PSD2, the second Payment Services Directive
PSD2 is Directive (EU) 2015/2366, the EU rulebook for payment services and for the firms that provide them. It opened bank accounts to licensed third parties and made strong customer authentication the rule for online payments. Germany carries it in the Payment Services Supervision Act (ZAG) and in the Civil Code, covered on payments regulation in Germany.
Payment services and account access under PSD2
PSD2 replaced the first Payment Services Directive of 2007, and member states had to transpose it by January 13, 2018, according to the Wikipedia article on the directive. Its annex lists the payment services that need a license: cash deposits and withdrawals, credit transfers, direct debits and card payments, issuing payment instruments and acquiring payment transactions, money remittance, payment initiation and account information.
Only listed kinds of firms may provide them: banks, e-money institutions, payment institutions, post office giro institutions, central banks and public authorities. A payment institution needs initial capital of 20,000 euros for money remittance alone, 50,000 euros for payment initiation alone and 125,000 euros for the other services, under Article 7 of the directive. Article 3 lists what stays outside, such as payments through a commercial agent who acts for only one side and instruments that work only in a limited network of shops.
Open banking: payment initiation and account information
PSD2 brought two services under supervision that had worked without a license before. A payment initiation service starts a transfer from the payer's online account at another bank, and an account information service shows the balances of several accounts in one place. The Bank of Slovenia describes both and notes that the initiation provider never holds the payer's funds.
The bank that keeps the account may not make access depend on a contract with the provider (Articles 66 and 67). The technical side sits in the regulatory technical standards on authentication and secure communication, Delegated Regulation (EU) 2018/389. Banks had to open their interfaces for testing from March 14, 2019 and comply in full from September 14, 2019. In Germany most banks use the Berlin Group standard for this, covered on the Berlin Group API page and on open banking in Germany.
Authentication, refunds and liability
Article 97 requires strong customer authentication when a payer logs into an account online, starts an electronic payment or acts through a remote channel that carries a risk of fraud. The European Banking Authority wrote the technical standards behind it and issues guidelines under PSD2, among them the guidelines on fraud reporting.
For an unauthorized payment the payer's provider refunds the amount at the latest by the end of the following business day (Article 73). A payer whose card was lost or stolen bears at most 50 euros, unless the payer acted with fraud or gross negligence (Article 74). For a direct debit the payer can ask for a refund for eight weeks after the debit (Article 76), and a transfer reaches the payee's bank by the end of the next business day (Article 83). A merchant may not charge a fee for paying with a consumer card whose interchange fee is capped (Article 62).
PSD2 in Germany and the step to PSD3
Germany transposed PSD2 in two laws. The supervisory part went into a rewritten ZAG, under which BaFin licenses and supervises payment and e-money institutions. The civil law part, from consent and refunds to liability, went into sections 675c and following of the Civil Code, and section 270a bans fees for paying by SEPA transfer, SEPA direct debit or consumer card, as the Bundesbank page on PSD2 (in German) explains.
The EU is replacing PSD2 with the PSD3 directive and the Payment Services Regulation. Until they apply, PSD2 and the German laws that carry it remain in force, and so do the licenses granted under them.
Upcoming payments events
What is PSD2 in simple terms?
PSD2 is the EU law that says who may move money for others, how a payment must be authenticated and what a customer gets back when a payment goes wrong. It also lets licensed apps start payments from a bank account or read its balance with the customer's consent.
Is PSD2 a directive or a regulation?
A directive. Each member state carried it into its own law, Germany through the ZAG and the Civil Code. The technical standards on strong customer authentication and secure communication are a delegated regulation and apply directly. Its successor splits the two: PSD3 is a directive, and the Payment Services Regulation applies directly.
Who needs a PSD2 license?
Any firm that provides one of the payment services in the annex as a business and is not a bank or another exempt body. In Germany the license comes from BaFin under the ZAG. A firm licensed in another EU or EEA state can serve German customers through the EU passport, after a notification to its home supervisor.
What is the difference between PSD2 and PSD3?
PSD3 keeps the services and licenses of PSD2 and adds the E-Money Directive to the same framework. The conduct rules move into the Payment Services Regulation, with a payee name check before transfers, refunds for some impersonation scams and firmer rules for bank interfaces. The PSD3 page follows the package.
PSD2 and Finance Loop
Finance Loop covers PSD2 in its Payments & Digital Money track, where open banking, card payments and instant transfers all run on its rules, and in Risk & Compliance. Finance Loop supports When Banks Say 'No', a payments seminar in Frankfurt for compliance, treasury and legal teams, and holds events in Frankfurt, Munich, Berlin and Hamburg.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.