ZHENESJAKOTHVIRUFRAR

Payment Services Directive 2

Payment Services Directive 2 (PSD2) is the European Union regulation, in force since 13 January 2018, that governs electronic payments across the EEA, forces banks to open their payment accounts to licensed third parties via APIs, and mandates Strong Customer Authentication (SCA) for most electronic transactions.

If you run a DTC brand selling into Europe, PSD2 is not a compliance footnote — it is the operating system underneath your checkout, your subscription billing, your refunds, and your fraud stack. It shapes how a Dutch customer pays with iDEAL, why a German shopper gets bounced to a 3DS challenge, and why your payment provider can now pull account data directly from a bank instead of asking the customer to type in an IBAN.


The real-life analogy: the EU opens the bank vault door — with a bouncer

Imagine every bank in Europe as a private members' club. Before PSD2, only the club's own staff could touch your money and your account records. If you wanted to pay a merchant, you either used the club's card (Visa/Mastercard) or physically walked in with a paper transfer form.

PSD2 did two things:

1. It cut a regulated side door into every club. Licensed fintechs (TPPs) can now walk in, but only with your explicit key (consent), only through a door the bank must build (API), and only for the specific rooms you authorised.

2. It put a bouncer at every door. Even with the key, high-risk actions require two proofs of identity — something you know (PIN), something you have (phone), something you are (fingerprint). That bouncer is SCA.

The club still owns the vault. It just can't lock everyone else out anymore.


The core formula

PSD2's practical effect can be reduced to:

**PSD2 = Open Banking Access (XS2A) + Strong Customer Authentication (SCA) + TPP Licensing + Liability Shift**

Where:

- XS2A = Access to Account — banks must expose a documented API for account information and payment initiation.

- SCA = two of three factors: knowledge, possession, inherence.

- TPPs = Third-Party Providers, split into AISPs (account information) and PISPs (payment initiation).

- Liability shift = if a transaction is fraudulently authorised because SCA was not applied where required, the bank generally bears the loss, not the merchant.

The regulation is a directive, not a regulation in the strict EU sense — each member state transposed it into national law, which is why enforcement nuance differs between, say, the Netherlands (DNB) and Germany (BaFin).


PSD2 compared with related terms

TermWhat it isRelationship to PSD2
**PSD1 (2007)**The original Payment Services DirectiveCreated the single EU payments market and the "passporting" licence. PSD2 replaced and extended it.
**PSD3 / PSR**The 2023 European Commission proposal to update PSD2Would merge PSD2 and EMD2 into a regulation (PSR) plus a directive (PSD3). Not yet fully in force.
**Open Banking (UK)**The UK's CMA-mandated open banking regimeRuns in parallel; post-Brexit the UK retained PSD2-derived rules under its own framework (FCA, OBIE).
**SCA**Strong Customer AuthenticationA core PSD2 requirement, detailed in the RTS (Regulatory Technical Standards).
**3DS2**EMV 3-D Secure version 2The dominant technical protocol used to satisfy SCA for card payments.
**GDPR**EU data protection regulationOverlaps with PSD2 consent; PSD2 consent is not the same legal basis as GDPR consent, a frequent point of confusion.
**SEPA**Single Euro Payments AreaThe payment rails PSD2 governs for credit transfers and direct debits.

Use cases for DTC and cross-border sellers

1. Account-to-account (A2A) checkout.

A PISP initiates a credit transfer directly from the customer's bank account to your merchant account, bypassing card networks. In markets like Poland (BLIK-adjacent rails), the Netherlands (iDEAL), and the Nordics, A2A already dominates. PSD2 made this legally uniform across the EEA. Typical cost saving vs. cards: 0.2–0.5% vs. 1.5–2.5% + €0.25 per transaction.

2. Instant payout and refunds.

Instead of waiting 3–5 business days for a card refund, you can push funds via SEPA Instant, which under the EU Instant Payments Regulation must reach the beneficiary within 10 seconds, 24/7/365.

3. Subscription and MIT (Merchant-Initiated Transactions).

PSD2 permits SCA exemptions for recurring payments after the first authenticated transaction, but only if the merchant flags the transaction correctly. Get this wrong and your renewal failure rate spikes — a common cause of 5–15% involuntary churn.

4. Fraud and risk scoring via AISP data.

With customer consent, an AISP can read 90+ days of transaction history to underwrite BNPL or verify income — far richer than a credit bureau pull for thin-file customers.

5. Reduced checkout friction with exemptions.

Low-value transactions under €30 are exempt from SCA (up to a cumulative limit of €100 or 5 consecutive transactions), and TRA (Transaction Risk Analysis) exemptions allow SCA-free flow up to €500 if the PSP's fraud rate stays below defined thresholds (e.g., 0.13% for €250–€500).


Common misconceptions

"PSD2 applies to my US business because my customers are in the EU."

It applies to *payment services provided in the EEA*. If you sell into the EU and use an EU-licensed PSP, you inherit PSD2 obligations contractually, but you are not directly the regulated entity. Your PSP is.

"SCA means every transaction needs 3DS."

No. SCA is the *requirement*; 3DS2 is one *implementation*. Exemptions exist (low value, MIT, TRA, whitelisting of trusted beneficiaries), and a well-tuned PSP applies them automatically.

"Open banking means anyone can see my customers' data."

No. Access requires explicit, revocable consent, a licensed TPP, and — since the RTS — at least every 90 days re-authentication for AISPs in many member states. Banks must also provide a dedicated interface (API) and a fallback only under strict conditions.

"PSD2 and GDPR consent are the same thing."

They are not. PSD2 consent is a regulatory permission for a specific payment service; GDPR consent is a data protection legal basis. You often need both, documented separately.

"PSD2 killed cards."

It didn't. Cards still dominate EU e-commerce, but A2A now accounts for a meaningful and growing share — particularly in the Netherlands, Poland, and the Nordics. PSD2 created the legal runway; the Instant Payments Regulation is the jet fuel.

"Compliance is the PSP's problem, not mine."

Commercially, no. If your checkout doesn't support SCA exemptions correctly, your authorisation rates drop. If you don't offer local A2A methods, you lose conversion in key markets. PSD2 is a conversion lever, not just a legal checkbox.


Related terms

- PSD3 / PSR — the next iteration, expected to consolidate rules and tighten open banking performance requirements.

- RTS on SCA and CSC — the technical standard defining SCA and common secure communication.

- EBA Guidelines — European Banking Authority guidance on PSD2 implementation.

- AISP / PISP / ASPSP — account information service provider, payment initiation service provider, account servicing payment service provider.

- SEPA Instant — the real-time euro credit transfer scheme.

- Instant Payments Regulation (IPR) — mandates instant payment availability and verification of payee.

- 3DS2 / EMVCo — the authentication protocol and standards body.

- Open Banking / Open Finance — the broader data-sharing movement PSD2 helped launch.

- FIDA — the proposed EU Financial Data Access framework, extending open banking logic to insurance, pensions, and investments.


Bottom line for DTC operators: PSD2 turned European payments into a programmable, API-driven, consent-based system. Treat it as infrastructure — configure SCA exemptions with your PSP, add local A2A methods where they convert, and design refunds and subscriptions around instant rails. The merchants who treat PSD2 as a growth lever, not a compliance tax, are the ones winning European checkout.