This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| Payment Services Directive (PSD2) | |
|---|---|
| Name | Payment Services Directive (PSD2) |
| Type | Directive |
| Issued by | European Union |
| Adopted | 2015 |
| Came into force | 2018 |
| Status | In force |
Payment Services Directive (PSD2) is a European Union directive that reformed rules for payment services, electronic money, and payment institutions across the European Union and the European Economic Area. It replaced the original Payment Services Directive to harmonize retail payments markets, foster innovation, strengthen consumer protection, and promote competition among incumbents and new entrants such as fintech firms. PSD2 intersected with regulatory work by the European Banking Authority, influenced national supervisors including the Bank of England and Deutsche Bundesbank, and shaped commercial strategies at Visa and Mastercard.
PSD2 arose from policy debates in the European Commission and legislative engagement by the European Parliament amid rapid growth in online banking, mobile payments, and services by firms like PayPal and Stripe. The directive aimed to update the 2007 Payment Services Directive framework to address issues surfaced during the 2008 financial crisis, the FinTech revolution, and developments led by Apple Inc., Google, and Amazon (company). Objectives included increasing market integration across the Single European Market, reducing barriers to entry for Third Party Providers (TPPs), enhancing consumer rights aligned with instruments like the Consumer Rights Directive, and responding to security incidents such as major data breaches at firms like Equifax.
PSD2 covers payment service providers established in the European Economic Area and sets conduct and prudential rules for entities such as credit institutions, payment institutions, and issuers of electronic money like Revolut and N26 (bank). Key provisions include the authorization and supervision regime for Third Party Providers including Account Information Service Providers and Payment Initiation Service Providers, new transparency rules for fees and exchange rates affecting cross-border payments within the European Union, and liability allocations for unauthorized transactions referencing standards used by the European Banking Authority and European Central Bank. The directive amended other legal instruments including the Anti-Money Laundering Directive and interacted with rules from bodies like the European Securities and Markets Authority.
PSD2 mandated Strong Customer Authentication (SCA) to mitigate fraud, specifying multifactor authentication combining elements categorized along the lines used in standards by EMVCo, FIDO Alliance, and guidance from the European Banking Authority. The directive promoted open banking by requiring banks such as HSBC and BNP Paribas to permit access to customer account data to authorized TPPs via APIs, enabling services comparable to offerings from Plaid (company), Yodlee, and Adyen. SCA implementation created technical and commercial interactions with payment rails like SEPA and infrastructures overseen by TARGET2 and regional operators such as EBA Clearing.
To operationalize PSD2, the European Banking Authority developed Regulatory Technical Standards (RTS) specifying SCA and secure communication requirements, which national supervisors in jurisdictions like France (Autorité de Contrôle Prudentiel et de Résolution) and Italy (Banca d'Italia) applied. The RTS process involved consultations with market actors including SWIFT, European Payments Council, and EBA Clearing, and subsequent delays prompted guidance from the European Commission and coordination through bodies such as the European System of Central Banks. Member states implemented PSD2 via national laws consistent with directives like the Markets in Financial Instruments Directive.
PSD2 disrupted business models of incumbent firms including large retail banks such as Banco Santander, ING Group, and Barclays by compelling them to open account access, which enabled market entry and growth for challengers like Revolut, Monzo, and TransferWise (now Wise). The directive accelerated partnerships between banks and technology firms such as IBM and Microsoft for API platforms, influenced product strategy at payment processors including Worldline and Fiserv, and reshaped competition across the European Union payments value chain. It also sparked strategic responses by card schemes Visa and Mastercard and attracted investment from venture capital firms active in FinTech startups.
National competent authorities including the Prudential Regulation Authority (UK), Autorité des Marchés Financiers (France), and Bundesanstalt für Finanzdienstleistungsaufsicht (Germany) are responsible for authorizations, supervision, and enforcement of PSD2 obligations. Enforcement tools range from fines to withdrawal of licenses under frameworks similar to measures used in Banking regulation and sanctions regimes applied by supervisors in high-profile actions against firms for breaches of consumer protection or security rules. Cross-border cooperation occurs through the European Banking Authority’s supervisory colleges and mechanisms akin to those used in bank resolution.
Critics have argued PSD2 created implementation complexity, regulatory fragmentation, and operational risk for banks and TPPs, citing incidents involving API outages and disputes involving platform providers like Plaid (company) and Yodlee. Privacy advocates raised concerns about data sharing in contexts overseen by the European Data Protection Board and the European Data Protection Supervisor, especially vis-à-vis the General Data Protection Regulation. Calls for revisions have emerged from industry groups such as the European Banking Federation and the European Payments Council proposing clearer rules on liability, standardization of APIs, and coordination with initiatives like Open Banking in the United Kingdom and international standards bodies including ISO.