation, dated to the day.

No other file about you reaches this level of granularity. And unlike your medical records or your criminal record, your financial history is not locked away in a safe: it circulates. It is analysed by anti-fraud algorithms, scored to grant or refuse you credit, sometimes exploited by "budget management" services, consulted by the tax authorities, and kept for years after the account is closed.
This guide takes stock of what is actually recorded when you pay, details who has the right to look and for how long, then offers concrete steps to regain a measure of privacy over your money — without stepping outside the legal framework, which in France imposes strict traceability rules.
Part 1 — The inventory: what a transaction really records
The statement you see, and the one you don't
In your app, a card payment line shows three things: a date, a merchant label, an amount. In the systems of your bank and the payment network, the same operation carries a great deal more:
| Data | Shown on your statement | Kept internally |
|---|---|---|
| Precise date and time (to the second) | No (date only) | Yes |
| Terminal / merchant identifier | Partially | Yes |
| Merchant category code | No | Yes |
| Location of the point of sale | No | Yes |
| Authentication method (PIN, contactless, 3-D Secure) | No | Yes |
| Device and IP address for an online payment | No | Yes |
| Anti-fraud risk score assigned to the operation | No | Yes |
The category code deserves a special mention. Every merchant is attached to a standardised category. This means a system can sort your spending by type — healthcare, gambling, bars, donations — without even reading the labels. It is the foundation of every "automatic spending categorisation" feature that banks present as a service.
The bank transfer: the chattiest free-text field in the banking system
A SEPA transfer carries a free-text reference field of 140 characters. It is not encrypted, it is not ephemeral, and it is readable by both banks, by the beneficiary and by anyone with access to either party's statement.
That is where you find, in plain text: "abortion contribution", "divorce lawyer", "2026 membership fee", "sublet deposit refund", "birthday present for Clara — don't tell". On a joint account, that reference is visible to the co-holder, for life. On a business account, it is visible to the accountant. Simple rule: write in a transfer reference only what you would be happy to see displayed on a screen you don't control.
Contactless and mobile payments
Contactless payment does not transmit "less" data: it transmits just as much, simply faster. Paying by phone actually adds more: the device used, its operating system, sometimes its location if the payment app has access to it. You are paying through two intermediaries instead of one — your bank and the wallet provider.
If that extra layer bothers you, the fix is mundane: keep a physical card for everyday use and disable the mobile wallet. Many readers also keep that card in an RFID-blocking sleeve, not so much out of fear of data theft — remote contactless fraud remains marginal — as to avoid accidental charges when brushing past a terminal on public transport.
Cash: the last untraceable payment method, and its limits
In France, cash payment remains legal and anonymous, but it is capped: €1,000 for an individual who is a French tax resident paying a business (article D112-3 of the Monetary and Financial Code), €15,000 for a non-resident. Above that, payment must go through a traceable method. Large, repeated withdrawals also trigger vigilance alerts at your bank.
Cash therefore remains the simplest privacy tool for day-to-day spending — pharmacy, bookshop, donations, gifts — provided you accept that it also makes you more vulnerable to loss or theft.
Part 2 — Who reads your transactions, and why
Your bank, for five different reasons
- To execute the operation. Legal basis: the contract.
- To fight fraud. Models analyse every payment in real time: unusual amount, country, time of day, sequence. That is why a card gets blocked at 3 a.m. for a €9 purchase abroad.
- To comply with anti-money-laundering rules (AML/CFT). Articles L561-1 et seq. of the Monetary and Financial Code require banks to maintain constant vigilance, to obtain evidence of the origin of funds and, where appropriate, to file a suspicious activity report with Tracfin. That report is never disclosed to you: the law forbids informing the customer.
- To assess your credit risk. Before a loan, your account history is analysed: overdrafts, incidents, maintenance payments, irregular income, gambling spend.
- To sell you products. This is the only use that requires your consent and that you can refuse without any consequence for your contract.
The State, in specific cases
French "banking secrecy" (article L511-33) protects your information from private third parties, but it is lifted for several authorities: the tax administration via its right of communication, customs, URSSAF, investigating magistrates, over-indebtedness commissions.
Two registers maintained by the Banque de France carry the heaviest consequences:
- the FICP (national register of consumer credit repayment incidents): entry in the event of unpaid credit instalments or an over-indebtedness case, generally for 5 years, and up to 7 years for an over-indebtedness plan;
- the FCC (central cheque register): bounced cheque, 5 years, or withdrawal of a payment card for improper use, 2 years.
These registers can be consulted: you can ask whether you are listed, free of charge, by going to a Banque de France branch with proof of identity, or by post. Never pay for that information.

Aggregators, the blind spot of PSD2
Since the European Payment Services Directive (PSD2), licensed providers can, with your agreement, connect to your accounts to read their history. That is what allows budgeting apps, insurance comparison sites, credit brokers and some landlords to "verify your income in one click".
The mechanism is legal and supervised by the ACPR. The problem is the scope of consent: by authorising the connection to prove an income, you often grant access to every single line of your accounts over 12, 24 or 36 months. The landlord who only wanted to check a salary also sees your healthcare spending and your subscriptions.
Before accepting this kind of connection, ask three questions: which periods, which accounts, and how to revoke. Access must be renewed periodically and you can withdraw it at any time, from your bank's customer area (a section often labelled "aggregation" or "third-party apps"). Do it as soon as the process is complete.
Part 3 — How long all of this is kept
Retention periods are not left to banks' discretion: they derive from the Monetary and Financial Code, the Commercial Code and the CNIL's positions.
| Data | Usual retention period |
|---|---|
| Operations and statements | 5 years after execution (evidence, AML/CFT) |
| Identity documents and onboarding evidence | 5 years after the end of the relationship |
| Account closure data | 5 years after closure, then intermediate archiving |
| Commercial prospecting information | 3 years after the last contact |
| Telephone call recordings | a few weeks to 5 years depending on purpose |
| In-branch video surveillance | 30 days in principle |
Practical consequence: asking for your transaction history to be erased will not work. The right to erasure under article 17 of the GDPR gives way to a legal retention obligation. On the other hand, you can demand the erasure of whatever is not mandatory: commercial profiles, marketing scores, in-app browsing history, inclusion on prospecting lists.
Key takeaway: with a bank account, the lever is not erasure, it is limiting uses and recipients.
Part 4 — Your rights, and how to exercise them effectively
The right of access, to see what exists
Send your bank's data protection officer (DPO) an access request based on article 15 of the GDPR. Word it precisely, otherwise you will receive a copy of statements you already have. Ask for:
- the list of categories of data held and their retention periods;
- the recipients (processors, subsidiaries, insurers, aggregators, scoring organisations);
- the existence of any automated decision concerning you, and the logic behind it (article 22 of the GDPR);
- any marketing categories or segments you have been assigned to.
The bank has one month to reply, extendable by two months for complex requests. If there is no reply, filing a complaint with the CNIL is free and can be done online.
Refusing a fully automated decision
A refusal of credit, of a card or of an account opening produced by an algorithm alone can be challenged: you have the right to obtain human intervention and an explanation. Say so explicitly in your letter, citing article 22.
The right to an account, when every door closes
If a bank refuses to open an account for you, you can apply to the Banque de France under the right to a bank account (article L312-1 of the Monetary and Financial Code): an institution will be designated and must provide you with basic banking services. This right also applies to people listed in the FICP.
Your documents, at home
Part of your exposure comes not from banks but from your own paperwork: annotated statements left on a desk, pre-filled credit offers thrown out as they are, old chequebooks. A cross-cut shredder and a lockable archive box settle the matter for a few tens of euros, and prevent a complete statement — account number, IBAN, habits — from ending up intact in a recycling bin.
Part 5 — The steps that really make a difference
Compartmentalise your accounts
The most effective principle is separating uses, just as you separate email addresses:
- a main account for income, rent, heavy direct debits;
- a secondary account or card for online purchases and subscriptions;
- a joint account strictly limited to shared expenses, so that every personal purchase doesn't become a topic of conversation.
Use single-use virtual cards
Most French banks offer a temporary card number service, sometimes capped and limited to a single merchant. The benefit is twofold: if the merchant suffers a data breach, the number is useless; and a subscription cannot renew itself behind your back.
Clean up your direct debit mandates
Once a year, review the list of your SEPA mandates in your online banking. You often find authorisations forgotten years ago. Revoking a pointless mandate also removes a company's reason to keep processing your IBAN.
Opt out of marketing, properly
In your customer area settings, untick commercial uses and profile enrichment. Register with Bloctel for telephone cold calling. And be aware that using your transaction data for advertising purposes requires separate consent: it can be withdrawn.

Manage your access without weakening it
Multiplying accounts only makes sense if access stays robust. A password manager stops you reusing the same code everywhere, and a physical security key protects your most sensitive accounts against SMS code theft. For those who want to understand the mechanics before acting, a practical guide to personal data protection remains a good investment: most banking mistakes are not technical, they are organisational.
Communicate without revealing everything
A negotiation with a seller, a classified ad between individuals, a dispute: it is not always desirable to tie your personal number to a transaction. A text message with a masked sender lets you send a one-off piece of information without handing over your number, which today serves as the pivot identifier between databases.
Conclusion: privacy does not mean opacity
Banking traceability is not an aberration: it protects against fraud, money laundering and abuse, and it serves as evidence when a dispute arises. The reasonable goal is therefore not financial invisibility — it is illegal beyond certain thresholds and would cut you off from the system.
The goal is more modest and more achievable: making sure that every piece of information about your money goes only to the people who have a reason to know it. That plays out in a handful of concrete decisions: what you write in a transfer reference, to whom you open your accounts via an aggregator, which boxes you untick, which papers you destroy.
Three things to do this week
- Open the list of third-party apps connected to your accounts and revoke everything that is no longer active.
- Disable the commercial uses of your data in your customer area, then send an access request to the DPO.
- Check free of charge with the Banque de France whether you are listed in the FICP or the FCC — and never pay a service that claims it can "delist" you.
Further reading
- CNIL — "banking and credit sector" fact sheets, retention periods, right of access (cnil.fr)
- Banque de France — right of access to the FICP and FCC, right to a bank account (banque-france.fr)
- ACPR — register of account information service providers
- Tracfin — annual activity reports
- Monetary and Financial Code — articles L511-33 (banking secrecy), L561-1 et seq. (AML/CFT), D112-3 (cash payment cap), on legifrance.gouv.fr



