They should at least tell you that a flag for fraudulent activity has been raised. At the same time I'd like for there to be some way to have an external auditor validate that it's not due to some bug or overzealous filter.
With GDPR such automated decision making can be stopped, and entities fined if not. Unless there's a big ol' exception for anything that falls under banking security & fraud.
With GDPR such automated decision making can be stopped, and entities fined if not. Unless there's a big ol' exception for anything that falls under banking security & fraud.