New technologies demand new insights.
New technologies demand new insights.
Businesses that facilitate, process or intermediate payments may fall within the regulatory framework for payment services. This is relevant not only for traditional payment institutions, but also for marketplaces, platforms, wallets, payment facilitators, merchant service providers, embedded finance models, open banking providers and crypto-linked business models involving fiat or electronic money flows.
The regulation of payment services is currently governed by Payment Services Directive 2 (PSD2) and its implementation in the Dutch Financial Supervision Act (Wet op het financieel toezicht, Wft). Payment services are the regulated services listed in Annex 1 to PSD2.
Among other things, Watsonlaw advises payment businesses on the scope of the payment services licence requirement, the availability of exclusions and exemptions, safeguarding of client funds, governance, outsourcing, DORA, AML/CFT, cross-border services and the preparation of licence applications.
A licence may be required where a company provides payment services in the Netherlands on a commercial basis. The starting point is therefore whether the relevant activities qualify as one or more regulated payment services under PSD2 and the Wft, and whether those services are provided on a commercial basis.
In practice, the analysis is fact-specific. Relevant questions include whether the company receives or controls funds, whether it operates payment accounts, whether it initiates or executes payment transactions, whether it issues payment instruments or acquires payment transactions, whether it provides money remittance, or whether it provides payment initiation or account information services.
Providing services to several customers or actively promoting payment services can indicate that the services are provided on a commercial basis. One-off or very incidental activity may fall outside the scope of acting as a payment service provider, but that assessment should be made carefully and by reference to the actual operational model.
Not every payment-related activity is a regulated payment service. PSD2 and the Wft contain a number of exceptions and exemptions. These may be relevant, for example, for purely technical service providers, certain commercial agent models, intra-group payment services, limited network instruments, certain telecom and digital content models, and services without a non-cash component.
Various exceptions, exemptions and exclusions are listed in PSD2. Notable exceptions and exemptions include:
Whether a payment services licence can be obtained is determined by the legal qualification alone. A licence application requires a sufficiently developed business model, a clear programme of operations, a credible governance structure, adequate internal controls, sufficient financial resources and a workable safeguarding structure.
For fintech businesses, the payment flow is usually the central element of the analysis. The legal qualification often depends on how funds move between users, merchants, platform entities, payment service providers and safeguarding accounts. Contractual wording is relevant, but it is not decisive if the operational reality points in another direction.
Another key consideration is local substance. Licence applicants are expected to be capable of operating the business in a sound and controlled manner. This includes clear decision-making, sufficient staff and expertise, appropriate outsourcing oversight, reliable systems and a governance structure that supports effective supervision.
A further key consideration is safeguarding. Safeguarding should be addressed early in the process. Licence applicants must clearly document their safeguarding methods. DNB recognizes three possible methods: a customer accounts foundation, a segregated assets account, or an insurance policy or guarantee. Incomplete safeguarding documentation may delay or prevent the substantive assessment of the licence application.
Payment services regulation may also be relevant for crypto and digital asset models. The applicability of MiCA does not automatically exclude the application of PSD2. A crypto-related business model may require a MiCA authorization, a payment services licence, an e-money licence, a partnership with a licenced payment services provider, or a combination thereof.
This is particularly relevant where the model involves fiat payment flows, payment accounts, custodial wallets with payment functionality, electronic money tokens, merchant settlement, or transfers involving funds. In those cases, the legal analysis should not stop at MiCA. The interaction between MiCA, PSD2, EMD2, the Transfer of Funds Regulation and AML/CFT requirements should be assessed together.
The European payments framework is also in transition. The European Parliament and the Council reached a provisional political agreement on the Payment Services Regulation and the Payment Services Directive 3 in November 2025. This will further harmonize the European payments framework, transitioning from a directive that must be implemented in national legislation, to a directly applicable regulation.
Payment institutions must have a clear governance structure. This includes a transparent allocation of responsibilities, clear reporting lines, effective management oversight and an organization that enables the business to operate in a sound and controlled manner.
The management body and other day-to-day policymakers must be suitable and reliable. In practice, the supervisory authority will also look at the applicant’s local substance, the independence and effectiveness of its internal control functions, and the way in which responsibilities are allocated within a group structure.
Where the business model is cross-border, group-based or heavily dependent on outsourced service providers, governance becomes particularly important. The applicant must remain in control of its regulated activities and must be able to demonstrate that It can oversee outsourced functions, manage incidents and respond to supervisory requests.
In various cases, a supervisory board may be required for obtaining a licence as a payment institutions.
A licence application as a payment institution requires a coherent set of internal policies and procedures. These should not be treated as standalone documents, but as part of a wider operating model that explains how the business will provide payment services in practice.
Depending on the model, the policy framework will typically cover the following subjects:
For payment institutions, DORA is now a key part of the operating framework. DORA applies since 17 January 2025 and introduces requirements on ICT risk management, incident reporting, digital operational resilience testing and ICT third-party risk.
A payment institution must have an organisation that is capable of supporting the regulated services for which authorisation is sought. This includes sufficient staff, expertise, systems, controls and operational capacity.
The organisation should be designed around the actual services to be provided. For example, a provider of payment initiation services will have a different operational risk profile than a payment institution that receives and safeguards client funds, operates payment accounts or provides acquiring services to merchants.
Outsourcing is often central to fintech payment models. Outsourcing is permitted, but it does not transfer regulatory responsibility. The applicant must retain sufficient knowledge, oversight and decision-making capacity internally and must ensure that outsourcing arrangements do not impair the supervisory authority’s ability to supervise the institution.
A payment institution must have an effective compliance and internal control framework. In practice, this means that the institution must be able to identify, assess, monitor and remediate legal, regulatory, operational and integrity risks on an ongoing basis.
AML/CFT and sanctions should be treated as core licensing topics. Depending on the business model, the payment institution may need customer due diligence procedures, transaction monitoring, sanctions screening, suspicious transaction reporting procedures, risk assessments, escalation processes and clear allocation of responsibilities.
Operational and security risks are also central. Payment institutions should be able to demonstrate how they protect payment users, manage fraud risk, secure payment data, handle incidents, ensure continuity and comply with applicable authentication and communication requirements.
A payment institution must meet applicable initial capital and own funds requirements. The required amount depends on the payment services provided and the method used for calculating ongoing own funds.
The prudential analysis should not be reduced to a formal capital number. The supervisory authorities will also expect the applicant to have a credible financial forecast, adequate funding, realistic assumptions, and sufficient resources to sustain the organization during and after the licensing process.
Safeguarding of client funds is a separate and important prudential topic. Payment institutions that receive funds for the execution of payment transactions must ensure that those funds are protected in accordance with applicable safeguarding rules. PSD2 requires safeguarding of funds received by payment institutions providing certain payment services, and supervisory guidance highlights the importance of selecting and documenting the safeguarding method early in the application process.
A payment institution licence application is a structured process. The applicant must first determine the exact scope of services for which authorisation is required and prepare an application file that explains the business model, programme of operations, governance, financial position, safeguarding arrangements, internal controls and compliance framework.
The application process consists of two phases: a completeness review and a substantive assessment. The substantive assessment is only conducted once the application is complete, and incomplete applications may be delayed or dismissed.
The statutory consideration period for a payment institution licence application is three months. However, DNB notes that the total processing time is often longer because the statutory period does not start until all information required for a decision has been received and may be suspended where information is missing or additional questions arise.
In practice, the quality of the application file is critical. DNB identifies completeness, legal substantiation, clear description of services and money flows, governance, capital, safeguarding, substance in the Netherlands and timely recruitment of key function holders as important success factors.
At Watsonlaw, we approach payment services matters in a practical and hands-on manner. We understand that payment businesses often operate in fast-moving and technically complex environments, where legal advice must be clear, commercially workable and aligned with the actual product and operational setup.
Our work often starts with the qualification of the relevant services and payment flows. We help clients assess whether their model falls within PSD2, whether a licence, exemption or notification may be required, and whether the model should be structured differently to fit the regulatory framework.
From there, we assist with the broader licensing and implementation process. This includes preparing the regulatory analysis, structuring safeguarding arrangements, drafting internal policies, reviewing outsourcing and merchant arrangements, preparing the licence application file and engaging with supervisory authorities where relevant.
Our advice is tailored to the business model at hand. Whether you are launching a marketplace, wallet, acquiring model, payment initiation service, embedded payments structure or crypto-linked payment product, we help identify the applicable framework and the practical next steps.
There are several ways in which client balances can be displayed in client accounts on a platform without requiring a licence as a payment services provider. One way of structuring is the issuance of a payment instrument under the limited network exception. This does not require a licence, but does require a notification to the supervisory authority after a threshold of EUR 1 million transactions has been reached within twelve months.
Safeguarding can be structured in different ways, including through a customer accounts foundation, a segregated assets account, or an insurance policy or guarantee. The appropriate method depends on the business model, the money flow, the role of third-party banks or payment service providers, and the way in which client funds are received and held.
Not always. Crypto-related payment models may also raise questions under MiCA and EMD2. Where a model involves both crypto-assets and fiat or electronic money flows, the licensing analysis must consider all relevant frameworks together.
Services provided by technical service providers, which support the provision of payment services, without them entering at any time into possession of the funds to be transferred, are not subject to PSD2. This includes processing and storage of data, trust and privacy protection mechanisms, data and entity authentication, information technology (IT) and communication network provision, and provision and maintenance of terminals and devices used for payment services. However, if the service qualifies as a payment initiation service or account information service, it is subject to PSD2.
Are you developing a payment, wallet, stored-value or platform model and unsure whether your activities qualify as regulated payment services, electronic money issuance, or fall outside the licensing perimeter?
Watsonlaw advises on the legal qualification of payment and e-money models under PSD2, EMD2 and the Wft, including the applicability of exemptions, exceptions and adjacent frameworks such as MiCA, DORA and AML/CFT regulation.
We are happy to assist with the legal qualification of your activities, the analysis of your payment and value flows, the structuring of your product or service and the next steps for your business.
Would you like to know more? Please contact Willem-Jan Smits or Rens Kattenbelt.
“It is common to be spinning many plates when establishing a start-up. What I consider most important from a collaboration with a lawyer is: reassurance. So that I can sleep at night. And that is what I got.”
Start-up entrepreneur
“They really dare to take steps. This often concerns untapped subject matter. You can count on them taking a position that can later be defended”
Tech sector consultant
“They are very proactive, and they are pre-emptive when it counts, they radiate this. They are on point. We see things the same way: transparent, direct, know what to expect from each other, we both want to build something. They are so much more than lawyers. And if they don’t know something, they do their homework. They are terrific at that.”
Crypto company entrepreneur
"Watsonlaw has truly contributed to the growth of our company. This is where the greatest added value lies. They give tangible advice and tell me what the best step is. That is exactly what I am looking for in a lawyer”
Crypto company entrepreneur