top of page

Why sharing vulnerability data matters across financial services

jonathan79727
4 hours ago
3 min read

People rarely experience financial services as a single, self-contained interaction. Their journey may involve an adviser, broker, lender, insurer, product provider, administrator or outsourced service partner (or a combination of some/all of these). If relevant vulnerability information remains trapped within one part of that journey, the support a customer needs can disappear at the next handover.

That can lead to customers having to repeat difficult personal circumstances, receiving unsuitable communications or being asked to complete processes that do not reflect their needs. In more serious cases, it can expose them to avoidable harm.

Sharing vulnerability data appropriately can help prevent this.


A clearer regulatory position

The FCA and ICO have provided welcome clarity on this issue. Their joint statement, published in March 2026, confirms that data protection law does not prevent firms from using or sharing personal information where this is appropriate and necessary to protect customers or provide the support they need. Firms must, of course, continue to meet their data protection obligations.

The Consumer Duty also expects firms across a distribution chain to work collaboratively and share relevant information where necessary to deliver good outcomes. This applies across banking, wealth management, mortgages, insurance, pensions, motor finance, consumer credit and payments.

The question is therefore less about whether vulnerability data can ever be shared and more about what information should be shared, for what purpose and with whom.


Creating continuity of support

Effective data sharing allows a customer’s identified needs to follow them through the financial services journey.

For example, a broker or intermediary may identify that a customer needs information in a different format, more time to make decisions or support from a trusted third party. Passing that relevant information securely to the lender or provider can help ensure those adjustments continue after the initial interaction.

Without this continuity, each firm sees only part of the customer’s circumstances. Support becomes inconsistent, and the customer carries the burden of explaining their needs repeatedly.

The FCA has highlighted that knowing how to record and access vulnerability information enables firms to respond promptly, consistently and fairly. It also warns that, without this information, customer service and communications may fail to meet customers’ needs.


Individual and aggregated data serve different purposes

There is an important distinction between sharing information about an individual customer and sharing aggregated insight.

Individual information may need to be shared where another firm requires it to provide appropriate support or prevent foreseeable harm. Only information that is relevant and necessary should be transferred.

Aggregated or effectively anonymised data can support a broader purpose. It can help manufacturers, providers and distributors understand whether customers in vulnerable circumstances are experiencing different outcomes, identify recurring problems and improve products, communications and support processes.

This matters because the FCA found that most firms in its outcomes-monitoring work could not demonstrate how they effectively monitored and acted on the outcomes experienced by customers in vulnerable circumstances. Firms performing well tended to use good-quality data, establish clear escalation processes and evidence the improvements they made.


Sharing responsibly

Vulnerability data can be sensitive, particularly where it relates to a customer’s physical or mental health. A responsible approach should include:

  • a clear and documented purpose for sharing;

  • an appropriate lawful basis and, where required, a special-category condition;

  • transparency with customers about how their information will be used;

  • sharing only the minimum information required;

  • controls to maintain accuracy and restrict access;

  • secure methods of transfer;

  • appropriate retention periods; and

  • clear agreements between the organisations involved.

Firms should also consider whether a data protection impact assessment (DPIA) is required and ensure customers can update information when their circumstances change.


A connected approach

At Comentis, we believe identifying vulnerability is only the first step. The information gathered must lead to appropriate action and, where necessary, follow the customer securely across the financial services journey.

Done well, vulnerability data sharing reduces repeated disclosure, creates more consistent support and gives firms stronger evidence that customers in vulnerable circumstances are receiving outcomes comparable with other customers.

That is better for the customer, better for the firms involved and central to meeting the expectations of the Consumer Duty.

Comments


bottom of page