EBA · 2018_4110 Final Q&A

Data authentication standards

Regulation
Directive 2015/2366/EU (PSD2)
Article
97, para. 2
Topic
Strong customer authentication and common and secure communication (incl. access)
Submitted by
Industry association
Submitted
2018-07-13
Answered
2019-12-20
Answer provided by
ESAs (EBA, ESMA, EIOPA)

Question

Does a non-remote card payment transaction with a secure, dynamic data authentication of the card (DDA or higher), based on ISO/IEC 7816 (for contact cards) and ISO/IEC 14443 (for contactless card) used with a static PIN meet the requirements of Article 4 of the RTS on Strong Customer Authentication (SCA)?

Background

Considering the published comments by EMVCo dated from 2016 and the EBA analysis from 2017 (see comment 272 of the Final Report of the RTS on SCA, dated 23 February 2017), EBA is asked to provide clarity that all face-to-face card transactions using the global EMV DDA or CDA standard fulfill all requirements for authentication codes of Article 4 of the Regulatory Technical Standards of Strong Customer Authentication and Common and Secure Communication. Without such a confirmation, the practical impact would be that more than 5 000 PSPs (card issuers and acquirers) in Europa have to prove the compliance of these standards with the RTS with their own technical and legal experts individually when being audited.   While it is well understood that EBA does not see SDA being compliant with the RTS, we believe it is neither feasible nor intended to burden all European PSPs with proving that DDA and CDA is in line with RTS individually.

Answer

The authentication of the payment card based on combined data authentication (CDA) and dynamic data authentication (DDA), as currently observed in the market, could meet the requirements of the elements categorised as possession under Article 7 of the  Commission Delegated Regulation (EU) 2018/389   for non-remote card-based payment transactions.  Moreover, CDA and DDA can be used for the generation of the authentication code, which should be compliant with the requirements of Article 4 of the Delegated Regulation. In line with the requirements of the Delegated Regulation, issuers should identify in their solutions which messages/data fields (or a combination of them) generate the “authentication code” and the dynamic element to prove the possession. In addition, as clarified in Table 3 of the EBA Opinion on the elements of strong customer authentication under PSD2 (EBA-Op-2019-06) , a static PIN could constitute a ‘knowledge’ element. It should be noted that card set-ups designed by issuers, other than those relying on CDA/DDA, could be compliant with the requirements of the Delegated Regulation. Finally, it should be noted that it is for each payment service provider to identify which are the authentication elements and authentication codes of their solutions and to prove that they meet the requirements of the Delegated Regulation.

Original source: European Banking Authority, Q&A ID 2018_4110

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.