Skip to main content
European Banking Authority logo
  • Extranet
  • Log in
  • About us
    Back

    About us

    The EBA is an independent EU Authority.  We play a key role in safeguarding the integrity and robustness of the EU banking sector to support financial stability in the EU.

    Learn more
      • Mission, values and tasks
      • Organisation and governance
        • Governance structure and decision making
        • EBA within the EU institutional framework
        • Internal organisation
        • Accountability
      • Legal and policy framework
        • EBA regulation and institutional framework
        • Compliance with EBA regulatory products
      • Sustainable EBA
      • Diversity and inclusion
      • Careers
        • Meet our team
        • Vacancies
      • Budget
      • Procurement
    Close icon
  • Activities
    Back

    Activities

    To contribute to the stability and effectiveness of the European financial system, the EBA develops harmonised rules for financial institutions, promotes convergence of supervisory practices, monitors, and advises on the impact of financial innovation and the transition to sustainable finance.

    Start here
      • Single Rulebook
      • Simplification and efficiency
      • Implementing Basel III in Europe
      • Supervisory convergence
        • Supervisory convergence
        • Supervisory disclosure
        • Peer Reviews
        • Mediation
        • Breach of Union Law
        • Colleges
        • Training
      • Direct supervision and oversight
        • Markets in Crypto-assets
        • Digital operational resilience Act
        • Validation of pro forma-initial margin models
      • Information for consumers
        • National competent authorities for consumer protection
        • How to complain
        • Personal finance at the EU level
        • Warnings
        • Financial education
        • National registers and national authorities responsible for handling complaints related to credit servicers
        • Frauds and scams
      • Research Workshops
      • Ad hoc activities
        • Our response to Covid-19
        • Brexit
    Close icon
  • Risk and data analysis
    Back

    Risk and data analysis

    To ensure the orderly functioning and stability of the financial system in the European Union, we monitor and analyse risks and vulnerabilities relevant for the regulation of banks and investment firms. We also facilitate information sharing among authorities and institutions through supervisory reporting and data disclosure.

    Learn more
      • European Data Access Portal (EDAP)
      • Risk analysis
        • EU-wide stress testing
        • EU wide transparency exercise
        • Risk monitoring
        • Thematic analysis
      • Remuneration and diversity analysis
      • Pillar 3 data hub
        • Access to P3DH
      • Reporting
        • Reporting frameworks
        • Reporting Time Traveller
        • DPM data dictionary
        • Integrated reporting
        • Joint Bank Reporting Committee (JBRC)
      • Data
        • Registers and other list of institutions
        • Guides on data
        • Aggregate statistical data
        • Secondary reporting: data from Competent Authorities to the EBA
        • Data analytics tools
    Close icon
  • Publications and media
    Back

    Publications and media

    Communicating to all our audiences in the most effective way and using the most appropriate channels is crucial for us. Through our publications, announcements, and participation in external events, we are committed to reaching out to all our stakeholders to report about our policies, activities, and initiatives.

    Learn more
      • Publications
        • Guidelines
        • Regulatory Technical Standards
        • Implementing Technical Standards
        • Reports
        • Consultation papers
        • Opinions
        • Decisions
        • Staff papers
        • Annual reports
      • Press releases
      • Speeches
      • Interviews
      • Events
      • Media centre
        • Factsheets
        • Media gallery
        • Media resources
    Close icon

Breadcrumb

  1. Home
  2. Single Rulebook Q&A
  3. 2025_7678 Clarification on the use of PSU-linked tokens in payment initiation services under the RTS
Question ID
2025_7678
Legal act
Directive 2015/2366/EU (PSD2)
Topic
Other topics
Article
n.a.
Paragraph
n.a.
Subparagraph
n.a.
COM Delegated or Implementing Acts/RTS/ITS/GLs/Recommendations
Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication
Article/Paragraph
5, 30 and 36
Type of submitter
Other
Subject matter
Clarification on the use of PSU-linked tokens in payment initiation services under the RTS
Question

In the context of payment initiation services, we would appreciate clarification from the EBA as to whether an ASPSP may require a PISP to use a specific token replacing the PSU’s online banking credentials, and whether such token must be reused by the PISP across the different stages of the payment order, in particular at the payment initiation stage and for subsequent query following the execution of the payment order. Furthermore, we would welcome clarification on the conditions under which this practice would be compatible with the provisions of Commission Delegated Regulation (EU) 2018/389.

Background on the question

Some ASPSPs, following the initial authentication of the PSU, issue tokens that are persistently linked to a specific PSU rather than being tied to a specific payment order. This operational approach raises significant security risks and introduces unnecessary operational complexity for PISPs, as it requires them to store and manage such tokens for reuse in subsequent stages of the payment initiation process and to transmit them in successive interactions with the ASPSP.

From the perspective of Commission Delegated Regulation (EU) 2018/389, this practice is particularly problematic, as authentication mechanisms and personalised security credentials are required to be strictly linked to a specific payment transaction, including its amount and payee, in accordance with the dynamic linking principle set out in Article 5. In this respect, the issuance of long-lived tokens linked to the PSU, rather than to a specific payment order, may undermine the requirements for Strong Customer Authentication (SCA), as it enables the initiation of new payment orders on behalf of the PSU, during the validity period of the token, without the PSU being required to undergo a new strong authentication process.

Furthermore, the use of tokens that, in practice, replicate the functionality of the PSU’s online banking credentials may conflict with Articles 30 and 36 of the Delegated Regulation, insofar as it facilitates ongoing access or the initiation of payment transactions without transaction-specific authentication and without the explicit involvement of the PSU. This increases the risk of misuse, weakens the PSU’s control over payment transactions, and may be considered incompatible with the security and consumer protection objectives underpinning the PSD2 regulatory framework.

Submission date
30/12/2025
Rejected publishing date
19/05/2026
Rationale for rejection

This question has been rejected because the matter it refers to is already covered in the answer to Q&A 7261.

Status
Rejected question

Footer

EUROPEAN BANKING AUTHORITY

Our mission is to contribute to the stability and effectiveness of the European financial system through simple, consistent, transparent, fair regulation and supervision that benefits all EU citizens.


UE logoAn agency of the EU

EU Agencies Network logoEU Agencies Network

EMAS logoSustainable EBA

Contact us

  • Contacts
  • Ask a general question
  • Send a press query
  • Ask a regulatory question
  • Request access to documents
  • File a complaint
  • Whistleblower reports

Stay up to date with our work

  • Subscribe to our email alerts
  • News & press RSS feed

Follow us on Social media

  • Bluesky
  • LinkedIn
  • X
  • YouTube

Find out about us

  • The EBA at a glance
  • Privacy policy
  • Legal notice
  • Cookies policy
  • Frauds and scams

Explore related sites

  • EIOPA
  • ESMA
  • ESRB
  • CEBS archive