EBA · 2019_4631 Final Q&A

TPP access only with PSU involvement

Regulation
Directive 2015/2366/EU (PSD2)
Article
98
Topic
Strong customer authentication and common and secure communication (incl. access)
Submitted by
Consultancy firm
Submitted
2019-03-27
Answered
2021-03-05
Answer provided by
ESAs (EBA, ESMA, EIOPA)

Question

Can a Payment Service User (PSU) allow a Third party provider (TPP) the access to his account only if he is involved?

Background

Article 36(5)(b) of Regulation (EU) 2018/389 – RTS on strong customer authentication and secure communication states that the TPP may access account information of the PSU a maximum of four times within 24 hours. This applies with the explicit consent of the user. Does this article also state that a PSU can prohibit the TPP from accessing the account independently meaning without the "presence" of the PSU? This means that the TPP has permission to access the account information of the PSU but this only applies if the PSU actively requests this information at TPPs application.

Answer

Article 36(5)(a) and (b) of the Commission Delegated Regulation (EU) 2018/389 provides that account information service providers (AISPs) shall be able to access information from designated payment accounts and associated payment transactions held by account servicing payment service providers (ASPSPs) for the purposes of performing the account information service in either of the following circumstances:  (a) whenever the Payment Service User (PSU) is actively requesting such information; (b) where the PSU does not actively request such information, no more than four times in a 24-hour period, unless a higher frequency is agreed between the AISP and the ASPSP, with the PSU's consent. This is, however, without prejudice to the obligation set out in Article 67(2)(a) of Directive 2015/2366/EU (PSD2) according to which AISPs shall provide services only where based on the PSU’s explicit consent. The PSD2 does not restrict the PSU from setting the conditions in which the AISP can access the account information, including the possibility for the PSU to restrict the AISP to access information only whenever the PSU is actively requesting such information.

Original source: European Banking Authority, Q&A ID 2019_4631

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.