Article 94 grounds the data-processing activities of PSD2 actors (ASPSPs, PISPs, AISPs, payment systems, payment service providers + their agents and outsourcees) in the GDPR. Personal data may be processed by payment systems / PSPs only where necessary to safeguard the prevention / investigation / detection of payment fraud (Article 94(1)). PSPs shall obtain explicit consent from PSUs to access / process / retain personal data necessary for the provision of the payment service - this is a PSD2-specific consent for service-provision-purpose, distinct from GDPR consent as a lawful basis (Article 94(2)). The Article 94 consent regime is the legal hook on which the EDPB Guidelines 06/2020 + 02/2023 (on the interplay between PSD2 + GDPR) and the EDPB Letter to the Commission on PSD3 / PSR clarify that GDPR remains the data-protection framework, but Article 94(2) imposes an additional service-specific consent requirement.
This control maps to 4 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.