EBA · 2021_5821 Final Q&A

Strong customer authentication (SCA) Knowledge element: Place of Birth and Date of Birth

Regulation
Directive 2015/2366/EU (PSD2)
Article
4, para. 30
Topic
Strong customer authentication and common and secure communication (incl. access)
Submitted by
Other
Submitted
2021-04-21
Answered
2021-07-30
Answer provided by
ESAs (EBA, ESMA, EIOPA)

Question

Does a payer’s date of birth and place of birth constitute a valid Knowledge Element for strong customer authentication.

Background

After reading many different articles, Knowledge should be something in the customers head. So if a date of birth can be viewed across many different forms of personal information (even through the window of some letters in your letterbox or my facebook page) and my Place of birth can be found on my passport., Should my bank be using this to validate Knowledge for making data changes?

Answer

Article 4(30) of Directive 2015/2366/EU (PSD2) defines knowledge as something only the user knows.   Article 6 of Regulation (EU) 2018/389 specifies the requirement for payment service providers (PSPs) to mitigate the risk that the element is ‘uncovered by, or disclosed to, unauthorised parties’ and to have mitigation measures in place ‘in order to prevent their disclosure to unauthorised parties’.   Accordingly, date and/or place of birth cannot constitute a knowledge element under PSD2 and the Delegated Regulation since these may be accessible by third parties other than the payment service user or the PSP.

Original source: European Banking Authority, Q&A ID 2021_5821

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.