Skip to content

Privacy and security of iDIN

Published on:

Dutch banks are making iDIN widely available to online shops, companies and organisations, referred to as participating organisations. This raises questions for some people about the security and protection of bank customers’ personal and financial data when they use this online identification and login method.
A detailed answer is available on the iDIN website (in Dutch)(opens in new window) .

Screen from DEMO Bank on which the customer agrees via iDIN to share address details with the Happy Cat Shop webshop.

iDIN is as secure as iDEAL

The banks offering iDIN have more than ten years of experience securing iDEAL. That security has proven itself extensively and is regarded as highly robust and reliable. As iDIN builds on many years of online banking experience and iDEAL’s proven technology, it benefits from the same strong security.

No access to customers’ financial data

iDIN does not provide customers’ financial data, such as balances or payment details. It shares only limited personal data about an individual bank customer with a participating organisation: gender, name, address and an age indication or date of birth. The bank already knows this information from when the customer opened their account.

Whenever a participating organisation asks a bank through iDIN to provide a customer’s personal data, the customer is shown exactly which data are being requested. The bank may send the data only after the customer has given explicit approval.

No access to customer activity at participating organisations

Banks do not receive information from participating organisations about what their customers otherwise do or see on those organisations’ websites. Banks therefore cannot see which pages their customers visit there or which actions and orders they carry out.

When customers choose to identify themselves or log in with iDIN on a participating organisation’s website, they are redirected to a secure iDIN page at their own bank. After approving identification or login with iDIN at the bank, the customer is returned to the participating organisation’s website. A bank has no direct access to the organisation’s systems or website, just as a participating organisation has no direct access to a bank’s systems or website. iDIN exchanges only securely encrypted data between the bank and participating organisation: the data for which the customer has given consent.

Banks’ privacy commitments

All banks offering iDIN promise to handle their customers’ personal and usage data carefully and confidentially. They will not provide those data to third parties unless legally required to do so, and will not use data about iDIN usage for their own commercial purposes.

Related articles