Provision of the "acquiring of payment transactions" payment service in the EU
EBA Q&A 2021_6283 →Nieuwe technologieën vereisen nieuwe inzichten.
Nieuwe technologieën vereisen nieuwe inzichten.
PSD2 beperkt zich niet tot de richtlijn zelf. Een substantieel deel van het regelgevend kader is uitgewerkt in diverse Guidelines en Q&A’s van verschillende toezichthoudende autoriteiten.
Deze maatregelen geven nadere operationele invulling aan de kernvereisten van PSD2. Zij zien onder meer op safeguarding, beloning, uitbesteding, klantauthenticatie en een nadere uitleg van belangrijke definities.
Het regelgevend landschap blijft zich ontwikkelen. Nieuwe maatregelen worden doorlopend aangenomen, afgerond of geactualiseerd. Het kan in de praktijk daarom lastig zijn om het volledige kader goed bij te houden.
Om cliënten en andere marktpartijen daarbij te ondersteunen, hebben wij onderstaande tracker ontwikkeld. Deze tracker biedt een gestructureerd en actueel overzicht van alle relevante Q&A’s en Guidelines onder PSD2.
PSD2 guidelines and Q&As tracker
Provision of the "acquiring of payment transactions" payment service in the EU
EBA Q&A 2021_6283 →Paper-based postal money orders as defined by the Universal Postal Union
EBA Q&A 2022_6391 →Money remittance
EBA Q&A 2020_5216 →Acquisition and money remittance payment service
EBA Q&A 2020_5181 →Access to account for FinTech Solutions that incorporate regulated services
EBA Q&A 2020_5249 →On the access to safeguarding accounts through the Application Programming Interface (API)
EBA Q&A 2021_5755 →Reading of the term "means of payment"
EBA Q&A 2022_6481 →Interpretation of payment instrument
EBA Q&A 2023_6910 →Clarification on whether a particular business model type constitutes the provision of an account information service as defined by Article 4(16) PSD2
EBA Q&A 2018_4098 →Type of accounts accessible through common and secure communication
EBA Q&A 2019_4856 →Collection of fees for utilities or other regular services
EBA Q&A 2020_5099 →Does SCA apply to electronically processed SEPA Direct Debits?
EBA Q&A 2018_4359 →Compliance of (1) card data (2) SMS OTP and (3) EMV 3DS behaviour-based inherence as an authentication information with the requirements of PSD2 and RTS on SCA
EBA Q&A 2019_4671 →Strong customer authentication (SCA) knowledge element: Place of Birth and Date of Birth
EBA Q&A 2021_5821 →Knowledge element of SCA
EBA Q&A 2024_7286 →On the access to names and surnames through the API
EBA Q&A 2018_4081 →Information to be provided / made available by ASPSP to payment initiation service provider (PISP)
EBA Q&A 2018_4188 →Final report on the EBA Guidelines under PSD2 on the information to be provided for the authorisation of PIs and EMIs and for the registration of AISPs
Guidelines →Final report Guidelines on remuneration policies
Guidelines on remuneration →Peer review follow-up report on authorisation under PSD2
Peer review follow-up report on authorisation →Final report on EBA Guidelines on outsourcing arrangements
Guidelines on outsourcing →Final Guidelines on Professional Indemnity Insurance under PSD2
Guidelines on PII →Consideration of own funds requirements as a comparable guarantee to the PII
EBA Q&A 2023_6675 →Minimum monetary amount of professional indemnity insurance in ongoing supervision
EBA Q&A 2025_7317 →Clarification on the protection requirements of a CustomerID when included in a payer-presented QR-code for the initiation of (instant) credit transfers at the Point of Interaction (POI)
EBA Q&A 2021_6298Multi-licensed entity capital requirement
EBA Q&A 2023_6790 →Calculation of "payment volume" for method B in Article 9 of PSD2
EBA Q&A 2021_6241 →Calculation of own funds required for payment institution in Article 9 PSD2 when the payment institution offers acquiring services
EBA Q&A 2018_4298 →Calculation of own funds required for payment institution in Article 9 PSD2 when "input funds" are credit transfers and "output funds" are direct debit
EBA Q&A 2018_4299 →Safeguarding
EBA Q&A 2020_5264 →Clarification of meanings 'transferring of funds' and 'another payment service provider' in the context of article 10(1)(a) PSD2
EBA Q&A 2020_5502 →Safeguarding with a credit institution in a third country
EBA Q&A 2023_6882 →Compliance of non-bank PSPs with the safeguarding requirements in PSD2
EBA Q&A 2024_7165 →"Triangular" passport
EBA Q&A 2021_5726 →Annex VI - Agents/distributors
EBA Q&A 2022_6437 →Information on the host Member State in which Third Party Providers (TPPs) provide services
EBA Q&A 2021_6078 →Credit
EBA Q&A 2024_7056 →Passporting and eIDAS certificates
EBA Q&A 2018_4432 →Showing a password after it has been masked
EBA Q&A 2018_4366 →Exchange rate mark-ups part of 'all charges payable'/'currency conversion charges'
EBA Q&A 2023_6777 →Ability of a creditor to change a mandate
EBA Q&A 2020_5479 →Information provided to the payee on individual payment transaction
EBA Q&A 2022_6612 →Explicit consent required by the ASPSP from the PSU to enable the PSU to use the services provided by TPPs
EBA Q&A 2018_4123 →Sanctions list screening in the context of TPP's services - risk management policy
EBA Q&A 2018_4117 →Consent for the provision of PIS and AIS
EBA Q&A 2018_4309 →"Authorisation number" in eIDAS certificates
EBA Q&A 2019_4679 →Account Data required by a ASPSP to execute a payment order via a PISP
EBA Q&A 2019_4854 →Proxy matrices
EBA Q&A 2024_7265 →Authentication process of the PSU with the ASPSP in a combined AIS and PIS journey in a redirection approach
EBA Q&A 2024_7358 →Future-dated payments and recurring transactions
EBA Q&A 2021_6318 →Individual's name to return in AISP/PISP calls
EBA Q&A 2020_5165 →PISP's access to payable charges applied by the ASPSP on the PSU's initiated payment via the ASPSP's dedicated interface
EBA Q&A 2021_6320 →Obstacles faced by PISPs in accessing payment status information under PSD2
EBA Q&A 2024_7261 →Interpretation of 'Active request for account information'
EBA Q&A 2018_4172 →Period to be covered by statistics pursuant to Article 32(4) of Commission Delegated Regulation (EU) 2018/389
EBA Q&A 2023_6687 →Setting limit (daily and/or per transaction) for the execution of payment transaction by PSP
EBA Q&A 2025_7425 →Application of SCA to issuing a payment instrument and tokenisation
EBA Q&A 2020_5622 →Evidences / records to be stored by ASPSP for PIS and AIS requests
EBA Q&A 2022_6526 →Liability for fraud when SCA exemption used
EBA Q&A 2018_4042 →Unattended terminals and Transaction Risk Analysis (TRA) exemption and related PSP's liabilities rules
EBA Q&A 2019_4480 →Articulation and interaction of the second and the third sub-paragraph of Article 74(1) PSD2
EBA Q&A 2021_6305 →PISP payment order cancellation due to fraud prevention reasons
EBA Q&A 2023_6873 →Credit value date for payment transactions with currency conversion
EBA Q&A 2018_4150 →Final report on Revised Guidelines on major incident reporting under PSD2
Revised Guidelines →Arbitrating between security and obstacles
EBA Q&A 2021_6156 →Major incidents reporting
EBA Q&A 2018_4144 →Service Downtime
EBA Q&A 2023_6744 →Losses due to fraud per liability bearer
EBA Q&A 2019_5008 →Fraud reporting
EBA Q&A 2023_6788 →Application of SCA for confirmation of funds requests made by a PISP
EBA Q&A 2021_6280 →SCA applicability / application of SCA at tokenisation stage
EBA Q&A 2021_6145 →App to app redirection with biometrics for PIS
EBA Q&A 2023_6767 →Trusted beneficiaries
EBA Q&A 2023_6827 →Payee-initiated transactions with irregular period or variable amounts for account payments
EBA Q&A 2021_6256 →Criteria for selecting the operations to be included in the calculation of fraud rates for the transaction risk analysis (TRA) exemption
EBA Q&A 2024_6989 →SCA exception for Contactless only terminals (SoftPOS) in case of emergency
EBA Q&A 2025_7482 →Bill-payment via postal service
EBA Q&A 2020_5534 →Transactions initiated via electronic mail (email)
EBA Q&A 2021_6315 →SCA for token replacement
EBA Q&A 2022_6464 →Application for low-value contactless exemption - Calculation of limits at Primary Account Number (PAN) / account level or at device / token level
EBA Q&A 2018_4036 →Criteria for the application of the transaction risk analysis (TRA) exemption - Application of the TRA exemption by authorized PSPs other than the issuer and the acquirer
EBA Q&A 2018_4035 →Criteria for the application of the TRA exemption - Relevant fraud rates
EBA Q&A 2018_4034 →Criteria for the application of the TRA exemption - Application of the TRA exemption at the level of individual brand, product or scheme
EBA Q&A 2018_4033 →Criteria for the application of the TRA exemption - Fraud rate calculation methodology for the application of the TRA exemption
EBA Q&A 2018_4032 →Applicability of SCA to 'card payments initiated by the payee only'
EBA Q&A 2018_4031 →Geographical scope of application of the RTS on strong customer authentication (SCA) and secure communication requirements - 'Two-leg' transactions
EBA Q&A 2018_4030 →Persistent authentication for wearable devices
EBA Q&A 2018_4049 →Applicability of Strong Customer Authentication (SCA) to existing recurring payments solutions
EBA Q&A 2018_4048 →Review of security measures
EBA Q&A 2018_4047 →Display of incorrect authentication factors in case of failed authentication attempts
EBA Q&A 2018_4041 →Currency conversion of the EUR thresholds contained in the RTS
EBA Q&A 2018_4040 →Qualification of SMS OTP as an authentication factor
EBA Q&A 2018_4039 →Applicability of the low-value contactless exemption to contactless-only devices
EBA Q&A 2018_4038 →Accessing payment account online in web browser shall exceed not 5 minutes without activity
EBA Q&A 2018_4065 →Exemption for secure corporate payment processes and protocols
EBA Q&A 2018_4060 →Transactions initiated via Interactive Voice Response (IVR) solutions
EBA Q&A 2018_4058 →SCA at vending machines without PIN pad
EBA Q&A 2018_4057 →Application of the exemption for transactions to trusted beneficiaries to Face-to-Face transactions
EBA Q&A 2018_4056 →Confidentiality of offline PIN
EBA Q&A 2018_4055 →Confidentiality of the application cryptogram for EMV transactions
EBA Q&A 2018_4054 →Length of authentication codes
EBA Q&A 2018_4053 →EMV cards and EMV terminals supporting online authentication
EBA Q&A 2018_4052 →Review of Security Measures - Auditors expertise
EBA Q&A 2018_4153 →Review of the security measures: Audit report
EBA Q&A 2018_4152 →Authentication code
EBA Q&A 2018_4141 →SMS OTP and credit card as a two authentication factor
EBA Q&A 2018_4135 →Payee-initiated transactions with irregular period or variable amount
EBA Q&A 2018_4131 →Data authentication standards
EBA Q&A 2018_4110 →Scope of ‘initiation of an electronic payment transaction’
EBA Q&A 2018_4108 →Exemption from strong customer authentication (SCA) for payment account information in combination with accessing account information online in web browser
EBA Q&A 2018_4068 →On the access to trusted beneficiaries lists (RTS Art 13) by TPPs in write mode
EBA Q&A 2018_4076 →Usage of SMS for dynamic linking
EBA Q&A 2018_4414 →Subsequent instances of a recurring card payment transaction, other than the first, initial one, are transactions initiated by the payee only. This is also the case for card instalment transactions.
EBA Q&A 2018_4404 →Strong Authentication
EBA Q&A 2018_4315 →Contactless payments at point of sale - Applications of the conditions
EBA Q&A 2018_4226 →Contactless payments at point of sale - Applications of the conditions
EBA Q&A 2018_4225 →Application of SCA when a PSU accesses payment transactions data older than on the last 90 days, without having access to sensitive payment data and for a period of 90 days after the last access using SCA
EBA Q&A 2018_4177 →Responsibility of national authority with regards to audit reports
EBA Q&A 2018_4155 →Definition of payee for dynamic linking
EBA Q&A 2019_4556 →Unattended terminals and Transaction Risk Analysis (TRA) exemption and related Payment Service Providers (PSP)’s liabilities rules
EBA Q&A 2019_4480 →Dynamic Linking for batch payments
EBA Q&A 2018_4435 →Application of the Low Value Transaction Limits
EBA Q&A 2018_4429 →Dynamic linking for batch transactions
EBA Q&A 2018_4415 →Mount unattended contactless device on general goods vending machines
EBA Q&A 2020_5288 →Payment Initiation Scope and Trusted Beneficiaries
EBA Q&A 2020_5135 →Dynamic linking: transactions for which the final amount is unknown and may be lower or higher than authenticated amount
EBA Q&A 2020_5133 →Using Trusted Beneficiary Lists to Auto Reject PISP Transactions
EBA Q&A 2020_5115 →Applicability of SCA to electronically processed SEPA Direct Debits / Interpretation of EBA Q&A 2018_4359
EBA Q&A 2019_4664 →Exemptions from Strong Customer Authentication (SCA): credit transfers
EBA Q&A 2019_4564 →Secure corporate payment processes and protocols and inactivity time period
EBA Q&A 2023_6949 →The use of strong and widely recognized encryption techniques
EBA Q&A 2025_7376 →Authentication procedures that ASPSPs’ interfaces are required to support (using re-direction)
EBA Q&A 2021_6321 →Exemption from strong customer authentication
EBA Q&A 2023_6820 →Mobile Banking Services and SCA in the same app
EBA Q&A 2023_6863 →API functionality
EBA Q&A 2022_6392 →Eligibility of communication by AISPs with ASPSP throughout two access interfaces in parallel
EBA Q&A 2023_6752 →Revocation of ASPSP's Exemption from the Contingency Mechanism due to Prolonged Service Disruption
EBA Q&A 2024_7103 →Obligatory nature of the SCA and exemption based on transaction risk analysis
EBA Q&A 2018_4089 →Ability of static card data to be considered a possession factor?
EBA Q&A 2018_4235 →Signature on a paper slip from a payment terminal, as a factor in a two-factor SCA
EBA Q&A 2018_4237 →Signature performed on the screen of a digital device as a factor in a two-factor SCA
EBA Q&A 2018_4238 →Showing a password after it has been masked
EBA Q&A 2018_4366 →Unsuccessful authentications and declined transactions effect on the counters of cumulative amount and number of consecutive transactions
EBA Q&A 2019_4785 →Exemptions from Strong Customer Authentication (SCA): trusted beneficiaries
EBA Q&A 2018_4120 →Access by AISPs when customer not present up to 4 times in a 24 hour period
EBA Q&A 2018_4210 →Applicability of exemption from strong customer authentication (SCA) under Article 17 for card payments
EBA Q&A 2018_4239 →Exemption of secure corporate payment processes and protocols
EBA Q&A 2018_4383 →Fraud rate calculation for TRA exemption – country dimension
EBA Q&A 2018_4439 →Compliance with SCA in offline mode on an aircraft without internet connection
EBA Q&A 2019_4740 →Delayed or deferred PIN for wearable devices
EBA Q&A 2019_4783 →"Push based" authentication and SCA requirements
EBA Q&A 2019_4984 →Scope of contingency mechanism
EBA Q&A 2019_4826 →Relying on vendor mechanisms processing the biometric data for strong customer authentication; Multiple fingerprint samples stored on a mobile device and used for purpose of user authentication.
EBA Q&A 2019_4651 →ASPSP is denied the waiver to the fall-back by an NCA
EBA Q&A 2018_4140 →Communication plans to inform payment service providers making use of the dedicated interface
EBA Q&A 2018_4071 →Knowledge element of SCA.
EBA Q&A 2024_7286 →Guidelines on the conditions to be met to benefit from an exemption from contingency measures under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA & CSC)
Guidelines →Change of TPP access rights for AIS consent by the PSU prior to authorisation
EBA Q&A 2021_6246 →Ability of Payee’s PSP to apply exemptions from SCA in credit transfers
EBA Q&A 2021_5845 →Arbitrating between security and obstacles
EBA Q&A 2021_6156 →Calculation of fraud rates in relation to Exemption Threshold Values (ETVs)
EBA Q&A 2018_4043 →Transaction Risk Analysis (TRA) exemption – Frequency of recalculation of fraud rate
EBA Q&A 2018_4045 →Communication plans to inform payment service providers making use of the dedicated interface
EBA Q&A 2018_4071 →Obligatory nature of the SCA and exemption based on transaction risk analysis
EBA Q&A 2018_4089 →Exemptions from Strong Customer Authentication (SCA): trusted beneficiaries
EBA Q&A 2018_4120 →Application of Transaction Risk Analysis (TRA) exemption – Real time risk analysis / monitoring
EBA Q&A 2018_4127 →Trusted Beneficiary exemption – Management of the exemption, information flows between PSPs in the payment transaction
EBA Q&A 2018_4128 →Testing eIDAS certificates before 14 September 2019
EBA Q&A 2018_4138 →ASPSP is denied the waiver to the fall-back by an NCA
EBA Q&A 2018_4140 →Fall back exemption
EBA Q&A 2018_4163 →Ability of static card data to be considered a possession factor?
EBA Q&A 2018_4235 →Signature performed on the screen of a digital device as a factor in a two-factor SCA
EBA Q&A 2018_4238 →Applicability of exemption from strong customer authentication (SCA) under Article 17 for card payments
EBA Q&A 2018_4239 →Trusted Beneficiaries
EBA Q&A 2018_4338 →Application of the exemption related to a trusted beneficiary
EBA Q&A 2018_4360 →Showing a password after it has been masked
EBA Q&A 2018_4366 →Chip and Signature cards and their inclusion in the remit of RTS Article 11
EBA Q&A 2018_4342 →Certification in relation to a Technical Service Provider (TSP)
EBA Q&A 2018_4375 →Applicability of Article 34 (eIDAS certificates) prior to application date of Regulation (EU) 2018/389
EBA Q&A 2019_4630 →Identification and access for testing purposes of entities that are not authorised third party providers (TPPs)
EBA Q&A 2019_4609 →Strong Customer Authentication (SCA) possession element requirement for cryptographic validation
EBA Q&A 2019_4532 →Content of eIDAS certificates if agents or outsource providers are involved
EBA Q&A 2019_4507 →Fraud rate calculation for TRA exemption – country dimension
EBA Q&A 2018_4439 →RTS on strong customer authentication and secure communication under PSD2
Final RTS →Final Report Guidelines on procedures for complaints of alleged infringements of Directive (EU) 2015/2366
Guidelines on procedures for complaints →Final Report on amending Guidelines on fraud reporting under PSD2
Guidelines on fraud reporting →Final Report Guidelines on information requirements in relation to transfers of funds and certain crypto-assets transfers under Regulation (EU) 2023/1113 ('Travel Rule Guidelines')
Travel Rule Guidelines →Joint Guidelines under Article 25 of Regulation (EU) 20215/847 on the measures PSPs should take to detect missing or incomplete information on the payer or the payee, and the procedures they should put in place to manage a transfer of funds lacking the required information
Joint Guidelines on missing or incomplete information →Recovery- and exitplans payment institutions
Guidelines on recovery- and exitplans →Supervisory boards of payment institutions and electronic money institutions
Q&A on supervisory boards →No measures match the current filters.
Lanceert u een betaal-, wallet- of stored-valueproduct, beoordeelt u of een dienst onder PSD2 of EMD2 valt, of bereidt u een vergunningaanvraag voor?
Watsonlaw adviseert over het volledige spectrum aan juridische en toezichtsvragen met betrekking tot betaaldiensten en elektronisch geld, waaronder kwalificatie, vergunningverlening, governance, interne documentatie, safeguarding en, waar relevant, de samenhang met aanpalende regelgevingskaders.
Wij helpen u graag met de juridische kwalificatie van uw activiteiten, de structurering van uw product of dienst, het toepasselijke juridische kader en de vervolgstappen voor uw onderneming.
Wilt u meer weten? Neem dan contact op met Willem-Jan Smits of Rens Kattenbelt.
“Ze durven echt stappen te zetten. Vaak gaat het om onontgonnen materie. Je kunt erop vertrouwen dat zij een positie innemen die later wel verdedigbaar is."
Consultant techsector
"Watsonlaw draagt echt bij aan de groei van ons bedrijf. Daar zit de grootste toegevoegde waarde. Ze geven concreet advies en vertellen mij wat de beste stap is. Dat is precies wat ik in een advocaat zoek."
Ondernemer cryptobedrijf
“Ze zijn heel proactief en ze zitten zelf ook proactief in de wedstrijd, dat straalt ervan af. Ze zijn on point. We zitten op dezelfde manier in de wedstrijd: transparant, direct, we weten elkaar te vinden, we willen allebei bouwen aan iets. Ze zijn veel meer dan advocaten. En als ze iets niet weten, lezen ze zich in. Daar zijn ze steengoed in.”
Ondernemer cryptobedrijf
“Bij een start-up heb je vaak honderd ballen tegelijk in de lucht. Het belangrijkste dat ik uit een samenwerking met een advocaat wil halen is: geruststelling. Zodat ik rustig kan slapen. En dat heb ik gekregen.”
Ondernemer start-up