Payment Services Directive 2
Payment services licensing, conduct, open banking, strong customer authentication and secure communication obligations.
Sectors
Articles (117)
Article 56 — Information before execution of individual payment transactionsArticle 57 — Information for the payer on individual payment transactionsArticle 58 — Information for the payee on individual payment transactionsArticle 59 — Currency and currency conversionArticle 60 — Information on additional charges or reductionsArticle 61 — ScopeArticle 62 — Charges applicableArticle 63 — Derogation for low value payment instruments and electronic moneyArticle 64 — Consent and withdrawal of consentArticle 65 — Confirmation on the availability of fundsArticle 66 — Rules on access to payment account in the case of payment initiation servicesArticle 67 — Rules on access to and use of payment account information in the case of account information servicesArticle 68 — Limits of the use of the payment instrument and of the access to payment accounts by payment service providersArticle 69 — Obligations of the payment service user in relation to payment instruments and personalised security credentialsArticle 70 — Obligations of the payment service provider in relation to payment instrumentsArticle 71 — Notification and rectification of unauthorised or incorrectly executed payment transactionsArticle 72 — Evidence on authentication and execution of payment transactionsArticle 73 — Payment service provider’s liability for unauthorised payment transactionsArticle 74 — Payer’s liability for unauthorised payment transactionsArticle 75 — Payment transactions where the transaction amount is not known in advanceArticle 76 — Refunds for payment transactions initiated by or through a payeeArticle 77 — Requests for refunds for payment transactions initiated by or through a payeeArticle 78 — Receipt of payment ordersArticle 79 — Refusal of payment ordersArticle 80 — Irrevocability of a payment orderArticle 81 — Amounts transferred and amounts receivedArticle 82 — ScopeArticle 83 — Payment transactions to a payment accountArticle 84 — Absence of payee’s payment account with the payment service providerArticle 85 — Cash placed on a payment accountArticle 86 — National payment transactionsArticle 87 — Value date and availability of fundsArticle 88 — Incorrect unique identifiersArticle 89 — Payment service providers’ liability for non-execution, defective or late execution of payment transactionsArticle 90 — Liability in the case of payment initiation services for non-execution, defective or late execution of payment transactionsArticle 91 — Additional financial compensationArticle 92 — Right of recourseArticle 93 — Abnormal and unforeseeable circumstancesArticle 94 — Data protectionArticle 95 — Management of operational and security risksArticle 96 — Incident reportingArticle 97 — AuthenticationArticle 98 — Regulatory technical standards on authentication and communicationArticle 99 — ComplaintsArticle 100 — Competent authoritiesArticle 101 — Dispute resolutionArticle 102 — ADR proceduresArticle 103 — PenaltiesArticle 104 — Delegated actsArticle 105 — Exercise of the delegationArticle 106 — Obligation to inform consumers of their rightsArticle 107 — Full harmonisationArticle 108 — Review clauseArticle 109 — Transitional provisionArticle 110 — Amendments to Directive 2002/65/ECArticle 111 — Amendments to Directive 2009/110/ECArticle 112 — Amendments to Regulation (EU) No 1093/2010Article 113 — Amendment to Directive 2013/36/EUArticle 114 — RepealArticle 115 — TranspositionArticle 116 — Entry into forceArticle 117 — AddressesArticle 1 — Subject matterArticle 2 — ScopeArticle 3 — ExclusionsArticle 4 — DefinitionsArticle 5 — Applications for authorisationArticle 6 — Control of the shareholdingArticle 7 — Initial capitalArticle 8 — Own fundsArticle 9 — Calculation of own fundsArticle 10 — Safeguarding requirementsArticle 11 — Granting of authorisationArticle 12 — Communication of the decisionArticle 13 — Withdrawal of authorisationArticle 14 — Registration in the home Member StateArticle 15 — EBA registerArticle 16 — Maintenance of authorisationArticle 17 — Accounting and statutory auditArticle 18 — ActivitiesArticle 19 — Use of agents, branches or entities to which activities are outsourcedArticle 20 — LiabilityArticle 21 — Record-keepingArticle 22 — Designation of competent authoritiesArticle 23 — SupervisionArticle 24 — Professional secrecyArticle 25 — Right to apply to the courtsArticle 26 — Exchange of informationArticle 27 — Settlement of disagreements between competent authorities of different Member StatesArticle 28 — Application to exercise the right of establishment and freedom to provide servicesArticle 29 — Supervision of payment institutions exercising the right of establishment and freedom to provide servicesArticle 30 — Measures in case of non-compliance, including precautionary measuresArticle 31 — Reasons and communicationArticle 32 — ConditionsArticle 33 — Account information service providersArticle 34 — Notification and informationArticle 35 — Access to payment systemsArticle 36 — Access to accounts maintained with a credit institutionArticle 37 — Prohibition of persons other than payment service providers from providing payment services and duty of notificationArticle 38 — ScopeArticle 39 — Other provisions in Union lawArticle 40 — Charges for informationArticle 41 — Burden of proof on information requirementsArticle 42 — Derogation from information requirements for low-value payment instruments and electronic moneyArticle 43 — ScopeArticle 44 — Prior general informationArticle 45 — Information and conditionsArticle 46 — Information for the payer and payee after the initiation of a payment orderArticle 47 — Information for payer’s account servicing payment service provider in the event of a payment initiation serviceArticle 48 — Information for the payer after receipt of the payment orderArticle 49 — Information for the payee after executionArticle 50 — ScopeArticle 51 — Prior general informationArticle 52 — Information and conditionsArticle 53 — Accessibility of information and conditions of the framework contractArticle 54 — Changes in conditions of the framework contractArticle 55 — Termination
Controls that address this (16)
EU_PSD2-CTRL-001 - Daily safeguarding reconciliationoperational · critical priority · Daily reconciliation between safeguarded customer balances, core ledger balances and safeguarded bank accounts. Variances above EUR 100 mustEU_PSD2-CTRL-002 - Critical ICT incident reportingoperational · critical priority · All major ICT incidents impacting payment services, customer data or availability must be classified within 4 hours and reported under DORA EU_PSD2-CTRL-003 - GDPR breach notification workflowoperational · critical priority · Personal data breaches must be assessed within 12 hours and reported to the Belgian DPA within 72 hours where risk to data subjects exists.