{"id":5303,"date":"2017-02-23T10:54:20","date_gmt":"2017-02-23T15:54:20","guid":{"rendered":"https:\/\/3dmerchant.com\/blog\/?p=5303"},"modified":"2021-12-03T03:23:53","modified_gmt":"2021-12-03T08:23:53","slug":"eba-paves-the-way-for-open-and-secure-electronic-payments-for-consumers-under-the-psd2","status":"publish","type":"post","link":"https:\/\/3dmerchant.com\/blog\/merchant-processing-industry-news\/eba-paves-the-way-for-open-and-secure-electronic-payments-for-consumers-under-the-psd2","title":{"rendered":"EBA paves the way for open and secure electronic payments for consumers under the PSD2"},"content":{"rendered":"\n<p><strong>The European Banking Authority (EBA) published today its  final draft Regulatory Technical Standards (RTS) on strong customer  authentication and common and secure communication. These RTS, which  were mandated under the revised Payment Services Directive (PSD2) and  developed in close cooperation with the European Central Bank (ECB),  pave the way for an open and secure market in retail payments in the  European Union.<\/strong>  \u00a0  <\/p>\n\n\n\n<p>Following 18 months  of intensive policy development work and an unprecedentedly wide number  of stakeholders&#8217; views and input, these final draft RTS are the result  of difficult trade-offs between the various, at times competing,  objectives of the PSD2, such as enhancing security, facilitating  customer convenience, ensuring technology and business-model neutrality,  contributing to the integration of the European payment markets,  protecting consumers, facilitating innovation, and enhancing competition  through new payment initiation and account information services.\u00a0  \u00a0   <\/p>\n\n\n\n<p>The EBA received 224 responses to its Consultation Paper, in which more  than 300 distinct concerns or requests for clarifications were raised.  In the feedback table published today as part of the RTS, the EBA has  summarised each one of them and provided its assessment as to whether  changes have been made to the RTS as a result of such concerns.\u00a0  \u00a0  <\/p>\n\n\n\n<p> In particular, one of the key concerns addressed by these final draft  RTS relates to the exemptions from the application of strong customer  authentication on the basis of the level of risk involved in the service  provided; the amount and recurrence of the transaction; and the payment  channel used for the execution of the transaction. In this respect, the  EBA has introduced two new exemptions: one based on transaction-risk  analysis based on defined fraud levels and the other for payments at so  called \u2018unattended terminals&#8217; for transport or parking fares. The  exemption on transaction risk analysis is linked to a predefined level  of fraud and is subject to an 18-month review clause after the  application date of the RTS.\u00a0  \u00a0 <\/p>\n\n\n\n<p>In addition, the  EBA has also increased the threshold for remote payment transactions  from EUR 10 to EUR 30, and has removed previous references to ISO 27001  and to other specific characteristics of strong customer authentication,  so as better to ensure the technological neutrality of the RTS and to  facilitate future innovations. \u00a0  \u00a0  <\/p>\n\n\n\n<p>With regards  to the communication between account servicing payment service providers  (ASPSPs), account Information service providers (AISPs) and payment  initiation service providers (PISPs), the EBA has decided to maintain  the obligation for the ASPSPs to offer at least one interface for AISPs  and PISPs to access payment account information. This is linked to the  PSD2 no longer allowing the existing practice of third party access  without identification (at times referred to as \u2018screen scraping&#8217; or,  mistakenly, as \u2018direct access&#8217;) once the transition period provided for  in PSD2 has elapsed and the RTS applies.\u00a0  \u00a0   <\/p>\n\n\n\n<p>However, in order to address the concerns raised by a few respondents,  the final RTS now also require that ASPSPs that use a dedicated  interface will have to provide the same level of availability and  performance as the interface offered to, and used by, their own  customers, provide the same level of contingency measures in case of  unplanned unavailability, and provide an immediate response to PISPs on  whether or not the customer has funds available to make a payment.  \u00a0 <\/p>\n\n\n\n<h3 class=\"wp-block-heading\"> Legal basis and background<\/h3>\n\n\n\n<p>   The draft RTS have been developed according to Article 98 of the  revised Payment Services Directive (EU) 2015\/2366 (PSD2), which mandates  the EBA, in close cooperation with the ECB, to draft Regulatory  Technical Standards (RTS) specifying the requirements of the strong  customer authentication (SCA), the exemptions from the application of  SCA, the requirements with which security measures have to comply in  order to protect the confidentiality and the integrity of the payment  service users&#8217; personalised security credentials, and the requirements  for common and secure open standards of communication (CSC) between  account servicing payment service providers, payment initiation service  providers, account information service providers, payers, payees and  other payment service providers (PSPs).  The PSD2 provides that the RTS will apply 18 months after adoption of the RTS by the EU Commission as a Delegated Act.<\/p>\n\n\n\n<p>Related documents:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li> <a href=\"https:\/\/eba.europa.eu\/documents\/10180\/1761863\/Final+draft+RTS+on+SCA+and+CSC+under+PSD2+%28EBA-RTS-2017-02%29.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">Final draft RTS on SCA and CSC under PSD2 (EBA-RTS-2017-02)<\/a> [PDF, 1334KB] <\/li><\/ul>\n\n\n\n<p>Related links:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li> <a href=\"https:\/\/eba.europa.eu\/regulation-and-policy\/payment-services-and-electronic-money\/regulatory-technical-standards-on-strong-customer-authentication-and-secure-communication-under-psd2\">Regulatory Technical Standards on strong customer authentication and secure communication under PSD2<\/a> <\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The European Banking Authority (EBA) published today its final draft Regulatory Technical Standards (RTS) on strong customer authentication and common and secure communication. These RTS, which were mandated under the revised Payment Services Directive (PSD2) and developed in close cooperation &hellip; <a href=\"https:\/\/3dmerchant.com\/blog\/merchant-processing-industry-news\/eba-paves-the-way-for-open-and-secure-electronic-payments-for-consumers-under-the-psd2\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[117,10],"tags":[639,641],"class_list":["post-5303","post","type-post","status-publish","format-standard","hentry","category-government-news","category-merchant-processing-industry-news","tag-sca","tag-strong-customer-authentication"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/5303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/comments?post=5303"}],"version-history":[{"count":1,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/5303\/revisions"}],"predecessor-version":[{"id":5304,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/posts\/5303\/revisions\/5304"}],"wp:attachment":[{"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/media?parent=5303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/categories?post=5303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/3dmerchant.com\/blog\/wp-json\/wp\/v2\/tags?post=5303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}