Financial inclusion depends on providing adjusted services for citizens with disclosed vulnerabilities. At the same time, the financial industry needs to adhere to a strict regulatory framework, which is often in conflict with the desire for inclusive, adaptive, privacy-preserving services. In this paper we study how this tension impacts the deployment of privacy-sensitive technologies aimed at financial inclusion. We conduct a qualitative study with banking experts to understand their perspective on service development for financial inclusion. We build and demonstrate a prototype solution based on open source decentralized identifiers and verifiable credentials software and report on feedback from the banking experts on this system. The technology is promising thanks to its selective disclosure of vulnerabilities to the full control of the individual. This support GDPR requirement, but at the same time, there is a clear tension between introducing these technologies and fulfilling other regulatory requirements, particularly with respect to `Know Your Customer.' We consider the policy implications stemming from these tensions and provide guidelines for the further design of related technologies.
翻译:同时,金融业需要坚持严格的监管框架,这往往与对包容性、适应性和隐私保护服务的愿望相冲突。在本文件中,我们研究了这种紧张关系如何影响旨在金融包容性的隐私敏感技术的部署。我们与银行专家进行定性研究,以了解他们对金融包容性服务发展的看法。我们建立并展示基于开放源分散的识别资料和可核查的认证软件的原型解决方案,并报告银行专家对该系统的反馈。由于技术有选择地披露个人受到全面控制的脆弱性,这种技术很有希望。这种支持GDPR的要求,但同时也在采用这些技术与满足其他监管要求,特别是“了解客户”方面,存在着明显的紧张关系。我们考虑这些紧张关系产生的政策影响,并为进一步设计相关技术提供指导。