Payment Services Directive 2
PSD2 is a European directive that regulates payment services and electronic money, building on the earlier Payment Services Directive (PSD1). It is intended to make online payments more secure while increasing competition in the payments industry, including by enabling regulated third parties to access payment accounts with customer consent. As a directive, it is transposed into national law by individual jurisdictions, so specific implementation details can vary by country.
PSD2 (the Revised Payment Services Directive) is a European Commission directive governing payment services and electronic money, succeeding the original Payment Services Directive (PSD1). It establishes the regulatory framework often associated with open banking, permitting authorized third-party providers to access payment accounts subject to customer consent, and underpins requirements for stronger authentication of electronic payments. Because it is a directive rather than a directly applicable regulation, it is implemented through national transposition, and its detailed technical and authentication obligations (for example, those set out in associated regulatory technical standards) should be confirmed against the applicable national implementation and the current published texts. Note that the strong customer authentication obligations frequently discussed in connection with PSD2 are distinct from, and should not be conflated with, PCI DSS or other PCI Security Standards Council standards.
Why it matters
PSD2 is a foundational piece of European payments regulation because it reshapes both the security and competitive landscape of payment services. By succeeding PSD1, it extends the regulatory framework to make online payments more secure while opening the market to greater competition, including by enabling regulated third-party providers to access payment accounts with customer consent. For anyone operating in or serving the European payments ecosystem, understanding PSD2 is essential to navigating obligations around authentication, third-party access, and customer consent.
Because PSD2 is a directive rather than a directly applicable regulation, it is transposed into national law by individual jurisdictions. This means that while the directive sets a common framework, the specific implementation details can vary from country to country. Security engineers, compliance officers, and merchant risk teams must therefore confirm obligations against the applicable national implementation rather than assuming a single uniform standard applies across all European markets.
It is important not to conflate PSD2 with PCI DSS or other PCI Security Standards Council standards. The strong customer authentication obligations frequently discussed in connection with PSD2 are distinct from PCI requirements and address different regulatory objectives. Treating them as interchangeable can lead to gaps in either compliance program, so teams should keep the two frameworks and their governing bodies clearly separated in their planning.
Who it's relevant to
Inside PSD2
Common questions
Answers to the questions practitioners most commonly ask about PSD2.