You can usually test a fintech prototype without using identifiable customer records: begin with synthetic, public, anonymised or pseudonymised data in a controlled development environment, and use only the data needed to answer a defined test question. If the question genuinely requires a live test with consumers or personal data, document why, limit the test, protect participants and confirm the relevant permissions and legal obligations for your jurisdiction.
In the UK, the FCA’s Digital Sandbox is aimed at early-stage development, while its Regulatory Sandbox supports controlled live-market tests with real consumers. They serve different stages and neither should be treated as permission to ignore privacy law or other regulatory requirements.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP &... | $39.99 | Buy on Amazon |
Define what the test needs to prove
Start with the uncertainty you need to resolve, not with a dataset you happen to have. A useful test question identifies the feature or model behaviour, the users or transactions it concerns, and the result that would count as success. For example: “Can the onboarding flow identify a missing document and tell an applicant what to do next?” is more testable than “Does onboarding work?”
Set the scope and success criteria before choosing data. Consider whether the test is about interface behaviour, a business process, model performance, fraud controls or the experience of real consumers. Some questions can be answered with representative test records or simulated transactions; others, particularly those about real-world consumer behaviour, may require a carefully controlled live test.
#1 Best Overall
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Choose a development or live-test route
The right sandbox depends on whether you need to develop a prototype, test with real consumers, or get support on an innovative service that uses personal data. The FCA’s Regulatory Sandbox is not a regulatory exemption. Regulated activity generally requires appropriate authorisation or registration unless an exemption applies, and any sandbox authorisation is restricted to the agreed test.
| Route | Best suited to | Data and testing implications | Key caution |
|---|---|---|---|
| FCA Digital Sandbox | Early-stage development and prototype experimentation. | The FCA describes a secure development environment and a marketplace of synthetic, public, anonymised and pseudonymised datasets, with APIs. Its page, last updated 5 August 2026, lists 300+ datasets and 1,000+ API endpoints; counts and access details may change. | Check current access and eligibility. Access to a development environment does not itself authorise live regulated activity. |
| FCA Regulatory Sandbox | A sufficiently developed proposition that needs a controlled test in the live market with real consumers. | Testing follows an agreed plan with safeguards and may involve real consumers. | It is not regulatory exempt. Confirm the permissions and consumer protections relevant to the proposed test. |
| ICO Regulatory Sandbox | Innovative products or services involving personal data where data-protection support may be useful. | The ICO describes a free service supporting innovative and safe uses of personal data. | Check the ICO’s current focus areas and application status. Participation is not a general legal waiver. |
The FCA says its Regulatory Sandbox is not only for start-ups that may need authorisation in future. Its eligibility criteria are that a proposition is in scope, genuinely innovative, offers consumer benefit, is ready to test and needs the FCA’s support. Readiness includes a developed plan with clear objectives, parameters and success criteria, along with resources, consumer safeguards and redress arrangements.
Use the least sensitive data that answers the question
Before requesting or copying any records, check whether non-personal data can answer the test. The FCA Digital Sandbox’s dataset categories include synthetic and public data as well as anonymised and pseudonymised data. These options are not interchangeable, and the appropriate choice depends on what you are testing.
- Synthetic data: Artificially generated records can help exercise workflows, test model behaviour or explore data-sharing approaches without simply reusing a customer file. It still needs governance and validation: a synthetic dataset is not automatically private, realistic or representative, and it may preserve bias or fail to reproduce the behaviour relevant to your test.
- Public data: Useful when publicly available information reflects the inputs or conditions being tested. Check that it is relevant and that its use is appropriate for the test; public availability alone does not make every use suitable.
- Anonymised data: May support analysis where people are no longer identifiable, but do not label a dataset anonymous without considering whether people can still be identified from it or from information that can be combined with it.
- Pseudonymised data: Identifiers have been replaced or separated, but the records remain personal data where re-identification is possible using additional information. Treat them accordingly rather than describing them as anonymous.
Match the data to the test. A synthetic dataset may be adequate for checking whether a system accepts expected fields or handles edge cases, but less useful if your question depends on patterns that are absent from the generated data. Evaluate whether the dataset preserves the characteristics needed for that specific purpose and whether it could distort results or reinforce bias.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesThe FCA’s 2024 synthetic-data report discusses data augmentation and bias mitigation, testing and model validation, and data sharing for fraud controls. The FCA described synthetic data as “one of many privacy enhancing technologies that can expand and support data sharing.” A separate FCA report published on 19 August 2025 discusses governance for generating and using synthetic data in financial-services models; the FCA states that report is not guidance. Use these reports as research and governance resources, not as a guarantee that a dataset is safe or as binding rules.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.If personal data or real consumers are necessary
Sometimes non-personal data cannot effectively answer the test question. That is a reason to assess a limited personal-data test, not a reason to upload an entire customer database to a prototype. Before proceeding, record why the test needs personal data or consumer participation, what alternatives you considered, and how the proposed scope is proportionate to the question.
- Identify the data involved, who controls or processes it, the intended purpose and the applicable legal basis. Confirm relevant data-protection, financial-services and other legal obligations for the countries in which the test and affected consumers are located.
- Limit the cohort, fields, duration, access and permitted uses to what the test needs. Use an appropriate secure environment and access controls, and define retention and deletion decisions.
- Set consumer safeguards, support and a route to redress. Explain the test appropriately to participants, monitor for harm and define how the team will pause or stop the test if necessary.
- Agree success measures, escalation and incident-handling steps in advance. Keep evidence of decisions, approvals, controls and outcomes.
For a UK FCA sandbox test, a well-developed plan should set out objectives, parameters, success criteria, resources, safeguards and redress. The FCA says tests normally last around six months under agreed plans and safeguards and require a final report; treat that as the FCA’s general description, not a guaranteed duration for every test.
For projects within scope of the EU AI Act, the cited consolidated text contains a narrow conditional provision concerning personal-data processing in an AI regulatory sandbox. It concerns personal data lawfully collected for other purposes and specified sandbox development, training or testing, and includes a condition that requirements cannot effectively be fulfilled with anonymised, synthetic or other non-personal data. This provision is specific to projects and conditions within its scope; it is not a general permission for fintech testing, does not apply everywhere, and should not be read as displacing data-protection law.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Keep an auditable test plan
Use one plan to connect the test question to the data, controls and decision to proceed. Record at least:
- the test objective, scope, cohort or transaction types, and measurable success and stop criteria;
- the route selected and why it fits the development stage and whether live consumers are needed;
- data sources, categories, fields, access permissions and the reason each is necessary;
- how synthetic, anonymised or pseudonymised data was assessed for fitness, privacy risks and potential bias;
- consumer safeguards, support, redress, escalation and incident response;
- retention, deletion and end-of-test reporting arrangements.
The FCA’s Digital Sandbox page, last updated 5 August 2026, lists 300+ datasets and 1,000+ API endpoints. Those are page-specific figures, not audited totals or a claim that every listed dataset is synthetic. Confirm current availability and access conditions before planning around a particular asset. Similarly, verify current FCA and ICO eligibility and application details directly with the relevant regulator.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

