Search for Q&As

Enquirers can use various factors to search for a Q&A:

  • These include searching by the Q&A ID; legal reference, date submitted, technical standard / guideline, or by keyword if known.
  • Searches can be extended to more than one legal act, topic, technical standard or guidelines by making multiple selections (i.e. pressing 'Ctrl' on your keyboard, and selecting the relevant ones from the drop-down lists by left mouse-click).

Disclaimer:

Q&As refer to the provisions in force on the day of their publication. The EBA does not systematically review published Q&As following the amendment of legislative acts. Users of the Q&A tool should therefore check the date of publication of the Q&A and whether the provisions referred to in the answer remain the same.

Please note that the Q&As related to the supervisory benchmarking exercises have been moved to the dedicated handbook page. You can submit Q&As on this topic here.

List of Q&A's

Requirement for loan agents to register as payment service providers under EU's Second Payment Services Directive 2015/2366 ("PSD2").

I would like some clarification on Directive 2015/2366/EU (PSD2) Article 4 paragraphh 22 - Money remittance. If a firm performs administrative services (including but not limited to the calculation of interest/fees and principal owing between lenders and a borrower) and as part of this service is required to regularly transfer money between lenders and a borrower (no fee involved), does this qualify as money remittance? No fees are charged for the transfer of money.  

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

The SCA-Exemption for account access based on art. 10 of Regulation (EU) 2018/389 as amended by Regulation (EU) 2022/2360.

We require a clarification with reference to the art. 10 of Regulation (EU) 2018/389 as amended by Regulation (EU) 2022/2360, regarding the meaning of the sentence: “…provided that access is limited to one of the following items online…”.  Does it mean that the 180days exemption is not allowed in case the PSU requires at the same time and in the same request: i) balance and ii) transactions-list of her/his payment account?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication

Eligibility of communication by AISPs with ASPSP throughout interface used for authentication and communication with the ASPSP's payment services users in case of ASPSP’s exemption from the fall back mechanism

Question no 1:   Does a fact, that based on art. 33(6) RTS, given ASPSP was granted by competent authority with exclusion from the obligation to set up the contingency mechanism described under art. 33(4) RTS, means, that such exemption merely gives this ASPSP a right not to set up the contingency mechanism, and hence, this is up to ASPSP to enjoy and to follow this exclusion, or whether, in opposition, this exemption creates on ASPSP side obligation to bring this exclusion to life.   Question no 2:   Does a fact, that given ASPSP was granted by competent authority with exclusion from the obligation to set up the contingency mechanism described under art. 33(4) RTS, creates on AISP’s end any kind of obligation, for instance lack of right to communicate with ASPSP in question throughout interface made available to the payment service users for the authentication and communication with their ASPSPs.

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication

requirements for professional experience of representatives and board members of EMIs

Dear Sir/Madam,    In the process of licensing an EMI, the management of the company aplying for a licese is required to have certain professional qualifications: experience, clean record, good reputation,etc... As PSD2 does not regulate this topic, each National Bank has set different requirments. The same pereon may be elidgible under the requirments of central bank of one country while not elidgible for another. Usually, the requirments are for banking and equivalent proffesional background and experience.  Profesionals with technology background (eg. Computer Science, blockchain, software development, AI, information management) are not elidgible. However technology is one of the main drivers of innovation and competitiveness in both banks and fintech.    In this regard, I have two questions:  1. Is EBA discussing any harmonisation of requirments for profesional experience of managing teams of EMIs to be enforced in a new updated PSD2? 2. If yes, does EBA consider allowing technology related profesionals to hold management possitions in EMIs?    Best regards,  Filip Mutafis  

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Initial Capital

What is the initial capital requirement if a payment institution is providing: (a) any of the payment services as referred to in points (1) to (5) of Annex I and service (6) and (7). (b) any of the payment services as referred to in points (1) to (5) of Annex I and service (6) . (c) any of the payment services as referred to in points (1) to (5) of Annex I and service (7).

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Publication of quarterly statistics, according to GL 3 of the “Guidelines on the conditions to benefit from an exemption from the contingency mechanism under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA & CSC)”

In what concerns the performance and availability statistics that ASPSPs need to make available on their websites in accordance to GL 3 of the “Guidelines on the conditions to benefit from an exemption from the contingency mechanism under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA & CSC)”, do ASPSPs need to disclose all their quarterly reports since the entry into production of their APIs? For instance, if the ASPSP made their API available in September 2019, does the ASPSP need to have all the reports online since then? If not, is there any recommended timeframe for the reports to be kept available online?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: EBA/GL/2018/07 - Guidelines on the exemption from the contingency mechanism under Regulation (EU) 2018/389

Online foreign exchange

Does the business of foreign currency exchange-Forex require an authorisation as payment institution under PSD2, provided that: (a) the currency exchange takes place via online exchange platform; and (b) the client deposits certain base in cash or sends it by bank transfer to a bank account of the Forex company; and (c) the client receives the quote (exchanged) currency in an online client account in the platform from where the exchanged amount may be sent to a client's bank account or may be withdrawn in cash at the Forex company's offices?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Services offered by means of ATM by providers

Which is the appropriate payment service for ATM withdrawals, where the ATM provider is required to be authorised but is acting on behalf of one or more card issuers, which are not a party to the framework contract with the customer withdrawing money from a payment account? 

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Safeguarding requirements

Are transactions where both the payer and the payee are outside the EEA (e.g. a transfer between China and Hong Kong) outside the scope of the safeguarding requirements or not?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Interpretation of payment instrument

What devices or procedures can be considered as payment instrument as per Art. 4(14) of PSD2.

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Roles that can be assigned to electronic money institutions in certificates

Please clarify which roles may be assigned to electronic money institutions (EU 2015/2366 Art 1(1) b) by qualified trust service providers (QTSPs) in the certificates. There seems to be some contradiction between EU 2015/2366 Art 11(1) and the EBA Opinion on the use of eIDAS certificates under the RTS on SCA and CSC (EBA-Op-2018-7) item 26.

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

The amount of a card payment transaction authorised online in HRK

Please clarify for card payment transactions authorised by the Payment Services User (PSU) in Member State A’s currency online on a web shop of an EU merchant that has an domain extension of Member State A, but that is not a Member State A merchant.The payment service provider is an EU acquirer (not from Member State A).The Member State A’s Payment Services Provider (PSP) issuing the payment card charges the PSU a different amount in Member State A’s currency (different from the amount that has been authorised).The difference between the original and charged amounts is caused by a currency conversion due to a card transactions settlement in another currency (EUR, USD, etc.) in the Payment Scheme.

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Requirement for credit institutions and electronic money institutions wishing to offer PIS and AIS to take out professional indemnity insurance or a comparable guarantee / Obbligo di dotarsi di un'assicurazione per la responsabilità civile o analoga garanzia, per gli Enti creditizi o Istituti di moneta elettronica che vogliono offrire i servizi di PIS e AIS

Can an electronic money institution or a credit institution wishing to offer Payment Initiation Service (PIS) and Account information service (AIS) consider its own funds to be a guarantee that is comparable to professional indemnity insurance (PII)?***IT:   Un Istituto di Moneta elettronica o un Ente creditizio che vuole offrire i servizi di PIS e AIS, può considerare i fondi propri come analoga garanzia rispetto all’assicurazione per la responsabilità civile professionale? 

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: EBA/GL/2017/08 - Guidelines on the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance

Surcharging

Is a ‘foreign exchange margin’ or 'currency conversion fee'  different from a ‘surcharge’ and do different foreign exchange margins above the ECB mid-market rate not constitute a surcharge?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Immediate Refund by the Payment Service Provider of unauthorised SEPA Direct Debit transactions after 8 weeks.

Our question is related to ‘unauthorised’ transactions, and as from when it is qualified as unauthorised? Is this as soon as any payment service user claims that the transaction is unauthorised?   -Or is this as soon as the payment service provider analysed if the transaction is really unauthorised?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Not applicable

Potential inconsistency on the application of Strong Customer Authentication exemptions to AISPs

Shall Account Servicing Payment Service Providers (ASPSPs) always grant Account Information Service Provider (AISPs) to be exempted from Strong Customer Authentication (SCA) according to rules defined in Article 10 of the RTS on strong customer authentication and secure communication (Delegated Regulation (EU) 2018/389), or is the final decision to apply such exemption always up to the ASPSP?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication

90 Day Access via Direct Access

Should any solution which involves direct access, whether as a strategic solution to PSD2, or in relation to the obligation to provide a fallback interface, ensure that Account Information Service Providers (AISPs) can access the interface in the same manner as the dedicated interface, specifically on an ongoing basis and for a maximum of 90 days once the customer has provided consent and authenticated using strong customer authentication (SCA)?

  • Legal act: Directive 2015/2366/EU (PSD2)
  • COM Delegated or Implementing Acts/RTS/ITS/GLs: Regulation (EU) 2018/389 - RTS on strong customer authentication and secure communication