Introduction
The European Union (“EU”) is currently undergoing a significant reform within its payment services framework. This development is reflected in the proposed Third Payment Services Directive (“PSD3”) and the accompanying Payment Services Regulation (“PSR”), which are intended to address shortcomings identified under Directive (EU) 2015/2366, also known as the Second Payment Services Directive (“PSD2”) and to modernise the EU’s regulatory framework for payment services.
The European Union’s payment services framework provides the legal foundation for the regulation of payment services within the Single Market. It seeks to facilitate secure and efficient cross-border payments through promoting innovation whilst ensuring high levels of consumer protection and an increase in competition across Member States. As technological developments and consumer expectations continue to reshape the payments landscape, the proposed reforms seek to ensure that the regulatory framework remains capable of responding effectively to these developments.
The PSD2’s Impact on EU Payment Services
PSD2 which was adopted in 2015 and became applicable in 2018, marked a significant step towards modernising the EU payments landscape. By allowing authorised third-party providers (“TPP”) to access customers’ financial information with their consent, the Directive reduced the traditional dominance of banks over payment data and fostered greater innovation, competition and consumer choice.
PSD2 also laid the foundations for Account Information Services (“AIS”), enabling users to view information from multiple accounts in one place, and Payment Initiation Services (“PIS”), allowing payments to be initiated directly from a bank account without relying on traditional card networks. At the same time, PSD2 strengthened payment security through Strong Customer Authentication (“SCA”) and enhanced consumer protection by reducing liability for unauthorised transactions, improving transparency and addressing surcharges. Its scope was also extended to certain one-leg transactions and payments in non-EU currencies where at least one party is located within the European Economic Area (“EEA”), reflecting the increasingly cross-border nature of the modern payments market.
The Rapid Evolution of Digital Payments
Although PSD2 achieved notable success, particularly in establishing the foundations for open banking and strengthening payment security, its implementation also revealed several practical and regulatory shortcomings. These limitations were compounded by the rapid transformation of the payments sector following its adoption, including the growth of fintech providers, digital banking, cross-border payment solutions, contactless payments and digital wallets.
The development of open banking, in particular, exposed difficulties concerning the consistent and effective sharing of payment account data. At the same time, fraudstechniques, particularly social engineering, demonstrated the need for stronger safeguards. These developments highlighted the need to modernise and strengthen the existing framework, ultimately leading to the proposed introduction of PSD3 and the PSR.
How the PSD3 and the PSR Address the Shortcomings of PSD2
PSD3 and the PSR seek to build upon the foundations established by PSD2 while addressing the practical limitations that emerged during its implementation. A significant development is the greater harmonisation introduced through the PSR. As a regulation, the PSR will be directly applicable across Member States, reducing the legal fragmentation that arose from differing national implementations and interpretations of PSD2 and thereby enhancing legal certainty within the Single Market.
Although the PSD2 introduced open banking, which although it was successful in principle, lacked further legislative intervention which made it susceptible to technical barriers in practice. Its practical implementation was heavily reliant on third-party providers (“TPPs”) obtaining access to payment account information through Application Programming Interfaces (“APIs”) provided by account-servicing payment service providers. However, the PSD2 framework solely required the mere provision of APIs and did not create obligations concerning the quality, nor the consistency of such APIs. In its evaluation, the European Commission found that the lack of further legislative intervention led to a reality where some banks would only comply technically by providing APIs which were technically unreliable or difficult to integrate. Thus, the PSD3 through imposing detailed obligations regarding the quality of such APIs seeks to ensure that authorised third party providers are not put to a disadvantage and receive effective access to payment account data.
Another shortcoming of the PSD2 concerns the practical operation of the passporting, whereby although such legal right was provided for by the PSD2, Member states would sometimes adopt different supervisory approaches leading to legal uncertainty and administrative burdens, where instead of operating within a genuine Single Market businesses would effectively deal with conflicting regulatory systems. In response, the PSD3’s framework seeks to clarify the operation of passporting and strengthen consistency and cooperation between national competent authorities to support the genuine functioning of the Single Market.
A notable development by the PSD3 is derived from the finding that although the PSD2 sought to increase competition by creating a level playing field, traditional banks still retained advantages against non-bank Payment Service Providers (“PSPs”). This is due to the fact that although the PSD2 did introduce open banking, traditional banks would continue to exclusively benefit from direct access to the central payment system whilst, non-bank PSPs would have to depend on the bank as an intermediary to complete payments, accordingly, creating a situation where non-bank PSPs would essentially be depending on their own competitor for business. Thereby, to promote fairer competition within the European payments market, the PSD3 allows eligible non-bank PSPs that satisfy required criterion to access certain payment systems directly.
Through the Commission’s evaluation of the PSD2 it also became clear that the framework had become unnecessarily complex with several overlapping requirements imposed on payment institutions rather than having one clear obligation, thereby increasing compliance workload without essentially generating corresponding benefits. Another issue concerned unclear legislative wording where some provisions were so broadly drafted that its ambiguity would result in differing interpretations from one regulator to another which would consequently induce increased business costs on legal advice to determine the law’s objectives, thus discouraging market entry especially for smaller companies with fewer resources. The PSD3 therefore addresses such ambiguities by providing greater clarity regarding the legal obligations of payment service providers as well as greater harmonisation across the Member states through the Payment Services Regulation (PSR), thereby reducing national divergence. Compliance is also sought to become more proportionate through the PSD3 by consolidating supervisory and administrative requirements, hence removing excessive burdens and reducing compliance costs whilst maintaining more than adequate consumer protection standards.
Emerging fraud trends
Another significant limitation of PSD2 emerged from the evolution of fraud, particularly Authorised Push Payment (“APP”) fraud, where fraudsters manipulate consumers into authorising transactions themselves rather than bypassing SCA. Techniques such as impersonation, fake sellers and malware exploit human behaviour rather than weaknesses in authentication systems, creating gaps in consumer protection and liability under the existing framework. In response, PSD3 and the accompanying PSR propose enhanced fraud prevention and consumer protection measures, including Verification of Payee, stronger transaction monitoring, improved fraud warnings and awareness, greater information sharing between payment service providers, and clearer liability rules for certain impersonation and fraud scenarios.
The Policy Objectives Underpinning PSD3 and the PSR.
The introduction of PSD3 and the PSR reflects a broader objective of establishing a more coherent, modern and future-oriented regulatory framework capable of responding to the rapidly evolving payments landscape. The reforms seek to strengthen consumer protection through enhanced fraud prevention, greater transparency and clearer liability rules, while promoting innovation and fair competition by improving the operation of open banking and reducing structural barriers faced by non-bank PSPs.
The reforms also seek to strengthen the Single Market through greater harmonisation and legal certainty, while simplifying regulatory requirements and reducing unnecessary compliance burdens. Finally, PSD3 and the PSR aim to achieve a more effective balance between security and user experience, maintaining robust safeguards such as Strong Customer Authentication while reducing unnecessary friction in the payment process.
Conclusion
The transition from PSD2 to PSD3 and the PSR reflects the EU’s broader effort to ensure that its payment services framework remains aligned with technological innovation, evolving consumer expectations and emerging risks. While PSD2 established the foundations for open banking, stronger authentication and greater competition, its implementation exposed practical limitations in areas such as access to payment account data, regulatory harmonisation and fraud protection.
PSD3 and the PSR seek to address these shortcomings through a more harmonised, proportionate and technologically responsive framework, while strengthening consumer protection and promoting fair competition. For payment service providers, the reforms will therefore represent not only an evolution of the existing regulatory framework but also the introduction of new operational and compliance expectations. Ultimately, the success of the new framework will depend on its ability to maintain an appropriate balance between innovation, security and consumer protection, while ensuring that the EU’s payments market remains competitive and capable of adapting to future technological developments.
