Data Monetisation
Creating value from insights without violating trust or rights
Identify the value and the information involved
Data monetisation creates economic value from data capabilities. Internal improvements may reduce cost or losses; an external service may sell reporting, analytical capability or a permitted information product. Cost savings are not automatically a new accounting revenue line, and selling an insight does not make it non-personal information.
State the payer, service, source information and permitted use. Assess authority, confidentiality, privacy, customer understanding and any sector-specific obligations before designing the commercial offer. Access to data through banking operations is not unrestricted authority to sell it.
Aggregate does not necessarily mean anonymous
Removing names or replacing identifiers can leave people identifiable through transactions, locations, rare attributes or combination with other sources. Pseudonymisation can reduce risk while the information remains personal data. Aggregation needs assessment of actual outputs and recipients, including repeated queries and small groups.
The UK ICO's anonymisation guidance discusses singling out and linkability. A fixed minimum cell size alone does not prove anonymity in every context. Use appropriate generalisation, suppression, query restrictions or other measures and test residual identification risk.
Purpose and product boundaries
Different outputs create different obligations. A merchant trend report, customer-level affordability feed and marketing audience are not interchangeable products. Assess the lawful basis, notices, permissions and recipient role for each. Consent is one possible basis in some regimes, not a universal substitute for all other conditions.
If future access depends on a permission that is withdrawn, enforce the relevant change at delivery and downstream systems. Distinguish stopping future collection or sharing from deletion of records already held. Retention, recipient duties and other lawful processing require their own assessment.
Contracts and controls
Define permitted uses, onward sharing, security, retention, audit and incident handling. Contract promises need enforceable controls and assurance proportionate to risk. A clause alone cannot prove the recipient never misuses delivered information.
Use access controls, rate and query restrictions where relevant, versioned output definitions and delivery logs with appropriate minimisation. Consider how to suspend the service and inform recipients when an output is inaccurate or a permission changes. Do not assume every external score can be withdrawn from every decision after delivery.
Worked example: merchant insights
In this fictional reporting service, merchants receive local spending trends. A proposed filter isolates a very small group, and combining repeated reports could reveal an individual's activity. The team broadens categories, limits overlapping queries and reviews identification risk before release.
The commercial forecast includes privacy engineering, quality assurance, support and contractual restrictions. A larger forecast built on individual targeting would describe a different product requiring separate assessment. The report's value is useful trend information within its permitted scope, not access to unrestricted customer histories.
Income, quality and monitoring
Tie pricing and recognised income to the applicable contract and delivery obligation. Reconcile billable reports or service periods to finance records. Costs, concentration and possible regulatory changes belong in scenario analysis; there is no universal requirement to net a generic regulatory buffer against statutory revenue.
Monitor stale or inaccurate outputs, recipient use, access anomalies, privacy incidents and complaints. Validate that the product remains useful after necessary privacy protections. Review new filters, recipients or data sources as changes to the actual information product.
Takeaway
Data creates sustainable value when its use is permitted, its outputs are reliable and identification risk is controlled. A commercial label does not change the rights attached to the underlying information.
Continue to Responsible AI in Digital Banking.