ComplianceTransparencyEUPSD2Financial InstitutionsFinancial operationsConsumer securityFraudPSD3

How will PSD3 shape the future of financial services?

PSD3 is set to come into force into 2026. How can financial institutions prepare? Our article tackles what changes from PSD2 and ways FIs can get ready for PSD3

Oscar Canario da Cunha17 April 20254 min read5,791

PSD3 is not just an update, but the evolution of trust in digital finance. Continuing the progress made by PSD2, the new regulation aims to further boost competition and consumer protection in electronic payments. It is also designed to empower consumers to securely share their data while gaining access to a wider range of affordable and innovative financial products and services.

PSD3 changes

The European Union estimates that electronic payments in the EU have increased by over 30% between 2017 and 2021 (from €184.2 trillion to €240 trillion). COVID-19, along with new players within the payments market, such as open banking providers, have accelerated this growth by driving digital adoption and increasing demand for more flexible, secure, and convenient payment solutions. In 2023, the EU unveiled its proposed framework for PSD3. What will change from PSD2 and how will this affect financial institutions? Let's explore the changes the regulation will bring.

What is the PSD3 regulation?

PSD3, or the Payment Services Directive 3, is the latest update to the European Union's regulatory framework governing electronic payments. Building on its predecessors, PSD1 and PSD2, PSD3 aims to enhance the security, competition, and innovation within the EU's payment services market. The directive focuses on improving consumer protection by addressing emerging payment risks, ensuring stronger authentication mechanisms, and setting new standards for transparency in payment transactions.

PSD3, or the Payment Services Directive 3, is the latest update to the European Union's regulatory framework governing electronic payments. Building on its predecessors, PSD1 and PSD2, PSD3 aims to enhance the security, competition, and innovation within the EU's payment services market. The directive focuses on improving consumer protection by addressing emerging payment risks, ensuring stronger authentication mechanisms, and setting new standards for transparency in payment transactions.

PSD3 safeguarding security

A key component of PSD3 is its emphasis on the evolving role of third-party payment providers, such as fintech companies and open banking platforms. By enabling safer and more efficient data sharing between financial institutions, PSD3 aims to unlock greater access to affordable and innovative financial products and services for consumers.

The regulation also seeks to create a more competitive market by fostering collaboration between traditional banks and new entrants, thereby encouraging innovation while safeguarding security and trust in digital payments.

What is the difference between PSD2 and PSD3?

PSD3 introduces several key advancements over PSD2:

PSD2

PSD3

Focused mainly on improving payment security, promoting innovation (especially through open banking), and enhancing consumer protection.

Expands on the foundations laid by PSD2, focusing not only on security and innovation but also on streamlining the regulatory framework. It aims to provide a more unified approach, particularly around data sharing, security, and consumer protection.

Introduced the concept of open banking, which allowed third-party providers to access consumer payment data with their consent to offer more tailored financial services.

Strengthens and expands the open banking framework. It focuses on giving consumers greater control over their data and ensures that third-party providers can access this data more seamlessly.

Introduced strong customer authentication (SCA) to reduce fraud and improve security in digital payments.

Builds on PSD2's security measures, introducing even stricter requirements for securing digital payments and reducing fraud.

PSD2 introduced complexities and inconsistencies in the regulatory environment, particularly in terms of enforcement across different EU Member States.

Aims to simplify and harmonize the regulatory environment by providing clearer guidelines for implementation and enforcement. It seeks to create a more consistent approach across all EU countries.

What are the key changes of the PSD3 directive?

Enhanced Strong Customer Authentication (SCA) / Spoofind Prevention / Fair Competition / Cash Withdrawals / Open Banking

How can financial institutions prepare for PSD3?

Once PSD3 is finalized and enacted, financial institutions will need to start aligning their operations with the new requirements. Below are five ways they can do this:

  • 1. Conduct impact assessments: perform a thorough analysis to identify how PSD3 will impact operations, services, and customer experience, and use the insights to adjust strategies for offering new products and services.

  • 2. Review and update compliance frameworks: ensure that internal policies and procedures align with PSD3's new requirements, such as enhanced data sharing, stronger customer authentication, and clearer fee disclosures.

  • 3. Collaborate with third-party providers: strengthen partnerships with third-party service providers (TPPs) and ensure their services comply with PSD3's updated data-sharing and security requirements.

  • 4. Focus on consumer transparency: implement tools that allow customers to easily view and manage their data access, as well as provide clear information on fees and exchange rates for cross-border transactions.

  • 5. Hire consultants: engaging with consultants who specialize in regulatory compliance can help financial institutions navigate the complexities of the new regulations, ensuring a smoother transition and minimizing the risk of non-compliance.

When will PSD3 come into effect?

When will PSD3 come into effect?

PSD3 is currently in draft form, but once adopted, it will take effect 20 days after publication, with EU Member States given 18 months to implement the directive into their national laws. This schedule indicates that PSD3 may be implemented by 2026. However, these dates are provisional and may be adjusted during the legislative process.

Financial institutions and stakeholders should monitor official EU updates and industry announcements to ensure they remain compliant with the upcoming regulations.

At Pideeco, our team of seasoned consultants combines legal insight with hands-on industry experience to help financial institutions align with PSD3 requirements efficiently and effectively. Whether it's conducting gap analyses, optimizing compliance frameworks, or implementing robust risk controls, we provide tailored solutions that turn regulatory challenges into strategic advantages. Don't hesitate to get in touch!
Oscar

Written by

Oscar Canario da Cunha

Consultant at Pideeco — supporting financial institutions on AML, KYC and regulatory transformation.

Found this article on Compliance helpful?

Our specialists are ready to help you tackle complex compliance and risk challenges.