As technology transforms the financial sector, identity proofing and authentication have become essential first steps in delivering digital financial services. As Your Data takes on a growing role, this journey can help create more seamless and personalized financial experiences.
For financial institutions, digital services begin with a fundamental question: Who is the customer? Opening an account, applying for a loan, investing, or completing an online transaction all require a process to verify that the customer is who they claim to be.
This is where e-KYC and Digital Identity technologies, such as NDID and ThaID, play an important role. They support Digital Onboarding and Customer Journeys by enabling identity proofing and authentication through digital channels based on the service, risk level, and relevant requirements.
However, as digital services evolve beyond simply signing up for or activating a service, the questions businesses need to answer begin to expand as well.
Today, the challenge no longer stops at asking:
“Who is the customer?”
It is now expanding to questions such as:
“What data is the customer granting
access to,and how will that data be used
within the service?”
This is where Digital Identity, Authentication, Consent, and Data Sharing begin to converge, making Your Data increasingly important to the development of Thailand’s financial Data Ecosystem.
The Your Data initiative is one of the key mechanisms supporting this ecosystem. It enables service providers, organizations, systems, and technologies to connect and exchange data in a structured manner, based on the rights and consent of data owners.
By enabling more effective access to and use of data, Your Data can support new data-driven services and innovation, particularly in the financial sector. It also has the potential to play an important role in the future of Thailand’s broader Digital Ecosystem.
What Is the Your Data Initiative?
The Your Data initiative is a collaborative initiative led by the Bank of Thailand (BOT) in partnership with 22 organizations and agencies. These include the Ministry of Finance, the Securities and Exchange Commission (SEC), the Office of Insurance Commission (OIC), the Revenue Department, the Digital Government Development Agency (DGA), electricity and water utilities, as well as various financial industry associations.
Through secure and convenient digital channels, individuals can share relevant data to access financial services that are more personalized and better suited to their needs.
![]()
The initiative brings together government agencies to establish secure mechanisms for data exchange within and beyond the financial sector. By supporting effective risk management and secure data sharing, it can help enable financial services that better meet the needs of individuals and businesses while supporting the growth of the digital economy.
With regulated service providers already capable of developing services at scale, Your Data has the potential to support new use cases across lending, investment, insurance, and financial planning.
This shift not only transforms the user experience but also requires businesses to take a more integrated approach to Identity and Data Sharing. Data sharing is more than simply transmitting information between systems. It also involves verifying who is requesting access, what data is being shared, and for what purpose.
From this perspective, Your Data is more than a Data Sharing initiative. It brings together Identity, Authentication, Consent, and Data Sharing to enable the secure and appropriate transfer and use of data.
For businesses, the question is no longer simply “Can our systems exchange data?” It is about designing the entire process—from identifying and authenticating users to managing consent, transferring data, and using it effectively within internal systems—while meeting relevant requirements.
The Bank of Thailand has also published the Your Data Project Guidelines o support the exercise of data-sharing rights within the financial sector. This reflects how the concept of Data Portability is beginning to move toward practical implementation and is likely to become another important component of the financial sector’s broader Digital Ecosystem.

From Identity to Consent and Data Sharing: Connecting eKYC, ThaID, NDID, and Your Data
As digital services access and exchange data from multiple sources, Digital Identity is no longer limited to onboarding. Before data can be accessed or shared, the system must answer several key questions.
– Who is taking the action?
The system must identify and authenticate the person requesting access to or authorizing the sharing of data.
– Is that person authorized?
For business services, the system may also need to determine whether the individual has the authority to act on behalf of a legal entity.
– What data has the user consented to share?
Users should clearly understand what data they are authorizing, who it will be shared with, and for what purpose.
– How is the data transferred and used?
Businesses need appropriate processes for Data Integration, Access Control, and Data Security, based on the service and relevant requirements.
– Can the process be audited?
As more systems become connected, businesses need to track who performed an action, what was done, when it happened, and how the process was completed. This makes Digital Identity a critical layer connecting Authentication, Consent Management, Data Security, and Audit Trails.
This is where NDID and ThaID become increasingly important within Data Ecosystems such as Your Data. Exercising the right to share data does not remove the need for identity verification. The system must still confirm that the person taking the action is the data owner or has the authority to use that data.
Modern digital financial journeys can therefore be viewed as two connected stages:
- Identity Verification: Users can verify their identity through e-KYC, NDID, ThaID, or other appropriate Digital Identity methods, depending on the service and requirements.
- Data Sharing: Once identified and authenticated, users can provide Consent to share relevant data through Your Data and other data-sharing services.
Together, these processes make Data Sharing more than a connection between systems. They create an end-to-end journey that connects Identity, Authentication, Authorization, Consent, and Data Sharing.
From Concept to Real-World Implementation
Several commercial banks have already announced the availability of data receiving and sharing services under the Bank of Thailand’s Your Data initiative, while others are currently preparing to launch their services in the near future. These include:
- Kasikornbank
- Krungthai Bank
- Bangkok Bank
- TMBThanachart Bank (ttb)
- Kiatnakin Phatra Bank (KKP)
- LH Bank
- TISCO Bank
- Siam Commercial Bank (SCB)
These banks act as Data Providers and/or Data Recipients, with their roles and service details outlined below:
| Types of Data That Users Can Choose to Share with Their Consent |
Digital Data Transfer Mechanism |
|
| Data Category | Data Details | |
| Deposit Accounts |
|
Users can exercise their |
| e-Money Payments |
|
|
| Credit Card Payments |
|
|
| Loan Accounts |
|
Users may also exercise their right to share financial data held by their bank with other service providers through channels provided by the National Credit Bureau (NCB). |
* The types of data that users can choose to share or request may vary by bank. Please refer to each bank’s website for specific details and applicable terms and conditions.
** The information and details regarding the available data receiving and sharing channels may change in the future. Users can refer to the respective banks’ websites or the Bank of Thailand’s Your Data project website for the latest information.
What Should Businesses Prepare for as the Digital Identity Ecosystem Expands?
Even if a business starts with a single use case—such as NDID integration or e-KYC—the Customer Journey often becomes more complex as the service grows. As the Digital Identity Ecosystem evolves, businesses should consider the following.
1. Design the Identity Journey Before Choosing the Technology
Start with the Customer Journey. Consider who the customer is, how they access the service, and what level of identity verification or authentication is required at each stage. Then determine whether NDID, e-KYC, Dip Chip, ePassport, or other methods are best suited to each use case.
2. Prepare an Alternative Flow
Not every customer can use the same channel. Businesses should plan for alternative processes when customers cannot complete the primary flow. A well-designed Alternative Flow can prevent the Customer Journey from stopping and reduce unnecessary customer drop-off.
3. Consider Both KYC and KYB
Businesses serving both individuals and legal entities need to support both KYC and KYB. Verifying an individual may not be enough when the service also needs to consider organizational information, relationships, and the authority to act on behalf of a legal entity.
4. Make Consent Part of the Product Experience
Consent should not be treated as a legal notice that users simply scroll through and click “Accept.” As services access or receive user data, businesses should ensure that users understand what they are authorizing, how their data will be used, and how it may affect the service.
5. Prepare Systems for Integration and Auditability
As Identity, Consent, and Data Sharing become more interconnected, systems need to support more than data exchange. Organizations should consider Data Flows, Access Control, Security, and Audit Trails from the design stage, making it easier to scale without redesigning the entire process.
Examples of areas businesses should prepare for include:
- Verifying the identity of the data owner
- Managing Consent and data-sharing permissions
- Identifying the types of data being shared and the purpose of sharing
- Integrating data with relevant systems
- Ensuring data security and proper data management
- Maintaining auditability and traceability throughout the process
Preparing for Your Data: Where BeID Fits In
BeID helps businesses design and develop Digital Identity solutions that align with the specific Use Cases and Customer Journeys of their organizations.
With expertise in NDID and Digital Identity, BeID can support businesses in designing and integrating solutions tailored to different use cases—from connecting to the NDID network in the roles of IdP, RP, and AS to implementing technologies and processes related to Digital Identity, including e-KYC, Dip Chip, ePassport, ICAO PKD Integration, Liveness Detection, Facial Recognition, KYB, Authentication, and Consent Management.
Our goal is not simply to help businesses
implement a system that can
“verify identity.” It is to make
identity proofing and authentication
an integral part of a service that
worksin the real world—and is ready
to evolve as the Data Ecosystem
continues to change.
If you are looking for an end-to-end consulting and development partner for Onboarding and e-KYC solutions that meet IAL 2.3 standards for both individuals and legal entities, BeID can help you build more secure and scalable digital services. Contact Us for a consultation today.
Source:
Information about the Your Data initiative and the guidelines for exercising data-sharing rights is based on the following sources:
- ธนาคารแห่งประเทศไทย: โครงการ Your Data
An overview of the Your Data initiative, including its objectives and the development of Open Data in Thailand’s financial sector. - ธนาคารแห่งประเทศไทย: ออกหลักเกณฑ์ภายใต้โครงการ Your Data
Guidelines supporting data-sharing rights in the financial sector.





