Skip to main content
European Banking Authority logo
  • Extranet
  • Log in
  • About us
    Back

    About us

    The EBA is an independent EU Authority.  We play a key role in safeguarding the integrity and robustness of the EU banking sector to support financial stability in the EU.

    Learn more
      • Mission, values and tasks
      • Organisation and governance
        • Governance structure and decision making
        • EBA within the EU institutional framework
        • Internal organisation
        • Accountability
      • Legal and policy framework
        • EBA regulation and institutional framework
        • Compliance with EBA regulatory products
      • Sustainable EBA
      • Diversity and inclusion
      • Careers
        • Meet our team
        • Vacancies
      • Budget
      • Procurement
    Close icon
  • Activities
    Back

    Activities

    To contribute to the stability and effectiveness of the European financial system, the EBA develops harmonised rules for financial institutions, promotes convergence of supervisory practices, monitors, and advises on the impact of financial innovation and the transition to sustainable finance.

    Start here
      • Single Rulebook
      • Simplification and efficiency
      • Implementing Basel III in Europe
      • Supervisory convergence
        • Supervisory convergence
        • Supervisory disclosure
        • Peer Reviews
        • Mediation
        • Breach of Union Law
        • Colleges
        • Training
      • Direct supervision and oversight
        • Markets in Crypto-assets
        • Digital operational resilience Act
        • Validation of pro forma-initial margin models
      • Information for consumers
        • National competent authorities for consumer protection
        • How to complain
        • Personal finance at the EU level
        • Warnings
        • Financial education
        • National registers and national authorities responsible for handling complaints related to credit servicers
        • Frauds and scams
      • Research Workshops
      • Ad hoc activities
        • Our response to Covid-19
        • Brexit
    Close icon
  • Risk and data analysis
    Back

    Risk and data analysis

    To ensure the orderly functioning and stability of the financial system in the European Union, we monitor and analyse risks and vulnerabilities relevant for the regulation of banks and investment firms. We also facilitate information sharing among authorities and institutions through supervisory reporting and data disclosure.

    Learn more
      • European Data Access Portal (EDAP)
      • Risk analysis
        • EU-wide stress testing
        • EU wide transparency exercise
        • Risk monitoring
        • Thematic analysis
      • Remuneration and diversity analysis
      • Pillar 3 data hub
        • Access to P3DH
      • Reporting
        • Reporting frameworks
        • Reporting Time Traveller
        • DPM data dictionary
        • Integrated reporting
        • Joint Bank Reporting Committee (JBRC)
      • Data
        • Registers and other list of institutions
        • Guides on data
        • Aggregate statistical data
        • Secondary reporting: data from Competent Authorities to the EBA
        • Data analytics tools
    Close icon
  • Publications and media
    Back

    Publications and media

    Communicating to all our audiences in the most effective way and using the most appropriate channels is crucial for us. Through our publications, announcements, and participation in external events, we are committed to reaching out to all our stakeholders to report about our policies, activities, and initiatives.

    Learn more
      • Publications
        • Guidelines
        • Regulatory Technical Standards
        • Implementing Technical Standards
        • Reports
        • Consultation papers
        • Opinions
        • Decisions
        • Staff papers
        • Annual reports
      • Press releases
      • Speeches
      • Interviews
      • Events
      • Media centre
        • Factsheets
        • Media gallery
        • Media resources
    Close icon

Breadcrumb

  1. Home
  2. Single Rulebook Q&A
  3. 2025_7608 Obstacle assessment of an ASPSP offering only web redirection to TPPs while a superior native app authentication method exists for its direct users
Question ID
2025_7608
Legal act
Directive 2015/2366/EU (PSD2)
Topic
Strong customer authentication and common and secure communication (incl. access)
Article
Article: 98
Paragraph
Paragraph: 1
Subparagraph
Letter: d)
COM Delegated or Implementing Acts/RTS/ITS/GLs/Recommendations
Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication
Article/Paragraph
Article: 32; Paragraph: 3
Name of institution / submitter
ZNPay a.s.
Country of incorporation / residence
Czech Republic
Type of submitter
Other
Subject matter
Obstacle assessment of an ASPSP offering only web redirection to TPPs while a superior native app authentication method exists for its direct users
Question

Does an Account Servicing Payment Service Provider's (ASPSP) decision to offer only a web-based redirection for Third Party Provider (TPP) initiated journeys constitute an obstacle under Article 32(3) of the RTS, if that ASPSP also makes available a more convenient, direct authentication procedure in its native mobile application for its Payment Service Users (PSUs) when they access their accounts directly?

Background on the question

We acknowledge that the EBA Opinion on obstacles (EBA/OP/2020/10), specifically in paragraph 16(i), establishes a clear principle for mobile journeys: where a PSU uses a TPP's app and the ASPSP has an authentication app, the PSU should be redirected to the ASPSP's authentication app.

However, an interpretive gap arises in practice. Many ASPSPs, while possessing a fully functional native mobile authentication app which provides a seamless experience for their direct users, deliberately do not make this app-to-app redirection path available for TPP-initiated journeys. Instead, they offer only a web-based redirection path for TPPs. These ASPSPs do not technically block their app, but they fail to implement the necessary technical means (e.g., universal links, app links) for the app-to-app redirect to function for the TPP channel, effectively forcing all TPP traffic through an inferior web-based channel.

The ambiguity lies in whether an ASPSP fulfills its obligations under the RTS by simply providing any compliant channel (the web redirect), or if it must provide the best and most equivalent channel (the native app journey) that it makes available to its own users for similar actions.

This situation leads to a fragmented market and a significant competitive disadvantage for TPPs. Therefore, a clarification is needed from the EBA.

Submission date
17/10/2025
Rejected publishing date
11/05/2026
Rationale for rejection

This question has been rejected because EBA guidance or clarification is not needed. The question has already been adressed in paragraph 16 of the EBA Opinion on obstacles (EBA/OP/2020/10).

Status
Rejected question

Footer

EUROPEAN BANKING AUTHORITY

Our mission is to contribute to the stability and effectiveness of the European financial system through simple, consistent, transparent, fair regulation and supervision that benefits all EU citizens.


UE logoAn agency of the EU

EU Agencies Network logoEU Agencies Network

EMAS logoSustainable EBA

Contact us

  • Contacts
  • Ask a general question
  • Send a press query
  • Ask a regulatory question
  • Request access to documents
  • File a complaint
  • Whistleblower reports

Stay up to date with our work

  • Subscribe to our email alerts
  • News & press RSS feed

Follow us on Social media

  • Bluesky
  • LinkedIn
  • X
  • YouTube

Find out about us

  • The EBA at a glance
  • Privacy policy
  • Legal notice
  • Cookies policy
  • Frauds and scams

Explore related sites

  • EIOPA
  • ESMA
  • ESRB
  • CEBS archive