Law · European Union

PSD2: Directive (EU) 2015/2366 on payment services in the internal market

Directive (EU) 2015/2366 (PSD2) is the European Union directive governing payment services, electronic transactions, and open banking across the internal market. It establishes the licensing frameworks for fully authorised payment institutions, registered account information service providers (AISPs), and small payment institutions under national exemption regimes, defining core prudential capital, customer safeguarding, and Strong Customer Authentication requirements.

Last verified 2026-09-24Markdown · Data (CC BY 4.0)
Directive (EU) 2015/2366 on payment services in the internal market: lawPSD2§

At a glance

Official titleDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC1
English titleDirective (EU) 2015/2366 on payment services in the internal market
CitationDirective (EU) 2015/2366
JurisdictionEuropean Union (applies in every EU/EEA state)
Typedirective
Adopted2015-11-25
In force from2016-01-12
Statusin force

Full text

Official full text: Directive (EU) 2015/2366 on payment services in the internal market (PDF, en)2 · 988 KB · file checked 2026-09-24 · consolidated version of 2025-01-17

Official page: eur-lex.europa.eu1

Summary

Directive (EU) 2015/2366 (PSD2) establishes the European Union regulatory framework for payment services and electronic payments within the internal market. It applies to payment service providers across the EEA, including payment institutions, credit institutions, electronic money institutions, and post office giro institutions. The directive creates three licensing statuses: fully authorised payment institutions, registered account information service providers (AISPs), and small payment institutions operating under optional national exemption regimes. Key obligations include maintaining initial capital between EUR 20,000 and EUR 125,000 depending on services offered, and holding ongoing own funds under one of three supervisory calculation methods (Methods A, B, or C). Institutions handling client funds must segregate them in designated accounts or back them with comparable insurance guarantees. PSD2 opens the payment ecosystem by requiring account servicing payment service providers to grant non-discriminatory access to payment initiation service providers (PISPs) and AISPs without contractual friction. It also mandates Strong Customer Authentication (SCA) to combat fraud and sets prior regulatory approval thresholds for qualifying holding acquisitions.

Summary written by the Atlas from the official text; the law itself prevails.

Main articles

  • Art. 1: Categorises payment service providers into credit institutions, electronic money institutions, post office giro institutions, payment institutions, ECB, national central banks, and public authorities.
  • Art. 5: Specifies comprehensive documentation required for payment institution authorisation, including business plan, governance, risk controls, ICT resilience arrangements, and anti-money laundering mechanisms.
  • Art. 6: Requires prior written notification to competent authorities before acquiring or disposing of qualifying holdings crossing the 20%, 30%, or 50% capital or voting rights thresholds.
  • Art. 7: Mandates initial capital of EUR 20,000 for money remittance, EUR 50,000 for payment initiation services, and EUR 125,000 for other core payment services.
  • Art. 8: Requires payment institutions to maintain ongoing own funds at least equal to initial capital or calculated own funds under Article 9, preventing group double-counting.
  • Art. 9: Defines three supervisory methods (A, B, C) for calculating ongoing own funds based on fixed overheads, transaction volume, or gross revenue indicators.
  • Art. 10: Obliges institutions to safeguard user funds by segregation in separate credit institution accounts, investment in secure low-risk assets, or comparable insurance guarantees.
  • Art. 11: Sets statutory conditions for granting payment institution authorisation, ensuring robust governance, sound management, and effective supervisory oversight across all Member States.
  • Art. 13: Governs conditions under which competent authorities may withdraw authorisation, including non-use within 12 months, irregular procurement, or threats to payment system stability.
  • Art. 18: Authorises payment institutions to provide ancillary services and credit linked to payments from own funds, strictly forbidding deposit-taking or holding non-payment accounts.
  • Art. 28: Establishes the EU passporting regime, enabling authorised payment institutions to provide cross-border services or establish branches across Member States via regulator notifications.
  • Art. 32: Allows Member States to exempt small payment institutions with monthly transactions under EUR 3 million from full authorisation, without EU passporting rights.
  • Art. 33: Exempts account information service providers from capital requirements, replacing them with professional indemnity insurance while granting full cross-border passporting rights.
  • Art. 35: Requires payment system operators to provide objective, non-discriminatory, and proportionate access rules to payment service providers, preventing unjustified access barriers.
  • Art. 36: Mandates credit institutions to provide payment institutions with payment account access on an objective, non-discriminatory, and proportionate basis with motivated refusal reasons.
  • Art. 66: Establishes payer rights to use payment initiation services and requires account servicing providers to facilitate payment initiation without requiring contractual agreements.
  • Art. 67: Guarantees rights to use account information services, requiring account servicing providers to share account data securely and without discrimination based on explicit user consent.
  • Art. 97: Mandates strong customer authentication for online account access, electronic payment initiation, and remote actions with fraud risks, requiring dynamic transaction linking.
  • Art. 103: Requires Member States to enact effective, proportionate, and dissuasive penalties for infringements and permits public disclosure of imposed administrative sanctions.
  • Art. 109: Provides transitional grandfathering arrangements allowing existing payment institutions licensed under Directive 2007/64/EC to continue activities while transitioning to PSD2.
  • Art. 114: Formally repeals Directive 2007/64/EC (PSD1) with effect from 13 January 2018, replacing references in Union law according to the correlation table.
  • Art. 115: Sets the national transposition deadline and date of application as 13 January 2018, with deferred application for specific technical security standards.

Licences it governs

Regulators that apply it

Upcoming changes

  • PSD3 (COM(2023) 366) and the Payment Services Regulation (COM(2023) 367) are to replace this directive. The European Parliament's committee approved the text agreed with the Council on 5 May 2026; as of September 2026 the procedure still awaits formal adoption.3
  • Conduct of business, open banking access, and Strong Customer Authentication rules currently in PSD2 will transfer to the directly applicable Payment Services Regulation (PSR, COM(2023) 367), introducing mandatory Confirmation of Payee verification across the EU.4
Last verified 2026-09-24Author Danil Marmysh, Founder & CEO, ProtegraReviewed by Anastasia Sidorenkova, Head of Licensing, ProtegraReport an errorReference information, not legal advice.

Sources

  1. eur-lex.europa.eu: TXT (32015L2366) · retrieved 2026-09-24
  2. eur-lex.europa.eu: TXT (02015L2366-20250117) · retrieved 2026-09-24
  3. oeil.europarl.europa.eu: procedure file · retrieved 2026-09-24
  4. eur-lex.europa.eu: TXT (52023PC0367) · retrieved 2026-09-24

Does PSD2 apply to your business?

Send us a short description of what you do. We tell you which obligations and licences follow from it, and what it takes to comply.

A free preliminary assessment: we check your business model against the licence before you spend on an application. We handle this licence and any other fintech licence, including jurisdictions the Atlas does not cover yet.