Explained: The Revised Payment Services Directive (PSD2)

Everything you need to know about the payment services directive, why it was updated, and how you can take advantage of the rules.

What are the “Payment Services Directive” (PSD) and PSD2?

EU Directive 2007/64/CE, or “Payment Services Directive” (PSD) was a legal act taken by the European Commission, the executive branch of the European Union, in 2007.

The PSD provided the legal basis for the Single Euro Payments Area (SEPA), an integrated payment services market for euro transactions across the EEA and Switzerland. Created at the initiative of the European banking industry, represented by the European Payments Council (EPC), the PSD aimed to increase competition in European markets by strengthening consumers' rights and expanding and clarifying the obligations of payment providers.

In 2015, the EU Parliament adopted EU Directive 2015/2366, also known as the Revised Payment Services Directive or PSD2. This updated regulation demanded new safeguards for consumers shopping online, encouraged the development and usage of innovative online and mobile payments and created safer European-wide payments.

In short, PSD2 is regulatory legislation that democratizes access to payment services such as account information and payment initiation. Thanks to PSD2, consumers and businesses can now choose with whom they share their account data and where they view it, and they benefit from more secure payments through Strong Customer Authentication (SCA).

This legislation introduced two new major agents to the financial services industry:

  1. Account Information Service Provider (AISP)

  2. Payment initiation Service Provider (PISP)

These two agents, also known as Third Party Providers (TPPs), are supervised by local Financial Supervisory Authorities (FSAs). They need to passport their registration or license to other EEA countries if they want to provide services there. These companies can be found on the European Banking Authority’s database.

PSD2 has been in place since January 2018, but given the magnitude of the changes it introduced, it has not been fully implemented by all banks across Europe even now, in 2023, though it has progressed significantly over these years. Currently, it is used in multiple business cases such as accounting, lending, invoicing and personal financial management (PFM) solutions.

What are the main changes that PSD2 introduced?

The updated directive requires banks and other payment service providers to take measures to protect customers' data and ensure that their transactions are safe and secure. Drivers of change are:

  • Increased Security, through Strong Customer Authentication (SCA) and supervision by Financial Supervisory Authorities (FSAs)

  • Increased competition in the payment industry, enabled by Payment Initiation Services (PIS)

  • Data ownership for consumers and businesses, enabled by Account Information Services (AIS)

SCA and supervision by Financial Supervisory Authorities

One of the most significant changes PSD2 introduced is the requirement for Strong Customer Authentication (SCA). This requires most electronic payments to be authenticated using two or more independent factors, such as:

  • Knowledge: something you know (PIN, one-time password)

  • Possession: something you own (a card or smartphone)

  • Inherence: something you are (usually biometric data such as a fingerprint or a facial scan)

This is designed to reduce fraud and increase the security of sharing financial information and making online payments. For end users, one visible change is that SCA is now also required when initiating credit card payments. All PSD2 service providers (TPPs) are supervised by local financial supervisory authorities, which is a huge improvement over an environment where any company could screen-scrape or reverse-engineer banks' APIs and provide services without any control.

Payment Initiation Service (PIS)

Payment Initiation Services (PIS) are provided by Payment Initiation Service Providers (PISPs). These are companies regulated by a Financial Supervisory Authority (FSA) and are licensed to enable direct account-to-account payments for their customers. PISPs can provide fast, easy payments without requiring users to enter card or account details. Because payments are initiated directly account-to-account, this method is more sustainable and cost-efficient than most traditional payment methods.

Since PIS payments require SCA, they're best suited to single or batch payments, such as e-commerce checkouts or paying invoices via a link. For automating high volumes of outgoing payments, however, it's worth exploring the premium payment APIs offered by your bank.

Account Information Service (AIS)

Account Information Services (AIS) are provided by supervised Account Information Service Providers (AISPs), which connect your or your company's payment account information to the services you use. For example, your accounting software can give you real-time business payment account information and automated bank reconciliation, with your consent. Consent is granted through SCA, and it can be valid for 90 days (soon 180 days), meaning the real-time payment account data can be accessed during that period without further authentication. AISPs can also access historical data. Normally, banks provide at least one year of historical data, though this varies by institution.

PSD2 has made it possible for any business beyond traditional financial institutions (that meets the strict requirements, of course) to become an AISP. It's also common for end-user solutions, such as accounting software providers, to become AISPs once connecting customers' payment accounts becomes core to their business. Before this regulation, this data was accessible only through screen scraping, reverse engineering, or file transfers. Now PSD2 gives consumers and businesses the freedom to use their financial data through the services of their choice.

This is one of the largest changes brought by the Revised Payment Services Directive: the democratization of financial and banking information. The financial sector has become one of the first real-world examples of an API economy, as thousands of European financial institutions open up their data and enable companies to build more efficient services for their customers.

Open Banking

In Europe, the regulation became a driver for Open Banking. PSD2 brought in a set of APIs (Application Programming Interfaces) allowing authorized TPPs in Europe to access account information and initiate payments on behalf of their customers, with customers remaining in control thanks to the SCA. Given the quick pace of progress so far, there's clear potential for even more data sources and innovation across other areas of financial services.

Europe is now working on new regulation known as Open Finance, a natural extension of Open Banking. It envisions a world in which financial institutions disclose all of their client's financial data upon request, enabling a much wider ecosystem of TPPs and organizations to act on this data. This can potentially include your investment, loan and savings account data from your banks, as well as your insurance data from the insurance companies.

In conclusion, the Revised Payment Services Directive (PSD2) is already delivering significant benefits to consumers and the financial services industry in Europe. Meanwhile, a broader shift toward open banking is underway worldwide, gaining traction in Australia, the United States, the Middle East, Asia, and many other markets, driven by a mix of regulation and market demand.

This global open data ecosystem has the potential to revolutionize the way financial services are delivered. Allowing users to share their data with the solutions and services they use opens up a huge range of possibilities for wildly innovative new services.


Explore More:

Previous
Previous

New Spotlight: FinanceKey

Next
Next

The Importance of Data Security