How does PSD2 affect businesses? Regulation for EU & UK online payments services (2024)

PSD2 is the acronym for Payment Services Directive 2. This regulation has completely transformed the way online payments are carried out. What's more, it's very likely that when using your bank you've received a notice about this standard in the last year. Both the most digital FinTech and eCommerce platforms must adapt their payment methods to comply with the provisions of this European directive.

Together with eIDAS (electronic IDentification, Authentication, and trust Services) and AML6 (Sixth Anti-money Laundering Directive) PSD2 further advances the European Union's objective of creating a secure reference framework in which to operate with agility and guarantees in a market of more than 500 million potential consumers. Although many businesses may think that the approval of this type of standard is a brake on their activity, the reality is just the opposite: this harmonization is resulting in astonishing ease for businesses to develop and deploy in Europe in days without large investments thanks to a secure online framework.

Start automating compliance with regulations such as PSD2

What is PSD2

PSD2 is a European directive on payment services over the Internet and in online environments that applies in the member countries of the European Union and in the United Kingdom. It is the second regulation to be implemented in this sense since the previous one - PSD - already defined a series of rules for online payments to be made under secure and consolidated standards.

This second law advances what its predecessor already started, including the concept of Strong Authentication (SCA). This concept is really important, as it is the main novelty of the new regulation. The first directive was launched in 2007 and the second one started the procedures for its approval and development in 2013, being a revision of its little sister.

Rather than talking about changes, we can talk about extensions. The main new features include the new role of TTPs (Third Party Payment Service Providers), the regulation of payment initiation services (PIS) and the definition of standards for account information services (AIS). With this, the financial and banking sector speak the same language throughout Europe and the UK to proceed with their operations, which facilitates intermediation, the creation of new businesses and the ease of developing new verticals.

Now, sensitive customer information is collected and stored in a single form and in a single place, allowing the emergence of financial aggregators. Similarly, this standard has led to the birth and expansion of the so-called wallet cards.

Now, a customer can make a payment to a third party from one bank's application to a different bank without the need for any complex obstacles. This is possible thanks to the PIS and the services provided by TTPs.

The way companies will comply with PSD2 is mainly through API integrations. This model, easily integrated thanks to the best RPA (Robot Process Automation) solutions, automates compliance with the PSD2 directive without blocking the IT and technology departments of companies or high costs.

The main advantages of the standard include the expansion of security for companies, eliminating AML risks beyond what specific standards such as 6AMLD or AML5 were already providing, as well as the possibility of unleashing innovation in terms of payment methods. This will enable FinTech and WealthTech to offer new types of products and services. Likewise, having less risk will accelerate business growth and avoid the costs associated with these problems.

Also, and for eCommerce, establishing reliable payment gateways will increase your online sales given the increased user confidence in your platforms.

Analyze with our experts the possibilities of PSD2 for your business

PSD2 as a standard and directive

Many people wonder whether PSD2 is a directive or a regulation, and what it really means. This law is not optional, it is mandatory for all entities operating in European countries. Put this way, it might seem like something that generates friction for companies to adopt, however, this transformation of certain processes brings more benefits and advantages than the cost of implementing these changes.

A directive is not a recommendation, but a reference framework for each member country to transpose those standards into their own legal framework, developing a specific law or updating the one they already have about that subject and social and economic area. And yes, we can say that the terms PSD2 Directive and PSD2 Regulation are synonymous with each other. All countries have already done the same, so the objectives of the standard are already taking effect and are mandatory.

Dates for adapting to PSD2 in the EU and UK

Now! PSD2 came into force in January 2018. However, the EU and the UK gave companies until 1 January 2021 to adapt to the regulation. From this date, all companies that are not performing their activities according to the standards set by the second European payments directive will be exposed to serious sanctions by the authorities.

The technical standards of the regulation were defined by the EBA - European Banking Authority - and can be freely consulted on their websites. On the other hand, the specifics on access, login and SCA took place in mid-September 2019, so companies have already had to adapt.

SCA: Strong Customer Authentication

PSD2's star new feature focuses on how users who have already passed a customer onboarding process - known as Know Your Customer (KYC) in this industry - authenticate themselves to access their contracted products and services, their management dashboard and perform transactions based on their customer personas.

However, we can say without a doubt that the adoption of SCA standards has been unambitious. While the vast majority of banks have put in place all the necessary controls to comply with this, all of them have provided temporary or "rudimentary" solutions that are not meeting the agility and user experience needs of today's users.

It all comes down to one term: Multi-Factor Authentication (MFA). This means that in order to be considered secure access to a client platform, access must be granted under security standards that require at least two factors of authentication (2FA). Furthermore, these factors must be absolutely secure and created under the strictest order.

The best way to apply PSD2 in business

How does PSD2 affect businesses? Regulation for EU & UK online payments services (4)

How does PSD2 affect businesses? Regulation for EU & UK online payments services (5)How does PSD2 affect businesses? Regulation for EU & UK online payments services (6)

In this sense, facial biometrics is revolutionizing the industry as it is one of the most convenient and common ways for users to access their mobile devices. The best customer onboarding solutions create a unique facial biometric pattern for the user when they first register and validate them during the purchase process. This should be able to be used to generate one of the authentication factors within the SCA strategy required by PSD2.

Now, banks are betting on one-time SMS tokens (OTPs), and PINs, and even many are still using coordinate cards. This is a delay not only in terms of security but also for the user. Authenticate for the signature of transactions with the same validity as a KYC of the highest level and seal it with electronic signature is the bet for the future to apply PSD2.

Discover the most agile strong customer authentication platform based on facial and voice biometrics

Tags

Risk ManagementLegal Framework Identity VerificationFraud Prevention

How does PSD2 affect businesses? Regulation for EU & UK online payments services (2024)

FAQs

How does PSD2 affect businesses? ›

By complying with the PSD2 regulation, businesses can demonstrate to their customers that their payment systems are secure and that their personal data is protected. This can help build trust and confidence in the brand, which can lead to increased customer loyalty and repeat business.

What is PSD2 regulation and what is the impact? ›

What is PSD2? PSD2 is a regulatory framework that ensures payments across the EU are secure, easy and efficient. The changes regulate entities that access or aggregate account information for electronic payments.

How does PSD2 aim to enhance online payments? ›

PSD2 is a European regulation for electronic payment services. It seeks to make payments more secure in Europe, boost innovation and help banking services adapt to new technologies. PSD2 is evidence of the increasing importance Application Program Interfaces (APIs) are acquiring in different financial sectors.

What is the European Payment Services Directive PSD2? ›

The Payment Service Directive 2 (PSD2), also known as The Revised Payment Services Directive, is a European regulation that creates a more open, competitive, and secure payments landscape across Europe. The PSD2 provides requirements for Strong Customer Authentication (SCA).

Does PSD2 still apply to the UK? ›

In the UK, PSD2 is enforced by the Financial Conduct Authority (FCA), the regulator of financial firms and markets in the United Kingdom. FCA is responsible for the determination of which third party provider (TPP) can be authorised or registered, as well as for the monitoring of TPPs reporting obligations under PSD2.

Who does PSD2 affect? ›

The PSD2 is targeted at EU banks and payment processors. But if you're a business that has any operations or offices in the EU, even if you're headquartered elsewhere, you must still be compliant.

What is the PSD2 regulation in the UK? ›

The PSD2 text makes it clear that customers have a right to use what are termed Payment Initiation Service Providers (PISPs) and Account Information Service Providers (AISPs) where the payment account is accessible online and where they have given their explicit consent.

What is the key disruptive part of PSD2 regulation? ›

The main impact of PSD2 regulations will involve the mandatory use of SCA. This is absolutely vital if your customers pay online by credit or debit card.

What is the impact of online payment? ›

Online payments make it easier to manage and store your money and other financial data. For both vendors and customers, there are a lot of tools available on the internet that will help you with transactions. You don't have to keep track of your finances and let the tools do the job.

What are the changes in PSD2? ›

PSD2 will create new PSPs but also new competitors given the “Third Party Access” requirements. The Open Banking provisions in PSD allow non-banks, corporates (like Amazon) or FinTech businesses to directly access consumer bank accounts to perform payments activities and/or gain access to customer data .

What is a PSD2 for dummies? ›

Simply put, PSD2 is the European Commission's legislation that opens up involvement for third-party providers and establishes robust customer authentication processes. PSD2 is the European Commission's (EC) second instalment of its payment related directives.

What are the effects of PSD2 on fintech? ›

PSD2 has significantly broadened the potential for fintech firms. With access to customer data and banking infrastructure through APIs, fintechs are innovating and offering personalized financial products and services. This surge in innovation is making the banking sector more diverse, inclusive, and customer-focused.

Does PSD2 apply to merchants? ›

While declining such transactions isn't mandatory, it's crucial for any merchant doing any business in the EU to understand these requirements to avoid causing themselves problems in the future. The PSD2 rules apply to all transactions that take place between issuers and acquirers that are both located within the EEA.

Does PSD2 apply to corporate accounts? ›

PSD2 introduces many benefits for corporates which will be described in more detail in the next section. With the right vision and implementation strategy, corporates can grow new revenue streams by introducing new value-added services to the customer and improve the efficiency of processes in daily business.

Top Articles
Latest Posts
Article information

Author: Melvina Ondricka

Last Updated:

Views: 5496

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Melvina Ondricka

Birthday: 2000-12-23

Address: Suite 382 139 Shaniqua Locks, Paulaborough, UT 90498

Phone: +636383657021

Job: Dynamic Government Specialist

Hobby: Kite flying, Watching movies, Knitting, Model building, Reading, Wood carving, Paintball

Introduction: My name is Melvina Ondricka, I am a helpful, fancy, friendly, innocent, outstanding, courageous, thoughtful person who loves writing and wants to share my knowledge and understanding with you.