Skip to content

Dutch Payments Association’s position on PSD2 ahead of House of Representatives round-table discussion

Published on:

The Dutch Payments Association fully supports the objectives of PSD2: more innovation, more competition and greater security in payments. We aim to contribute constructively to the round-table discussion by sharing our position and several concerns.

1. Prevent further delays in implementing PSD2 into Dutch law

Further delays will prolong uncertainty in the market. They will also delay the introduction of new and innovative payment services under PSD2 in the Netherlands. The Netherlands’ competitive position as a location for innovative new payment service providers, compared with the rest of the European Union, is also at stake.

2. Claims that PSD2 jeopardises consumer privacy require nuance

From a legal perspective, consumer privacy is adequately protected under PSD2. If consumers do not give third parties explicit consent to access their payment account or information from it, nothing will change from the current situation. The question is whether consumers will always fully understand exactly what they are consenting to. In this context, the public debate about privacy protection in relation to PSD2 provides a good opportunity to raise consumer awareness further.

3. Dedicated open interfaces (APIs) provide the best guarantee for secure and reliable communication between third parties and customers through the banking infrastructure

APIs are secure, protect privacy and are future-proof

Under PSD2, banks are required to make a ‘digital gateway’ available to third parties, giving them access to payment accounts held with those banks. Through dedicated open Application Programming Interfaces (APIs) designed specifically for this purpose, banks can provide third parties with proper, reliable and secure access to the payment accounts they hold. This allows them to grant precisely the access and share precisely the data for which the account holder has given consent. In principle, this is also the European Commission’s position.

In our view, a fallback option using screen scraping presents risks

The secondary legislation that the European Commission will submit to Parliament and the Council at the end of November 2017 – the Regulatory Technical Standards (RTS) on strong customer authentication and common and secure communication standards – stipulates that banks which provide an API to third parties must also offer a fallback option through the regular customer interface if the API is temporarily unavailable or not working properly. Such a fallback option has several significant disadvantages:

We understand that the forthcoming RTS will fortunately allow banks – subject to strict conditions – to be exempted by their national supervisory authority from the obligation to offer a fallback option. We consider this an important and valuable addition to the draft RTS proposed by the European Commission in May 2017. We therefore advise the Dutch House of Representatives to support, through the European Parliament, the RTS that the European Commission will submit at the end of November 2017.

Further explanation

PSD2 is a reality, even though its implementation into Dutch law will take a little longer and several more technical matters are not yet entirely clear. PSD2 is a step towards new and innovative payment services and a more efficient and secure European payments landscape, offering consumers and businesses more choice.

For the round-table discussion about PSD2 with the Dutch House of Representatives’ Standing Committee on Finance on 15 November 2017, the Dutch Payments Association wishes to contribute constructively to the debate by presenting the position below.

Our position can be summarised as follows:

  1. Prevent further delays in implementing PSD2 into Dutch law;
  2. Claims that PSD2 jeopardises consumer privacy require nuance;
  3. Dedicated open interfaces (APIs) provide the best guarantee for secure and reliable communication between third parties and customers through the banking infrastructure.

1. Prevent further delays in implementing PSD2 into Dutch law

The process of implementing PSD2 into Dutch law is running approximately six months behind schedule (1). Rather than by PSD2’s deadline of 13 January 2018, it is expected to be implemented into Dutch law by mid-June 2018. In our view, further delays – for example due to a prolonged privacy debate that also covers the forthcoming General Data Protection Regulation (GDPR) in its entirety – are not in the interests of Dutch consumers or payment service providers. From a legal perspective, consumer privacy is adequately protected under PSD2 and the GDPR (see our second point below).

The longer it takes to implement PSD2 into Dutch law, the longer uncertainty will persist in the market and the longer it will take before new and innovative payment services can also be offered in the Netherlands. The Netherlands’ competitive position relative to the rest of the European Union is also at stake. Until PSD2 has been implemented into Dutch law, innovative new companies cannot apply in the Netherlands for a licence to provide payment initiation services or for registration to provide account information services. They may therefore turn away from the Netherlands and establish themselves elsewhere in the European Union – where PSD2 has already been implemented into national law – and apply for a licence or registration there.

Claims that PSD2 jeopardises consumer privacy require nuance

Recent public debate has sometimes suggested that the introduction of PSD2 will jeopardise consumer privacy, particularly where payment data is concerned. Privacy protection was not the direct reason why European legislators revised PSD1; their objective was to promote competition and innovation in the European payments market. We would like to add nuance to perceptions about PSD2’s possible negative consequences for privacy. If consumers do not give third parties explicit consent to access their payment account, nothing will change from the current situation. Only the consumer and their bank will then have access to the payment account.

More specifically, PSD2 stipulates the following:


In the Implementation Decree for the revised Payment Services Directive, which was recently published for consultation, the Dutch legislator explains the relationship between PSD2 and the GDPR. The term ‘explicit consent’ occurs twice in PSD2: in relation to obtaining access to payment accounts and processing personal data. In the context of PSD2, the meaning that PSD2 assigns to this term takes precedence over its meaning in the GDPR. De Nederlandsche Bank (DNB) is initially the relevant national supervisory authority for the substance of the PSD2 concept and its implementation. This does not alter the fact that any processing of personal data must comply with the GDPR’s other requirements, which are supervised by the Dutch Data Protection Authority.

The Dutch legislator also states that a third party may pass retrieved payment-account-related information to other parties only if the payment service user has given explicit consent. Consider, for example, a mortgage provider that, with the consumer’s explicit consent, obtains access through an account information service provider to information from the consumer’s payment account. The mortgage provider then analyses incoming and outgoing payments to assess the consumer’s creditworthiness and prepare a tailored mortgage offer. This processing of information by the third party, or by any other party to which the third party passes on the data, falls outside the scope of PSD2. The generally applicable European privacy rules, such as the GDPR, then apply.

Overall, consumer privacy is adequately protected under PSD2 from a legal perspective. The question is whether consumers will always fully understand exactly what they are consenting to when they give third parties access to their payment accounts or information from them. Many parties will try to persuade consumers to do so by offering free online services, discounts or other benefits. Will consumers always realise that in such cases they are paying with their personal data rather than money? Many online businesses base their revenue model on trading personal data. The more privacy a consumer gives up, the more often they can use free online services. We see the current public debate about privacy protection in relation to PSD2 as a good opportunity to increase consumer awareness. In our view, however, it should not cause further delays in implementing PSD2 into Dutch law.

3. Dedicated open interfaces (APIs) provide the best guarantee for secure and reliable communication between third parties and customers through the banking infrastructure

The principal technical and legal secondary legislation that the European Banking Authority (EBA) was required to develop under PSD2 consists of the Regulatory Technical Standards (RTS) on strong customer authentication and common and secure standards of communication. These standards apply to electronic payments generally and to the technical interaction between banks and third parties. The European Commission will adopt the final RTS at the end of November 2017 and will then submit them to the European Parliament and the Council. This means that the RTS will take effect no earlier than September 2019, at which point payment service providers must comply with their requirements. The existing security rules will continue to apply in the meantime.

Under PSD2, banks are required to make a ‘digital gateway’ available to third parties, giving them access to payment accounts held with the banks. Like the European Commission (4), we believe that open interfaces developed specifically for this purpose – in practice, Application Programming Interfaces (APIs) (5) – provide the best guarantee for secure and reliable communication between third parties and customers through the banking infrastructure.

We understand from unofficial sources that the RTS which the European Commission will submit at the end of November 2017 stipulate that banks providing a dedicated interface to third parties must, in principle, also offer a fallback option. This applies if the dedicated interface is temporarily unavailable or not working properly for any reason. In that case, the fallback option must give third parties access to payment accounts held with the bank through the bank’s regular online customer interface using screen scraping (6), albeit with identification between the bank and the third party.

In our view, this fallback option has several significant disadvantages. It gives third parties unrestricted access to all data available in the account holder’s secure online banking environment. This includes payment and savings account data, but also mortgage details, overdraft limits and address information.

It also means that account holders become accustomed to sharing the security codes they received from their bank with third parties. This puts customer privacy at risk and makes customers more vulnerable to online fraud and misuse. After all, cybercriminals also try to obtain consumers’ security codes, but with the intention of committing online fraud or otherwise misusing them.

The forthcoming RTS will, however, very probably allow banks – subject to strict conditions – to be exempted by the designated national supervisory authority from the obligation to provide this fallback option. The conditions include that the dedicated interface complies with the requirements of PSD2 and the RTS, has been adequately tested and used by third parties, and that any availability or functionality problems are resolved immediately. Third parties must use the dedicated interface provided, but may use the fallback option under certain conditions if it is disrupted. The national supervisory authority must be informed and may withdraw the exemption.

We consider the exemption subject to strict conditions described above an important and valuable addition to the draft RTS proposed by the European Commission in May 2017. We therefore advise the Dutch House of Representatives to support, through the European Parliament, the RTS that the European Commission will submit at the end of November 2017.

(1) Letter ‘Progress on implementing the revised Payment Services Directive (PSD2)’ of 22 September 2017 from former Finance Minister Dijsselbloem to the Dutch House of Representatives. >>> back

(2) A payment initiation service provider that can initiate a payment on behalf of the payment service user – in this case the payment account holder – or an account information service provider that retrieves payment account data on behalf of the payment service user. >>> back

(3) A payment service user may be either a consumer or a business. >>> back

(4) See, among other sources, the recent letter dated 20 October 2017 from Valdis Dombrovskis, Vice-President of the European Commission, to Walsh, CEO of the Fin Tech & Payments Association of Ireland, Beaumont, CEO of Vector, and Morgan, Director of Policy & Regulation at Innovate Finance. >>> back

(5) An API is a set of definitions that enables software programs to communicate with each other. It acts as an interface between different software applications, allowing their code to provide automated access to information and/or functionality without developers needing to know exactly how the other program works.
APIs are the market standard and are widely used to enable different software programs to communicate with each other effectively, efficiently, securely and reliably. APIs can be used for many purposes, including enabling banks to give third parties proper, reliable and secure access to payment accounts held with them. >>> back

(6) Screen scraping is a computer technique in which data is read from a web page designed for display on a computer screen and used as input for another underlying program. Existing providers that already offer payment initiation or account information services generally use screen-scraping techniques. >>> back

Related articles