- Regulation
- Directive 2015/2366/EU (PSD2)
- Article
- 98
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Submitted by
- Consultancy firm
- Submitted
- 2023-06-06
- Answered
- 2023-09-29
- Answer provided by
- ESAs (EBA, ESMA, EIOPA)
Background
Article 10(1) of Delegated Regulation (EU) 2018/389 provided that, “Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2 and to paragraph 2 of this Article and, where a payment service user is limited to accessing either or both of the following items online without disclosure of sensitive payment data: (a) the balance of one or more designated payment accounts; (b) the payment transactions executed in the last 90 days through one or more designated payment accounts. Commission Delegated Regulation (EU) 2022/2360 has revised Art.10 and introduced a new Art.10a which now provide: Art.10(1) Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where a payment service user is accessing its payment account online directly, provided that access is limited to one of the following items online without disclosure of sensitive payment data: the balance of one or more designated payment accounts; the payment transactions executed in the last 90 days through one or more designated payment accounts. Art. 10a(1) Payment service providers shall not apply strong customer authentication where a payment service user is accessing its payment account online through an account information service provider, provided that access is limited to one of the following items online without disclosure of sensitive payment data: (a) the balance of one or more designated payment accounts; (b) the payment transactions executed in the last 90 days through one or more designated payment accounts. Under the original Art.10 exemption, a payment service user could access “either or both of”, meaning the account balance AND/OR transaction details whereas in both the revised Art.10 and the new Art.10a access is limited to “one of” the account balance or transaction details which would seem to restrict the levels of access enjoyed today. Did the Commission intend to introduce such a material change with the revised wording, and if so, why?
Answer
Article 10(1) of Delegated Regulation (EU) 2018/389, as amended by Commission Delegated Regulation (EU) 2022/2360, allows Payment service providers (PSPs) not to apply strong customer authentication (SCA), where a payment service user (PSU) is accessing its payment account online directly, “provided that access is limited to one of the following items online without disclosure of sensitive payment data: (a) the balance of one or more designated payment accounts; (b) the payment transactions executed in the last 90 days through one or more designated payment accounts”. Furthermore, Article 10a(1) of Delegated Regulation (EU) 2018/389, as amended by Commission Delegated Regulation (EU) 2022/2360, requires PSPs not to apply SCA where a PSU is accessing its payment account online through an account information service provider (AISP), “provided that access is limited to one of the following items online without disclosure of sensitive payment data: (a) the balance of one or more designated payment accounts; (b) the payment transactions executed in the last 90 days through one or more designated payment accounts”. In relation to the above, recital 4 of Commission Delegated Regulation (EU) 2022/2360 clarifies that the above exemption from SCA “should be limited to access to the balance and the recent transactions of a payment account without disclosure of sensitive payment data”. It follows from the above that the exemptions in Articles 10 and 10a also apply where the access request refers to both the payment account balance and the last 90-days transaction history, provided that the other conditions set out in the Delegated Regulation (EU) 2018/389 are met. In this regard, the scope of data that can be accessed using the exemptions in Article 10 and 10a remains the same as before the amendments introduced by Commission Delegated Regulation (EU) 2022/2360.
This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated
weekly from official ESA sources.