PSD III: The Next Chapter in EU Payment Services Regulation

For a decade, the European payment services landscape has been defined by tension posed by the desire to open markets to innovation and competition, counterbalanced by the imperative to protect consumers and maintain financial stability. Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, which is also referred to as Payment Services Directive II (“PSD2”), was a bold experiment ushering in the era of open banking, empowering third-party providers, and demanding strong customer authentication. Yet, as often happens with ambitious experiments, its implementation exposed unintended consequences. Divergent national interpretations, inconsistent supervisory practices, and persistent operational risks revealed the limits of a framework that had relied heavily on the discretion of Member States.

With the introduction of the Proposal for a Directive of the European Parliament and of the Council on payment services and electronic money services in the Internal Market amending Directive 98/26/EC and repealing Directives 2015/2366/EU and 2009/110/EC (“PSD III”), rather than patching over the cracks of its predecessor, the European Commission has sought to rethink the architecture of payment services law entirely.

An important innovation under PSD III is the combination of a Directive and a directly applicable Regulation, a structure designed to provide both flexibility at the national level and consistency across the European Union. The Directive sets out the overarching legal framework for licensing, authorisation, and supervision, allowing national competent authorities, such as the Malta Financial Services Authority (“MFSA”) to continue exercising their supervisory powers over payment institutions and electronic money institutions (“EMIs”). It addresses matters such as who may operate as a PSP or EMI, governance requirements, internal controls, and national reporting obligations. The accompanying Regulation, by contrast, applies uniformly and automatically in all Member States. For Maltese institutions, this dual framework has significant implications while the MFSA retains its oversight role, operational practices, such as transaction monitoring, disclosure obligations, and customer authentication, it must comply with EU-wide standards, leaving less room for local adaptation. The combination therefore ensures legal certainty for cross-border operations, strengthens consumer protection, and establishes a predictable operational environment, while still preserving national supervisory authority over licensing and enforcement.

PSD III also confronts the persistent ambiguity around mixed-service institutions. The distinction between payment institutions and electronic money institutions (“EMIs”), which was once a source of regulatory uncertainty, is now rationalised, with licensing and supervision aligned to reflect the convergence of business models in practice. For an institution in Malta operating in both spheres, this means a careful reconsideration of governance structures, internal reporting lines, and compliance policies to ensure alignment with the new framework.

In conclusion, PSD III represents more than a regulatory update, it signals a profound shift in the governance of payment services across the European Union. Maltese institutions are no longer navigating a framework defined by national discretion alone, they must now align with harmonised EU standards while continuing to satisfy the MFSA’s oversight. This dual reality despite presenting challenges in operational alignment, risk management, and compliance, it also provides opportunities in building trust, demonstrating regulatory excellence, and positioning for cross-border growth.

For institutions seeking to understand the full impact of PSD III, ensure seamless compliance, or strategically adapt their governance, operational, and risk frameworks, specialised legal guidance is essential. Our team at Zerafa Advocates offers tailored advisory services, including licensing and regulatory compliance reviews, guidance on operational policies, fraud prevention strategies, and support for cross-border regulatory alignment