Search for Q&As

Enquirers can use various factors to search for a Q&A:

  • These include searching by the Q&A ID; legal reference, date submitted, technical standard / guideline, or by keyword if known.
  • Searches can be extended to more than one legal act, topic, technical standard or guidelines by making multiple selections (i.e. pressing 'Ctrl' on your keyboard, and selecting the relevant ones from the drop-down lists by left mouse-click).

Disclaimer:

Q&As refer to the provisions in force on the day of their publication. The EBA does not systematically review published Q&As following the amendment of legislative acts. Users of the Q&A tool should therefore check the date of publication of the Q&A and whether the provisions referred to in the answer remain the same.

Please note that the Q&As related to the supervisory benchmarking exercises have been moved to the dedicated handbook page. You can submit Q&As on this topic here.

List of Q&A's

Online foreign exchange

Does the business of foreign currency exchange-Forex require an authorisation as payment institution under PSD2, provided that: (a) the currency exchange takes place via online exchange platform; and (b) the client deposits certain base in cash or sends it by bank transfer to a bank account of the Forex company; and (c) the client receives the quote (exchanged) currency in an online client account in the platform from where the exchanged amount may be sent to a client's bank account or may be withdrawn in cash at the Forex company's offices?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Services offered by means of ATM by providers

Which is the appropriate payment service for ATM withdrawals, where the ATM provider is required to be authorised but is acting on behalf of one or more card issuers, which are not a party to the framework contract with the customer withdrawing money from a payment account? 

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Safeguarding requirements

Are transactions where both the payer and the payee are outside the EEA (e.g. a transfer between China and Hong Kong) outside the scope of the safeguarding requirements or not?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Interpretation of payment instrument

What devices or procedures can be considered as payment instrument as per Art. 4(14) of PSD2.

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Roles that can be assigned to electronic money institutions in certificates

Please clarify which roles may be assigned to electronic money institutions (EU 2015/2366 Art 1(1) b) by qualified trust service providers (QTSPs) in the certificates. There seems to be some contradiction between EU 2015/2366 Art 11(1) and the EBA Opinion on the use of eIDAS certificates under the RTS on SCA and CSC (EBA-Op-2018-7) item 26.

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

The amount of a card payment transaction authorised online in HRK

Please clarify for card payment transactions authorised by the Payment Services User (PSU) in Member State A’s currency online on a web shop of an EU merchant that has an domain extension of Member State A, but that is not a Member State A merchant.The payment service provider is an EU acquirer (not from Member State A).The Member State A’s Payment Services Provider (PSP) issuing the payment card charges the PSU a different amount in Member State A’s currency (different from the amount that has been authorised).The difference between the original and charged amounts is caused by a currency conversion due to a card transactions settlement in another currency (EUR, USD, etc.) in the Payment Scheme.

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Requirement for credit institutions and electronic money institutions wishing to offer PIS and AIS to take out professional indemnity insurance or a comparable guarantee / Obbligo di dotarsi di un'assicurazione per la responsabilità civile o analoga garanzia, per gli Enti creditizi o Istituti di moneta elettronica che vogliono offrire i servizi di PIS e AIS

Can an electronic money institution or a credit institution wishing to offer Payment Initiation Service (PIS) and Account information service (AIS) consider its own funds to be a guarantee that is comparable to professional indemnity insurance (PII)?***IT:   Un Istituto di Moneta elettronica o un Ente creditizio che vuole offrire i servizi di PIS e AIS, può considerare i fondi propri come analoga garanzia rispetto all’assicurazione per la responsabilità civile professionale? 

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: EBA/GL/2017/08 - Guidelines on the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance

Surcharging

Is a ‘foreign exchange margin’ or 'currency conversion fee'  different from a ‘surcharge’ and do different foreign exchange margins above the ECB mid-market rate not constitute a surcharge?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Immediate Refund by the Payment Service Provider of unauthorised SEPA Direct Debit transactions after 8 weeks.

Our question is related to ‘unauthorised’ transactions, and as from when it is qualified as unauthorised? Is this as soon as any payment service user claims that the transaction is unauthorised?   -Or is this as soon as the payment service provider analysed if the transaction is really unauthorised?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Potential inconsistency on the application of Strong Customer Authentication exemptions to AISPs

Shall Account Servicing Payment Service Providers (ASPSPs) always grant Account Information Service Provider (AISPs) to be exempted from Strong Customer Authentication (SCA) according to rules defined in Article 10 of the RTS on strong customer authentication and secure communication (Delegated Regulation (EU) 2018/389), or is the final decision to apply such exemption always up to the ASPSP?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication

90 Day Access via Direct Access

Should any solution which involves direct access, whether as a strategic solution to PSD2, or in relation to the obligation to provide a fallback interface, ensure that Account Information Service Providers (AISPs) can access the interface in the same manner as the dedicated interface, specifically on an ongoing basis and for a maximum of 90 days once the customer has provided consent and authenticated using strong customer authentication (SCA)?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication