← Fintech GlossaryRegulation & Compliance

PSD2 (Payment Services Directive 2)

PSD2

PSD2 is a European Union directive that regulates payment services and payment service providers across the EU and EEA. It introduced the concept of Open Banking by requiring banks to provide third-party payment service providers with access to customer account data through APIs, subject to customer consent. PSD2 also introduced Strong Customer Authentication requirements for electronic payments, reduced payment fraud liability for consumers, and established a regulatory framework for new payment services like payment initiation and account information services.

In Financial Services

PSD2 transformed the European banking landscape by breaking banks' monopoly on customer payment data and enabling third-party providers to offer innovative payment services. Banks must provide dedicated APIs for Account Information Service Providers and Payment Initiation Service Providers, with the customer's explicit consent. Strong Customer Authentication requires two-factor authentication for electronic payments above certain thresholds, impacting e-commerce checkout flows and online banking. PSD2 also introduced new rules for surcharging, execution times, and refund rights. The directive has spawned a thriving FinTech ecosystem of account aggregation apps, payment initiation services, and personal finance management tools that rely on bank API access.

Real-World Example

A European digital bank implements PSD2 APIs by deploying a developer portal with sandbox environments, API documentation, and consent management dashboards. The bank exposes account information, transaction history, and payment initiation APIs. A FinTech personal finance app uses the bank's APIs to aggregate the customer's accounts, analyse spending patterns, and initiate payments through the app. The customer provides consent through a standardised screen, and the bank authenticates the request using Strong Customer Authentication.

Why It Matters for Finance

PSD2 is the regulatory foundation for Open Banking in Europe. For finance professionals in banking, payments, and FinTech, understanding PSD2 is essential for API strategy, compliance with Strong Customer Authentication requirements, and navigating the competitive landscape of third-party payment services. PSD3 is now building on PSD2 with stronger consumer protection.

Related Terms

PSD3 (Payment Services Directive 3)Open BankingOpen Banking APIGeneral Data Protection Regulation (GDPR)SEPA (Single Euro Payments Area)

Explore in Finatune

PlaidMercury

Frequently Asked Questions

What is PSD2 and how does it affect financial institutions?

PSD2 is an EU directive requiring banks to open customer payment data to third-party providers via APIs. It affects banks by mandating Open Banking access, Strong Customer Authentication, and new payment service regulations.

How does PSD2 enable open banking innovation?

PSD2 requires banks to provide APIs for account information and payment initiation services. This enables FinTech apps to aggregate accounts, analyse spending, and initiate payments with customer consent.

What is the difference between PSD2 and PSD3?

PSD3 builds on PSD2 with stronger consumer protection, improved API standards, streamlined supervision, and extended scope to cover new payment services and digital wallets not fully addressed by PSD2.

← Previous Term: PCI DSS (Payment Card Industry Data Security Standard)
Next Term: PSD3 (Payment Services Directive 3) β†’
View All Fintech Terms β†’