PSD2 (PSD2)
PSD2, the Second Payment Services Directive, is the EU law governing payment services. It sets the authorization categories for payment firms, opened bank account access to licensed third parties, and required strong customer authentication for electronic payments.
Also called: Second Payment Services Directive
PSD2 replaced the original Payment Services Directive and did three things that still shape European payments. It set out the authorization categories and conduct rules for payment institutions. It obliged banks to let licensed third parties reach customer accounts with the customer’s consent, which is the legal foundation of open banking in Europe. And it required strong customer authentication for electronic payments and account access.
The access rules created two regulated roles alongside the older ones: account information service providers, which read account data, and payment initiation service providers, which instruct a payment from the customer’s own account. Both are authorized or registered activities, not free-for-all API use. Strong customer authentication means verifying the customer with two independent factors — something they know, something they have, something they are — with a defined set of exemptions for low-risk cases.
The UK and the EU are now separate
The UK implemented PSD2 while it was a member state, and those rules stayed in domestic law after Brexit, supervised by the Financial Conduct Authority. Changes made at EU level since then do not flow into UK law automatically, and UK changes do not flow the other way. A firm serving customers in both places must read each regime on its own terms rather than assuming one answer covers both.
In practice
PSD2 is a directive, so it binds member states rather than firms directly and takes effect through each state’s implementing law. The detail differs between states, and the UK regime has diverged since Brexit — so “PSD2 compliant” is not a single, portable standard.
Commonly confused with
| Term | How it differs |
|---|---|
| Open Banking | Open banking is the practice of sharing account access through APIs; PSD2 is the EU law that made banks permit it and set the conditions. |
| PSD3 and the Payment Services Regulation | These are European Commission proposals to succeed PSD2; until they take effect, PSD2 as implemented in each member state remains the law that applies. |
See also
- Open BankingOpen banking is regulated access to bank account data and to payment initiation through APIs, with the account holder’s consent. In the European Union and the United Kingdom it is a licensed activity under payment services law, not a private arrangement between a fintech and a bank.
- Payment InstitutionA payment institution is a firm authorized in the United Kingdom or a European Union member state to provide payment services — transfers, acquiring, remittance, payment initiation — but not to issue electronic money. It may hold customer funds in payment accounts used only for payment transactions; those funds are neither deposits nor e-money.
- Electronic Money InstitutionA firm authorized in the United Kingdom or in an EU member state to issue electronic money and to provide payment services. The e-money it issues is a claim its holders have against the institution, redeemable at par and expressly not a deposit, which is why the funds behind it must be safeguarded.
- PassportingPassporting is the mechanism by which a firm authorized in one EEA state may provide its services in the other EEA states without seeking separate authorization in each one. The home state regulator continues to supervise the firm throughout.
- SEPASEPA, the Single Euro Payments Area, is the set of schemes that makes a euro transfer between participating European countries work like a domestic one. It comes in credit transfer, instant credit transfer and direct debit variants.
Regulatory information checked: 22/Sep/2026
