What PSD2 is and how it affects your online payments
PSD2 is one of those European rules that almost nobody has read, but that applies every time you confirm an online payment with your phone, authorise an app to read your account activity or dispute a charge you do not recognise. It is the basis of the current rules for electronic payments in the European Union, and in 2026 it begins to be renewed through PSD3 and the new Payment Services Regulation.
What PSD2 is and when it came into force
The PSD2 Directive (Directive (EU) 2015/2366) was approved in November 2015 and came into force in January 2016. It replaced the first Payment Services Directive of 2007, which could no longer respond to a market shaped by mass online banking, growing e-commerce and new fintech companies operating outside the traditional banking perimeter. Member States had until 13 January 2018 to transpose it into national law, and strong authentication for online purchases became fully enforceable across the EU from 31 December 2020, following the extension set by the European Banking Authority (EBA).
Its objective was not to create a new technology, but to organise the electronic payments market across the European Union around three principles: strengthening the security of online transactions, opening the banking sector to new players (fintechs, payment platforms, aggregators) and improving consumer protection against fraud. Before PSD2, each country applied different rules and each bank imposed its own conditions without a common framework.
The rule applies to all payment service providers operating in the EU: banks, electronic money institutions such as the one that issues Bitsa, payment gateways, open banking fintechs and card issuers.
Strong authentication when paying online
One of the most visible changes for users is strong authentication, technically known as SCA (Strong Customer Authentication). PSD2 requires online payments to be confirmed with at least two independent factors from three categories: something you know (a password or PIN), something you have (a mobile phone or token) and something you are (fingerprint or face recognition).
That is why today, when you buy from an online store for more than €30, you receive a confirmation on your phone, an SMS code or biometric validation in your banking app. This process combines the 3D Secure standard with the card issuer’s own authentication systems. At Bitsa, every online transaction goes through the 3D Secure protocol with in-app confirmation before being charged to the card balance.
There are specific exemptions: payments under €30, purchases from whitelisted trusted merchants, certain recurring payments or low-risk charges detected by the issuer. Outside those cases, two-factor authentication is the rule, not the exception.
Open Banking and third-party access to your banking data
The other major change introduced by PSD2 is Open Banking. Under this rule, banks are required to share your account data with authorised third parties if you give your consent. That third party may be a personal finance management app, a loan comparison platform, an accounting tool or even a merchant that wants to initiate a payment without going through the traditional payment gateway.
In practice, PSD2 recognises two new roles. AISPs (Account Information Service Providers) read information from your accounts to bring it together in a single app or offer personalised services. PISPs (Payment Initiation Service Providers) execute payments on your behalf directly from your account, without needing a card or an additional intermediary. In both cases, access requires your explicit authorisation and is channelled through APIs regulated by the bank.
For users, this means more control over their data, more competition in the sector and apps that bring accounts from different banks together on a single screen. It also opens the door for electronic money institutions such as Bitsa to operate under a European licence, without depending on bilateral agreements with each bank.
Consumer protection against fraud
PSD2 tightens the liability of the payment service provider when an unauthorised charge occurs. If you report a payment you do not recognise, the entity must refund the amount immediately, unless it can prove gross negligence on your part, for example, knowingly sharing your credentials.
In addition, the user’s maximum liability for unauthorised transactions is limited to €50, and it does not apply if the fraud takes place after you have notified the provider that the card has been stolen or lost. This applies equally to credit cards, debit cards and a prepaid wallet card, as long as the issuer is regulated in the EU.
For users, this has meant a real change. Before PSD2, many claims for unauthorised charges could remain unresolved for weeks, and the burden of proof fell on the cardholder. Now, except in clear cases, reimbursement is the starting point and the investigation comes afterwards.
From PSD2 to PSD3
In November 2025, the European Parliament and the Council reached a political agreement on the new PSD3 (Payment Services Directive 3) and the Payment Services Regulation (PSR). The final compromise text was published in April 2026, and its effective entry into force is expected in 2027, after a 21-month transposition period from publication in the Official Journal of the EU.
The planned changes do not rewrite the logic of PSD2. They correct its weak points. The four most relevant are: mandatory verification of the beneficiary’s name against the IBAN before executing any transfer (Verification of Payee), extension of fraud refunds to identity impersonation cases, the unification of payment institutions and electronic money institutions under a single regulatory category, and real harmonisation between countries through a directly applicable regulation, instead of a directive that each Member State adapts in its own way.
For users, the biggest difference will be protection against impersonation fraud (for example, fake bank calls that today often fall into a legal grey area) and stronger transfer security, with verification of the account holder before the money leaves.
PSD2 has been shaping how online payments work in the European Union for almost eight years. Its real role is not only technical. It defines who is responsible when something goes wrong, who can access your data and under what conditions. With PSD3 on the way, that perimeter is about to expand.
FAQs – frequently asked questions
Where does PSD2 apply?
PSD2 applies across the 27 EU Member States and the three EEA countries (Iceland, Liechtenstein and Norway). Each country had to transpose the Directive into national law by 13 January 2018. All banks, electronic money institutions, fintechs and payment service providers operating in the EU or EEA are subject to it, regardless of where they are headquartered.
What is Strong Customer Authentication (SCA)?
It is the mechanism required by PSD2 to confirm online payments. It requires combining at least two independent factors from these three categories: knowledge (password), possession (mobile phone or token) and biometrics (fingerprint or face recognition). It is what triggers in-app confirmations or SMS codes when you make a purchase.
Do all online payments require two-factor authentication?
No. PSD2 allows exemptions for payments under €30, certain recurring payments, transactions marked as low-risk by the issuer and merchants added by the user to a whitelist. Outside those cases, two-factor authentication is mandatory.
What is Open Banking under PSD2?
It is the framework that requires banks to share your account data with authorised third parties if you give your consent. It enables services such as account aggregators, financial management apps or platforms that initiate payments without going through a card or the usual payment gateway.
When does PSD3 come into force?
The political agreement on PSD3 and the new Payment Services Regulation (PSR) was reached in November 2025. The final compromise text was approved in April 2026, and effective entry into force is expected in 2027, with a 21-month transposition period from its publication in the Official Journal of the EU.
What happens if I am charged for a payment I do not recognise?
Under PSD2, you should notify your card issuer or bank as soon as possible. The entity is required to refund the amount unless it proves gross negligence on your part. In addition, the user’s maximum liability for unauthorised transactions is limited to €50, and does not apply if you had already notified the theft or loss of the card.