The revised Payment Services Directive (PSD2) (2024)

MIP OnLine - 2018

March 2018

The revised Payment Services Directive (PSD2) (1)

The revised Payment Services Directive (PSD2) updates and enhances the EU rules put in place by the initial PSD adopted in 2007. The PSD2 entered into force on 12 January 2016 and EU Member States were given until 13 January 2018 to transpose it into national law.

The main objectives of the PSD2 are (i) to contribute to a more integrated and efficient European payments market; (ii) to further level the playing field for payment service providers by including new players; (iii) to make payments safer and more secure; and (iv) to enhance protection for European consumers and businesses. In other words, the PSD2 supports innovation and competition in retail payments and enhances the security of payment transactions and the protection of consumer data.

The PSD2 is supplemented by regulatory technical standards on strong customer authentication and common and secure open standards of communication, as well as guidelines on incident reporting and guidelines on security measures for operational and security risks. The three documents were developed by the European Banking Authority in close cooperation with the ECB and payment service providers must comply with all of them.

The regulatory technical standards were published in the Official Journal of the European Union on 13 March 2018 and apply as of 14 September 2019. Thus, there is a transition period during which payment service providers can already provide their services under the PSD2, but are not yet legally required to implement the respective security measures. Nevertheless, in the interest of their own security, all payment service providers are strongly encouraged to fulfil the requirements of the regulatory technical standards as soon as possible. This includes, in particular:

  • the issuance and use of strong customer authentication solutions, allowing for authorisation to be dynamically linked to the specific amount and payee;
  • the offering of transaction and device monitoring to identify unusual payment patterns;
  • the provision of a standardised and reliable access interface to payment accounts (i.e. an application programming interface, API) which makes it possible to identify third-party payment service providers in a secure way and secures all related communication between all parties involved. The aim is to reach a market agreement on one technical specification so that all systems across Europe could ultimately be based on one or a few technical API standards.

A short overview of how the PSD2 fosters innovation, consumer protection and security

Rules for third-party payment service providers

The PSD2 opens up the EU payments market to third-party payment service providers offering services based on access to information from the payment account. In particular, the PSD2 covers the following three types of services:

  • payment initiation services, which help consumers make online payments and inform the merchant immediately of the payment initiation, allowing for the immediate dispatch of goods or immediate access to services purchased online;
  • account information services, which give consumers and businesses an overview of their financial situation by consolidating information across the different payment accounts they may have with one or more payment service providers;
  • issuance of card-based payment instruments by third-party payment service providers that request confirmation of the availability of funds from the payment service provider servicing the account.

The PSD2 requires that all such third-party payment services providers be authorised and regulated. It authorises the relevant authorities to monitor and supervise their activities.

The PSD2 sets rules for access to payment accounts for third-party payment service providers. Member States must ensure that account-servicing payment service providers are not blocking or obstructing the use of payment initiation and account information services for the accounts they hold. Account-servicing payment service providers cannot deny access to the accounts they hold unless the third-party payment service provider is unauthorised or if there is a suspicion of fraud. Explicit consent is required from the payer for a transaction to be executed.

Clarification of liability regime

The PSD2 clarifies liability issues between the bank holding the account and the payment initiation service provider. In case of an unauthorised payment transaction initiated through a payment initiation service provider, the account-servicing payment service provider must refund the payment service user. If the payment initiation service provider is liable for the unauthorised payment transaction, it must immediately compensate the account-servicing payment service provider.

Enhanced consumer protection

The PSD2 enhances consumer protection. In case of an unauthorised transaction, the payment service user must be refunded immediately. The payment service user is not liable if it was not possible for him/her to be aware of a loss that resulted from theft or misappropriation of the payment instrument (e.g. data breaches, hacking attacks, copied payment cards). In other cases of lost or stolen payment instruments (e.g. a lost wallet), the payment service user can be held liable for a maximum of €50, provided he/she fulfilled the obligation to notify the payment service provider and did not act in a grossly negligent or fraudulent manner. Payment users have an eight-week unconditional refund right for direct debits in euro.

No surcharges on payments covered by the Interchange Fee Regulation

The PSD2 prohibits merchants from charging consumers additional fees for specified payment methods. The surcharge ban applies where the consumer’s bank or card issuer and the payment service provider of the merchant are both located in the European Economic Area (EEA) and the consumer makes a payment either using a debit or credit card, or by direct debit or credit transfer. Even when the surcharge ban does not apply, the amount of any surcharge imposed cannot exceed the cost incurred by the merchant in accepting the particular payment method.

Increased security for payment services

The PSD2 sets out strict security requirements for electronic payments and the protection of consumers’ financial data. Payment service providers are required to ensure strong customer authentication for the initiation and processing of electronic payments.

Customer authentication is a process whereby the identity of the user of a payment service is validated. Customer authentication is considered to be strong if it is based on the use of two or more of the following elements: (i) knowledge (something only the user knows, e.g. a password or a PIN); (ii) possession (something only the user possesses, e.g. the card or an authentication code generating device) and (iii) inherence (something the user is, e.g. the use of a fingerprint or voice recognition). These elements are independent (the breach of one element does not compromise the reliability of the others) and designed in such a way as to protect the confidentiality of the authentication data.

For remote transactions (e.g. online payments), the security requirements go even further, requiring a dynamic link to the amount of the transaction and the account of the payee, to further protect the user by minimising the risks in case of mistakes or fraudulent attacks.

There are, however, exemptions from the requirement to have strong customer authentication. For example, this may be the case for low-value payments at the point of sale or for remote transactions, in line with certain conditions.

The revised Payment Services Directive (PSD2) (2024)

FAQs

What is the revised payment service directive PSD2? ›

The Payment Service Directive 2 (PSD2), also known as The Revised Payment Services Directive, is a European regulation that creates a more open, competitive, and secure payments landscape across Europe.

What is the PSD2 directive? ›

The Payment Services Directive (PSD2) empowers the Commission to adopt delegated and implementing acts to specify how competent authorities and market participants shall comply with the obligations laid down in the directive.

What are payment services under PSD2? ›

PSD2 sets out common rules in relation to electronic payments such as credit transfers, direct debits, card payments, and mobile and online payments. It also regulates payment service providers in EEA Member States.

What is the PSD2 payment method? ›

The PSD 2 gives payers the right to use third-party payment service providers and obligates the account servicing payment service provider to provide the third-party payment service provider with a (dedicated) interface that can be used to initiate transfers ( e.g. to online retailers), download account information, or ...

What is the equivalent of PSD2 in the US? ›

There currently is no equivalent to PSD2 in the States, however, several data protection regulations such as The California Consumer Privacy Act, the recent ban of facial recognition in several states, and NIST standards.

Who needs to be PSD2 compliant? ›

Which Regions/Entities Require PSD2 Compliance? PSD2 applies directly to payment services providers, including banking institutions and payment processors operating in the European Economic Area (EEA). However, the regulation may have a far-reaching application, including organizations outside the EU.

What is a PSD2 for dummies? ›

Simply put, PSD2 is the European Commission's legislation that opens up involvement for third-party providers and establishes robust customer authentication processes. PSD2 is the European Commission's (EC) second instalment of its payment related directives.

Does PSD2 apply to US companies? ›

The Revised Payment Services Directive does not apply in the United States, being enforced exclusively in Europe.

What is the goal of PSD2? ›

PSD2 has been designed to increase competition by creating a level playing field for both banks and non-banks. It removes the monopoly banks have on the use of customer data, allowing other businesses to use that data as well, with the customer's permission.

What is the purpose of the payment services directive? ›

The Payment Services Directive is an EU Directive administered by the European Commission (Directorate General Internal Market) to regulate payment services and payment service providers throughout the European Union (EU) and European Economic Area (EEA).

Does PSD2 apply to credit cards? ›

PSD2 prohibits surcharging, which is additional charges for payments with consumer credit or debit cards, both in shops or online.

What countries does PSD2 apply to? ›

Who is subject to PSD2? PSD2 affects all member countries of the EU as well as those within the European Economic Area and anyone wishing to engage in the European payments market.

What is PSD2 revised payment service directive? ›

The revised payment service directive (PSD2) is an update of the existing PSD1, which was introduced in 2007 and provided a single market for making payments in the European Union (EU). Soon after the introduction of the initial PSD, many new service providers introduced new ways to make online payments.

Who governs PSD2? ›

However, PSD2 empowers the European Banking Authority (EBA) to develop a number of guidelines and technical standards, including a mandate (under Article 98) to deliver regulatory technical standards (RTS) on strong customer authentication and secure communication, implementation of which will run to a different ...

What is revision of the payment services directive? ›

The revised Payment Services Directive (PSD2) is a European law that governs payment systems in the European Union (EU). It regulates access to your payment data by other parties than your bank. This fosters innovation and competition in the European payments market.

What are the new rules of PSD2? ›

PSD2 gave open banking a stable regulatory framework. It imposed an obligation on banks to facilitate access to payments data for AISPs and PISPs via a secure interface.

What is the difference between GDPR and PSD2? ›

Under the GDPR, consent must be freely given, specific, informed, and unambiguous. Under PSD2, explicit consent is required specifically for payment service providers to access, process, and retain personal data.

What is the meaning of SCA required under PSD2? ›

Strong Customer Authentication (SCA) is a new requirement of the second Payment Services Directive (PSD2), which aims to add extra layers of security to electronic payments.

Top Articles
What Happens if Someone Gets Hurt on Your Rental Property?
I have the app Fetch Rewards. I shared my referral code on TikTok, giving me about $10,000 in points. Is this taxable? It was a one time thing. I am dependent & jobless.
2018 Jeep Wrangler Unlimited All New for sale - Portland, OR - craigslist
DPhil Research - List of thesis titles
Best Big Jumpshot 2K23
Ofw Pinoy Channel Su
What Happened To Dr Ray On Dr Pol
Truist Park Section 135
Apply A Mudpack Crossword
Kostenlose Games: Die besten Free to play Spiele 2024 - Update mit einem legendären Shooter
Texas (TX) Powerball - Winning Numbers & Results
Boat Jumping Female Otezla Commercial Actress
Notisabelrenu
Valentina Gonzalez Leak
Hijab Hookup Trendy
Belle Delphine Boobs
How to find cash from balance sheet?
Craigslist Free Stuff Santa Cruz
Find Such That The Following Matrix Is Singular.
Roof Top Snipers Unblocked
Hanger Clinic/Billpay
Hollywood Bowl Section H
Teacup Yorkie For Sale Up To $400 In South Carolina
Kashchey Vodka
Maxpreps Field Hockey
About My Father Showtimes Near Copper Creek 9
Walgreens 8 Mile Dequindre
Defending The Broken Isles
Bn9 Weather Radar
Craigs List Jonesboro Ar
Craig Woolard Net Worth
Best Middle Schools In Queens Ny
Cor Triatriatum: Background, Pathophysiology, Epidemiology
Farm Equipment Innovations
Dhs Clio Rd Flint Mi Phone Number
Anesthesia Simstat Answers
417-990-0201
Nextdoor Myvidster
Studio 22 Nashville Review
Muziq Najm
301 Priest Dr, KILLEEN, TX 76541 - HAR.com
Isabella Duan Ahn Stanford
Sechrest Davis Funeral Home High Point Nc
Breaking down the Stafford trade
The Many Faces of the Craigslist Killer
Jane Powell, MGM musical star of 'Seven Brides for Seven Brothers,' 'Royal Wedding,' dead at 92
Page 5747 – Christianity Today
60 Days From August 16
Automatic Vehicle Accident Detection and Messageing System – IJERT
Convert Celsius to Kelvin
Dinargurus
Latest Posts
Article information

Author: Rob Wisoky

Last Updated:

Views: 5760

Rating: 4.8 / 5 (48 voted)

Reviews: 95% of readers found this page helpful

Author information

Name: Rob Wisoky

Birthday: 1994-09-30

Address: 5789 Michel Vista, West Domenic, OR 80464-9452

Phone: +97313824072371

Job: Education Orchestrator

Hobby: Lockpicking, Crocheting, Baton twirling, Video gaming, Jogging, Whittling, Model building

Introduction: My name is Rob Wisoky, I am a smiling, helpful, encouraging, zealous, energetic, faithful, fantastic person who loves writing and wants to share my knowledge and understanding with you.