Payment services

Building
a framework
for growth
Our point
of view:

Here’s our point of view:
We can help you prepare for what the future holds for your business.

 

Businesses that facilitate, process or intermediate payments may fall within the regulatory framework for payment services. This is relevant not only for traditional payment institutions, but also for marketplaces, platforms, wallets, payment facilitators, merchant service providers, embedded finance models, open banking providers and crypto-linked business models involving fiat or electronic money flows.

 

The regulation of payment services is currently governed by Payment Services Directive 2 (PSD2) and its implementation in the Dutch Financial Supervision Act (Wet op het financieel toezicht, Wft). Payment services are the regulated services listed in Annex 1 to PSD2.

 

Among other things, Watsonlaw advises payment businesses on the scope of the payment services licence requirement, the availability of exclusions and exemptions, safeguarding of client funds, governance, outsourcing, DORA, AML/CFT, cross-border services and the preparation of licence applications.

Licensing regime.

When is a licence required?

A licence may be required where a company provides payment services in the Netherlands on a commercial basis. The starting point is therefore whether the relevant activities qualify as one or more regulated payment services under PSD2 and the Wft, and whether those services are provided on a commercial basis.

 

In practice, the analysis is fact-specific. Relevant questions include whether the company receives or controls funds, whether it operates payment accounts, whether it initiates or executes payment transactions, whether it issues payment instruments or acquires payment transactions, whether it provides money remittance, or whether it provides payment initiation or account information services.

 

Providing services to several customers or actively promoting payment services can indicate that the services are provided on a commercial basis. One-off or very incidental activity may fall outside the scope of acting as a payment service provider, but that assessment should be made carefully and by reference to the actual operational model.

What are exceptions to the licensing requirement?

Not every payment-related activity is a regulated payment service. PSD2 and the Wft contain a number of exceptions and exemptions. These may be relevant, for example, for purely technical service providers, certain commercial agent models, intra-group payment services, limited network instruments, certain telecom and digital content models, and services without a non-cash component.

 

Various exceptions, exemptions and exclusions are listed in PSD2. Notable exceptions and exemptions include:

 

  • The Commercial Agent Exclusion. This exclusion if often relevant for platforms and marketplace models, but it is not a general platform exemption. The exclusion applies where the commercial agent acts only on behalf of the payer or only on behalf of the payee, is authorized by agreement to negotiate or conclude the sale or purchase of goods or services, and has a commercial relationship going beyond the mere facilitation of payments.

 

  • The Limited Network Exception. This exception applies to payment instruments that can be used only in a limited way. These payment instruments must allow the holder to acquire goods or services only in the premises of the issuer or within a limited network of service providers, or be used only to acquire a very limited range of goods or services.

 

  • An exemption for small payment service providers. Certain small payment service providers that do not provide money remittance, payment initiation or account information services, and that meet several conditions may be exempt from the licensing requirements. These conditions include providing the services only in the Netherlands, and having an average aggregate transaction amount that does not exceed EUR 3 million per month over the past twelve months.

What are key considerations for a PSD2 licence?

Whether a payment services licence can be obtained is determined by the legal qualification alone. A licence application requires a sufficiently developed business model, a clear programme of operations, a credible governance structure, adequate internal controls, sufficient financial resources and a workable safeguarding structure.

 

For fintech businesses, the payment flow is usually the central element of the analysis. The legal qualification often depends on how funds move between users, merchants, platform entities, payment service providers and safeguarding accounts. Contractual wording is relevant, but it is not decisive if the operational reality points in another direction.

 

Another key consideration is local substance. Licence applicants are expected to be capable of operating the business in a sound and controlled manner. This includes clear decision-making, sufficient staff and expertise, appropriate outsourcing oversight, reliable systems and a governance structure that supports effective supervision.

 

A further key consideration is safeguarding. Safeguarding should be addressed early in the process. Licence applicants must clearly document their safeguarding methods. DNB recognizes three possible methods: a customer accounts foundation, a segregated assets account, or an insurance policy or guarantee. Incomplete safeguarding documentation may delay or prevent the substantive assessment of the licence application.

What is the connection between MiCA and PSD2?

Payment services regulation may also be relevant for crypto and digital asset models. The applicability of MiCA does not automatically exclude the application of PSD2. A crypto-related business model may require a MiCA authorization, a payment services licence, an e-money licence, a partnership with a licenced payment services provider, or a combination thereof.

 

This is particularly relevant where the model involves fiat payment flows, payment accounts, custodial wallets with payment functionality, electronic money tokens, merchant settlement, or transfers involving funds. In those cases, the legal analysis should not stop at MiCA. The interaction between MiCA, PSD2, EMD2, the Transfer of Funds Regulation and AML/CFT requirements should be assessed together.

 

The European payments framework is also in transition. The European Parliament and the Council reached a provisional political agreement on the Payment Services Regulation and the Payment Services Directive 3 in November 2025. This will further harmonize the European payments framework, transitioning from a directive that must be implemented in national legislation, to a directly applicable regulation.

Licensing requirements.

Which key governance arrangements are required?

Payment institutions must have a clear governance structure. This includes a transparent allocation of responsibilities, clear reporting lines, effective management oversight and an organization that enables the business to operate in a sound and controlled manner.

 

The management body and other day-to-day policymakers must be suitable and reliable. In practice, the supervisory authority will also look at the applicant’s local substance, the independence and effectiveness of its internal control functions, and the way in which responsibilities are allocated within a group structure.

 

Where the business model is cross-border, group-based or heavily dependent on outsourced service providers, governance becomes particularly important. The applicant must remain in control of its regulated activities and must be able to demonstrate that It can oversee outsourced functions, manage incidents and respond to supervisory requests.

 

In various cases, a supervisory board may be required for obtaining a licence as a payment institutions.

What kind of internal policy documentation is required?

A licence application as a payment institution requires a coherent set of internal policies and procedures. These should not be treated as standalone documents, but as part of a wider operating model that explains how the business will provide payment services in practice.

 

Depending on the model, the policy framework will typically cover the following subjects:

  • Governance;
  • Risk management;
  • Compliance;
  • AML/CFT;
  • Sanctions;
  • Safeguarding;
  • Outsourcing;
  • Complaints handling;
  • Incident management;
  • Business continuity;
  • ICT and security risk;
  • Data protection;
  • Operational resilience; and
  • Internal reporting.

 

For payment institutions, DORA is now a key part of the operating framework. DORA applies since 17 January 2025 and introduces requirements on ICT risk management, incident reporting, digital operational resilience testing and ICT third-party risk.

What are key organisational requirements?

A payment institution must have an organisation that is capable of supporting the regulated services for which authorisation is sought. This includes sufficient staff, expertise, systems, controls and operational capacity.

 

The organisation should be designed around the actual services to be provided. For example, a provider of payment initiation services will have a different operational risk profile than a payment institution that receives and safeguards client funds, operates payment accounts or provides acquiring services to merchants.

 

Outsourcing is often central to fintech payment models. Outsourcing is permitted, but it does not transfer regulatory responsibility. The applicant must retain sufficient knowledge, oversight and decision-making capacity internally and must ensure that outsourcing arrangements do not impair the supervisory authority’s ability to supervise the institution.

What are key compliance and internal control requirements?

A payment institution must have an effective compliance and internal control framework. In practice, this means that the institution must be able to identify, assess, monitor and remediate legal, regulatory, operational and integrity risks on an ongoing basis.

 

AML/CFT and sanctions should be treated as core licensing topics. Depending on the business model, the payment institution may need customer due diligence procedures, transaction monitoring, sanctions screening, suspicious transaction reporting procedures, risk assessments, escalation processes and clear allocation of responsibilities.

 

Operational and security risks are also central. Payment institutions should be able to demonstrate how they protect payment users, manage fraud risk, secure payment data, handle incidents, ensure continuity and comply with applicable authentication and communication requirements.

What are key prudential requirements?

A payment institution must meet applicable initial capital and own funds requirements. The required amount depends on the payment services provided and the method used for calculating ongoing own funds.

 

The prudential analysis should not be reduced to a formal capital number. The supervisory authorities will also expect the applicant to have a credible financial forecast, adequate funding, realistic assumptions, and sufficient resources to sustain the organization during and after the licensing process.

 

Safeguarding of client funds is a separate and important prudential topic. Payment institutions that receive funds for the execution of payment transactions must ensure that those funds are protected in accordance with applicable safeguarding rules. PSD2 requires safeguarding of funds received by payment institutions providing certain payment services, and supervisory guidance highlights the importance of selecting and documenting the safeguarding method early in the application process.

Licence application procedure.

What does a licence application procedure look like?

A payment institution licence application is a structured process. The applicant must first determine the exact scope of services for which authorisation is required and prepare an application file that explains the business model, programme of operations, governance, financial position, safeguarding arrangements, internal controls and compliance framework.

 

The application process consists of two phases: a completeness review and a substantive assessment. The substantive assessment is only conducted once the application is complete, and incomplete applications may be delayed or dismissed.

 

The statutory consideration period for a payment institution licence application is three months. However, DNB notes that the total processing time is often longer because the statutory period does not start until all information required for a decision has been received and may be suspended where information is missing or additional questions arise.

 

In practice, the quality of the application file is critical. DNB identifies completeness, legal substantiation, clear description of services and money flows, governance, capital, safeguarding, substance in the Netherlands and timely recruitment of key function holders as important success factors.

Our approach.

What is the Watsonlaw approach?

At Watsonlaw, we approach payment services matters in a practical and hands-on manner. We understand that payment businesses often operate in fast-moving and technically complex environments, where legal advice must be clear, commercially workable and aligned with the actual product and operational setup.

 

Our work often starts with the qualification of the relevant services and payment flows. We help clients assess whether their model falls within PSD2, whether a licence, exemption or notification may be required, and whether the model should be structured differently to fit the regulatory framework.

 

From there, we assist with the broader licensing and implementation process. This includes preparing the regulatory analysis, structuring safeguarding arrangements, drafting internal policies, reviewing outsourcing and merchant arrangements, preparing the licence application file and engaging with supervisory authorities where relevant.

 

Our advice is tailored to the business model at hand. Whether you are launching a marketplace, wallet, acquiring model, payment initiation service, embedded payments structure or crypto-linked payment product, we help identify the applicable framework and the practical next steps.

FAQ.

Can I display client balances on my platform?

There are several ways in which client balances can be displayed in client accounts on a platform without requiring a licence as a payment services provider. One way of structuring is the issuance of a payment instrument under the limited network exception. This does not require a licence, but does require a notification to the supervisory authority after a threshold of EUR 1 million transactions has been reached within twelve months.

How should client funds be safeguarded?

Safeguarding can be structured in different ways, including through a customer accounts foundation, a segregated assets account, or an insurance policy or guarantee. The appropriate method depends on the business model, the money flow, the role of third-party banks or payment service providers, and the way in which client funds are received and held.

Is a payment services licence sufficient for crypto-related payment models?

Not always. Crypto-related payment models may also raise questions under MiCA and EMD2. Where a model involves both crypto-assets and fiat or electronic money flows, the licensing analysis must consider all relevant frameworks together.

Do technical service providers require a payment services licence?

Services provided by technical service providers, which support the provision of payment services, without them entering at any time into possession of the funds to be transferred, are not subject to PSD2. This includes processing and storage of data, trust and privacy protection mechanisms, data and entity authentication, information technology (IT) and communication network provision,  and provision and maintenance of terminals and devices used for payment services. However, if the service qualifies as a payment initiation service or account information service, it is subject to PSD2.

Contact us.

Are you developing a payment, wallet, stored-value or platform model and unsure whether your activities qualify as regulated payment services, electronic money issuance, or fall outside the licensing perimeter?

 

Watsonlaw advises on the legal qualification of payment and e-money models under PSD2, EMD2 and the Wft, including the applicability of exemptions, exceptions and adjacent frameworks such as MiCA, DORA and AML/CFT regulation.

 

We are happy to assist with the legal qualification of your activities, the analysis of your payment and value flows, the structuring of your product or service and the next steps for your business.

 

Would you like to know more? Please contact Willem-Jan Smits or Rens Kattenbelt.

Client experiences.