What Is PSD2 Compliance? Key Rules for Businesses
Learn what PSD2 compliance means, why it matters, and how businesses can meet SCA, open banking, transparency, and consumer protection rules.
What PSD2 Compliance Means
PSD2 compliance means meeting the EU rules for safer, fairer payment services. PSD2 stands for Payment Services Directive 2. It applies to banks, payment firms, online sellers, and other payment service providers.
The directive aims to cut payment fraud and open the market to new firms. It also gives customers more control over account data. In simple terms, businesses must protect payments, explain fees, and follow set customer rights.
PSD2 took effect across the European Union through national laws. Each country may set its own enforcement process. The core duties remain much the same across the EU.
The full legal text appears in the Payment Services Directive 2. It sets the main duties for firms and payment providers.
Why the EU Introduced PSD2
Online payments grew fast after the first payment services rules. New risks grew with them. PSD2 updates those rules for digital commerce and mobile banking.
Its first goal is stronger payment security. The directive uses strong customer authentication for many online payments. This check asks for two separate forms of proof.
Its second goal is more choice. Banks must support safe access for approved third-party providers. This model supports open banking PSD2 services.
- Lower fraud risk for online payments
- More choice between payment providers
- Clearer fees and payment terms
- Better rights when a payment goes wrong
- More room for useful financial tools
Competition can also put pressure on poor service and high fees. Customers may gain faster account tools and more payment options. Firms must still protect data and ask for clear consent.
The Main Parts of PSD2
Strong customer authentication is one of PSD2's best-known rules. It uses two factors from separate groups. These groups are something the customer knows, owns, or is.
A password counts as something the customer knows. A phone or hardware token may count as something the customer owns. A fingerprint may count as something the customer is.

The two factors must work together. A stolen password should not be enough to approve a risky payment. Some payments may qualify for an exemption based on risk, value, or payment type.
PSD2 also supports access by third-party providers. Account Information Service Providers can show account data in one place. Payment Initiation Service Providers can start payments with customer approval.
These providers need permission before they access an account. Banks must provide a secure way to connect. Customers can withdraw consent and should know what data they share.
PSD2 Compliance Requirements for Businesses
Businesses should first map every payment journey. List the buyer, payment firm, bank, and data flows. Mark where the firm stores, sends, or views payment data.
Next, check which rules apply to each journey. Online sellers may rely on a payment provider for SCA. They still need clear customer notices and sound records.
- Review payment flows. Find every route for card, bank, and account payments.
- Check SCA controls. Confirm that the payment flow can request two valid factors.
- Test exemptions. Record why a payment avoided an extra check.
- Check provider contracts. Set duties for fraud, outages, data, and complaints.
- Run audits. Test access, logs, consent records, and incident plans.
- Train staff. Teach teams how to handle payment errors and customer questions.
Technical work may include secure application links, access logs, and fraud checks. Firms should limit access to the data each worker needs. They should also patch systems and test weak points often.
Customer messages need care. Explain why a second check appears and what the customer should do. Avoid wording that makes a security check look like a scam.
Keep proof of key checks and decisions. Auditors may ask for test results, risk records, and consent logs. Good records can shorten reviews and help teams fix gaps.
How PSD2 Changes Financial Services
PSD2 changed the role of banks and payment firms. Banks now need secure channels for approved third-party access. Payment firms must work across a more connected market.
That change has helped account tools, payment apps, and new lending services grow. A customer may view several accounts through one trusted service. A business may start a bank payment without sending a customer away.

Cross-border payments can also become easier to manage. Firms can serve customers in more EU markets through shared rules. Local law and licensing duties still matter.
Payment providers now share more responsibility for fraud and service failure. They must explain payment status and handle complaints. Clear roles matter when several firms touch one payment.
| Area | What changes | What firms should check |
|---|---|---|
| Security | More payment checks may apply | SCA, fraud tools, and fallback paths |
| Data access | Approved TPPs may connect with consent | Access scope, consent, and records |
| Customer rights | Rules cover fees, refunds, and fraud | Terms, notices, and complaint handling |
| Market access | New firms can offer payment services | Licences, contracts, and risk controls |
Benefits for Businesses and Customers
Strong checks can reduce losses from stolen payment details. They can also build trust with buyers. A safer payment flow may support repeat sales.
Open banking can cut steps for some customers. It may offer faster account checks and direct bank payments. Firms can gain new ways to tailor useful services.
Clear fee rules help customers compare services. They also force firms to review hidden costs. Better notices can reduce disputes and support fair treatment.
- Lower fraud and chargeback risk
- More payment choices for customers
- Faster access to account-based services
- Clearer pricing and payment terms
- New routes for financial innovation
These gains depend on good design. A hard or confusing check can cause failed sales. Firms should track both fraud rates and successful payment rates.
Common Challenges of PSD2 Compliance
The main challenge is balancing security with a smooth checkout. Extra checks can slow a payment or fail on an old phone. Firms need backup routes for lost devices and weak connections.
Another challenge is shared responsibility. A seller may use one firm for cards and another for bank payments. Contracts must state who handles fraud, outages, records, and complaints.
Data access creates another risk. A TPP may need account data for one task. The firm should not grant broad access without a clear reason.
Rules can also vary through local laws and regulator guidance. A business that serves several EU states needs a country-by-country check. It should ask legal counsel about its exact service model.
What happens if a business falls short?
Regulators can order fixes, restrict services, or issue fines. Penalties depend on the country, breach, and firm. Some national regimes may allow fines of up to four percent of annual revenue.
That figure is not a single EU-wide fine for every breach. The real cost may also include refunds, legal work, lost sales, and harm to trust. Firms should treat PSD2 as an ongoing control task.
A Practical PSD2 Compliance Plan
Start with a gap review. Compare each payment journey with the rules for SCA, data access, fees, and fraud. Rank gaps by customer harm and payment risk.
Build a written plan with owners and dates. Include product, security, legal, support, and finance teams. Review the plan after major system or provider changes.
Use live tests, not only policy checks. Try failed codes, lost devices, revoked consent, and duplicate payments. Record the result and fix weak steps.
Review performance each month. Useful measures include failed checks, fraud loss, complaint time, and payment approval rates. These figures show whether controls work without blocking good customers.
PSD2 compliance is not a one-time project. It is a set of payment, data, and customer care controls. A clear owner and regular testing make the work far easier.
Frequently asked questions
- What is PSD2 compliance?
- PSD2 compliance means meeting EU rules for payment security, customer rights, fees, and data access. It affects banks, payment firms, online sellers, and other payment providers.
- What is strong customer authentication under PSD2?
- Strong customer authentication uses two separate proof factors. These factors come from knowledge, possession, or inherence, such as a password and phone.
- Does PSD2 require banks to share customer data?
- Banks must support approved third-party providers when customers give consent. Access should match the agreed service and should not exceed its need.
- Who must follow PSD2 compliance requirements?
- Banks, payment institutions, electronic money firms, and many businesses involved in payments may have duties. The exact duties depend on the service and country.
- What are the penalties for PSD2 non-compliance?
- Penalties depend on national law and the breach. They may include orders to fix problems, service limits, refunds, and large fines.
Related reading
Can a Buyer Back Out After the Due Diligence Period?
Learn when a buyer can withdraw and what the contract may cost.
Regulatory Compliance: A Practical Guide for Organizations
Understand the rules, risks, and steps behind strong regulatory compliance.
Reg Z Compliance Explained: Rules, Duties, and Consumer Rights
A clear guide to Reg Z rules, lender duties, and consumer rights.