EU Payment Services Directive (PSD2)
PSD2: Authorisation of Payment Transactions and Open Banking (PIS / AIS)

EU Payment Services Directive (PSD2) PSD2-Art.66_67: Payment initiation services and account information services (PSD2 Articles 66 and 67) - the Open Banking rules

Article 66 (PIS) gives PSUs the right to use a payment initiation service provider (PISP) when the underlying payment account is accessible online. The PISP must: be authorised; have explicit consent from the PSU; not hold the PSU's funds in connection with the provision of the PIS; not store sensitive payment data of the PSU; not request data other than necessary; not use / access / store data for purposes other than the provision of the payment initiation service explicitly requested by the PSU; not modify the amount + payee + any other feature of the transaction; treat personalised security credentials as secure. ASPSPs must communicate with PISPs in a secure manner under Article 98 RTS and must not block PISP access. Article 67 (AIS) gives PSUs the right to use an account information service provider (AISP) when the underlying payment account is accessible online. The AISP must: have explicit consent; not request sensitive payment data; not use / access / store data for purposes other than that explicitly requested by the PSU; comply with data-protection rules. ASPSPs must communicate with AISPs securely under Article 98 RTS and must not require contractual relationship with the AISP.

Maintained by Gerard BlokdykVerified against the published standard

Other controls in PSD2: Authorisation of Payment Transactions and Open Banking (PIS / AIS)

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.