EBA · 2018_4339 Rejected question

90 Day Access via Direct Access

Regulation
Directive 2015/2366/EU (PSD2)
Article
98
Topic
Strong customer authentication and common and secure communication (incl. access)
Submitted by
Other
Submitted
2018-10-24

Question

Should any solution which involves direct access, whether as a strategic solution to PSD2, or in relation to the obligation to provide a fallback interface, ensure that Account Information Service Providers (AISPs) can access the interface in the same manner as the dedicated interface, specifically on an ongoing basis and for a maximum of 90 days once the customer has provided consent and authenticated using strong customer authentication (SCA)?

Background

All the Application Programming Interface (API) standards being developed to support the RTS on strong customer authentication and secure communication dedicated interfaces support AISPs gaining access to account information for 90 days a time. Some Account Servicing Payment Service Providers (ASPSPs) seem to think they can avoid this obligation when access "direct access" rather than via a dedicated interface.
No answer published yet.

Original source: European Banking Authority, Q&A ID 2018_4339

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.