PSD2
Published on
02/10/2026
Updated on
02/10/2026
Reading time
2 min
As of 2 October 2026
Definition
PSD2 (the Payment Services Directive, Directive (EU) 2015/2366) is the legal framework that has shaped European payments since 2018. It replaced the first Payment Services Directive of 2007 and governs who may provide payment services, how payments are authorised and what rights customers have in the process.
The most common misconception: PSD2 is a directive, not a regulation. It does not apply directly, but through the law of the Member States – in Germany through the Payment Services Supervision Act and sections 675c ff. of the Civil Code. Anyone looking to settle a legal question therefore ends up at the national text, not at the directive.
Timeline and status
The directive entered into force on 12 January 2016 and applied from 13 January 2018. The technical rules are not in the directive itself but in Delegated Regulation (EU) 2018/389 – the regulatory technical standards on strong customer authentication and secure communication. They have applied since 14 September 2019.
PSD2 is being replaced by the package of PSD3 and the PSR. Until its deadlines bite, PSD2 and the technical standards remain the basis of what institutions implement.
Third-party access to the account
The most visible part of PSD2 is the entitlement of licensed third parties to access the payment account – with the customer’s consent and without a contract with the account-servicing bank. The directive created two new payment services for this and gave a third type of provider a right of access:
- Account information service – reads transactions and balances, for multibanking or budgeting, for example
- Payment initiation service – triggers a credit transfer from the customer’s account without holding the money itself
- Card issuer that does not hold the account – issues a card that draws on an account held at another institution and, before the payment, obtains no more than a yes-or-no confirmation that the amount is available
For this the bank provides a dedicated interface and identifies itself to the third party with certificates under eIDAS – the QWAC for the connection and the seal certificate for the data.
Strong customer authentication
A payment is only released once the customer supplies two out of three independent elements: knowledge (a PIN, for instance), possession (a device, for instance) and inherence (a fingerprint, for instance). Independent means that the breach of one element does not compromise the reliability of the others.
The technical standards allow exemptions, for low-value amounts, recurring payments to the same payee, payees the customer has registered, and procedures with a low fraud rate. The exemption is a right of the bank, not an obligation, and it shifts liability.
What PSD2 brought customers
Alongside authentication, the directive governs liability for unauthorised payments with a limited excess borne by the customer, prohibits surcharges on card and credit transfer payments across much of the market, and sets deadlines for execution.