Directive (EU) 2015/2366, known as DSP2, aims to modernize the legal framework for payment services in the European Union. It addresses the developments in the retail payment market, particularly the rise of electronic and mobile payments, by introducing new rules to enhance competition and security. This directive complements previous payment legislations and imposes specific requirements regarding fees and…
Directive (EU) 2015/2366, known as PSD2, was adopted by the European Parliament and the Council of the European Union on 25 November 2015. It concerns payment services in the internal market of the European Union, amending several previous directives (2002/65/EC, 2009/110/EC, 2013/36/EU) and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC. The document contains 93 pages, with approximately the first 30 pages provided here. The directive aims to regulate electronic, mobile, and internet payment services, taking into account technical innovations and new business models that have emerged since 2007. It applies to payment service providers in the European Union, including credit institutions, payment institutions, and electronic money institutions, for the period following its adoption (2015). (p. 1-15)
PSD2 aims to modernize and harmonize the legal framework for payment services in the European Union, in response to the rapid developments in the electronic and mobile payments market. This topic is crucial to ensure an integrated, secure, and transparent market, fostering economic growth and consumer confidence. The main findings are that the previous Directive 2007/64/EC no longer adequately covers new services and business models, leading to regulatory gaps, payment security risks, and insufficient consumer protection. PSD2 introduces a technologically neutral definition of payment services, includes payment initiation and account information services, and clarifies exclusions and provider obligations. It imposes strengthened requirements regarding transparency, fund protection, fraud prevention, and liability, notably limiting user liability to EUR 50 in case of unauthorized transactions. The directive also provides rules on access to payment systems, cooperation between national authorities, and dispute management. In conclusion, PSD2 establishes a clear and coherent framework to promote innovation while protecting users and ensuring fair competition. It notably recommends mandatory declaration of providers’ activities, the establishment of a central register of providers, and the strengthening of prudential requirements adapted to risks. (p. 1-15)
Since the adoption of Directive 2007/64/EC, the retail payments market has experienced rapid growth and major innovations, notably in electronic, mobile, and internet payments. The existing legal framework proved insufficient in the face of these developments, with regulatory grey areas, ambiguous exclusions, and sometimes inadequate consumer protection. The review of the framework, supported by consultations and impact analyses, highlighted the need for an update to guarantee security, transparency, and market integration in payments within the Union. The challenges are to ensure fair conditions for all providers, encourage innovation and adoption of new services, while protecting users against fraud risks and legal uncertainty. PSD2 thus aims to fill gaps, clarify definitions, strengthen cooperation between authorities, and establish a harmonized framework applicable to all Member States. The scope covers electronic payment services, providers established in the EEA, and applies to transactions in official EEA currencies. Limits notably concern cash payments and certain paper instruments excluded from the scope. (p. 1-15)
Definition and scope of payment services: PSD2 adopts a technologically neutral definition of payment services, including traditional services and new models such as payment initiation services (PIS) and account information services (AIS). It specifies exclusions, notably for cash payments, paper cheques, and certain operations via limited networks (store cards, service vouchers). It restricts ambiguous exclusions from Directive 2007/64/EC, notably regarding commercial agents and e-commerce platforms, to limit consumer risks and harmonize application. (p. 2-5)
Consumer protection and transparency: The directive imposes strict pre-contractual and ongoing information requirements on providers, with modalities adapted depending on whether transactions are isolated or under framework contracts. Consumers have the right to clear, free, and accessible information on conditions, fees, and transactions. PSD2 prohibits surcharging card-related payments when interchange fees are regulated, to avoid unfair practices. It establishes a limited liability regime for users in case of unauthorized transactions, capped at EUR 50 except in cases of fraud or gross negligence, and provides precise reimbursement deadlines. (p. 9-13)
Regulation of payment service providers: PSD2 distinguishes several categories of providers: credit institutions, payment institutions, electronic money institutions, and new actors such as payment initiation and account information service providers. It maintains an adapted prudential regime, with requirements proportionate to risk, notably regarding initial capital and professional civil liability insurance for PIS and AIS. Payment institutions cannot receive deposits and must segregate user funds. The directive imposes obligations to declare activities to competent authorities, maintain a central register managed by the European Banking Authority (EBA), and strengthens cross-border cooperation between authorities. (p. 4-8)
Access to payment systems and competition: The directive guarantees non-discriminatory access to technical infrastructures of payment systems for all authorized providers, subject to conditions ensuring system stability and security. It excludes closed (three-party) systems from the scope of these access rules. PSD2 aims to foster competition, notably by allowing issuance of card-related payment instruments by providers other than the account manager, and by regulating confirmation of fund availability. (p. 8-9)
Security and fraud prevention: The directive emphasizes the importance of security of personalized data used for authentication, ensuring that conditions imposed on users do not restrict access to services from other providers. It provides rules for rapid notification of unauthorized transactions, allocation of responsibilities between providers, and protection of users against excessive losses. (p. 12-14)
Execution of payment transactions: PSD2 specifies deadlines and conditions for receipt, execution, revocation, and refusal of payment orders, as well as the obligation that the full amount transferred be credited to the beneficiary without deductions by intermediaries, unless otherwise agreed. It introduces an unconditional right to refund for euro direct debits within SEPA, while allowing more favorable rules for payers in certain cases. (p. 13-15)
Established facts: The previous legal framework (Directive 2007/64/EC) became obsolete facing innovations in electronic, mobile, and internet payments, with exclusions and ambiguities that created legal uncertainty and risks for security and consumer protection. Payment initiation and account information services are new actors previously unregulated. PSD2 establishes a harmonized framework applicable to all providers in the EEA, with requirements adapted to their risks and activities. (p. 3-7)
Assumptions: The directive assumes that clarifying rules, increasing transparency, and adapting regulation will encourage innovation, competition, and consumer confidence. It assumes that limiting user liability to EUR 50 in case of unauthorized transactions is an adequate harmonized protection level. (p. 12-13)
Interpretations: PSD2 interprets that previous exclusions were applied divergently, harming competition and consumer protection. It considers that payment initiation and account information services must be integrated into the regulatory framework to guarantee security and liability. (p. 4-6)
Uncertainties: The precise impact of new rules on emerging business models, notably regarding security and competition, remains to be assessed over time. Effective implementation of proportionate prudential requirements and cooperation between national authorities are key factors to monitor. (p. 7-8)
PSD2 concludes on the need for a modernized, clear, and harmonized legal framework for payment services in the European Union, to support market integration, security, transparency, and consumer protection. It recommends:
- Adoption of a technologically neutral definition of payment services, including payment initiation and account information services.
- Clarification of exclusions and obligation for providers to declare their activities to competent authorities.
- Strengthening of prudential requirements adapted to specific risks of different providers, notably segregation of user funds.
- Establishment of a central register of providers managed by the EBA to improve transparency and cooperation.
- Implementation of strict information and transparency obligations towards users, with enhanced rights regarding reimbursement and liability.
- Guarantee of non-discriminatory access to payment systems for all authorized providers.
- Strengthening cooperation between national authorities, with mechanisms to manage emergencies and cross-border disputes.
These measures aim to foster innovation, fair competition, payment security, and consumer confidence in the single market for electronic payments. (p. 1-15)
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.