PDS2 (Payment Services Directive 2)
PSD2 (Payment Services Directive 2) is EU/UK regulation that governs electronic payments, introduces Strong Customer Authentication (SCA) and enables Open Banking.

PSD2 is the second Payment Services Directive. It is the EU law that reshaped how payments work across the region, and it did two big things. It made banks open up account access to licensed third parties, which is the legal basis of open banking. It also called for stronger checks on who is buying, which is why a bank app prompt now interrupts so many card payments. Between them, those two changes explain a great deal of what a modern checkout looks like.
The law is an EU one, and that scope matters. The UK kept the substance after leaving, through its own payment services rules, and Schedule 1 of those rules lists the regulated payment services. Other markets have their own rule sets, some alike and some not. A firm trading in several places cannot read one country's position across to another. What follows sets out the shape of it, not the detail in any one market.
Opening Up Account Access
Before the law, a bank account was a closed system. PSD2 set up licensed roles for firms that want in, with the customer's consent. One reads account data, and another starts payments from the account. That second role is what a payment initiation service provider plays. Banks have to offer a route for these firms and keep it working. That duty is what made open banking a product instead of a plan.
Checks That Prove Who Is Buying
The second pillar is the check on who is paying. Most online payments need two factors drawn from different groups: something the customer knows, something they hold, or something they are. That is strong customer authentication. It is the reason a bank app prompt, or a code, became a normal part of buying online. A password plus a code sent to a phone works. Two passwords do not, since both sit in the same group.
Where The Detail Actually Lives
The law sets the principles, and the working detail sits in technical standards beneath it, which are usually more use to read than the law itself. The regulatory technical standards cover what counts as a valid code, when a check can be skipped, and what banks must offer third parties. Article 30 of those standards sets out the duties on that access route: banks must publish the technical detail free of charge, and they must give notice before changing it.
The Carve-Outs Matter
Not every payment needs a full check, and using the carve-outs well is a large part of running a good checkout. Smaller payments can qualify, and so can some repeat payments, trusted payees, and payments judged low risk. Each comes with conditions. Those conditions and figures are written into the standards. They are revised from time to time, and they differ by market. Using an SCA exemption well means knowing which one applies, and who carries the risk when it is used.
What It Meant For Merchants
Three effects show up in practice. Checkout gained a step for many payments, which cost some sales and cut some fraud. Risk moved as well. Where a payment is properly checked, fraud risk tends to shift towards the bank that issued the card. Rules vary by card network and get updated from time to time, so merchants should confirm the current ones with their acquirer or the card scheme. And a new set of options appeared, since bank based payments became something a shop could offer directly.
Licensing And Who Needs It
The law also set out who must hold a licence to offer payment services. That catches more firms than people expect, marketplaces and platforms that hold funds for others among them. An electronic money institution is one common licence type here, and whether a given model needs one depends on the structure and on the market, which makes it a question for advisers and not a rule of thumb.
What Changed For Shoppers
From the customer's side the shift was simple and not welcome to everyone. Buying online gained a step. A code, an app prompt or a fingerprint now sits between the basket and the receipt. Most people adjusted quickly, and the friction is lower where banks use an app instead of a text message. The gain is harder to see, because fraud that did not happen leaves no trace. That is the usual shape of it: the cost shows and the benefit does not.
Living With It Across Markets
Local jurisdiction is the theme that keeps coming back. Limits differ. Carve-out treatment differs, and the way rules get enforced differs too, so a rule that is settled in one country may still be moving in another. Firms that keep a per-market view of what applies tend to have fewer surprises, since one global setting seldom survives contact with local law. It also helps to date any internal guidance. The standards get revised, and an undated note goes wrong without warning.
Working Through It Market By Market
Work out which markets you actually trade in and what applies in each. Get the identity check path working cleanly before tuning it. Learn the carve-outs, and track which ones your provider uses on your behalf. Watch how many shoppers finish a challenge as closely as you watch approval rate. And treat bank based payments as an option to test, not a threat to cards. Open banking payments covers that side, and this guide on whether a business is ready for open banking is a sensible first read.
Frequently Asked Questions
The directive itself is EU law, and the UK kept the substance after leaving through its own payment services rules. The two have not moved in lockstep since, so the practical answer depends on which market a business operates in. Anyone trading in both needs to track them separately rather than assume they match.
Account access and authentication. Licensed third parties gained a route into bank accounts with the customer's consent, which is the legal basis of open banking. And most electronic payments gained a requirement for two independent identity factors, which is why a bank app prompt became a normal part of buying online.
In technical standards beneath the directive rather than in the directive itself. Those standards cover what counts as an authentication code, when a check may be skipped, and what banks must offer third parties. Reading them is usually more useful than reading the directive, since that is where the operational rules sit.
In defined cases, yes. Lower value payments, certain repeat payments, trusted payees and payments assessed as low risk can all qualify subject to conditions. Those conditions and figures are written into the standards, revised from time to time, and differ by market, so the version in force locally is the one to work from.
It depends on the structure and the market. The rules catch more businesses than people expect, particularly those that hold funds on behalf of others. Whether a given model requires authorisation, and which licence type fits, is a question for advisers rather than something that can be settled from a general description.

Still Have Questions?
Let’s Find the Right Solution for You
Stay Connected with Us!
Follow us on social media to stay up to date with the latest news, updates, and exclusive insights!


