Payment Services Directive
The Revised Payment Services Directive (PSD2, Directive (EU) 2015/2366,[1] which replaced the Payment Services Directive (PSD), Directive 2007/64/EC[2]) is an EU Directive, administered by the European Commission (Directorate General Internal Market) to regulate payment services and payment service providers throughout the European Union (EU) and European Economic Area (EEA). The PSD's purpose was to increase pan-European competition and participation in the payments industry also from non-banks, and to provide for a level playing field by harmonizing consumer protection and the rights and obligations of payment providers and users.[3]
Overview
[edit]The Single Euro Payments Area (SEPA) is a self-regulatory initiative by the European banking sector represented in the European Payments Council, which defines the harmonization of payment products, infrastructures and technical standards (Rulebooks for credit transfer/direct debit, BIC, IBAN, ISO 20022 XML message format, EMV chip cards/terminals). The PSD provides the legal framework within which all payment service providers must operate.
The PSD's purpose in regard to the payments industry was to increase pan-European competition with participation also from non-banks, and to provide for a level playing field by harmonizing consumer protection and the rights and obligations for payment providers and users.[3] The PSD's purpose in regard to consumers was to increase customer rights, guarantee faster payments (no later than next day since 1 January 2012), describe refund rights, and give clearer information on payments.[4] Although the PSD was a maximum harmonisation directive, certain elements allowed for different options by individual countries.[5] Both PSD1 and PSD2 set out to help open the payments ecosystem to new providers and play a significant role in enabling the development of open banking.
The final adopted text of PSD went into force 25 December 2007 and was transposed into national legislation by all EU and EEA member states by 1 November 2009.[2][6]
Technical overview
[edit]The PSD contained two main sections:
- The "market rules" described which type of organisations could provide payment services. Next to credit institutions (i.e. banks) and certain authorities (e.g. central banks, government bodies), the PSD mentioned electronic money institutions (EMI), created by the E-Money Directive in 2000, and created the new category of "payment institutions" (PI) with its own prudential regime rules. Organisations that are neither credit institutions nor EMIs could apply for an authorisation as a payment institution if they met certain capital and risk management requirements. The application could be made in any EU country where they are established and they could then "passport" their payment services into all other EU member states without additional PI requirements.
- The "business conduct rules" specified what transparency of information payment service institutions needed to provide, including any charges, exchange rates, transaction references and maximum execution time. It stipulated the rights and obligations for both payment service providers and users, how to authorise and execute transactions, liability in case of unauthorised use of payment instruments, refunds on payments, payment orders, and value dating of payments.
Each country had to designate a "competent authority" for prudential supervision of the PIs and to monitor compliance with business conduct rules, as transposed into national legislation.[7]
Updates
[edit]The PSD was updated in 2009 (EC Regulation 924/2009) and 2012 (EU Regulation 260/2012). An implementation report from 2013 found the PSD facilitated "provision of uniform payment services across the EU" and reduced legal and production costs for many payment service providers and that "the expected benefits have not yet been fully realised". The same report found the 2009 update "to be functioning well. For example, charges for €100 transfers followed a further downward trend to €0.50 euro-area average for transfers initiated online and remained low, at €3.10 for transfers initiated at the bank counter".[8]
In October 2021 the EBA launched a public consultation on amending its Regulatory Technical Standards on strong customer authentication and secure communication (SCA&CSC), regarding the 90-day exemption from SCA for account access.[9] In the UK, the FCA published a parallel policy statement, PS21/19, proposing to replace the 90-day re-authentication requirement with a requirement for users to reconfirm their consent directly with the account information service provider.[10]
A joint December 2025 report by the European Central Bank and the European Banking Authority found that strong customer authentication remained effective against the fraud types it was designed to mitigate, particularly for card payments: card payment fraud was seventeen times higher when the payee was located outside the EEA, where SCA is not legally required. The same report found that total payment fraud losses across the EEA rose to €4.2 billion in 2024, up from €3.5 billion in 2023, driven in part by a growing category of "manipulation of payer" (authorised push payment) fraud that strong customer authentication alone does not address.[11]
More broadly, the United Kingdom transposed PSD2 into the Payment Services Regulations 2017.[12] This framework remained in place after Brexit, with the FCA continuing as the competent authority, though the UK government has said continued participation in the Single Euro Payments Area will be balanced against its ability to chart its own regulatory course.[13] Since Brexit, the FCA and EU authorities have also amended their strong customer authentication standards independently, producing a growing divergence between the two regimes.[14]
Remaining issues
[edit]- The PSD only applied to payments within the European Economic Area, but not to transactions to or from third countries. Outside the EEA, comparable PSP registration regimes have emerged in other jurisdictions, such as Canada's Retail Payment Activities Act (RPAA), under which registration became mandatory in 2024. Entities registered under the RPAA include global providers such as Stripe Inc., Clarity Global Inc. and Wise Payments Canada Inc., all listed in the Bank of Canada's PSP registry.[15]
- PSD exemptions related to payment activities left users unprotected.
- The PSD option for merchants to charge a fee or give a rebate, combined with the option for countries to limit this, led to "extreme heterogeneity in the market".
- So-called "third party payment service providers" emerged, facilitating online shopping through low-cost payments that used customers' existing online banking with their agreement; "account information services" offered consolidated views across accounts. The report proposed harmonising direct-debit refund rules, narrowing the "small payment institutions" exemption, and addressing security, account-data access and privacy, potentially through licensing and supervision.[8]
Revised Directive on Payment Services (PSD2)
[edit]On 8 October 2015, the European Parliament adopted the European Commission proposal to create safer and more innovative European payments (PSD2, Directive (EU) 2015/2366). The current rules aim to better protect consumers when they pay online, promote the development and use of innovative online and mobile payments such as through open banking, and make cross-border European payment services safer.[16]
Then-Commissioner Jonathan Hill, responsible for Financial Stability, Financial Services and Capital Markets Union, said, "This legislation is a step towards a digital single market; it will benefit consumers and businesses, and help the economy grow."[16]
On 16 November 2015, the Council of the European Union passed PSD2. Member states then had two years to incorporate the directive into their national laws and regulations.[17] On 27 November 2017, Commission delegated Regulation (EU) 2018/389 supplemented PSD2 with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication.[18]
PSD2 came into force on 13 January 2018, prompting banks to adapt to new technical challenges and strategic opportunities, such as collaboration with fintech providers.[19]
An important element of PSD2 is the requirement for strong customer authentication on the majority of electronic payments.[11]
Another important element of the directive is the requirement for common and secure communication (CSC): eIDAS-defined qualified certificates for website authentication and electronic seals are required for communication between financial-services players, per the technical specification ETSI TS 119 495.
PSD2 went into full effect on 14 September 2019, but due to delays in the implementation, the European Banking Authority allowed for a time extension of the strong customer authentication (SCA) until 31 December 2020.[20][21]
Third Payment Services Directive
[edit]On 28 June 2023, the European Commission published legislative proposals for a Third Payment Services Directive (PSD3) combined with a directly applicable Payment Services Regulation (PSR), repealing the Electronic Money Directive and incorporating electronic money institutions as a sub-category of payment institutions.[22][23]
On 27 November 2025, the European Parliament and the Council of the European Union reached a provisional political agreement on the PSD3 and PSR texts, under which payment service providers must implement fraud-prevention mechanisms, verify payee names before completing a transfer, and fully reimburse victims of impersonation fraud.[24] As of May 2026[update], formal adoption by the European Parliament and the Council remained pending, with publication in the Official Journal of the European Union projected for the end of the second quarter of 2026. Most PSD3 and PSR provisions would then apply within 18 months of entry into force, or 24 months for the payee-name verification requirement.[25][26][27]
Key dates
[edit]- March 2000: Lisbon Agenda to make Europe "the world's most competitive and dynamic knowledge-driven economy" by 2010
- December 2001: regulation EC 2560/2001 on cross-border payments in Euro
- 2002: European Payments Council created by the banking industry, driving the Single Euro Payments Area initiative to harmonise the main non-cash payment instruments across the Euro area (by end 2010)
- 2001–2004: consultation period and preparation of PSD
- December 2005: proposal for PSD by DG Internal Market Commissioner McCreevy
- 25 December 2007: PSD entered into force
- 1 November 2009: deadline for transposition in national legislation
- 2009 update: eliminated differences in charges for cross-border and national payments in euro (EC Regulation 924/2009)
- 2012 update: Regulation on cross-border payments, "multilateral interchange fees" (EU Regulation 260/2012)
- July 2013: report on implementation of PSD and its two updates[8]
- 16 November 2015: The Council of the European Union passes PSD2, giving member states two years to incorporate the directive into their national laws and regulations.[17]
- 13 January 2018: Directive 2007/64/EC is repealed and replaced by Directive (EU) 2015/2366
- 14 March 2019: All Financial Institutions offering an API solution must have it available for external testing by PISPs and AISPs.[28]
- 14 September 2019: The final deadline for all companies within the EU to comply with PSD2's Regulatory Technical Standard (RTS) pertaining to directive (EU) 2015/2366 (PSD2)
- 31 December 2020: Extended deadline for all companies within the EU to implement PSD2's Strong Customer Authentication (SCA)
- 29 November 2021: FCA publishes changes to 90-day reauthentication rules in the UK[10]
Privacy concerns
[edit]This section may contain information not important or relevant to the article's subject. (May 2020) |
Privacy First, a privacy organisation, criticised the open banking elements of the new legislation, claiming it focuses too much on improving competition and innovation while the privacy interests of account holders are overlooked.[29]
See also
[edit]References
[edit]- ↑ Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC (Text with EEA relevance), vol. OJ L, 23 December 2015, retrieved 12 July 2020
- 1 2 "Directive 2007/64/EC of the European Parliament and of the Council of 13 November 2007 on payment services in the internal market amending Directives 97/7/EC, 2002/65/EC, 2005/60/EC and 2006/48/EC and repealing Directive 97/5/EC". Official Journal of the European Union. 5 December 2007. Retrieved 2 August 2014.
- 1 2 "Payment services (PSD 1) - Directive 2007/64/EC". European Commission. Retrieved 13 February 2017.
- ↑ "The Payment Services Directive – What it means for Consumers" (PDF). European Commission. Archived from the original (PDF) on 30 May 2013. Retrieved 20 March 2014.
- ↑ "Directive on Payment Services (PSD) – Member States' options". EC.Europa.eu. European Commission. Archived from the original on 27 February 2015. Retrieved 27 February 2015.
- ↑ "Payment Services". EC.Europa.eu. European Commission. Retrieved 13 February 2017.
- ↑ "Competent authorities for the authorisation and supervision of payment institutions (Article 20)" (PDF). EC.Europa.eu. Archived from the original (PDF) on 27 February 2015. Retrieved 27 February 2015.
- 1 2 3 "Report from the Commission to the European Parliament and the Council on the application of Directive 2007/64/EC on payment services in the internal market and on Regulation (EC) No 924/2009 on cross-border payments in the Community". Eur-lex.europa.eu. 24 July 2013. Retrieved 27 February 2015.
- ↑ "EBA consults on the amendment to its technical standards on strong customer authentication and secure communication in relation to the 90-day exemption for account access" (Press release). European Commission. 28 October 2021. Retrieved 1 February 2021.
- 1 2 "PS21/19: Changes to the SCA-RTS and to guidance in the Approach Document and the Perimeter Guidance Manual" (Press release). The Financial Conduct Authority. 29 November 2021. Retrieved 1 February 2021.
- 1 2 2025 Joint EBA-ECB Report on Payment Fraud (Report). 15 December 2025. Retrieved 30 July 2026.
{{cite report}}: CS1 maint: date and year (link) - ↑ "PS17/19: Implementation of the revised Payment Services Directive (PSD2)" (Policy statement). 2017. Retrieved 30 July 2026.
- ↑ "Review of the UK Payment Services Regulations: Considerations for Firms". January 2023. Retrieved 30 July 2026.
- ↑ "How UK and EU strong customer authentication rules differ". 2023. Retrieved 30 July 2026.
- ↑ "Registry of payment service providers". Bank of Canada. Retrieved 30 July 2026.
- 1 2 "European Parliament adopts European Commission proposal to create safer and more innovative European payments" (Press release). European Commission. 8 October 2015. Retrieved 4 May 2016.
- 1 2 "Electronic payment services: Council adopts updated rules" (Press release). Council of the EU. 16 November 2015. Retrieved 16 November 2015.
- ↑ "COMMISSION DELEGATED REGULATION (EU) 2018/389". 27 November 2017.
- ↑ "Capitalizing on the potential benefits of open banking". McKinsey. Retrieved 21 September 2019.
- ↑ "strong customer authentication (SCA) Enforcement Date : Stripe: Help & Support". Retrieved 21 September 2019.
- ↑ "EBA publishes an Opinion on the elements of strong customer authentication under PSD2" (Press release). European Banking Authority. Archived from the original on 21 September 2019. Retrieved 21 September 2019.
- ↑ DLA Piper (July 2023). "The European Commission announces its proposal for Payment Services Directive 3 (PSD3)". Retrieved 30 July 2026.
- ↑ "PSD3 Impacts on Payment and Electronic Money Institutions: get ready!". Retrieved 30 July 2026.
- ↑ European Parliament (27 November 2025). "Payment services deal: More protection from online fraud and hidden fees" (Press release). Retrieved 30 July 2026.
- ↑ William Fry (2026). "PSD3/PSR: Final compromise texts are published". Retrieved 30 July 2026.
- ↑ "Payment services regulation". Legislative Train Schedule. European Parliament. Retrieved 30 July 2026.
- ↑ "PSD3 and PSR: From provisional agreement to 2026 readiness". March 2026. Retrieved 30 July 2026.
- ↑ Jones, Brendan (23 October 2018). "The Implications and Requirements of PSD2 open banking for Programme Managers". Finextra.
- ↑ "European PSD2 legislation puts privacy under pressure. Privacy First demands PSD2 opt-out register". www.privacyfirst.eu. Retrieved 26 May 2020.
Further reading
[edit]- Dimitrios Linardatos: "Das Haftungssystem im bargeldlosen Zahlungsverkehr nach Umsetzung der Zahlungsdiensterichtlinie", Nomos-Verlag, 2013, ISBN 978-3-8487-0709-6. (German)
External links
[edit]- Text of the Payment Services Directive
- European Union PSD official website
- European Payments Council
- Payment services (PSD 2) - Directive (EU) 2015/2366
- Opinion on the elements of strong customer authentication under PSD2 Archived 21 September 2019 at the Wayback Machine European Banking Authority, June 2019