European Banking Authority Seeks to Address Divergence on Use of Strong Customer Authentication Exemption

A&O Shearman
Contact

Shearman & Sterling LLP

The European Banking Authority is consulting on draft Regulatory Technical Standards to amend the existing RTS on strong customer authentication and common and secure open standards of communication under the EU Payment Services Directive (known as PSD2). Responses to the consultation may be submitted until November 25, 2021.

PSD2 requires payment service providers to apply SCA each time a customer accesses their payment account online. The existing RTS govern the process by which payment service providers authenticate the identity of customers and provide exemptions to the SCA requirements. One of the exemptions is available, on a voluntary basis, when a customer accesses limited payment account information, provided that SCA is applied for the first access and at least every 90 days subsequently. The EBA is proposing to make the exemption mandatory for PSPs where the account information is accessed through an account information service provider, subject to certain conditions being met to ensure the safety of the user's data. The exemption would remain voluntary when a user directly accesses the account information.

[View source.]

Written by:

A&O Shearman
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

A&O Shearman on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide