EU Payment Services Directive (PSD2)
PSD2: Operational Security, Strong Customer Authentication and Incident Reporting

EU Payment Services Directive (PSD2) PSD2-Art.96: Incident reporting to competent authority (PSD2 Article 96)

Article 96 requires PSPs to notify, without undue delay, the home Member State competent authority of any major operational or security incident. Where the incident has or may have an impact on the financial interests of its PSUs, the PSP shall, without undue delay, inform its PSUs of the incident and of all measures that they can take to mitigate the adverse effects of the incident. The home competent authority shall, without undue delay, provide the EBA + the ECB with the relevant details of the incident; after assessment of the relevance of the incident to other relevant authorities in the Member State, the home competent authority shall notify them accordingly. The EBA + the ECB shall assess in cooperation with the home authority the relevance of the incident to other relevant Union authorities and shall notify them accordingly. EBA Guidelines EBA/GL/2017/10 (revised by EBA/GL/2021/03) operationalise Article 96, including initial / intermediate / final report templates + classification criteria.

Other controls in PSD2: Operational Security, Strong Customer Authentication and Incident Reporting

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.