PSD2 Guidelines en Q&As

Building
a framework
for growth
Our point
of view:

Here’s our point of view:
We can help you prepare for what the future holds for your business.

PSD2 beperkt zich niet tot de richtlijn zelf. Een substantieel deel van het regelgevend kader is uitgewerkt in diverse Guidelines en Q&A’s van verschillende toezichthoudende autoriteiten.

 

Deze maatregelen geven nadere operationele invulling aan de kernvereisten van PSD2. Zij zien onder meer op safeguarding, beloning, uitbesteding, klantauthenticatie en een nadere uitleg van belangrijke definities.

 

Het regelgevend landschap blijft zich ontwikkelen. Nieuwe maatregelen worden doorlopend aangenomen, afgerond of geactualiseerd. Het kan in de praktijk daarom lastig zijn om het volledige kader goed bij te houden.

 

Om cliënten en andere marktpartijen daarbij te ondersteunen, hebben wij onderstaande tracker ontwikkeld. Deze tracker biedt een gestructureerd en actueel overzicht van alle relevante Q&A’s en Guidelines onder PSD2.

PSD2 guidelines and Q&As tracker

EBA Q&A

Provision of the "acquiring of payment transactions" payment service in the EU

EBA Q&A 2021_6283 →
1
EBA Q&A

Paper-based postal money orders as defined by the Universal Postal Union

EBA Q&A 2022_6391 →
3
EBA Q&A

Acquisition and money remittance payment service

EBA Q&A 2020_5181 →
4(12), (24), (44), 10
EBA Q&A

Access to account for FinTech Solutions that incorporate regulated services

EBA Q&A 2020_5249 →
4(12), (17)
EBA Q&A

On the access to safeguarding accounts through the Application Programming Interface (API)

EBA Q&A 2021_5755 →
4(12)
EBA Q&A

Clarification on whether a particular business model type constitutes the provision of an account information service as defined by Article 4(16) PSD2

EBA Q&A 2018_4098 →
4(16)
EBA Q&A

Type of accounts accessible through common and secure communication

EBA Q&A 2019_4856 →
4(16)
EBA Q&A

Collection of fees for utilities or other regular services

EBA Q&A 2020_5099 →
4(22), (44)
EBA Q&A

Does SCA apply to electronically processed SEPA Direct Debits?

EBA Q&A 2018_4359 →
4(23)
EBA Q&A

Compliance of (1) card data (2) SMS OTP and (3) EMV 3DS behaviour-based inherence as an authentication information with the requirements of PSD2 and RTS on SCA

EBA Q&A 2019_4671 →
4(30)
EBA Q&A

Strong customer authentication (SCA) knowledge element: Place of Birth and Date of Birth

EBA Q&A 2021_5821 →
4(30)
EBA Q&A

Information to be provided / made available by ASPSP to payment initiation service provider (PISP)

EBA Q&A 2018_4188 →
4(32)
EBA Guidelines

Final report on the EBA Guidelines under PSD2 on the information to be provided for the authorisation of PIs and EMIs and for the registration of AISPs

Guidelines →
EBA Guidelines

Final Guidelines on Professional Indemnity Insurance under PSD2

Guidelines on PII →
5
EBA Q&A

Consideration of own funds requirements as a comparable guarantee to the PII

EBA Q&A 2023_6675 →
5(2), (3)
EBA Q&A

Minimum monetary amount of professional indemnity insurance in ongoing supervision

EBA Q&A 2025_7317 →
5(4)
EBA Q&A

Clarification on the protection requirements of a CustomerID when included in a payer-presented QR-code for the initiation of (instant) credit transfers at the Point of Interaction (POI)

EBA Q&A 2021_6298
6(1)
EBA Q&A

Calculation of "payment volume" for method B in Article 9 of PSD2

EBA Q&A 2021_6241 →
9(1)
EBA Q&A

Calculation of own funds required for payment institution in Article 9 PSD2 when the payment institution offers acquiring services

EBA Q&A 2018_4298 →
9(1)
EBA Q&A

Calculation of own funds required for payment institution in Article 9 PSD2 when "input funds" are credit transfers and "output funds" are direct debit

EBA Q&A 2018_4299 →
9(1)
EBA Q&A

Clarification of meanings 'transferring of funds' and 'another payment service provider' in the context of article 10(1)(a) PSD2

EBA Q&A 2020_5502 →
10(1)
EBA Q&A

Safeguarding with a credit institution in a third country

EBA Q&A 2023_6882 →
10(1)
EBA Q&A

Compliance of non-bank PSPs with the safeguarding requirements in PSD2

EBA Q&A 2024_7165 →
10(1)
EBA Q&A

Information on the host Member State in which Third Party Providers (TPPs) provide services

EBA Q&A 2021_6078 →
15
EBA Q&A

Exchange rate mark-ups part of 'all charges payable'/'currency conversion charges'

EBA Q&A 2023_6777 →
45(1)
EBA Q&A

Information provided to the payee on individual payment transaction

EBA Q&A 2022_6612 →
58
EBA Q&A

Explicit consent required by the ASPSP from the PSU to enable the PSU to use the services provided by TPPs

EBA Q&A 2018_4123 →
64
EBA Q&A

Sanctions list screening in the context of TPP's services - risk management policy

EBA Q&A 2018_4117 →
66
EBA Q&A

Account Data required by a ASPSP to execute a payment order via a PISP

EBA Q&A 2019_4854 →
66
EBA Q&A

Authentication process of the PSU with the ASPSP in a combined AIS and PIS journey in a redirection approach

EBA Q&A 2024_7358 →
66
EBA Q&A

PISP's access to payable charges applied by the ASPSP on the PSU's initiated payment via the ASPSP's dedicated interface

EBA Q&A 2021_6320 →
66(4)
EBA Q&A

Obstacles faced by PISPs in accessing payment status information under PSD2

EBA Q&A 2024_7261 →
66(4)
EBA Q&A

Interpretation of 'Active request for account information'

EBA Q&A 2018_4172 →
67
EBA Q&A

Period to be covered by statistics pursuant to Article 32(4) of Commission Delegated Regulation (EU) 2018/389

EBA Q&A 2023_6687 →
67
EBA Q&A

Setting limit (daily and/or per transaction) for the execution of payment transaction by PSP

EBA Q&A 2025_7425 →
68(1)
EBA Q&A

Application of SCA to issuing a payment instrument and tokenisation

EBA Q&A 2020_5622 →
70
EBA Q&A

Evidences / records to be stored by ASPSP for PIS and AIS requests

EBA Q&A 2022_6526 →
72
EBA Q&A

Unattended terminals and Transaction Risk Analysis (TRA) exemption and related PSP's liabilities rules

EBA Q&A 2019_4480 →
74
EBA Q&A

Articulation and interaction of the second and the third sub-paragraph of Article 74(1) PSD2

EBA Q&A 2021_6305 →
74(1)
EBA Q&A

PISP payment order cancellation due to fraud prevention reasons

EBA Q&A 2023_6873 →
80
EBA Q&A

Credit value date for payment transactions with currency conversion

EBA Q&A 2018_4150 →
87(1)
EBA Guidelines

Final report on Revised Guidelines on major incident reporting under PSD2

Revised Guidelines →
95
EBA Q&A

Application of SCA for confirmation of funds requests made by a PISP

EBA Q&A 2021_6280 →
97
EBA Q&A

SCA applicability / application of SCA at tokenisation stage

EBA Q&A 2021_6145 →
97
EBA Q&A

Payee-initiated transactions with irregular period or variable amounts for account payments

EBA Q&A 2021_6256 →
97
EBA Q&A

Criteria for selecting the operations to be included in the calculation of fraud rates for the transaction risk analysis (TRA) exemption

EBA Q&A 2024_6989 →
97
EBA Q&A

SCA exception for Contactless only terminals (SoftPOS) in case of emergency

EBA Q&A 2025_7482 →
97
EBA Q&A

Application for low-value contactless exemption - Calculation of limits at Primary Account Number (PAN) / account level or at device / token level

EBA Q&A 2018_4036 →
97(1)
EBA Q&A

Criteria for the application of the transaction risk analysis (TRA) exemption - Application of the TRA exemption by authorized PSPs other than the issuer and the acquirer

EBA Q&A 2018_4035 →
97(1)
EBA Q&A

Criteria for the application of the TRA exemption - Relevant fraud rates

EBA Q&A 2018_4034 →
97(1)
EBA Q&A

Criteria for the application of the TRA exemption - Application of the TRA exemption at the level of individual brand, product or scheme

EBA Q&A 2018_4033 →
97(1)
EBA Q&A

Criteria for the application of the TRA exemption - Fraud rate calculation methodology for the application of the TRA exemption

EBA Q&A 2018_4032 →
97(1)
EBA Q&A

Applicability of SCA to 'card payments initiated by the payee only'

EBA Q&A 2018_4031 →
97(1)
EBA Q&A

Geographical scope of application of the RTS on strong customer authentication (SCA) and secure communication requirements - 'Two-leg' transactions

EBA Q&A 2018_4030 →
97(1)
EBA Q&A

Applicability of Strong Customer Authentication (SCA) to existing recurring payments solutions

EBA Q&A 2018_4048 →
97(1)
EBA Q&A

Display of incorrect authentication factors in case of failed authentication attempts

EBA Q&A 2018_4041 →
97(1)
EBA Q&A

Currency conversion of the EUR thresholds contained in the RTS

EBA Q&A 2018_4040 →
97(1)
EBA Q&A

Applicability of the low-value contactless exemption to contactless-only devices

EBA Q&A 2018_4038 →
97(1)
EBA Q&A

Accessing payment account online in web browser shall exceed not 5 minutes without activity

EBA Q&A 2018_4065 →
97(1)
EBA Q&A

Exemption for secure corporate payment processes and protocols

EBA Q&A 2018_4060 →
97(1)
EBA Q&A

Transactions initiated via Interactive Voice Response (IVR) solutions

EBA Q&A 2018_4058 →
97(1)
EBA Q&A

Application of the exemption for transactions to trusted beneficiaries to Face-to-Face transactions

EBA Q&A 2018_4056 →
97(1)
EBA Q&A

Confidentiality of the application cryptogram for EMV transactions

EBA Q&A 2018_4054 →
97(1)
EBA Q&A

EMV cards and EMV terminals supporting online authentication

EBA Q&A 2018_4052 →
97(1)
EBA Q&A

SMS OTP and credit card as a two authentication factor

EBA Q&A 2018_4135 →
97(1)
EBA Q&A

Payee-initiated transactions with irregular period or variable amount

EBA Q&A 2018_4131 →
97(1)
EBA Q&A

Scope of ‘initiation of an electronic payment transaction’

EBA Q&A 2018_4108 →
97(1)
EBA Q&A

Exemption from strong customer authentication (SCA) for payment account information in combination with accessing account information online in web browser

EBA Q&A 2018_4068 →
97(1)
EBA Q&A

On the access to trusted beneficiaries lists (RTS Art 13) by TPPs in write mode

EBA Q&A 2018_4076 →
97(1)
EBA Q&A

Subsequent instances of a recurring card payment transaction, other than the first, initial one, are transactions initiated by the payee only. This is also the case for card instalment transactions.

EBA Q&A 2018_4404 →
97(1)
EBA Q&A

Contactless payments at point of sale - Applications of the conditions

EBA Q&A 2018_4226 →
97(1)
EBA Q&A

Contactless payments at point of sale - Applications of the conditions

EBA Q&A 2018_4225 →
97(1)
EBA Q&A

Application of SCA when a PSU accesses payment transactions data older than on the last 90 days, without having access to sensitive payment data and for a period of 90 days after the last access using SCA

EBA Q&A 2018_4177 →
97(1)
EBA Q&A

Responsibility of national authority with regards to audit reports

EBA Q&A 2018_4155 →
97(1)
EBA Q&A

Unattended terminals and Transaction Risk Analysis (TRA) exemption and related Payment Service Providers (PSP)’s liabilities rules

EBA Q&A 2019_4480 →
97(1)
EBA Q&A

Mount unattended contactless device on general goods vending machines

EBA Q&A 2020_5288 →
97(1)
EBA Q&A

Dynamic linking: transactions for which the final amount is unknown and may be lower or higher than authenticated amount

EBA Q&A 2020_5133 →
97(1)
EBA Q&A

Using Trusted Beneficiary Lists to Auto Reject PISP Transactions

EBA Q&A 2020_5115 →
97(1)
EBA Q&A

Applicability of SCA to electronically processed SEPA Direct Debits / Interpretation of EBA Q&A 2018_4359

EBA Q&A 2019_4664 →
97(1)
EBA Q&A

Exemptions from Strong Customer Authentication (SCA): credit transfers

EBA Q&A 2019_4564 →
97(1)
EBA Q&A

Secure corporate payment processes and protocols and inactivity time period

EBA Q&A 2023_6949 →
97(1)
EBA Q&A

The use of strong and widely recognized encryption techniques

EBA Q&A 2025_7376 →
97(1)
EBA Q&A

Authentication procedures that ASPSPs’ interfaces are required to support (using re-direction)

EBA Q&A 2021_6321 →
97(5)
EBA Q&A

Eligibility of communication by AISPs with ASPSP throughout two access interfaces in parallel

EBA Q&A 2023_6752 →
98(1)
EBA Q&A

Revocation of ASPSP's Exemption from the Contingency Mechanism due to Prolonged Service Disruption

EBA Q&A 2024_7103 →
98(1)
EBA Q&A

Obligatory nature of the SCA and exemption based on transaction risk analysis

EBA Q&A 2018_4089 →
98(1)
EBA Q&A

Ability of static card data to be considered a possession factor?

EBA Q&A 2018_4235 →
98(1)
EBA Q&A

Signature on a paper slip from a payment terminal, as a factor in a two-factor SCA

EBA Q&A 2018_4237 →
98(1)
EBA Q&A

Signature performed on the screen of a digital device as a factor in a two-factor SCA

EBA Q&A 2018_4238 →
98(1)
EBA Q&A

Unsuccessful authentications and declined transactions effect on the counters of cumulative amount and number of consecutive transactions

EBA Q&A 2019_4785 →
98(1)
EBA Q&A

Exemptions from Strong Customer Authentication (SCA): trusted beneficiaries

EBA Q&A 2018_4120 →
98(1)
EBA Q&A

Access by AISPs when customer not present up to 4 times in a 24 hour period

EBA Q&A 2018_4210 →
98(1)(4)
EBA Q&A

Applicability of exemption from strong customer authentication (SCA) under Article 17 for card payments

EBA Q&A 2018_4239 →
98(1)
EBA Q&A

Exemption of secure corporate payment processes and protocols

EBA Q&A 2018_4383 →
98(1)
EBA Q&A

Fraud rate calculation for TRA exemption – country dimension

EBA Q&A 2018_4439 →
98(1)
EBA Q&A

Compliance with SCA in offline mode on an aircraft without internet connection

EBA Q&A 2019_4740 →
98(1)
EBA Q&A

Relying on vendor mechanisms processing the biometric data for strong customer authentication; Multiple fingerprint samples stored on a mobile device and used for purpose of user authentication.

EBA Q&A 2019_4651 →
98(1)
EBA Q&A

Communication plans to inform payment service providers making use of the dedicated interface

EBA Q&A 2018_4071 →
98(1)
EBA Guidelines

Guidelines on the conditions to be met to benefit from an exemption from contingency measures under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA & CSC)

Guidelines →
98(3)
EBA Q&A

Change of TPP access rights for AIS consent by the PSU prior to authorisation

EBA Q&A 2021_6246 →
98(4)
EBA Q&A

Ability of Payee’s PSP to apply exemptions from SCA in credit transfers

EBA Q&A 2021_5845 →
98(4)
EBA Q&A

Calculation of fraud rates in relation to Exemption Threshold Values (ETVs)

EBA Q&A 2018_4043 →
98(4)
EBA Q&A

Transaction Risk Analysis (TRA) exemption – Frequency of recalculation of fraud rate

EBA Q&A 2018_4045 →
98(4)
EBA Q&A

Communication plans to inform payment service providers making use of the dedicated interface

EBA Q&A 2018_4071 →
98(4)
EBA Q&A

Obligatory nature of the SCA and exemption based on transaction risk analysis

EBA Q&A 2018_4089 →
98(4)
EBA Q&A

Exemptions from Strong Customer Authentication (SCA): trusted beneficiaries

EBA Q&A 2018_4120 →
98(4)
EBA Q&A

Application of Transaction Risk Analysis (TRA) exemption – Real time risk analysis / monitoring

EBA Q&A 2018_4127 →
98(4)
EBA Q&A

Trusted Beneficiary exemption – Management of the exemption, information flows between PSPs in the payment transaction

EBA Q&A 2018_4128 →
98(4)
EBA Q&A

Ability of static card data to be considered a possession factor?

EBA Q&A 2018_4235 →
98(4)
EBA Q&A

Signature performed on the screen of a digital device as a factor in a two-factor SCA

EBA Q&A 2018_4238 →
98(4)
EBA Q&A

Applicability of exemption from strong customer authentication (SCA) under Article 17 for card payments

EBA Q&A 2018_4239 →
98(4)
EBA Q&A

Application of the exemption related to a trusted beneficiary

EBA Q&A 2018_4360 →
98(4)
EBA Q&A

Chip and Signature cards and their inclusion in the remit of RTS Article 11

EBA Q&A 2018_4342 →
98(4)
EBA Q&A

Certification in relation to a Technical Service Provider (TSP)

EBA Q&A 2018_4375 →
98(4)
EBA Q&A

Applicability of Article 34 (eIDAS certificates) prior to application date of Regulation (EU) 2018/389

EBA Q&A 2019_4630 →
98(4)
EBA Q&A

Identification and access for testing purposes of entities that are not authorised third party providers (TPPs)

EBA Q&A 2019_4609 →
98(4)
EBA Q&A

Strong Customer Authentication (SCA) possession element requirement for cryptographic validation

EBA Q&A 2019_4532 →
98(4)
EBA Q&A

Content of eIDAS certificates if agents or outsource providers are involved

EBA Q&A 2019_4507 →
98(4)
EBA Q&A

Fraud rate calculation for TRA exemption – country dimension

EBA Q&A 2018_4439 →
98(4)
EBA RTS

RTS on strong customer authentication and secure communication under PSD2

Final RTS →
98(4)
EBA Guidelines

Final Report Guidelines on information requirements in relation to transfers of funds and certain crypto-assets transfers under Regulation (EU) 2023/1113 ('Travel Rule Guidelines')

Travel Rule Guidelines →
EBA, ESMA, EIOPA Guidelines

Joint Guidelines under Article 25 of Regulation (EU) 20215/847 on the measures PSPs should take to detect missing or incomplete information on the payer or the payee, and the procedures they should put in place to manage a transfer of funds lacking the required information

Joint Guidelines on missing or incomplete information →

Neem contact op.

Lanceert u een betaal-, wallet- of stored-valueproduct, beoordeelt u of een dienst onder PSD2 of EMD2 valt, of bereidt u een vergunningaanvraag voor?

 

Watsonlaw adviseert over het volledige spectrum aan juridische en toezichtsvragen met betrekking tot betaaldiensten en elektronisch geld, waaronder kwalificatie, vergunningverlening, governance, interne documentatie, safeguarding en, waar relevant, de samenhang met aanpalende regelgevingskaders.

 

Wij helpen u graag met de juridische kwalificatie van uw activiteiten, de structurering van uw product of dienst, het toepasselijke juridische kader en de vervolgstappen voor uw onderneming.

 

Wilt u meer weten? Neem dan contact op met Willem-Jan Smits of Rens Kattenbelt.

Klantervaringen.