EU Payment Services Directive (PSD2)
PSD2: Operational Security, Strong Customer Authentication and Incident Reporting

EU Payment Services Directive (PSD2) PSD2-Art.94: Data protection (PSD2 Article 94) - GDPR alignment

Article 94 grounds the data-processing activities of PSD2 actors (ASPSPs, PISPs, AISPs, payment systems, payment service providers + their agents and outsourcees) in the GDPR. Personal data may be processed by payment systems / PSPs only where necessary to safeguard the prevention / investigation / detection of payment fraud (Article 94(1)). PSPs shall obtain explicit consent from PSUs to access / process / retain personal data necessary for the provision of the payment service - this is a PSD2-specific consent for service-provision-purpose, distinct from GDPR consent as a lawful basis (Article 94(2)). The Article 94 consent regime is the legal hook on which the EDPB Guidelines 06/2020 + 02/2023 (on the interplay between PSD2 + GDPR) and the EDPB Letter to the Commission on PSD3 / PSR clarify that GDPR remains the data-protection framework, but Article 94(2) imposes an additional service-specific consent requirement.

Maintained by Gerard BlokdykVerified against the published standard

What else in your programme already covers this

This control maps to 4 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

GDPR · 4 controls

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PSD2: Operational Security, Strong Customer Authentication and Incident Reporting

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.