Article 94 grounds the data-processing activities of PSD2 actors (ASPSPs, PISPs, AISPs, payment systems, payment service providers + their agents and outsourcees) in the GDPR. Personal data may be processed by payment systems / PSPs only where necessary to safeguard the prevention / investigation / detection of payment fraud (Article 94(1)). PSPs shall obtain explicit consent from PSUs to access / process / retain personal data necessary for the provision of the payment service - this is a PSD2-specific consent for service-provision-purpose, distinct from GDPR consent as a lawful basis (Article 94(2)). The Article 94 consent regime is the legal hook on which the EDPB Guidelines 06/2020 + 02/2023 (on the interplay between PSD2 + GDPR) and the EDPB Letter to the Commission on PSD3 / PSR clarify that GDPR remains the data-protection framework, but Article 94(2) imposes an additional service-specific consent requirement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.