MiCA · EMI/PSD · DORA · Reference data
ESMA / EBA Regulatory Q&A
Search the official ESMA and EBA Q&As for crypto & payments firms — MiCA, CASP, ART/EMT, e-money, PSD2 and DORA — by regulator, theme and year.
Last updated: 25 Sep 2026 · Source: live EBA Single Rulebook Q&A + curated ESMA Q&A documents · 316 entries (314 EBA Q&As · 2 ESMA documents)
Regulators settle the hard interpretation questions through formal Q&As. This is a searchable, daily-refreshed view of the EBA Single Rulebook Q&As on the rules that matter for crypto-asset and payments firms — MiCA (issuers of asset-referenced and e-money tokens, and the CASP regime), e-money & PSD2, and DORA — alongside the official ESMA Q&A resources for MiCA. Each entry links to the official Q&A; we show the question and a short excerpt, never the full official answer. For who is authorised, see the CASP Licence Tracker and the MiCA White-Paper Register.
Reference only. Entries are sourced from the EBA Single Rulebook Q&A and ESMA. We show the question and a short excerpt and link to the official Q&A — we do not reproduce the full official answer. A Q&A can be updated or withdrawn; always read the official text. Not legal or financial advice.
Search the Q&As
316 Q&As — search, filter, or browse all.
ESMA MiCA Q&As — official Q&A platform (CASP, white papers, market abuse)
ESMAMiCAESMA’s official questions and answers on the Markets in Crypto-Assets Regulation — authorisation and conduct of crypto-asset service providers (CASPs), crypto-asset white papers and market abuse.
- Regulator
- ESMA
- Regulation
- Regulation (EU) 2023/1114 (MiCAR)
- Topic
- MiCA / CASP
- Updated
- 26 Sep 2026 · continually updated
- Reference
ESMA · MiCAObstacle assessment of a mandatory client segment selection screen in a redirection journey
EBAEMI/PSDDoes a mandatory step in a redirection journey, where a Payment Service User (PSU) must manually select their client segment (e.g., retail or corporate) on an intermediary screen (web interface) before being redirected to the ASPSP's authentication app, constitute an obstacle under Article 32(3) of the RTS, if such a step is not present when the PSU accesses their account directly via the ASPSP's native mobile application?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Jun 2026
- Reference
2025_7602Clarification of the scope of the term "authentication procedures" in the context of the RTS and the EBA Opinion on obstacles
EBAEMI/PSDDoes the term "authentication procedures" in the context of the EBA Opinion on obstacles (EBA/OP/2020/10) refer only to the final SCA method, or does it encompass the entire end-to-end user journey required to complete the authentication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Jun 2026
- Reference
2025_7606Definition of "equivalent authentication procedure" for journeys initiated from a mobile application
EBAEMI/PSDWhen a Payment Service User (PSU) initiates a service from a Third Party Provider's (TPP) mobile application, what is the correct "equivalent authentication procedure" of the ASPSP that should be used as the benchmark for assessing whether "unnecessary steps" have been added?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Jun 2026
- Reference
2025_7607Obligations of ASPSPs to inform PISPs about the execution status of individual payments executed under a standing order initiated via API.
EBAEMI/PSDUnder PSD2, when a PISP initiates a standing order on behalf of a PSU, the ASPSP generally communicates only the result of the standing order setup (i.e. whether the standing order has been accepted or rejected).
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 12 Jun 2026
- Reference
2025_7644PSU support in dedicated and redirected interfaces.
EBAEMI/PSDIn the context of Article 32 of the RTS (Commission Delegated Regulation (EU) 2018/389), are ASPSPs required to provide PSUs with access to support channels (e.g., helpdesk, chat, telephone) within redirected authentication and authorisation interfaces for payment initiation, at a level equivalent to that in their standard online banking interfaces?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 12 Jun 2026
- Reference
2025_7672Provision of rejection reasons for payment orders initiated via PISPs.
EBAEMI/PSDWhen an ASPSP provides a PSU, through its online banking channels, with specific information on the reason for the rejection of a payment order, in accordance with Article 36(1)(b) of Commission Delegated Regulation (EU) 2018/389, should that same information also be provided to the PSU via the interface made available for a payment initiation order, whether through a decoupled or redirection flow?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 12 Jun 2026
- Reference
2025_7675Issuers of EMTs and scope of application AML requirements
EBAMiCATo what extent should electronic money institutions (EMIs) that issue e-money tokens (EMTs) under MiCAR comply with the obligations in relation to anti-money laundering and terrorist financing under Directive 2015/849/EU (as amended, AMLD5)?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2023/1114 (MiCAR)
- Topic
- Other MiCAR topics
- Published
- 22 May 2026
- Reference
2024_7078Publication of white papers
EBAMiCARegarding entities exempted from authorisation pursuant to Article 16(2) of MiCAR, they shall notify the white paper to the competent authority of the home Member State, and the NCA is responsible for forwarding on the white paper of these entities to ESMA.
- Regulator
- EBA
- Regulation
- Regulation (EU) 2023/1114 (MiCAR)
- Topic
- Authorisation of issuers of ARTs and EMTs (MiCAR)
- Published
- 8 May 2026
- Reference
2024_7166Passporting procedure for CIs and EMIs issuing tokens under MICAR
EBAMiCAAre articles 146 (for credit institutions) and 48(3) (for e-money institutions) to be interpreted as submitting credit institutions and e-money institutions issuing ART/EMT on a crossborder basis to comply with the existing passporting framework set for these categories of establishments respectively by directives 2013/36/EU and 2009/110/EC?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2023/1114 (MiCAR)
- Topic
- Other MiCAR topics
- Published
- 8 May 2026
- Reference
2024_7168Qualification of crypto-asset service in case of exchange of electronic money tokens for other crypto-assets
EBAMiCAShould the service consisting in exchanging electronic money tokens for other crypto-assets be qualified as exchange of crypto-assets for crypto assets or as exchange of funds for crypto assets?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2023/1114 (MiCAR)
- Topic
- Scope and definitions (MiCAR)
- Published
- 8 May 2026
- Reference
2024_7084Classification of phishing-attacks as a reportable major ICT-related incident
EBADORACan individual phishing incidents that target the customers of a financial entity in their “private sphere” be subsumed under “compromises the security of the network and information systems” pursuant to Article 3 No.
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT-related incidents (management / classification / reporting)
- Published
- 6 Feb 2026
- Reference
2025_7613Types of "telephone services" included under the definition of "ICT services"
EBADORAWhich types of telephone services fall within the scope of the definition of "ICT services"?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT-related incidents (management / classification / reporting)
- Published
- 6 Feb 2026
- Reference
2025_7539Public Authorities Exemption
EBADORAIs the exemption for public authorities as quoted in recital 63 sentence 3 last half-sentence meant to be a general exemption for all public authorities as defined under art. 3 no.
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Other DORA topics
- Published
- 6 Feb 2026
- Reference
2025_7466Setting limit (daily and/or per transaction) for the execution of payment transaction by PSP
EBAEMI/PSDIs PSP allowed, according to the Article 68(1) of PSD2, to set a general limit (daily and/or per transaction) for the execution of payment transaction to the payee with the PSP in another EU Member state, under the certain payment initiation channel (for example mobile banking), in order to mitigate the risk of fraud (to prevent fraud)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 12 Dec 2025
- Reference
2025_7425Definition and scope of ICT services
EBADORAWhat is the correct reading of Article 3 (21) and Recital 63, Article 2 and Article 58(2) of Regulation (EU) No. (EU) 2022/2554 (DORA Reg) in combination with the COM/2023/0365 European Commission Report on the review of Directive 2015/2366/EU ?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT third-party risk management
- Published
- 14 Nov 2025
- Reference
2024_7290Staff costs
EBADORADo imputed staff costs count as part of staff costs in accordance with Article 18(1)(f) of Regulation (EU) 2022/2554 in conjunction with Article 7(1)(c) Delegated Regulation (EU) 2024/1772 and Article 4(e) Delegated Regulation (EU) 2025/301 and must, therefore, be reported as part of gross direct and indirect costs and losses of an incident?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT-related incidents (management / classification / reporting)
- Published
- 14 Nov 2025
- Reference
2025_7439Authentication process of the PSU with the ASPSP in a combined AIS and PIS journey in a redirection approach
EBAEMI/PSDConsider an ASPSP that offers a dedicated interface using a redirection approach.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 3 Oct 2025
- Reference
2025_7358the use of strong and widely recognized encryption techniques
EBAEMI/PSDAll strong and widely recognized encryption techniques (e.g.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 3 Oct 2025
- Reference
2025_7376SCA exception for Contactless only terminals (SoftPOS) in case of emergency
EBAEMI/PSDWe are in the process of developing a backup solution for our SoftPOS terminal application, intended for use during exceptional circumstances such as cyber-attacks or other disruptions to internet connectivity and acquirer systems.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 3 Oct 2025
- Reference
2025_7482Minimum monetary amount of professional indemnity insurance in ongoing supervision
EBAEMI/PSDAre points 5.4, 5.7, 5.10 and 7.4 of EBA/GL/2017/08 guideline applicable only while applying for authorisation or in ongoing supervision as well? Is 50 000 per indicator minimal amount after authorisation procedure/first year as well?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Monetary amount of the professional indemnity insurance
- Published
- 3 Oct 2025
- Reference
2025_7317Passporting procedure for non-CI ART issuers
EBAMiCAShall NCAs consider that articles 18, 21, 25 and 109 of MICA regulation set a specific passporting framework for “pure” ART issuers where: ART issuers are authorized to market tokens in Member States they declared during the authorization process as soon as
- Regulator
- EBA
- Regulation
- Regulation (EU) 2023/1114 (MiCAR)
- Topic
- Other MiCAR topics
- Published
- 5 Sep 2025
- Reference
2024_7167Knowledge element of SCA.
EBAEMI/PSDCan an API key be considered as a Knowledge element of SCA?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 29 Aug 2025
- Reference
2024_7286Proxy matrices
EBAEMI/PSDAre credit institutions (ASPSPs) allowed to facilitate proxy matrices implemented by their (corporate) clients that allocate proxy to only certain users to invoke the services of third party payment service providers (TPPs)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 29 Aug 2025
- Reference
2024_7265Obstacles Faced by PISPs in Accessing Payment Status Information Under PSD2
EBAEMI/PSDAre ASPSPs allowed to require PISPs to provide any additional identifier beyond what is specified in Article 35.4.b of the RTS in order to access information about the execution of a payment order?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 29 Aug 2025
- Reference
2024_7261ANNUAL REPORT ON NEW ARRANGEMENTS ON THE USE OF ICT SERVICES
EBADORADoes Article 28(3) DORA require a separate and specific communication in addition to the Register of Information, or whether the communication of such data is already fulfilled through the annual submission of the same Register, constituting a single compliance obligation?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 14 Aug 2025
- Reference
2025_7309Identification of ICT Service Providers
EBADORACan the ESAs confirm there is no expectation to capture within the Register of Information the ICT subcontractors of non-ICT service providers?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT third-party risk management
- Published
- 8 Aug 2025
- Reference
2024_7089How to fill the refPeriod field of the parameters.csv file for the DORA register of information
EBADORAAs part of the DORA register of information packaging process, we are required to include a parameters.csv file that contains a refPeriod field. Could you please confirm what specific date should be used for the refPeriod?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 8 Aug 2025
- Reference
2025_7387Obligation to maintain a register of information for FEs exempt under article 16
EBADORAAre financial entities, which according to article 16(1) in DORA are excluded from application of Articles 5 to 15, also are excluded from application of article 28 of DORA?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 8 Aug 2025
- Reference
2025_7388Scope of Register of Information for Contractual Arrangements on the use of ICT Services Provided by ICT Third-party Service Providers
EBADORAAccording to Article 28(3) of DORA, must an EU parent bank, which has subsidiaries both within and outside the EU, maintain the register of information regarding all contractual arrangements for the use of ICT services only for subsidiaries that are subject to DORA (financial entities established in the EU), or does this requirement extend to subsidiaries established outside the EU for which DORA does not apply?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT third-party risk management
- Published
- 25 Jul 2025
- Reference
2024_7098Elaboration on the meaning of a separated and dedicated network for ICT asset administration
EBADORAIn the "RTS on ICT Risk Management Framework and on simplified ICT Risk Management Framework"; How should we read: ''A separate and dedicated network for ICT asset administration, along with strict prohibition of direct internet access[...]''?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT third-party risk management
- Published
- 25 Jul 2025
- Reference
2024_7178The scope of the regulation described in Article 6 mismatches what is presented as an option in the Annex I, Part 2 of the same regulation
EBADORADo financial entities must include non-financial entities within the same group in the Register of Information? If not, why is there an option to do so?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 25 Jul 2025
- Reference
2025_7297Credit
EBAEMI/PSDDoes this credit qualify as consumer credit, exclusively available to individual consumers? Or can it also be extended to legal entities?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 11 Jul 2025
- Reference
2024_7056Interpretation of payment instrument
EBAEMI/PSDWhat devices or procedures can be considered as payment instrument as per Art. 4(14) of PSD2?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 11 Jul 2025
- Reference
2023_6910Paper-based postal money orders as defined by the Universal Postal Union
EBAEMI/PSD1. Should postal transfers as defined by the Universal Postal Union, which are not made in paper form but by electronic means, be excluded from the scope of PSD2? 2.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 11 Jul 2025
- Reference
2022_6391Compliance of non-bank PSPs with the safeguarding requirements in PSD2
EBAEMI/PSDWhere PIs and EMIs (referred to as non-bank PSPs) have direct access to central bank operated payment systems for settling payment transactions, would keeping a balance on a settlement account with the central bank/payment system, without the central bank maintaining a safeguarding account for the non-bank PSP, be compliant with the safeguarding requirements under Article 10 of PSD2?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 8 May 2025
- Reference
2024_7165Part 2 – Template specific instructions to template B_06.01
EBADORAData point B_06.01.0050 is missing from the official ITS templates. Is this data point no longer applicable?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2025_7313Template specific instructions – primary keys
EBADORAHow to report data fields in case of missing values?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7285Template specific instructions – field B_05.02.0060 (Identification code of the recipient of sub-contracted ICT services)
EBADORAHow to report data field B_05.02.0060 if the ICT third-party service provider is a direct provider (rank =1)?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7284Template specific instructions – field B_05.01.0020 (Type of code to identify the ICT third-party service provider)
EBADORAHow to report type of identification code in data field B_05.01.0020 when using codes other than LEI or EUID?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7283Template specific instructions – field B_04.01.0040 (Identification code of the branch)
EBADORAHow to report data field B_04.01.0040 if the financial entity is not a branch?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7282Template specific instructions – field B_02.02.0160 (Location of management of the data)
EBADORAHow to report data field B_02.02.0160 where the ICT service is not based or does not foresee data processing?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7281Template specific instructions – field B_02.02.0130 (Country of the governing law of the contractual arrangement)
EBADORAHow to report field B_02.02.0150 where the ICT service is not related to storage of data (B_02.02.0140 = 'No')?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7280Template specific instructions – field B_02.02.0130 (Country of the governing law of the contractual arrangement)
EBADORAHow to report field B_02.02.0130 where the ICT service is not supporting a critical or important function considering that according to the data model this data field is a primary key?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7279Template specific instructions - field B_01.02.0060 (LEI of the direct parent undertaking of the financial entity)
EBADORAWhat should be reported in case the financial entity does not have a direct parent undertaking (for example, is the parent undertaking itself) or reports the register on an individual basis?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7278Template specific instructions – field B_01.02.0050 (Hierarchy of the financial entity within the group)
EBADORAWhat does ‘where applicable’ mean in the title of data field B_02.01.0050?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Register of information (DORA)
- Published
- 28 Mar 2025
- Reference
2024_7277Scope of public offering
EBAMiCA"Question: Regarding ARTs or EMTs under MiCAR, what services provided in or into the EU constitute an offering to the public, a seeking admission to trading or a placing of an ART or EMT?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2023/1114 (MiCAR)
- Topic
- Scope and definitions (MiCAR)
- Published
- 17 Jan 2025
- Reference
2024_7185Safeguarding with a credit institition in a third country
EBAEMI/PSDMay a PI authorised and operating in an EU Member State use a credit institution based in a third country (e.g. UK) for the purpose of safeguarding funds in accordance with Art. 10(1)(a) of PSD2?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 17 Jan 2025
- Reference
2023_6882PISP payment order cancellation due to fraud prevention reasons
EBAEMI/PSDDue to fraud prevention reasons, could an ASPSP (Account Servicing Payment Service Provider) block a payment order initiated through a PISP (Payment Initiation Service Provider) despite having informed the PISP immediately upon authentication, that the payment was going to be executed (i.e., after having provided the PISP with the code ACSC (AcceptedSettlementCompleted) under the Berlin Group Standard)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Jan 2025
- Reference
2023_6873Multi-licensed entity capital requirement
EBAEMI/PSDShould a payment institution that also has a crowdfunding license meet the capital requirements of both authorizations in aggregate?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 17 Jan 2025
- Reference
2023_6790Exchange rate mark-ups part of 'all charges payable'/'currency conversion charges'
EBAEMI/PSDIs an exchange rate mark-up (the difference between the interbank rate and the exchange rate offered by the PSP to its PSUs) to be considered as part of ‘all charges payable’ as per PSD2 and the ‘currency conversion charges’ as per CBPR2 prior to the initiation of the payment?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 17 Jan 2025
- Reference
2023_6777Consideration of own funds requirements as a comparable guarantee to the PII
EBAEMI/PSDWould it be acceptable to consider, has a possible comparable guarantee, an increase of own funds’ requirements, in an amount corresponding to the minimum monetary amount calculated in accordance with the EBA’s tool, while ensuring that this amount would be fulfilled with highly liquid assets?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Monetary amount of the professional indemnity insurance
- Published
- 17 Jan 2025
- Reference
2023_6675Information provided to the payee on individual payment transaction
EBAEMI/PSDIf a framework contract includes a condition on providing all required information to the payee at least once a month, is the payment service provider still obliged to provide the information to the payee after the execution of individual payment transaction?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 17 Jan 2025
- Reference
2022_6612Provision of the "acquiring of payment transactions" payment service in the EU
EBAEMI/PSDPlease provide your opinion on whether the payment service – acquiring of payment transactions on an EU webshop – can be provided by a payment service provider from a third country. Please refer to Q&A 4233.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 17 Jan 2025
- Reference
2021_6283EMI's application of negative interest rates to its clients
EBAEMI/PSDIs an electronic money institution (EMI) allowed to apply negative interest rates to its clients (electronic money holders)?
- Regulator
- EBA
- Regulation
- Directive 2009/110/EC (EMD)
- Topic
- Not applicable
- Published
- 17 Jan 2025
- Reference
2022_6421Definition of electronic money
EBAEMI/PSDDoes the wording “accepted by a natural or legal person other than the electronic money issuer” in the definition of electronic money (article 2.2) imply that a third party (payee) must become the holder of the electronic money as such and thus that there
- Regulator
- EBA
- Regulation
- Directive 2009/110/EC (EMD)
- Topic
- Not applicable
- Published
- 17 Jan 2025
- Reference
2022_6336Duplicate ICT Incident Reporting
EBADORAIs duplicate incident reporting via the ECB SSM Cyber Incident Reporting Framework required, alongside DORA incident reporting under Article 19?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT-related incidents (management / classification / reporting)
- Published
- 11 Dec 2024
- Reference
2024_7050Exemption for Non-EU ICT Intra-group Service Providers
EBADORAIs it accurate to interpret that an ICT intra-group service provider established outside the EU (non-EU country), providing critical services to an EU-based financial institution (parent undertaking), falls within the exemption outlined in Article 31(8) of DORA, thereby exempting the need for establishing a subsidiary within the EU?
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- Oversight framework of CTPPs
- Published
- 11 Dec 2024
- Reference
2024_7096Critical Services Affected
EBADORAArticle 6 of the Delegated Act on the Classification of Major Incidents states that: "For the purpose of determining the criticality of the services affected as referred to in Article 18(1), point (e), of Regulation (EU) 2022/2554, financial entities shall
- Regulator
- EBA
- Regulation
- Regulation (EU) 2022/2554 (DORA)
- Topic
- ICT-related incidents (management / classification / reporting)
- Published
- 11 Dec 2024
- Reference
2024_7047Card data (PAN) to be returned in AISP calls
EBAEMI/PSDDoes the ASPSP have to return the card number (PAN) attached to a fetched payment account in case the user can access this data during a standard session with its ASPSP in the direct internet banking interface?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 11 Oct 2024
- Reference
2023_6946Payment account
EBAEMI/PSDWhat is the difference between payment account, e-money account and a bank account (account held at the credit institution) in terms of allowed transactions?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 11 Oct 2024
- Reference
2022_6611The definition of payment services and in particular the definition of execution of payment transaction in relation to netting centers
EBAEMI/PSD1.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 11 Oct 2024
- Reference
2022_6489Exclusion of cash withdrawal services from PSD2
EBAEMI/PSDIf a provider offers cash ATM withdrawal services, not acting on behalf of one or more card issuers but rather through an agreement with the main payment circuits, shall this type of provision be considered exempt from the PSD2?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 11 Oct 2024
- Reference
2022_6360Identify when EMD2 needs to be applied to vouchers/gift cards issued by an electronic money institution.
EBAEMI/PSDDo vouchers/gift cards issued by an electronic money institution (EMI) to top-up an e-money account (managed by the EMI itself) in order to purchase on an e-commerce platform: i) goods and services sold directly by companies belonging to the same corporate group of the EMI (thus falling out of the scope of PSD2, encompassing the exemption provided for intra-group transactions in Article 3(1)(n) of the PSD2); ii) goods and services of third-party merchants, have to be qualified as e-money at the time of issuing (i.e.
- Regulator
- EBA
- Regulation
- Directive 2009/110/EC (EMD)
- Topic
- Not applicable
- Published
- 11 Oct 2024
- Reference
2023_6736Revocation of ASPSP's Exemption from the Contingency Mechanism due to Prolonged Service Disruption
EBAEMI/PSDIn a scenario where an incident lasting more than two consecutive weeks preventing Payment Service Users (PSUs) from initiating their payments through a dedicated interface, considering that the Account Servicing Payment Service Provider (ASPSP) has an exemption from the contingency mechanism under Regulation (EU) 2018/389, and the National Competent Authority (NCA) has been notified about the incident: Should the National Competent Authority (NCA) revoke the ASPSP's exemption from the contingency mechanism?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 27 Sep 2024
- Reference
2024_7103Criteria for selecting the operations to be included in the calculation of fraud rates for the transaction risk analysis (TRA) exemption
EBAEMI/PSDWhich of the following would be the correct temporal criterion for selecting the unauthorized transactions to be included in the numerator of the fraud rates calculated for the transactions risk analysis (TRA) exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 27 Sep 2024
- Reference
2024_6989Secure corporate payment processes and protocols and inactivity time period
EBAEMI/PSDMay the period time of inactivity required by the (EU) 2018/389 - RTS on strong customer authentication and secure communication (hereinafter: RTS on SCA & CSC) Article 4 (3) (d) be changed from 5 minutes to 20 minutes if the exemption based on Article 17 of RTS on SCA & CSC has been granted by the competent authority to the Payment service provider?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 27 Sep 2024
- Reference
2023_6949PISP’s access to payable charges applied by the ASPSP on the PSU’s initiated payment via the ASPSP’s dedicated interface
EBAEMI/PSDShall the account servicing payment service provider (ASPSP) make the transaction fees accessible to payment initiation service providers (PISPs) via the dedicated interface?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 28 Jun 2024
- Reference
2021_6320Payee-initiated transactions with irregular period or variable amounts for account payments.
EBAEMI/PSDPlease clarify whether payee-initiated account transactions available in Account Servicing Payment Service Providers (ASPSPs)’ online banking channels are considered discriminatory under PSD2 when not available in the PSD2 Application Programming Interfaces (APIs).
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 28 Jun 2024
- Reference
2021_6256Mobile Banking Services and SCA in the same app
EBAEMI/PSDWe use a mobile app, software installed in a separate sandbox on a multi-purpose device, for the elements of strong customer authentication.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Jun 2024
- Reference
2023_6863Fraud reporting
EBAEMI/PSDHow we should treat the transactions that are initiated by PSP (for example refunds, chargebacks, etc.), but those transactions are related to cardholder's actions.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 14 Jun 2024
- Reference
2023_6788Eligibility of communication by AISPs with ASPSP throughout two access interfaces in parallel
EBAEMI/PSDQuestion no 1: Do art. 30(1), art. 31 and art.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 22 Mar 2024
- Reference
2023_6752Trusted Beneficiaries
EBAEMI/PSDPlease clarify whether under Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication (hereinafter: RTS on SCA & CSC) is it allowed to use the same SCA element to authorize a payment and at the same time (using the same session ID) approve (technically using by a checkbox) the payee as a trusted beneficiary?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 29 Sep 2023
- Reference
2023_6827Exemption from strong customer authentication
EBAEMI/PSDDo the revisions to Art.10 set out in Commission Delegated Regulation (EU) 2022/2360 of 3 August 2022 amending the regulatory technical standards laid down in Delegated Regulation (EU) 2018/389 as regards the 90-day exemption for account access mean that a payment service user or account information service provider is now limited to accessing only the account balance OR the transaction details for the last 90 days when availing of the revised exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 29 Sep 2023
- Reference
2023_6820App to app redirection with biometrics for PIS
EBAEMI/PSDAre ASPSPs required to offer redirected authentication with biometrics to users accessing their payment accounts through an AISP or initiating a payment through a PISP, if they offer redirected authentication with biometrics to users accessing accounts or initiating payments directly via the ASPSP?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 29 Sep 2023
- Reference
2023_6767Service Downtime
EBAEMI/PSDThe question refers to the case that an incident with a duration of two hours that disrupts transaction processing occurs around the daily cut off time of same-day transactions processing.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Major incidents reporting
- Published
- 29 Sep 2023
- Reference
2023_6744Period to be covered by statistics pursuant to Article 32(4) of Commission Delegated Regulation (EU) 2018/389
EBAEMI/PSDWhich period should the statistics to be published by ASPSPs under Article 32(4) of Commission Delegated Regulation (EU) 2018/389 cover in total?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 29 Sep 2023
- Reference
2023_6687Evidences / Records to be stored by account servicing payment service providers (ASPSP) for payment initiation service (PIS) and account information service (AIS) requests
EBAEMI/PSDShall ASPSP keep record of PIS requests received through a PISP and evidences on the authenticity and execution of these payment transactions when SCA is managed by ASPSP ?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 29 Sep 2023
- Reference
2022_6526Reading of the term "means of payment"
EBAEMI/PSDWhat are the 'means of payment' in the LNE Guidelines (guidelines 1.6 and 1.7)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 29 Sep 2023
- Reference
2022_6481ESMA Q&As on the DLT Pilot Regime
ESMAMiCAESMA’s questions and answers on the pilot regime for market infrastructures based on distributed ledger technology (DLT) — trading and settlement of tokenised financial instruments, sitting alongside MiCA.
- Regulator
- ESMA
- Regulation
- Regulation (EU) 2022/858 (DLT Pilot)
- Topic
- Crypto market infrastructure
- Published
- 2 Jun 2023
- Reference
ESMA70-460-189SCA for token replacement
EBAEMI/PSDIs SCA required for the replacement of a tokenized card happening in the background without any ‘action by the payer’ under Article 97(1)(c) PSD2 in the following cases: Expiry of the token and update of the token Replacement of the card, and the new card has
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 31 Jan 2023
- Reference
2022_6464SCA applicability / Application of SCA at tokenisation stage
EBAEMI/PSDDoes the authentication to unlock the mobile device count as one of the elements of strong customer authentication when a payment service user is tokenising a card on an e-wallet solution such as Apple Pay?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 31 Jan 2023
- Reference
2021_6145Application of SCA to issuing a payment instrument and tokenisation
EBAEMI/PSDIs strong customer authentication (SCA) required when a Payment Service Provider (PSP) issues a payment instrument or creates a token?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 31 Jan 2023
- Reference
2020_5622Authentication procedures that ASPSPs’ interfaces are required to support (using re-direction)
EBAEMI/PSDIn a pure redirection-based approach, can an ASPSP, which is not offering a mobile web browser to its PSU’s, decide not to support an authentication via a mobile web browser authentication page (no app-to-mobile web browser or mobile web browser-to-mobile web browser redirection) for PISPs/AISPs on the basis of duly justified security risks, without being considered a breach of Article 97 (5) PSD2 and Article 30(2) of the RTS on SCA and CSC and/or an obstacle under Article 32(3) of the RTS on SCA and CSC?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 27 Jan 2023
- Reference
2021_6321Application of SCA for confirmation of funds requests made by a PISP
EBAEMI/PSD1) Should two SCAs be applied when a fund confirmation is made by a PISP? i.e. one for fund confirmation and one for payment initiation? 2) Should ASPSPs provide confirmation to a CoF request made by a PISP before or after the payment is submitted?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 27 Jan 2023
- Reference
2021_6280Arbitrating between security and obstacles
EBAEMI/PSDCan an Account Servicing Payment Service Provider (ASPSP) know a mobile phone number inside of the Third Party Provider (TPP)’s organisation in order to send a decryption password to the TPP out-of-band via SMS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 27 Jan 2023
- Reference
2021_6156Ability of Payee’s PSP to apply exemptions from SCA in credit transfers
EBAEMI/PSDCan the Payee’s Payment Services Provider (PSP) apply an exemption from strong customer authentication (SCA) in credit transfers that are initiated through the payee?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 27 Jan 2023
- Reference
2021_5845Transactions initiated via electronic mail (email)
EBAEMI/PSDDo transactions initiated via electronic mail (email) qualify as initiations pursuant to Article 97 para. 1 (b) PSD2 and are therefore subject to the RTS SCA requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 6 Jan 2023
- Reference
2021_6315Articulation and interaction of the second and the third sub-paragraph of Article 74 (1) of the PSD2
EBAEMI/PSDIn cases where the payer could not possibly detect the loss, theft or misappropriation of his instrument before it was used, is it correct to state that there can be no liability at all, including if the payer has acted with gross negligence?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 6 Jan 2023
- Reference
2021_6305Calculation of “payment volume” for method B in the Article 9 of Directive EU 2015/36 (PSD2)
EBAEMI/PSDCan you please clarify the definition of 'previous year' when computing the “total amount of payment transactions executed” referred to in the calculation of “payment volume” for method B in the Article 9 of Directive EU 2015/36 (PSD2) as to whether it should be the previous 12 months from the date of calculation, therefore a rolling calculation, or whether it refers to the 'previous accounting year'?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 6 Jan 2023
- Reference
2021_6241On the access to safeguarding accounts through the Application Programming Interface (API)
EBAEMI/PSDShall a safeguarding account of the e-money institution (EMI) or/and of the payment institution (EMI and PI) within the account servicing payment service provider (ASPSP) be considered as a payment account and therefore should be accessible (displayed) through the Application Programming Interface (API) of ASPSP?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 6 Jan 2023
- Reference
2021_5755Bill-payment via postal service
EBAEMI/PSDDoes bill-payment via snail-mail (postal service) fall into the definition of Article 97 1(c) and thus are subject to strong customer authentication (SCA) requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 6 Jan 2023
- Reference
2020_5534Clarification of meanings 'transferring of funds' and 'another payment service provider’ in the context of article 10(1)(a) of PSD2
EBAEMI/PSD1) How to understand the meaning 'another payment service provider', specified in Article 10(1)(a) of PSD2? What is the definition of this meaning in the context of Article 10(1)(a) of PSD2?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 6 Jan 2023
- Reference
2020_5502“Triangular ” passport
EBAEMI/PSDAre “triangular” passports possible under the current legal framework governing the passporting rights among the EU Member States?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Passporting
- Published
- 6 Jan 2023
- Reference
2021_5726Ability of a creditor to change a mandate
EBAEMI/PSDCan a creditor introduce changes to a mandate, in accordance to Article 64(2) PSD2, by observing the same procedure as described in Article 54(1), i.e.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 6 Jan 2023
- Reference
2020_5479Safeguarding
EBAEMI/PSDAre payment institutions able to simultaneously adopt different safeguarding methods with respect to funds held?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 6 Jan 2023
- Reference
2020_5264Collection of fees for utilities or other regular services
EBAEMI/PSDDoes a business model where the contributions (collected fees for utilities or other regular services) received from the payers are transferred to the payees (service providers) in individual transfers, without opening or maintaining accounts on behalf of
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 6 Jan 2023
- Reference
2020_5099Information on the host member State in which Third Party Providers (TPPs) provide services
EBAEMI/PSDIf a payment institution, in the specific form present in the EBA register under PSD2, presents an EU passport, does this mean that the Third Party Provider (TPP) is authorised to operate for the services indicated in all EU countries?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Central register of the EBA
- Published
- 14 Oct 2022
- Reference
2021_6078Change of TPP access rights for AIS consent by the PSU prior to authorisation
EBAEMI/PSDA clarification / harmonised guidance on the Scope of the Bank Offered Consent, as defined in the Berlin Group standard, is needed.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Oct 2022
- Reference
2021_6246Clarification on the protection requirements of a CustomerID when included in a payer-presented QR-code for the initiation of (instant) credit transfers at the Point of Interaction (POI)
EBAEMI/PSDAre the Customer ID’s security measures (e.g., encryption, tokenisation, transport layer security) mentioned under Q&A 5476 to be always applied in any payer-presented QR code, regardless of who generates it (e.g., including a non-PSP)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Oct 2022
- Reference
2021_6298Future-dated payments and recurring transactions
EBAEMI/PSDWhen it comes to recurring transactions and future-dated payments, would an implementation of the PSD2-interface that requires that the TPPs store the payment details until due date, and not until due date are they allowed to send the transactions to the ASPSP for execution, satisfy the requirements in Opinion on the implementation of the RTS on SCA and SCA (EBA-Op-2018-04) of June 13, 2018' paragraph 29, in cases where the ASPSP itself offers future-dated payments and recurring transactions in their mobile/web-bank application?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Oct 2022
- Reference
2021_6318API functionality
EBAEMI/PSDIs it allowed to use a dedicated PSD2 interface by a TPP that identifies itself with an eIDAS certificate for purposes other than those specified in Article 30(1)(b) - (c) of the RTS on strong customer authentication (SCA) and secure communication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Oct 2022
- Reference
2022_6392Annex VI - Agentes/distributors
EBAEMI/PSDPlease clarify whether under Directive 2015/2366, in the exchange of notifications between NCAs, Annex VI of the Commission Delegated Regulation (EU) 2017/2055 should be sent concerning each new agent/distributor or only for the first agent/distributor acting on behalf of a payment/e-money institution.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Passporting
- Published
- 14 Oct 2022
- Reference
2022_6437Clarification of remote payment for dynamic linking
EBAEMI/PSDIs a SEPA Credit Transfer (SCT) transaction, whereby a user mobile phone interacts locally via Near Field Communication (NFC) with a merchant payment terminal to initiate the SCT transaction, whereby the user mobile phone does not communicate remotely over a mobile network for this purpose but whereby the payment terminal connects on-line to a payment system and handles the required strong customer authentication (SCA) through this on-line channel, considered an electronic remote payment transaction?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 13 Apr 2022
- Reference
2020_5247ASPSP restricting access for TPPs who embeds the redirect
EBAEMI/PSDDo Account Servicing Payment Service Providers (ASPSPs) have the right to block access to payment accounts for a Third Party Provider (TPP) who embeds the ASPSP-provided redirection website in order to provide the Payment Service User (PSU) with a TPP-provided user interface?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 13 Apr 2022
- Reference
2021_6245Payment Initiation Service - Batch payment / bulk payment
EBAEMI/PSDCan you apply the PSD2 non-discrimination principle to batch/bulk payment?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 13 Apr 2022
- Reference
2021_6236Application of the exemption under Article 10 RTS and EBICS T
EBAEMI/PSDCan an Account Servicing Payment Service Provider (ASPSP) consider that it is not applying the Article 10 Exemption under the Commission Delegated Regulation (EU) 2018/389 “at all” where it permits its Payment Services Users (PSUs) to access balances and transactions information through another direct interface (such as Electronic Banking Internet Communication Standard (EBICS) T) with no systematic or daily strong customer authentication (SCA)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 13 Apr 2022
- Reference
2021_6235Re-engineering by TPP of the ASPSP’s redirect API and PSU customer journey
EBAEMI/PSDMay a Payment Initiation Services Provider (PISP) connect to the dedicated interface of the ASPSP, only to subsequently embed (“screen scrape”) the redirection approach into their own environment, without redirecting the PSU to the ASPSP’s mobile banking app, for authentication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 13 Apr 2022
- Reference
2021_6044SCA requirements with dynamic linking for mobile initiated credit transfers (MSCTs)
EBAEMI/PSDCan mobile initiated credit transfers (MSCT) solutions whereby a proximity technology (e.g.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 13 Apr 2022
- Reference
2020_5367Individual's name to return in AISP/PISP calls
EBAEMI/PSDIs the name returned in an Account Information Service Provider (AISP) / Payment Initiation Service Provider (PISP) call expected to be that of the Payment Service User (PSU) who has initiated the transaction with the Third Party Provide (TPP), or of the actual account owner/holder?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 18 Mar 2022
- Reference
2020_5165Acquisition and money remittance payment service
EBAEMI/PSDCan a payment institution (PI) which provides a payment service of acquiring of payment transactions for its users can provide this service without holding payment account.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 18 Mar 2022
- Reference
2020_5181Money Remittance
EBAEMI/PSDWhere an entity accepts payment on behalf of a payee (such as a debt collector and the debt due to the payee is extinguished upon receipt of payment by the debt collector), is it correct to say that this does not constitute Money Remittance? (i.e.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 18 Mar 2022
- Reference
2020_5216Access to account for FinTech Solutions that incorporate regulated services
EBAEMI/PSDDo FinTech companies offer payment accounts by their use of regulated services as part of their offering and are they therefore required to provide access to accounts to Third Party Providers (TPPs)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 18 Mar 2022
- Reference
2020_5249Fees on issuing eletronic money
EBAEMI/PSDIs charging fees on issuing of the e-money, in compliance with Article 11(1) of the Directive 2009/110/EC (E-money directive – EMD)?
- Regulator
- EBA
- Regulation
- Directive 2009/110/EC (EMD)
- Topic
- Not applicable
- Published
- 18 Mar 2022
- Reference
2020_5494Topping-up e-money accounts with voucher-based products
EBAEMI/PSDIf an e-money institution (EMI) sells, through an external network of points of sale, pre-paid non-reloadable vouchers of a fixed value that can only be used to top-up e-money accounts opened with such EMIs, shall the sale of such vouchers be considered as distribution of e-money for the purposes of Directive 2009/11/EC (EMD2)?
- Regulator
- EBA
- Regulation
- Directive 2009/110/EC (EMD)
- Topic
- Not applicable
- Published
- 18 Mar 2022
- Reference
2020_5566Subcontractor of electronic money distributor
EBAEMI/PSDDoes Article 3, paragraph 4 of Directive 2009/110/EC (EMD) mean that that a legal person acting as an electronic money distributor on behalf of an electronic money institution may enter into a contract with another legal person (subcontractor) for the execution of distribution and redeeming of electronic money?
- Regulator
- EBA
- Regulation
- Directive 2009/110/EC (EMD)
- Topic
- Not applicable
- Published
- 18 Mar 2022
- Reference
2020_5624AISPs and scope of application AML requirements
EBAEMI/PSD1. To what extend do AISPs need to comply with the obligations in relation to anti-money laundering and terrorist financing under Directive (EU) 2015/849 of the European Parliament? 2.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 11 Mar 2022
- Reference
2019_4712Mount unattended contactless device on general goods vending machines
EBAEMI/PSDWith the limits described in Articles 11 and 16 of the Regulatory Technical Standards on strong customer authentication and secure communication under Directive 2015/2366/EU (PSD2), could a vendor mount an unattended "contactless only" device without pinpad on a general goods vending machine?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Mar 2022
- Reference
2020_5288API functionality
EBAEMI/PSDDoes Article 64(2) of PSD2 limit the ability of Payment Initiation Service Providers (PISPs) to initiate a single payment transaction for immediate execution only?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Jan 2022
- Reference
2018_4096Strong customer authentication requirement on pay-by-invoice payment transactions
EBAEMI/PSDDoes Article 97(1)(b) PSD2 apply for pay-by-invoice when the payer's funds are covered by a credit line extended by a payment service provider?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Jan 2022
- Reference
2019_4484Irrevocability of a payment order initiated by a PISP
EBAEMI/PSDThe EBA Opinion on the implementation of the RTS on SCA and CSC (EBA-Op-2018-04) contains a Table entitled “Main requirements for dedicated interfaces and API initiatives” and Row 9 refers to the possibility of “cancelling an initiated transaction in accordance with PSD2, including recurring transactions”.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Jan 2022
- Reference
2018_4095Definition of an electronic remote payment transaction
EBAEMI/PSDWhat are the demarcation criteria of the term „remote payment transaction“, which is an essential term in the RTS on SCA and CSC?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Jan 2022
- Reference
2019_4594Scope - Limited network exclusion
EBAEMI/PSDIs there a geographical limitation with regard to a limited network of service providers?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 21 Jan 2022
- Reference
2019_4604More than one transaction from a single consumer initiated transaction
EBAEMI/PSDWhen a consumer elects to add an additional item to their purchase at the time of checkout (a cross sale) they are making two purchases from two different merchants in a single session. Is SCA required for both of these transactions?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Jan 2022
- Reference
2019_4776SCA for staff assisted electronic channel
EBAEMI/PSDPlease clarify where a customer is physically present and identified in branch, the strong customer authentication (SCA) requirements if that customer completes a Standing Order instruction (Setup, Amend or Cancel) or initiates a credit transfer through a staff assisted electronic channel (i.e.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Jan 2022
- Reference
2020_5124Association of personalised security credentials to the payment service user
EBAEMI/PSDShould strong customer authentication (SCA) elements always be issued under control of the Account service Payment Services Provider (ASPSP)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Dec 2021
- Reference
2021_6141Confirmation of Funds (CoF) request by a PISP in case of batch processing system
EBAEMI/PSDWith respect to confirmation of funds request made by a Payment Initiation Service Provider (PISP), in the event that the Account Servicing Payment Service Providers (ASPSP) makes use of a batch processing system, should the ASPSP take into account batches that are in the queue waiting to be processed at the point when the fund confirmation request is made?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Dec 2021
- Reference
2021_6077Payers right to make use of payment initiation service providers for all types of payment transactions
EBAEMI/PSDShall payers be able to make use of payment initiation service providers for transmitting all types of credit-transfer based online payment orders from their payment accounts?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Dec 2021
- Reference
2020_5498Alternative strong customer authentication for citizens without mobile
EBAEMI/PSDWhy does the PSD2 allow banks to deny the access to the electronic financial services to customers without a mobile but with a PC?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Dec 2021
- Reference
2020_5325Revocation / Invalidation of SCA proof before execution date
EBAEMI/PSDIn order for a payment instruction to be regarded as 'authorised', is the Account Servicing Payment Service Provider (ASPSP) obliged to verify the strong customer authentication (SCA) proof immediately prior to the execution of each future dated payment instruction?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Dec 2021
- Reference
2018_4440Home / host cooperation
EBAEMI/PSDShould banks notify only National Competent Authorities (NCAs) of the home Member State when they use Strong customer authentication (SCA) exemptions on Secure corporate payment processes and protocols (Article 17 of Regulation (EU) 2018/389 – RTS on strong customer authentication and secure communication) and Transaction risk analysis (Article 18 of the Delegated Regulation)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Dec 2021
- Reference
2018_4170Scope of “additional registrations” as obstacles in the sense of Article 32(3) Delegated Regulation (EU) 2018/389
EBAEMI/PSDIs a process that requires Third Party Providers (TPPs) to upload an electronic IDentification, Authentication and trust Services (eIDAS) certificate for receiving additional client credentials before first access to a payment account provided by an Account Servicing Payment Service Provider (ASPSP) to be considered an “additional registration” and therefore an obstacle?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 17 Dec 2021
- Reference
2021_6029The implementation of commercial agent exclusion for B2C e-commerce platforms
EBAEMI/PSDIn what situation a business-to-consumer (B2C) e-commerce platform can be subjected to the exclusion foreseen in Article 3 (b) from PSD2?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 6 Dec 2021
- Reference
2020_5355Revocation of future dated Payment Initiation Services (PIS) payments
EBAEMI/PSDIs the Bank (an ‘Account Servicing Payment Service Provider’(ASPSP)) prohibited under PSD2 from acting on the following unsolicited customer instruction:- Customer asks their Bank to cancel a future-dated payment, or a series of recurring future-dated
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 3 Dec 2021
- Reference
2019_4496The implementation of commercial agent exclusion for e-commerce platforms
EBAEMI/PSDShould the settlement of the debt by an e-commerce platform be considered a sufficient reason to exclude the e-commerce platform from the scope of PSD2 or an indispensable requirement for a commercial agent mandate?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 3 Dec 2021
- Reference
2020_5354Consumer explicit consent to the PISP for processing of personal data
EBAEMI/PSDCan the presentation by the consumer of its identification data to the merchant (e.g.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 3 Dec 2021
- Reference
2020_5570Information to be provided by the PISP to the payer prior to the initiation of the transaction
EBAEMI/PSDIs it sufficient that the merchant makes available upon request by the payer (consumer) the information about the Payment Initiation Service Provider (PISP) in the Point of Interaction (POI) environment before the consumer presents their data (e.g., via a QR code) to meet the requirements of Articles 44 and 45, (2), PSD2?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 3 Dec 2021
- Reference
2020_5573Elements of possession (SIM card) and knowledge (knowledge-based responses to challenges or questions)
EBAEMI/PSD1. Can evidence of possession (SIM card) can also be verified by reading and identifying the phone number used for the phone call? 2. Can a knowledge element be based on a) transaction history of the customer; b) contact information of the customer?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Nov 2021
- Reference
2020_5215Merchant IDs and SCA
EBAEMI/PSDIn the situation where Strong Consumer Authentication (SCA) was completed at the time of completing a hotel booking by an Online Travel Agent (OTA) or hotelbrand.com under their Merchant ID but the actual payment will take place at the time of arrival: will the SCA authentication token remain valid for the hotel (merchant) making the charges and its respective Merchant ID?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Nov 2021
- Reference
2019_4797Requirements towards SCA if association is done based on phone call
EBAEMI/PSDDoes the requirement to apply Strong customer authentication (SCA) under Article 24 paragraph 2 b of Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication apply when customer is served using telephone call?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Sep 2021
- Reference
2020_5650Delegation of 2-Factor Authentication (2FA) to PISP, AISP or other third party
EBAEMI/PSDWhere a Payment Service Provider (PSP) is providing financial services via a third party application - either through a Payment Initiation Services Provider (PISP), Account Information Service Provider (AISP) or by providing embedded financial products or banking as a service solutions (i.e.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Sep 2021
- Reference
2020_5643Association with the payment service user by means of a remote channel
EBAEMI/PSDIs it sufficient to use a company level knowledge element, in combination with a peronal posession element to associate a user of a business application with personalised security credentials such as authentication software or a knowledge element?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Sep 2021
- Reference
2020_5626Clarification on level of protection required for the processing of the IBAN outside the inter-PSP environment
EBAEMI/PSDCan the IBAN of the payer or payee be handled in cleartext outside the inter Payment Service Provider (PSP) environment?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Sep 2021
- Reference
2020_5477Clarification on the qualification and protection requirements of a CustomerID when included in a payer-presented QR-code for the initiation of (instant) credit transfers at the point of interaction (POI)
EBAEMI/PSDIs the CustomerID (i.e.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Sep 2021
- Reference
2020_5476Intermediaries and Merchant-ID
EBAEMI/PSDIn the hotel industry, given that when a customer reserves a room, a payment is often not taken at this time, should an entity (intermediary, online travel agent or brand/hotel group) that collects payment details from a customer also facilitate strong customer authentication (SCA), regardless of when or by whom the actual payment transaction may be processed?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Sep 2021
- Reference
2019_4796Validity of SCA
EBAEMI/PSDIf Strong customer suthentication (SCA) is required at the time of booking which is more than 90 days before the guest’s arrival, will hotels be able to process the payment at location with an expired authentication token?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Sep 2021
- Reference
2019_4795Strong customer authentication (SCA) Knowledge element: Place of Birth and Date of Birth
EBAEMI/PSDDoes a payer’s date of birth and place of birth constitute a valid Knowledge Element for strong customer authentication.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 30 Jul 2021
- Reference
2021_5821Clarification on where the creation of the authentication code with dynamic linking for strong customer authentication (SCA) for electronic remote payment needs to be done
EBAEMI/PSDShould the authentication code be computed and dynamically linked to the transaction data in a unique processing step prior or together with the payer’s authentication on the payer’s device, or can the authentication code be computed and dynamically linked in one or several subsequent steps in the payment process, possibly not on the payer’s device?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 30 Jul 2021
- Reference
2020_5366Applicability of SCA to wallet solutions
EBAEMI/PSDIs a single Strong Customer Authentication (SCA) sufficient for transactions performed in staged wallet solutions?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 May 2021
- Reference
2018_4133Obstacle to the provision of payment initiation and account information services
EBAEMI/PSDShould Article 32.3 of Regulation (EU) 2018/389, read together with paragraphs 33 to 41 of the Opinion of the European Banking Authority on obstacles under Article 32(3) of the RTS on SCA and CSC, be interpreted so as to consider that interface implementations that require, in a redirection approach, Payment Initiation Services Providers (PISPs) to always transmit the payer’s IBAN to initiate a payment order, are an obstacle to the provision of payment initiation services because the payment service user is required to manually enter their IBAN while in the PISP’s domain?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 23 Apr 2021
- Reference
2021_5763Use of new technology for SCA
EBAEMI/PSDIs a Payment Services Provider (PSP) allowed to adopt innovative technologies for verifying Payment Services Users (PSUs) where the PSP maintains fraud levels below a certain threshold?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 23 Apr 2021
- Reference
2020_5621Use of behavioural data for SCA
EBAEMI/PSDCan a Payment Service Provider (PSP) use behavioural data and auditable scores to apply Strong customer authentication (SCA) in a way that protects consumer privacy?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 23 Apr 2021
- Reference
2020_5620Independence of the elements for SCA
EBAEMI/PSDCan a Payment Service Provider (PSP) apply Strong customer authentication (SCA) using elements from the same category provided that the elements are independent (i.e. breach of one does not compromise reliability of the other elements)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 23 Apr 2021
- Reference
2020_5619On the requirements for 'inherence' in strong customer authentication (SCA)
EBAEMI/PSDDo the elements required for ‘inherence’ in strong customer authentication (SCA) provide the complete authentication or can they form a part of an authentication decision with some non-biometric elements and still satisfy the inherence condition, for example, as one element of a user profile of several elements.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 23 Apr 2021
- Reference
2020_5353Contingency Measures under Article 33
EBAEMI/PSDDoes fallback access to a secondary instance of the dedicated interface in a different data center with dedicated resources, provide an acceptable strategy and plan for the contingency mechanism?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 23 Apr 2021
- Reference
2019_5054Application of the strong customer authentication (SCA) in case of refund
EBAEMI/PSDDoes a refund, which is considered as an electronic payment transaction, be subject to strong customer authentication (SCA)? Does a merchant that initiates a refund request be considered as a payer?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 23 Apr 2021
- Reference
2019_4855Legal requirements for the authentication procedure when SCA exemptions are applied for remote payment transactions
EBAEMI/PSDWhat are the legal requirements for the type of authentication procedure used when conditions for the application of of Strong customer authentication (SCA) exemption for remote payment transactions are fulfilled?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Apr 2021
- Reference
2020_5673How to use bank guarantees instead of PII
EBAEMI/PSDIs it acceptable to use third party (other than credit institutions) commitments that are covered by a guarantee from a credit institution as a comparable guarantee instead of professional indemnity insurance (PII)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Monetary amount of the professional indemnity insurance
- Published
- 9 Apr 2021
- Reference
2020_5335Card payments - acquirer
EBAEMI/PSDIf an acquirer is not able to distinguish whether a card used for a payment is a card with an e-money function, is the acquirer required to report transactions with such cards under the EBA Guidelines on fraud reporting, and if so, under what breakdown?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 9 Apr 2021
- Reference
2019_5045Chip and Signature cards and their inclusion in the remit of RTS Article 11
EBAEMI/PSDIs cardholder signature a strong method of authentication when transacting with card present?If so, is there a requirement to ensure that on Chip and Signature cards we step up to signature from contactless after 5 contactless /cumulative value of 150 euros?If a signature is not considered to be strong customer authentication (SCA), are chip and signature cards exempt from SCA requirements under Article 11 of the RTS on strong customer authentication and secure communication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Apr 2021
- Reference
2018_4342Trusted Beneficiaries
EBAEMI/PSDArticle 13 of the RTS on strong customer authentication (SCA) and secure communication does not seem to restrict the use of trusted beneficiaries beside the fact that the payee must be in the list of trusted beneficiaries when initiating the payment transaction.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Apr 2021
- Reference
2018_4338Type of accounts accessible through common and secure communication
EBAEMI/PSDShould credit lines (namely “credit cards accounts”), accessible online, be available to Account Information Service Provider (AISP), Payment Initiation Service Provider (PISP) and Card Based Payment Instrument Issuer (CBPII)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2019_4856Payment accounts and reference accounts
EBAEMI/PSDAre payment accounts, which are coupled with a reference account, in scope of PSD2 especially Regulation (EU) 2018/389 – RTS on strong customer authentication (SCA) and secure communication (CSC)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2018_4272Ability of a payment account operated by a payment institution to hold a credit balance in readiness for future payment transactions
EBAEMI/PSDCan a payment institution hold clients funds in the related payment accounts for undefined future transactions?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 12 Mar 2021
- Reference
2018_4221Credit value date for payment transactions with currency conversion
EBAEMI/PSDAs a credit entry on an account is possible only in the currency the account is maintained, does this mean that for a payment transaction the credit value date for the payee's account is no later than the business day on which the amount in the payee's account currency is credited to the payee's payment service provider's account?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 12 Mar 2021
- Reference
2018_4150Sanctions list screening in the context of TPPs' services - risk management policy
EBAEMI/PSDIs the Account Servicing Payment Service Provider (ASPSP) obliged to recognise if a Third Party Payment Service Providers (TPP) is named on a sanctions list or even take some actions when the TPP becomes a designated entity?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2018_4117On the application of SCA when cancelling a payment transaction
EBAEMI/PSDShould Account Servicing Payment Service Providers (ASPSPs) apply strong customer authentication (SCA) when cancelling recurring transactions?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 12 Mar 2021
- Reference
2018_4083On the use and storage of Personalised Security Credentials (PSC)
EBAEMI/PSDDo third party providers (TPPs) have the right to ask for payment service users (PSUs)' Personalised Security Credentials (PSC)?Do TPPs have the right to store PSUs' PSC ?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2018_4077Consumer mandate under Merchant Initiated Transactions
EBAEMI/PSDTerms and Conditions to outline future charges (under Merchant Initiated Transactions (MITs)) may be disclosed by the booking entity (such as online travel agent or brand/hotel group) instead of the hotel merchant.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2019_4794Merchant Initiated Transactions exemption for hotel transactions
EBAEMI/PSDFor the following scenarios, does digital acknowledgement by the consumer at time of booking that subsequent charges may be collected adequately meet the requirement for Merchant Initiated Transactions if SCA is also taken at time of booking:i.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2019_4792Processing payments for hotel reservations
EBAEMI/PSDCan hotels continue to process payments for which strong customer authentication (SCA) has not been completed at the time of reservation, or for charges which do not become apparent until after the customer has departed the hotel and for which he/she may refuse to conclude a first or additional SCA?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2019_4791Keyed Mail Order or Telephone Order (MO-TO) transactions
EBAEMI/PSDIn the hotel industry, if a consumer contacts the hotel directly to make a reservation, the hotel may need to manually key the payment details into their payment terminals. Does this qualify as a Mail Order or Telephone Order (MO-TO) transaction?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2019_4790Treatment of electronic bookings similar to Mail Order and Telephone Orders (MO-TO) transactions
EBAEMI/PSDWould hotel use-cases, which include reservations taken by third parties (such as online travel agents or brand/hotel group) for the merchant and subsequent transactions (such as post-booking processing of prepaid rates or deposits, processing of cancellation/no-show fees, processing of post-checkout charges) fall under the scope of Mail Order and Telephone Orders (MO-TO) transactions and are they therefore excluded from the strong customer authentication (SCA) requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Mar 2021
- Reference
2019_4788Calculation of own funds required for payment institution in the Article 9 of Directive EU 2015/36 (PSD2) when "input funds" are credit transfers and "output funds" are direct debit
EBAEMI/PSDHow to compute the “total amount of payment transactions executed” referred to in the calculation of “payment volume” for method B in the Article 9 of Directive EU 2015/36 (PSD2) when "input funds" on the payment account are credit transfers and "output funds" are direct debit?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 12 Mar 2021
- Reference
2018_4299Calculation of own funds required for payment institution in Article 9 of Directive EU 2015/36 (PSD2) when the payment institution offers acquiring services
EBAEMI/PSDHow to compute the “total amount of payment transactions executed” referred to in the calculation of “payment volume” for method B in the Article 9 of Directive EU 2015/36 (PSD2) when the payment institution offers acquiring services?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 12 Mar 2021
- Reference
2018_4298Obstacles to the payment initiation service
EBAEMI/PSDCan the impossibility for a Third Party Provider (TPP) to add new beneficiaries for payment initiation, coupled with the impossibility to initiate payments for unregistered beneficiaries, be considered as an obstacle?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Mar 2021
- Reference
2020_5184Account Data required by a ASPSP to execute a payment order via a PISP
EBAEMI/PSDIn the context of Payment Initiation Service (PIS) where a Payment Service User (PSU) payment order is to be carried out, the Payment Initiation Service Provider (PISP) accesses the PSU e-banking account to require a payment.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Mar 2021
- Reference
2019_4854Compliance of (1) card data (2) SMS OTP and (3) EMV 3DS behaviour-based inherence as an authentication information with the requirements of PSD2 and RTS on SCA
EBAEMI/PSDCould the use of (1) card data (2) SMS One Time Password (OTP) and (3) Europay, MasterCard, Visa (EMV) 3-D secure (3DS) behaviour-based inherence information as an authentication solution be considered compliant with the PSD2 and RTS on strong customer authentication and secure communication requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Mar 2021
- Reference
2019_4671TPP access only with PSU involvement
EBAEMI/PSDCan a Payment Service User (PSU) allow a Third party provider (TPP) the access to his account only if he is involved?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Mar 2021
- Reference
2019_4631Usage of SMS for dynamic linking
EBAEMI/PSDPlease clarify whether payment information and an authentication code sent via SMS to a mobile phone complies with the requirements for Dynamic Linking as defined in Article 5 of the RTS, and in particular paragraph 5.2.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Feb 2021
- Reference
2018_4414Exemption of secure corporate payment processes and protocols
EBAEMI/PSDIs the exemption of applying strong customer authentication, in respect of legal persons initiating electronic payment transactions through the use of dedicated payment processes or protocols that are only made available to payers who are not consumers applicable to both payment initiation and account information services?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Feb 2021
- Reference
2018_4383Perform SCA by reusing an element used in an authentication exempted from SCA
EBAEMI/PSDWhen an element is used to access the payment account online, in the case the Payment Service Provider (PSP) is allowed not to apply Strong Customer Authentication (SCA) (only applying a single-factor authentication : login + password), is it possible to reuse this element to perform SCA to authenticate a transaction ?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 Jan 2021
- Reference
2020_5516Transport and parking exemption for parking and electric vehicle charging
EBAEMI/PSDDoes the transport and parking exemption under Article 12 of Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication apply to transactions at unattended terminals for the payment of a parking fee that includes electric charging?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 Jan 2021
- Reference
2020_5224Payment Initiation Scope and Trusted Beneficiaries
EBAEMI/PSDShould non-payment accounts be listed as trusted beneficiaries where they are exempted from Strong Customer Authentication (SCA) as Beneficiaries of a Payment Transaction?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 Jan 2021
- Reference
2020_5135Using Trusted Beneficiary Lists to Auto Reject PISP Transactions
EBAEMI/PSDIs an Account Servicing Payment Service Provider (ASPSP) able to block a Payment Initiation Services Provider (PISP) transaction before attempting Strong Customer Authentication (SCA) if the beneficiary account does not appear in the Payment Services User (PSU)'s regular payee list/trusted beneficiary list?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 Jan 2021
- Reference
2020_5115Strong Authentication
EBAEMI/PSDIs one time passcode (OTP) Mail considered as a "Strong Customer Authentication" under Regulation (EU) 2018/389 – RTS on strong customer authentication and secure communication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 Jan 2021
- Reference
2018_4315Ability of static card data to be considered a possession factor?
EBAEMI/PSDCan static card data (Card number PAN + cardholder name +Exp. Date + static CVV2/CVC2) be considered a as a possession factor, and if so: is it strong enough to be a valid factor in a 2-factor Strong customer authentication (SCA)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 Jan 2021
- Reference
2018_4235SMS OTP and credit card as a two authentication factor
EBAEMI/PSDCan we consider Credit card and One Time Password (OTP) SMS as a two authentication factor ?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 Jan 2021
- Reference
2018_4135Authorisation for the provision of PIS and AIS on behalf of other legal entities belonging to the same corporate group / Autorizzazione ad offrire servizi di PIS e AIS per conto di altre Legal Entity appartenenti allo stesso Gruppo societario
EBAEMI/PSDIn a corporate group which is not listed in the register of banking groups and in which there is both an electronic money institution and a credit institution, can the electronic money institution offer payment initiation services (PIS) and account information services (AIS), including on behalf of the group’s credit institution that also provides the same service?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 25 Sep 2020
- Reference
2019_4752Losses due to fraud per liability bearer / Perdite dovute a frode per portatore di responsabilità
EBAEMI/PSDPlease clarify the requirement in guideline 1.6 (b) of the EBA Guidelines on fraud reporting under PSD2 with regard to recognising losses due to fraud per liability bearer.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 25 Sep 2020
- Reference
2019_5008SCA profiles and multiple-use of devices
EBAEMI/PSDCan multiple users use the same device (i.e. smartphone) and have different strong customer authentication (SCA) profiles on the same device?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4560Relying on vendor mechanisms processing the biometric data for strong customer authentication; Multiple fingerprint samples stored on a mobile device and used for purpose of user authentication.
EBAEMI/PSDAre the obligations of a payment service provider (PSP) laid down in the Article 8 of RTS on strong customer authentication and secure communication fulfilled in case the biometric credentials of customer are stored at the device level and the strong customer authentication itself is processed by the mobile device?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4651Delayed or deferred PIN for wearable devices
EBAEMI/PSDIs the PIN entered when the cardholder takes on wearable device on, still valid as a knowledge element for one or several transactions later the same day, if it can be ensured that the device has not been taken off?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4783Whitelisting
EBAEMI/PSDWill a clearing house for distribution be enabled to facilitate the on-going maintenance of the whitelisting process?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4800Failed Authentication Code
EBAEMI/PSDPlease clarify under what circumstances Article 4 Paragraph 3(a) of the Regulation (EU) 2018/389 – RTS on SCA and SC might it be impossible to apply in remote authentication where SMS based One time passwords (OTPs) are used as the authentication method.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4875Authentication code
EBAEMI/PSDIs an extra strong customer authentication (SCA) required, after logging in (with or without SCA) in the mobile application, to initiate the provisioning step to add the customers card to a third party wallet (e.g. Apple or Google pay)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4910SCA for contactless payments at a POS executed via a mobile device
EBAEMI/PSD1) Can we consider the strong customer authentication (SCA) outsourced from the issuer of cards to the payer? 2) Is it necessary for the issuer of the cards to perform SCA based on the elements of identification that are beyond its control?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4937"Push based" authentication and SCA requirements
EBAEMI/PSDDoes "push based" authentication fall in the Strong customer authentication (SCA) requirements, based on the security risks "push authentication" poses?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Sep 2020
- Reference
2019_4984Tokenised card details as a SCA possession element.
EBAEMI/PSDIn relation to card tokenisation that can be used for the purposes of various payment solutions, does the token that is created from the card details qualify as a “possession element” according to the strong customer authentication (SCA) requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Aug 2020
- Reference
2019_4827Insurance policy on minimum monetary amount of the professional indemnity insurance of PSD2
EBAEMI/PSDIf an e-money payment institution (for the purpose of new PSD2 services - Payment Initiation Service Provider (PISP) and Account Information Service Provider (AISP) in line with insurance industry standards signed an insurance policy with insurance company for several thousand/million euros with franchise deductible (e.g.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Monetary amount of the professional indemnity insurance
- Published
- 31 Jul 2020
- Reference
2019_4542Reporting of e-commerce card-based payment transactions falling within the scope of EBA Opinion EBA-Op-2019-06 for which no strong customer authentication was applied
EBAEMI/PSDShould e-commerce card-based payment transactions – falling within the scope of the EBA Opinion on the elements of strong customer authentication under PSD2 (EBA-Op-2019-06) and for which no strong customer authentication was applied – be reported under the higher-level category “Of which authenticated via non-strong customer authentication”?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2020_5070Data breakdown on fraud by different card functions for cash withdrawals
EBAEMI/PSDDoes the breakdown on “card payments by fraud types” in Table E of the EBA Guidelines on fraud reporting under PSD2 refer only to cards with a credit/delayed debit function?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_5056Recording of card payments
EBAEMI/PSDIf a card has both an e-money and non e-money function, how should a payment be recorded? Should the recording be different based on the type of the reporting institution (for example, depending on whether is an electronic money institution (EMI) or a bank)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_5046Recording of e-money
EBAEMI/PSDIf a card issued by an E-money institution has a cash function, how should the cash withdrawal from that card be recorded? Should it be recorded on the debit card withdrawal, as the E-money breakdown section does not include a cash withdrawal category?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_5044Direct debts fraud reporting
EBAEMI/PSDIn relation to the direct debits fraud, please clarify the reporting criteria for direct debit fraud.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_5043Reporting of PISP transactions
EBAEMI/PSDShould payment initiation service provider (PISP) initiated payments be reported under both Table A (1.1) and Table H (8.x)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_5042Reporting of PISP initiated payments
EBAEMI/PSDIs there a requirement to segregate the Payment Initiation Service Provider (PISP) initiated payments which were executed without Strong customer authentication (SCA), by the relevant availed exemption used?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_5041Reporting of fraud by the acquirers
EBAEMI/PSDRegarding the fraud definition, could you please clarify how the following fraud examples should be classified by the acquirers
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_5039Reporting of card transactions that are out-of-scope from the requirement for SCA
EBAEMI/PSDIn the Fraud Reporting, how should payment service providers (PSPs) report card transactions without Strong Customer Authentication (SCA) that are out of scope of the requirement for SCA, i.e. one-leg transactions and merchant-initiated transaction?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_4866Report of fraud rates by issuers and acquirers
EBAEMI/PSDFor card-based transactions: - When the issuer reports frauds under the EBA Guidelines on fraud reporting (EBA/GL/2018/05), shall the issuer provide information on the unauthorised transactions for which the acquirer has applied an exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2019_4703Transaction risk analysis (TRA) exemption – Calculation of fraud rate – Impact of unauthorized transactions on issuers and acquirers
EBAEMI/PSDIn the case of card-based transactions, shall issuers include in their fraud rate calculation only the unauthorized transactions for which they apply strong customer authentication (SCA) or an exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Jul 2020
- Reference
2019_4702Strong Customer Authentication (SCA) possession element requirement for cryptographic validation
EBAEMI/PSDFor a device to be considered possession:-a) should the device perform "cryptographically underpinned validity assertions using keys or cryptographic material stored in" the device?b) should the device be in the physical possession of the Payment Service User (PSU)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 Jul 2020
- Reference
2019_4532Electronic chip transactions authenticated with a hand signature
EBAEMI/PSDAs a Payment Service Provider (PSP) acquirer, how should we report the German chip + signature transactions in the “EBA fraud report under PSD2” given the fact this kind of transactions are non-Strong Customer Authentication (SCA) and do not fall under any allowed exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Fraud reporting
- Published
- 24 Jul 2020
- Reference
2018_4399Separation of factors for strong customer authentication
EBAEMI/PSDIf a mobile phone has two different e-banking apps on it, one for the banking agendas (a banking app where payments are initiated by entering password, possibly in combination with OTPs) and one for receiving the SMS OTPs (authorization app),would this scenario fulfill the PSD2 requirements of sufficient separation of both factors (since both factors reside on the same smartphone, but in different apps)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jun 2020
- Reference
2019_4637Exemptions from Strong Customer Authentication (SCA): credit transfers
EBAEMI/PSDCan the exemption under Article 15 of the RTS on SCA be applied to credit transfers between a personal account and a business account held by the same person.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jun 2020
- Reference
2019_4564Unattended terminals and Transaction Risk Analysis (TRA) exemption and related Payment Service Providers (PSP)’s liabilities rules
EBAEMI/PSDProvided that both the payer’s Payment Service Provider (PSP) and the payee’s PSP can apply the strong customer authentication (SCA) exemption, without prejudice to the last say of the payer’s PSP, can a payment made at highway toll booths be treated as the one performed at the unattended terminals for transport fares?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jun 2020
- Reference
2019_4480Scope of contingency mechanism
EBAEMI/PSDShould the interfaces – referred to in Article 33(4) of the RTS - be interpreted to include not only the internet banking interface of the account servicing payment service provider (ASPSP) but also its proprietary mobile banking interface?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jun 2020
- Reference
2019_4826Define what is “given period of time”
EBAEMI/PSDWhat constitutes a “given period of time” as expressed in Article 4.3 (b) of the RTS on strong customer authentication and secure communication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jun 2020
- Reference
2019_4662EBA register providing a list of third party providers (TPPs)
EBAEMI/PSD1° Does the EBA register under PSD2 provide a list of third party providers (TPPs)?2° If yes :2.1 Could you provide a procedure to get a TPP list?2.2 Should we filter on services 5 (Payment Initiation Service Provider (PISP) / Card Based Payment Instrument
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Central register of the EBA
- Published
- 19 Jun 2020
- Reference
2019_4650Categories of Registration
EBAEMI/PSDIs it a requirement that all EU countries include the categories the institution is approved for within their respective registers i.e. in their publicly available data?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 19 Jun 2020
- Reference
2018_4371Dynamic linking: transactions for which the final amount is unknown and may be lower or higher than authenticated amount
EBAEMI/PSDFor remote card transactions, is it acceptable that there are legitimate cases where the final amount may be lower or higher than the amount authenticated by the cardholder?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 29 May 2020
- Reference
2020_5133Signature on a paper slip from a payment terminal, as a factor in a two-factor SCA
EBAEMI/PSDCould Signature on a paper slip from a payment terminal, be considered a valid factor in a two-factor strong customer authentication (SCA) under the RTS – and what type of element is it?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 15 May 2020
- Reference
2018_4237Definition of payee for dynamic linking
EBAEMI/PSDArticle 5 of the RTS on strong customer authentication and secure communication requires the authentication code to be specific to the amount of the payment transaction and the payee.Does it suffice to include a meaningful part of the identifier into the calculation of the authentication code?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 20 Dec 2019
- Reference
2019_4556Dynamic Linking for batch payments
EBAEMI/PSDWith regards to dynamic linking for a batch of remote electronic payments, should the authentication code be linked to each and every IBAN of all the beneficiaries in a batch file?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 20 Dec 2019
- Reference
2018_4435Dynamic linking for batch transactions
EBAEMI/PSDIn relation to payment transactions for a batch of remote electronic payments to one or several payees, please clarify whether the payer needs to be made aware of every payee in the batch?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 20 Dec 2019
- Reference
2018_4415Data authentication standards
EBAEMI/PSDDoes a non-remote card payment transaction with a secure, dynamic data authentication of the card (DDA or higher), based on ISO/IEC 7816 (for contact cards) and ISO/IEC 14443 (for contactless card) used with a static PIN meet the requirements of Article 4 of the RTS on Strong Customer Authentication (SCA)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 20 Dec 2019
- Reference
2018_4110Scope of ‘initiation of an electronic payment transaction’
EBAEMI/PSDDoes a card payment transaction, authenticated with a signature at the point of sale, fall under the scope of Article 97 (I) (b) PSD2? Is there a difference if the signature is provided on a paper or on a signature pad (e.g.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 20 Dec 2019
- Reference
2018_4108Confidentiality of the application cryptogram for EMV transactions
EBAEMI/PSDAre EMV (Europay, MasterCard, Visa) transactions (for which the application cryptogram is not enciphered during its transmission) compliant with the RTS on strong customer authentication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 20 Dec 2019
- Reference
2018_4054Compliance with SCA in offline mode on an aircraft without internet connection
EBAEMI/PSDHow can Strong Customer Authentication (SCA) be applied in an offline environment onboard an airplane when chip and pin cannot be verified with a Point of Sale (POS) device?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 6 Dec 2019
- Reference
2019_4740Unsuccessful authentications and declined transactions effect on the counters of cumulative amount and number of consecutive transactions
EBAEMI/PSDDo failed authentications or declined transactions increase the counters of cumulative amount or number of hits?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 6 Dec 2019
- Reference
2019_4785Transaction Risk Analysis (TRA) exemption – Time period for calculation of initial fraud rate
EBAEMI/PSDWhat is the relevant time period to use when calculating the initial fraud rate for use when the Strong Customer Authentication (SCA) comes into force?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 8 Nov 2019
- Reference
2018_40443 month notification period on interface changes to ASPSPs’ interfaces
EBAEMI/PSDDo account servicing payment service providers (ASPSPs) need to adhere to a 3 month notification period for all interface changes, or only for breaking interface changes, as specified in the RTS on on strong customer authentication (SCA) and secure communication (CSC) Article 30 Paragraph 4?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2019_4823Applicability of exemption under RTS Article 16 for payee’s PSPs (acquirers)
EBAEMI/PSDCan an exemption under Article 16 of the RTS on strong customer authentication and secure communication be applied by the payee’s payment service provider (PSP) (the acquirer) for card-based payments?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2018_4242Applicability of exemption under RTS Article 11 for payee’s PSPs (acquirers)
EBAEMI/PSDCan an exemption under Article 11 of the RTS on strong customer authentication and secure communication be applied by the payee's payment service provider (PSP) (the acquirer) for card-based payments?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2018_4241Contactless counting
EBAEMI/PSDFor the purpose of counting previous cumulative contactless transactions in order to assess the eligibility of the exemption in Article 11 of the RTS, should contactless transactions initiated outside of the EEA be included?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2018_4227Contactless payments at point of sale - Applications of the conditions
EBAEMI/PSDWith respect to Article 11 Paragraph b) of the RTS can we setup control for either 150 € or 5 transactions?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2018_4225Application of limits for Strong customer authentication (SCA) exemption
EBAEMI/PSDHow should payment service providers (PSPs) apply the cumulative limits set in Articles 11 and 16 of the RTS on strong customer authentication and secure communication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2018_4182Application of the low-value contactless exemption – Calculation of limits at Primary Account Number (PAN) / account level or at device / token level
EBAEMI/PSDMay the counters for the application of the low-value contactless exemption be calculated at device/token level?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2018_4036Criteria for the application of the transaction risk analysis (TRA) exemption – Relevant fraud rates
EBAEMI/PSDIs only the Payment Service Provider (PSP) applying the TRA exemption required to have a fraud level below the reference fraud rate?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Oct 2019
- Reference
2018_4034Clarification on whether a particular business model type constitutes the provision of an account information service as defined by Article 4 (16) of PSD2
EBAEMI/PSDDoes a business model where the provider offers a service sending the account information to third parties (different from the payment service user) (detail provided in the background) constitute the provision of an account information service, particularly as it is not proposed that the account information obtained will be given directly to the Payment Service User?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Authorisation and registration
- Published
- 13 Sep 2019
- Reference
2018_4098Is the scope of the RTS on strong customer authentication (SCA) and secure communication one-leg or two-leg?
EBAEMI/PSDDoes the PSD2 requirement on SCA, and subsequently the detailed requirements in the RTS on SCA including the practical usage of the allowed exemptions, apply also to one-leg transactions, with regards to:Transactions with the payer’s payment service providers
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 6 Sep 2019
- Reference
2018_4233The Implementation of the electronic communications exclusion in the voiced-based premium rate services market
EBAEMI/PSDConsidering the organisation of the voiced-based premium rate services market, and considering the interpretations proposed for the electronic communications exclusion (ECE) in the different countries, as far as a payment transaction complies with the conditions imposed by the ECE, does the ECE apply to the whole value chain, and therefore, all the providers of electronic communications networks or services involved in payment transactions covered by the ECE should not have to register as payment institutions or agents for these operations?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 6 Sep 2019
- Reference
2018_4181Geographical scope of application of the RTS on strong customer authentication (SCA) and secure communication requirements – ‘Two-leg’ transactions
EBAEMI/PSDIs it necessary that issuer, acquirer, cardholder and merchant be all located in the EEA for the RTS on SCA requirements to apply to two-leg transactions?May the issuer use the merchant’s location as a proxy (in lieu of the acquirer’s location)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 6 Sep 2019
- Reference
2018_4030What is considered as a dedicated interface
EBAEMI/PSDPayment Service Users (PSUs) communicate with an account servicing payment service provider (ASPSP) via Web using HTTP while mobile PSUs and Third Party Providers (TPPs) via REST Application Programming Interfaces (APIs) but in all cases the processing is done by the same back-end server using the same credentials, authorisations and business logic.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Aug 2019
- Reference
2019_4681Inclusion of time taken for SCA in the performance KPI
EBAEMI/PSDDoes the Key Performance Indicator (KPI) for the performance of the dedicated interface include the time taken for conducting Strong Customer Authentication (SCA)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Aug 2019
- Reference
2019_4661Contactless transactions - SCA
EBAEMI/PSDDoes the cumulative count / authorised sum amount apply to any contactless authorisation request, regardless if the request was approved or not?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Aug 2019
- Reference
2018_4230SCA at vending machines without PIN pad
EBAEMI/PSDDo transactions at vending machines without PIN pad require Strong Customer Authentication (SCA)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Aug 2019
- Reference
2018_4057Review of security measures
EBAEMI/PSDWhen an issuer delegates strong customer authentication (SCA) to a third-party (e.g. a smartphone manufacturer), what are the requirements for such delegation?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Aug 2019
- Reference
2018_4047Liability for fraud when SCA exemption used
EBAEMI/PSDWho is liable for fraud on Strong Customer Authentication (SCA) exempted transactions? Which payment service provider (PSP) is liable (payer’s or payee’s) when both PSPs choose to trigger an exemption to SCA?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jul 2019
- Reference
2018_4042Confidentiality of offline PIN
EBAEMI/PSDShould the PIN transmitted offline from a terminal to an Europay, MasterCard and Visa (EMV) card always be enciphered?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jul 2019
- Reference
2018_4055Responsibility for comprehensive assessment according to Article 95(2) PSD2
EBAEMI/PSDIt is not clear, whether comprehensive assessment of the operational and security risks relating to the payment services has to be carried out by the payment service providers (PSP), or it can be delegated / outsourced to a third entity (e.g.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Jul 2019
- Reference
2018_4231Scope of the corporate SCA exemption.
EBAEMI/PSDDoes the corporate SCA exemption apply only if the payer initiates (and transmits) payments directly to their ASPSP and not for payments transmitted via a 3rd party service provider (i.e. a PISP)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Jun 2019
- Reference
2019_4693"Authorisation number" in eIDAS certificates
EBAEMI/PSDThere are two possible interpretations of the Regulation (EU) 2018/389 (RTS) Article 34 paragraph (2) in the case of payment service providers registered in Member State “A”:1) The authorisation number is the number of the resolution of the NCA (or its
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Central register of the EBA
- Published
- 14 Jun 2019
- Reference
2019_4679Requirement on the use of a Qualified Certificate for Electronic Seals (QSealC) for integrity and authenticity
EBAEMI/PSDPlease clarify whether in the EBA’s Opinion on the use of eIDAS under the RTS on SCA and CSC, under Paragraph 11, Qualified Electronic Seals employing a Qualified Seal creation Device are required to provide integrity and authenticity through the reference to Article 35(2) of Regulation (EU) No 910/2014?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 14 Jun 2019
- Reference
2019_4586Qualified certificate under eIDAS for ASPSP
EBAEMI/PSDIs it required for an Account Servicing Payment Service Provider (ASPSP) to use qualified certificates under eIDAS to identify itself to a Third Party Provider (TPP)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Jun 2019
- Reference
2018_4413Secure corporate payment processes and protocols
EBAEMI/PSDAre USB drives (containing a certificate) used only by corporate clients compatible with RTS requirements?Can USB drives be considered as payment processes exempted from strong customer authentication ?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Jun 2019
- Reference
2018_4400ASPSP providing updated payment status to PISP
EBAEMI/PSDAre account servicing payment service providers (ASPSPs) required to provide information on the initiation and execution of the payment transaction, including updates, in order for a payment initiation service provider (PISP) to comply with Article 46(a) PSD2 and pursuant to Article 36(1)(b) RTS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Jun 2019
- Reference
2019_4601Applicability of SCA to electronically processed SEPA Direct Debits / Interpretation of EBA Q&A 2018_4359
EBAEMI/PSDAre mandates for direct debits which are set up without direct involvement of the payer’s PSP subject to SCA requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Jun 2019
- Reference
2019_4664Currency conversion of the EUR thresholds contained in the RTS
EBAEMI/PSDMay payment service providers (PSPs) and card schemes set rounded and easily understandable non-EUR currency equivalents for the EUR thresholds set out in the RTS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Jun 2019
- Reference
2018_4040Testing eIDAS certificates before 14 September 2019
EBAEMI/PSDHow can Third Party Providers (TPPs) and Account servicing payment service providers (ASPSPs) test their interfaces using PSD2 eIDAS-certificates during the testing period prior to September 2019 as it is only mandatory to use PSD2 eIDAS certificates from September 2019 onwards?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Jun 2019
- Reference
2018_4138Application of Transaction Risk Analysis (TRA) exemption – Real time risk analysis / monitoring
EBAEMI/PSDIs it acceptable if a payment service provider (PSP) looking to apply the TRA exemption makes a best effort using the information available to them to identify that none of the six individual factors mentioned in Article 18(2)(c) of the Commission Delegated Regulation 2018/389 are applicable, but does not have to actually identify non-applicability of all of these factors to be able to use the TRA exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Jun 2019
- Reference
2018_4127Exemption for secure corporate payment processes and protocols
EBAEMI/PSDMay lodged and virtual cards benefit from the exemption for secure corporate payment processes and protocols under Article 17 RTS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Jun 2019
- Reference
2018_4060Transaction Risk Analysis (TRA) exemption – Frequency of recalculation of fraud rate
EBAEMI/PSDShould the fraud rate, in accordance with Article 19 of the RTS, be recalculated every day using the trailing 90 days of data, or should it be recalculated once every 90 days (using the trailing 90 days of data)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Jun 2019
- Reference
2018_4045Certfication in relation to a Technical Service Provider (TSP)
EBAEMI/PSDWhen performing the role of a Technical Service Provider (TSP) is the TSP required to update the certificate received from the Third Party Payment Service Providers (TPP) (to demonstrate our involvement) to enable the Account Servicing Payment Service Provider (ASPSP) to authorise the certificate and provide the appropriate requested data back through to the TPP and establish the session?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 May 2019
- Reference
2018_4375Authentication code
EBAEMI/PSDIs it allowed to use the (authenticated) session that a user has (after logging in (with or without SCA)) as 1 of the authentication factor when performing SCA for a payment transaction?For example: A customer logs in with its username & password (knowledge) + SMS One Time Password (possession).
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 24 May 2019
- Reference
2018_4141Information to be provided / made available by ASPSP to payment initiation service provider (PISP)
EBAEMI/PSDIn the context of PIS:(a) shall the ASPSP, upon initiation of the payment session, provide or make available to the PISP the IBANs/account numbers for all payment accounts from which the user can transfer funds, and the associated currencies; and(b) shall the ASPSP, in each communication session, provide or make available to the PISP/AISP the name of the payment service user that is accessing the accounts.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 10 May 2019
- Reference
2018_4188Application of the Low Value Transaction Limits
EBAEMI/PSDShould the limits according the Article 16 RTS be applied to the account itself (account holder and authorized persons together) or should they be applied to the account holder (owner) and each authorized person (i.e. proxy of account holder) separately?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Apr 2019
- Reference
2018_4429Wide usage portability between Member States
EBAEMI/PSDCould three months’ data, showing wide usage of the dedicated interface, produced in one Member State by a regulated entity (ASPSP) belonging to an ASPSP Group, be used as evidence to support the ‘widely used’ condition in a further Member State for a separate regulated entity (ASPSP) belonging to the same ASPSP Group, on the condition that both entities employ the same dedicated interface?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 26 Apr 2019
- Reference
2019_4638Applicability of Article 34 (eIDAS certificates) prior to application date of Regulation (EU) 2018/389
EBAEMI/PSDIs the use of eIDAS certificates mandatory for accessing payment accounts via dedicated interfaces (APIs) already prior to the application date of the Commission Delegated Regulation (EU) 2018/389, i.e. 14 September 2019?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Apr 2019
- Reference
2019_4630Content of eIDAS certificates if agents or outsource providers are involved
EBAEMI/PSDWho shall be the Subject Distinguished Name (DN) in the situation described in EBA Opinion on eIDAS (EBA-Op-2018-7) item 21? Does information on agents or outsource providers has to show up in the certificates?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Apr 2019
- Reference
2019_4507Passporting and eIDAS certificates
EBAEMI/PSDDo account servicing payment service providers (ASPSPs) have to check that third party providers (TPPs) are authorised to operate in their Member State via freedom to deliver services passporting? If so, how shall this be done?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Passporting
- Published
- 26 Apr 2019
- Reference
2018_4432Fraud rate calculation for TRA exemption – country dimension
EBAEMI/PSDCould – or should – the fraud rate for the TRA exemption be calculated per member state where a PSP provides payment services (one legal entity with branches in different countries), or should the fraud rate be aggregated as one for the whole legal entity?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Apr 2019
- Reference
2018_4439Fall back exemption
EBAEMI/PSDArticle 33, § 6 of the RTS for strong customer authentication and common and secure open standards of communication (the “RTS”) provides that “Competent authorities, after consulting EBA to ensure a consistent application of the following conditions, shall exempt the account servicing payment service providers that have opted for a dedicated interface from the obligation to set up the contingency mechanism […]” (the “fall back exemption”).
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 12 Apr 2019
- Reference
2018_4163Identification and access for testing purposes of entities that are not authorised third party providers (TPPs)
EBAEMI/PSDHow would account servicing payment service providers (ASPSPs) identify entities that have applied for authorisation as a TPP?Should ASPSPs offer access to their testing facility to entities that are not (i) authorised payment service providers or (ii) entities that have applied for authorisation as a TPP (e.g.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 29 Mar 2019
- Reference
2019_4609ASPSP is denied the waiver to the fall-back by an NCA
EBAEMI/PSDIf an Account Servicing Payment Service Provider (ASPSP) is denied the waiver to the fall-back by a National Competent Authority (NCA) (i.e. at 13 September 2019), will the ASPSP still have 2 months to build the fall-back?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 22 Mar 2019
- Reference
2018_4140Application of the exemption related to a trusted beneficiary
EBAEMI/PSDHas the exemption related to a trusted beneficiary to be applied on an account basis or rather to a list of accounts included in an online banking agreement ?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 8 Mar 2019
- Reference
2018_4360Applicability of SCA to ‘card payments initiated by the payee only’
EBAEMI/PSDAre card payments that are initiated by the payee only on the basis of (1) an initial mandate by the payer authorizing the payee to initiate the periodic payments and (2) a pre-existing agreement between the payer and the payee for the provision of products or services, subject to the RTS SCA requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 1 Mar 2019
- Reference
2018_4031Subsequent instances of a recurring card payment transaction, other than the first, initial one, are transactions initiated by the payee only. This is also the case for card instalment transactions.
EBAEMI/PSDAre the subsequent instance of card payment recurring transactions (other than the first, initial one) and of instalment transactions (again, subsequent to the initial one) transactions initiated by the payee only?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 1 Mar 2019
- Reference
2018_4404Payee-initiated transactions with irregular period or variable amount
EBAEMI/PSDPlease clarify whether standing agreements between a customer and a merchant resulting in subsequent billing (irregular or otherwise) to be payee-initiated transactions, and as such excluded from the SCA requirement.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 1 Mar 2019
- Reference
2018_4131Transactions initiated via Interactive Voice Response (IVR) solutions
EBAEMI/PSDDo transactions initiated via Interactive Voice Response (IVR) solutions qualify as telephone orders and are therefore excluded from the scope of the RTS SCA requirements?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 1 Mar 2019
- Reference
2018_4058Does SCA apply to electronically processed SEPA Direct Debits ?
EBAEMI/PSDWhen processing SEPA Direct Debits electronically (assuming that the Direct Debit mandate has been signed digitally), does SCA apply to transactions? If not, what is the legal basis for this exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 22 Feb 2019
- Reference
2018_4359Contactless payments at point of sale - Applications of the conditions
EBAEMI/PSDWhat activity can be considered a proper application of strong customer authentication according to the Article 11 Paragraph b of the Commission Delegated Regulation (EU) 2018/389?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 8 Feb 2019
- Reference
2018_4226Communication plans to inform payment service providers making use of the dedicated interface
EBAEMI/PSDIs it sufficient to publish the measures to restore the system and the further descriptions on the website in an area, which is secured by the certificates of the payment service providers?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 8 Feb 2019
- Reference
2018_4071Length of authentication codes
EBAEMI/PSDIs a 3 decimal-digit authentication code, which (1) is unique per each transaction and (2) complies with the other security requirements set out in Article 4 RTS, compliant with the RTS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 8 Feb 2019
- Reference
2018_4053Showing a password after it has been masked
EBAEMI/PSDArticle 22, 2(a) states that "personalised security credentials are masked when displayed and are not readable in their full extent when input by the payment service user during the authentication".
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 8 Feb 2019
- Reference
2018_4366Trusted Beneficiary exemption – Management of the exemption, information flows between PSPs in the payment transaction
EBAEMI/PSDFor the seamless management of the Article 13 exemption, should ASPSPs provide a feature that: 1) informs Acquirers and PISPs whether the payee is included in the payer’s list of trusted beneficiary; and 2) allows Acquirers and PISPs to suggest new entries or amendments to a payer’s list of trusted beneficiaries?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 25 Jan 2019
- Reference
2018_4128On the access to names and surnames through the API
EBAEMI/PSDShall names and surnames associated with payment accounts be displayed through the Application Programming Interface (API)??
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 25 Jan 2019
- Reference
2018_4081Explicit consent required by the ASPSP from the PSU to enable the PSU to use the services provided by TPPs / Consenso esplicito richiesto dall’ASPSP al PSU per consentirgli di avvalersi dei servizi prestati dai TPP
EBAEMI/PSDMay the requirement by the ASPSP for the PSU to give additional explicit consent in order to be allowed to use the services provided by TPPs, in addition to the consent given by the PSU to the TPP, be considered an ‘obstacle to the provision of payment
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Other topics
- Published
- 11 Jan 2019
- Reference
2018_4123Applicability of the low-value contactless exemption to contactless-only devices
EBAEMI/PSDFor contactless-only devices that (1) do not have a contact interface and (2) do not support on-device authentication, may the counters for the application of the low-value contactless exemption be reset through an out-of-band mechanism such as a mobile phone application?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 11 Jan 2019
- Reference
2018_4038Calculation of fraud rates in relation to Exemption Threshold Values (ETVs)
EBAEMI/PSDIs it acceptable to calculate the fraud rate for the application of the TRA exemption per ETV band?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Dec 2018
- Reference
2018_4043Exemption from strong customer authentication (SCA) for payment account information in combination with accessing account information online in web browser
EBAEMI/PSDIs it acceptable to abstain from applying the 5-minute-rule when the strong customer authentication (SCA)-exemption for payment account information is in use?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Dec 2018
- Reference
2018_4068Exemptions from Strong Customer Authentication (SCA): trusted beneficiaries
EBAEMI/PSDShould a Payment Service User (PSU) recreate a list of trusted beneficiaries that was already approved in accordance with the EBA Guidelines on the security of internet payments?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Dec 2018
- Reference
2018_4120Access by AISPs when customer not present up to 4 times in a 24 hour period
EBAEMI/PSDIs the intention that the '4 times in 24 hour period' is implemented based on 4 sessions for access for account information per consented customer account, or 4 Application Programming Interface (API) calls (where APIs are used for the decicated interface) for account information, or another basis?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Dec 2018
- Reference
2018_4210Signature performed on the screen of a digital device as a factor in a two-factor SCA
EBAEMI/PSDCould a signature performed on the screen of a digital device be considered a valid factor in a two-factor strong customer authentication (SCA) under the RTS – and what type of element is it?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Dec 2018
- Reference
2018_4238Consent for the provision of PIS and AIS
EBAEMI/PSDCould the consent to Account Information Service Providers (AISP)/ Payment Initiation Service Provider (PISP) to provide services to a Payment Service User (PSU) also be revoked by the bank directly for PSU’s ease of use and could ASPSPs offer the PSU to generally “opt out” of being able to use the services of bank-independent Third Party Providers (TPPs)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Dec 2018
- Reference
2018_4309Operation and security risk assessment of a branch of a credit institution
EBAEMI/PSDDoes a branch of an EU credit institution operating in another Member State have to prepare separate assessment for its payment related activity and if yes which competent authority shall be responsible for receiving the assessment - is it the competent authority of the host or the home Member State?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Dec 2018
- Reference
2018_4176Applicability of exemption from strong customer authentication (SCA) under Article 17 for card payments
EBAEMI/PSDIs Article 17 of Regulation (EU) 2018/389 applicable for the payer’s Payment service provider (PSP) for card-based payments?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Dec 2018
- Reference
2018_4239Interpretation of 'Active request for account information'
EBAEMI/PSDHow should 'active request for account information' by a Payment Service User (PSU) be interpreted the wording of article 36(5)(a)(b) of the RTS SCA?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Dec 2018
- Reference
2018_4172Major incidents reporting
EBAEMI/PSDMust Payment Service Providers (PSPs) submit major incident reports to their home National Competent Authority (NCA) when the cause of the major incident is outside the control of the PSP and when updates on the major incident are dependent on information provided by a third party?Where there is consolidated reporting of an incident to the EBA/ECB in the context of, for example, card payments schemes, is reporting of the major incident by PSPs to their NCA under PSD2 required?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Major incidents reporting
- Published
- 14 Dec 2018
- Reference
2018_4144Applicability of Strong Customer Authentication (SCA) to existing recurring payments solutions
EBAEMI/PSDIs Strong Customer Authentication (SCA) required if the series of recurring transactions was initiated before the date of application of the RTS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 14 Dec 2018
- Reference
2018_4048Criteria for the application of the transaction risk analysis (TRA) exemption – Fraud rate calculation methodology for the application of the TRA exemption
EBAEMI/PSDShould ‘friendly’ frauds be included in the “total value of unauthorised or fraudulent remote transactions” considered for the calculation of the fraud rates for the application of the TRA exemption?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 7 Dec 2018
- Reference
2018_4032Application of SCA when a PSU accesses payment transactions data older than on the last 90 days, without having access to sensitive payment data and for a period of 90 days after the last access using SCA
EBAEMI/PSDCould Payment Service Providers (PSPs) be allowed to choose between applying SCA(Strong Customer Authentication) or not when a PSU (Payment Service User) accesses payment transactions data older than on the last 90 days without having access to sensitive payment data and for a period of 90 days after its last access using SCA?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 9 Nov 2018
- Reference
2018_4177Persistent authentication for wearable devices
EBAEMI/PSDIs persistent authentication for wearable devices compliant with the RTS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4049Criteria for the application of the transaction risk analysis (TRA) exemption – Application of the TRA exemption at the level of individual brand, product or scheme
EBAEMI/PSDMay a PSP calculate its fraud rate at the level of individual brand, product or scheme?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4033Responsibility of national authority with regards to audit reports
EBAEMI/PSDShould all audit reports required under Article 3 of the RTS on strong customer authentication and secure communication be monitored by the competent national authorities?And, what are the consequences if the audit report addressing the audit (referred to in Article 3, paragraph 1 of the RTS) shows significant findings?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4155On the access to trusted beneficiaries lists (RTS Art 13) by TPPs in write mode
EBAEMI/PSDDo the TPPs have the right to access trusted beneficiaries lists in write mode?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4076Accessing payment account online in web browser shall exceed not 5 minutes without acitvity
EBAEMI/PSDIs it necessary to stop the complete web session or would it be enough to deactivate the relevant items of PSD2 and to reduce the display to the available balance so trading functionality in the same session can stay available?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4065EMV cards and EMV terminals supporting online authentication
EBAEMI/PSDIs there a need for Europay, MasterCard, Visa (EMV) cards and EMV terminals supporting online authentication in compliance with the RTS to support also offline authentication?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4052Criteria for the application of the transaction risk analysis (TRA) exemption – Application of the TRA exemption by authorized PSPs other than the issuer and the acquirer
EBAEMI/PSDMay an authorized PSP other than the issuer and acquirer apply the TRA exemption on the basis of its own fraud rate and risk analysis?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4035Review of the security measures: Audit report
EBAEMI/PSDShould the Audit for the implementation of the security measures be incorporated into an existing ISAE3402 report or COS3000 report or should a separate report be used?If a separate report should be used: Are there any templates available for reporting?Also, how detailed should the report be?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4152Review of Security Measures - Auditors expertise
EBAEMI/PSDAre internal auditors able to perform the audits as mentioned in paragraphs 1 and 2 of the RTS on strong customer authentication and secure communication?Is there a difference in the answer of this question between the audit as referred to in paragraph 1 and 2 of Article 3 of this RTS?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 26 Oct 2018
- Reference
2018_4153Obligatory nature of the SCA and exemption based on transaction risk analysis
EBAEMI/PSDDoes the exemption to the strong customer authentication (SCA) apply to any connection the payment service user (PSU) makes to his/her payment account(s), or only to the connections made through the use of third party processors (TPPs, such as AISPs or PISPs) via the interfaces (dedicated or not) set up by the bank with the TPPs, when a transaction risk analysis is performed and results on a low level of risk?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 19 Oct 2018
- Reference
2018_4089Does transaction monitoring need to be real time?
EBAEMI/PSDArticle 2(1) of the RTS stipulates that "payment service providers shall have transaction monitoring mechanisms in place that enable them to detect unauthorised or fraudulent payment transactions…" and Article 2(2) explains the minimum requirements.However, Article 2 does not specify timing aspects of the transaction monitoring.Is it correct to conclude that the transaction monitoring described in Article 2 does not need to be real time?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Oct 2018
- Reference
2018_4090Qualification of SMS OTP as an authentication factor
EBAEMI/PSDPlease clarify whether a One-Time Password (OTP) sent via SMS to a mobile phone qualifies as an ownership factor (“something only the user possesses”), and shall be subject to Article 7 of the RTS on strong customer authentication and secure communication.
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Oct 2018
- Reference
2018_4039Display of incorrect authentication factors in case of failed authentication attempts
EBAEMI/PSDFor remote card transactions, may the user be informed of the incorrect authentication factor in case of a failed authentication attempt provided this does not increase the risk of fraud (e.g. for in-app transactions)?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 5 Oct 2018
- Reference
2018_4041Application of the exemption for transactions to trusted beneficiaries to Face-to-Face transactions
EBAEMI/PSDMay the exemption for transactions to trusted beneficiaries (‘white-listing’) set out in Article 13 of Regulation (EU) 2018/389 (RTS on strong customer authentication and secure communication) apply to face-to-face transactions?
- Regulator
- EBA
- Regulation
- Directive (EU) 2015/2366 (PSD2)
- Topic
- Strong customer authentication and common and secure communication (incl. access)
- Published
- 21 Sep 2018
- Reference
2018_4056
No Q&As match your search and filters. Try a different keyword, regulator, theme or year — or Reset.
About these Q&As
- EBA Single Rulebook Q&As are the EBA’s formal answers on the EU banking, payments and crypto single rulebook. We include the legal acts that matter here: MiCAR (incl. ART/EMT issuers), PSD2, the E-Money Directive and DORA. Each shows the question, a short excerpt, topic, reference ID and date, and links to the official EBA Q&A.
- ESMA Q&As for MiCA (and the related DLT Pilot Regime) are published by ESMA as documents / on its Q&A platform — there is no machine-readable per-question feed — so they appear here as document-level pointers that link straight to the official ESMA Q&A. We do not reproduce them.
- A Q&A is the regulator’s interpretation of a specific question — it is not legislation and can be updated or withdrawn. Always read the official text. For who is licensed, see the CASP Licence Tracker; for crypto-asset white papers, the MiCA White-Paper Register.
Methodology & sources
- Data: the EBA Single Rulebook Q&A (parsed daily and filtered to MiCAR, PSD2, EMD and DORA) plus a curated set of official ESMA Q&A documents. Last successful EBA fetch: 25 Sep 2026.
- EBA — granular Q&As parsed from the EBA Single Rulebook Q&A tool (HTML; the EBA offers no JSON/CSV export). We never reproduce the full official answer (copyright) — only the question, a short excerpt and a link to the official Q&A. Dates are the EBA final-publication date (or submission date where not yet final).
- ESMA — document-level pointers to ESMA’s official Q&A platform and documents (e.g. the DLT Pilot Regime Q&A). ESMA platform entries are marked “continually updated”; we link out rather than mirror.
- HELMS commentary is interpretation, not part of the ESMA/EBA data, and not legal advice.
Official Q&As: EBA Single Rulebook Q&A ↗ · ESMA Questions & Answers ↗. HELMS is not affiliated with ESMA or the EBA.
Trying to apply a MiCA, e-money/PSD2 or DORA Q&A to your actual setup, and want it done right? HELMS maps the rule to your operating model, licence and finance function. Book a 30-min call.
Indicative reference, sourced from ESMA and the EBA — verify against the official Q&A before relying on it. A Q&A is the regulator’s view on a specific question, can be updated or withdrawn, and is not legal or financial advice.
