Financial Service Apps Meet New Google SMS Compliance Mandates
—Strategies for Credit Companies Facing Policy Tightening
During their journey of digital transformation, financial institutions are grappling with unprecedented challenges in data acquisition. As these countries strengthen personal privacy laws and public awareness of data security grows, the traditional data collection and use practices of financial institutions are coming under intense scrutiny.
This issue is particularly acute in the credit sector. Credit companies traditionally depend on extensive customer data to evaluate credit risks, verify identities, and ensure transaction accuracy. Traditional method of assessing credit data involved reading SMS content on mobile phones. There’re significant contribution to this method — Utilizing SMS content for SMS cleaning, feature engineering and model development can provide a good foundation of user risk profile. Understanding lending and repayment records through SMS can also enrich data for decision-making. However, heightened consumer awareness about data security and new app store policy requirements are now compelling financial institutions to reevaluate their data strategies within the framework of the elevated security and privacy standards.
Google Play’s regulatory policies have made it difficult for financial institutions to access SMS permissions and related data compliantly and conveniently over the past year. The challenge is particularly severe in emerging countries where trustworthy credit data sources are already scarce.
Against this backdrop, we’ve been exploring how financial institutions can overcome these data acquisition challenges in the current regulatory climate. What strategies can be adopted to both obtain the necessary data and ensure its compliance and security without relying on app installation lists and SMS?
In this article, we’ll be sharing TrustDecision’s solutions, including compliant device ID collection, advanced device risk environment detection, and capabilities for identifying fake IDs and live attacks. These solutions can help credit and digital lending companies to enhance risk management while adhering to regulatory standards.
Latest Privacy Policy Updates on Google Play
App Permission Policies
Starting from October 25, 2023, Google Play has set forth a series of platform policy adjustments targeting app developers in the Financial Services category. Together with the criteria on Mobile Unwanted Software (MUwS), malware, privacy, deception, and device abuse, Google Play has prohibited unauthorized access to device data including call logs, SMS, precise location, and installed app lists.
Goolge Play Protection
Privilege escalation is an important signal in malware detection algorithms. It refers to a situation where an attacker gains unauthorized access to the privileges or access rights of a system that are normally reserved for higher-level users, such as administrators. In most of the cases, there will be corresponding detection during and after the app is listed at the store.
Some developers may employ a Web to App (W2A) approach to circumvent the app review process, but Google offers a safeguard known as Google Play Protect. This security service automatically scans all applications installed on a device, including those not downloaded from the Google Play Store, to identify any potentially harmful activities.
Real-time protections for non-Play installs
"Google Play Protect offers protection for apps that are installed from sources outside of Google Play. When a user tries to install an app, Play Protect conducts a real-time check of the app against known harmful or malicious samples that Google Play Protect has cataloged. The app is also checked by on-device machine learning, similarity comparisons and other techniques to confirm if it's suspicious. If the app is identified as malicious or suspicious, we will warn users or block the installation in extreme cases.
Google Play Protect also offers new protections for emerging threats that were previously not scanned before. When Play Protect does not recognize any malicious code from the collected samples, it recommends a real-time code-level scan of the app to extract important signals for evaluation by Google. This helps combat novel malicious apps that may have been altered to avoid detection. If a user agrees to scan the app, they will upload the app data to Google for analysis. A short time later, Play Protect will let users know if the app appears safe to install or is potentially harmful."
Designing Solutions That DON’T Rely on Sensitive Information
In contexts where credit data coverage and effectiveness are limited, mobile device profiling and retained personal data have become crucial for assessing customer credit risk and managing risk - analyzing repayment reminders and overdue notifications from financial institutions can provide insights into customers' credit records and repayment intentions. Additionally, the frequency and type of app usage can reveal insights into customers' interests and preferences.
With the strengthen regulations and growing customer concerns about privacy protection, financial institutions must explore alternative and innovative technologies for data acquisition and analysis. For instance, using device IDs to identify and track devices ensures personal privacy is not compromised. Also, by assessing the risk environment of devices, financial institutions can indirectly evaluate customer credit risks.
Specifically, financial institutions can implement several strategies based on the basic environmental parameters of the devices used in applications:
TrustDecision‘s Global Risk Decisioning System
TrustDecision specializes in delivering advanced risk decision services. With a decade of experience in device fingerprinting, TrustDecision has accumulated substantial local device fingerprint data across the globe, especially in emerging markets such as Indonesia, the Philippines, Mexico, and Nigeria. This invaluable data, coupled with extensive expertise in fraud prevention within the credit sector, enables tailored and effective risk management solutions for each of our client.
领英推荐
As a foundational product serving key global markets, TrustDecision upholds the security and compliance of device fingerprints as the fundamental baseline and core value throughout our risk decision-making processes.
TrustDecision employs sophisticated data analytics to seamlessly merge device information with application behavior data, enabling thorough oversight and deep insights into the credit application process. Our aim is to meticulously reconstruct the entire application pathway with precision and stability, and to detect anomalies at each critical juncture through targeted feature analysis.
By addressing fraudulent applications, enhancing identity verification capabilities, and implementing advanced credit management, TrustDecision empowers clients to expand into new markets fast and secure.
In a Nutshell
In the face of increasingly stringent data protection regulations, financial institutions are encountering unprecedented challenges in accessing data. TrustDecision has observed firsthand how these institutions have adeptly navigated these hurdles through innovative strategies that optimize their data acquisition and risk management processes.
Strategic Responses
Financial institutions are pivoting from traditional data sources to alternative data and advanced analytical techniques to maintain high-quality credit services. By employing tools like device fingerprinting, behavioral analysis, and network traffic monitoring, they manage to assess credit risks effectively without compromising user privacy.
Compliance as Priority
For financial institutions, compliance is not merely a legal requirement but a crucial factor in building customer trust. TrustDecision's solutions rigorously comply with international data protection laws, ensuring that financial institutions operate within regulatory frameworks while delivering their services.
Tech Innovation as a Catalyst
Technological advancements are vital for financial institutions to adapt to shifts in the market and stay competitive. By integrating cutting-edge data analytics and machine learning technologies, these institutions can pinpoint fraudulent activities more accurately and refine their credit decision processes.
Future Outlook
Looking ahead, we anticipate the credit sector will continue to evolve towards the more intelligent and personalized direction. Financial institutions will increasingly focus on using technological means to enhance user experience while strengthening their risk management capabilities. Privacy protection and data security will become central considerations in product design.
As a leading provider of decisioning intelligence solution in the risk management space, TrustDecision is dedicated to pushing the envelope in technological innovation, offering precise and efficient tools for managing fraud, credit, and compliance risks to help our clients stay competitive in a volatile market. By developing risk management strategies that do not rely on restricted data access, we aim to foster sustainable business growth for all our clients.
Appendix