PSD2: Directive (EU) 2015/2366 on payment services in the internal market
Directive (EU) 2015/2366 (PSD2) is the European Union directive governing payment services, electronic transactions, and open banking across the internal market. It establishes the licensing frameworks for fully authorised payment institutions, registered account information service providers (AISPs), and small payment institutions under national exemption regimes, defining core prudential capital, customer safeguarding, and Strong Customer Authentication requirements.
At a glance
| Official title | Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC1 |
|---|---|
| English title | Directive (EU) 2015/2366 on payment services in the internal market |
| Citation | Directive (EU) 2015/2366 |
| Jurisdiction | European Union (applies in every EU/EEA state) |
| Type | directive |
| Adopted | 2015-11-25 |
| In force from | 2016-01-12 |
| Status | in force |
Full text
Official full text: Directive (EU) 2015/2366 on payment services in the internal market (PDF, en)2 · 988 KB · file checked 2026-09-24 · consolidated version of 2025-01-17
Official page: eur-lex.europa.eu1
Summary
Directive (EU) 2015/2366 (PSD2) establishes the European Union regulatory framework for payment services and electronic payments within the internal market. It applies to payment service providers across the EEA, including payment institutions, credit institutions, electronic money institutions, and post office giro institutions. The directive creates three licensing statuses: fully authorised payment institutions, registered account information service providers (AISPs), and small payment institutions operating under optional national exemption regimes. Key obligations include maintaining initial capital between EUR 20,000 and EUR 125,000 depending on services offered, and holding ongoing own funds under one of three supervisory calculation methods (Methods A, B, or C). Institutions handling client funds must segregate them in designated accounts or back them with comparable insurance guarantees. PSD2 opens the payment ecosystem by requiring account servicing payment service providers to grant non-discriminatory access to payment initiation service providers (PISPs) and AISPs without contractual friction. It also mandates Strong Customer Authentication (SCA) to combat fraud and sets prior regulatory approval thresholds for qualifying holding acquisitions.
Summary written by the Atlas from the official text; the law itself prevails.
Main articles
- Art. 1: Categorises payment service providers into credit institutions, electronic money institutions, post office giro institutions, payment institutions, ECB, national central banks, and public authorities.
- Art. 5: Specifies comprehensive documentation required for payment institution authorisation, including business plan, governance, risk controls, ICT resilience arrangements, and anti-money laundering mechanisms.
- Art. 6: Requires prior written notification to competent authorities before acquiring or disposing of qualifying holdings crossing the 20%, 30%, or 50% capital or voting rights thresholds.
- Art. 7: Mandates initial capital of EUR 20,000 for money remittance, EUR 50,000 for payment initiation services, and EUR 125,000 for other core payment services.
- Art. 8: Requires payment institutions to maintain ongoing own funds at least equal to initial capital or calculated own funds under Article 9, preventing group double-counting.
- Art. 9: Defines three supervisory methods (A, B, C) for calculating ongoing own funds based on fixed overheads, transaction volume, or gross revenue indicators.
- Art. 10: Obliges institutions to safeguard user funds by segregation in separate credit institution accounts, investment in secure low-risk assets, or comparable insurance guarantees.
- Art. 11: Sets statutory conditions for granting payment institution authorisation, ensuring robust governance, sound management, and effective supervisory oversight across all Member States.
- Art. 13: Governs conditions under which competent authorities may withdraw authorisation, including non-use within 12 months, irregular procurement, or threats to payment system stability.
- Art. 18: Authorises payment institutions to provide ancillary services and credit linked to payments from own funds, strictly forbidding deposit-taking or holding non-payment accounts.
- Art. 28: Establishes the EU passporting regime, enabling authorised payment institutions to provide cross-border services or establish branches across Member States via regulator notifications.
- Art. 32: Allows Member States to exempt small payment institutions with monthly transactions under EUR 3 million from full authorisation, without EU passporting rights.
- Art. 33: Exempts account information service providers from capital requirements, replacing them with professional indemnity insurance while granting full cross-border passporting rights.
- Art. 35: Requires payment system operators to provide objective, non-discriminatory, and proportionate access rules to payment service providers, preventing unjustified access barriers.
- Art. 36: Mandates credit institutions to provide payment institutions with payment account access on an objective, non-discriminatory, and proportionate basis with motivated refusal reasons.
- Art. 66: Establishes payer rights to use payment initiation services and requires account servicing providers to facilitate payment initiation without requiring contractual agreements.
- Art. 67: Guarantees rights to use account information services, requiring account servicing providers to share account data securely and without discrimination based on explicit user consent.
- Art. 97: Mandates strong customer authentication for online account access, electronic payment initiation, and remote actions with fraud risks, requiring dynamic transaction linking.
- Art. 103: Requires Member States to enact effective, proportionate, and dissuasive penalties for infringements and permits public disclosure of imposed administrative sanctions.
- Art. 109: Provides transitional grandfathering arrangements allowing existing payment institutions licensed under Directive 2007/64/EC to continue activities while transitioning to PSD2.
- Art. 114: Formally repeals Directive 2007/64/EC (PSD1) with effect from 13 January 2018, replacing references in Union law according to the correlation table.
- Art. 115: Sets the national transposition deadline and date of application as 13 January 2018, with deferred application for specific technical security standards.
Licences it governs
- EMI · Lithuania
Electronic money institution licence for non-limited activity
LB · capital EUR 350,000
- PI · Czech Republic
Account Information Service Provider authorisation (povolení k činnosti správce informací o platebním účtu)
CNB
- PI · Czech Republic
Small-scale Payment Service Provider authorisation (povolení k činnosti poskytovatele platebních služeb malého rozsahu - PPSMR)
CNB
- PI · Czech Republic
Payment Institution licence (povolení k činnosti platební instituce)
CNB
- PI · Germany
Account information service provider registration (Registrierung als Kontoinformationsdienstleister nach § 34 ZAG)
BaFin
- PI · Germany
Payment institution licence (Erlaubnis zur Erbringung von Zahlungsdiensten nach § 10 ZAG)
BaFin
- PI · Estonia
Payment institution operating with an exception
FI
- PI · Estonia
Operating licence as a payment institution
FI
- PI · Spain
Entidad de pago (EP) / Payment institution authorization
BdE
- PI · Ireland
Account Information Service Provider Registration
CBI
- PI · Ireland
Payment Institution Authorisation
CBI
- PI · Lithuania
Payment institution licence for restricted activity
LB
- PI · Lithuania
Payment institution licence
LB
- PI · Luxembourg
Payment institution authorisation
CSSF
- PI · Latvia
Registered payment institution
LB
- PI · Latvia
Authorised payment institution licence
LB
- PI · Malta
Account information service provider registration
MFSA
- PI · Malta
Payment institution licence
MFSA
- PI · Netherlands
Exempt payment service provider registration (Vrijstelling betaaldienstverlener)
DNB
- PI · Netherlands
Payment institution licence (Vergunning betaalinstelling)
DNB
- PI · Poland
Account Information Service Provider registration (dostawca świadczący wyłącznie usługę dostępu do informacji o rachunku - AISP)
KNF
- PI · Poland
National Payment Institution licence (krajowa instytucja płatnicza - KIP)
KNF
- PI · Poland
Small Payment Institution registration (mała instytucja płatnicza - MIP)
KNF
- PI · Slovakia
Payment institution licence (povolenie na poskytovanie platobných služieb bez obmedzenia rozsahu)
NBS
Regulators that apply it
- Germany
Federal Financial Supervisory Authority (BaFin)
BaFin operates as Germany's unified federal financial supervisor under the Federal Ministry of Finance, supervising credit institutions, fin
- Spain
Bank of Spain (BdE)
Banco de España is Spain's national central bank and banking supervisor, operating as an integral part of the European System of Central Ban
- Lithuania
Bank of Lithuania (LB)
The Bank of Lithuania operates as the central bank of the Republic of Lithuania and member of the Eurosystem, conducting integrated prudenti
- Ireland
Central Bank of Ireland (CBI)
The Central Bank of Ireland serves the public interest by maintaining monetary and financial stability while ensuring that the financial sys
- Czech Republic
Czech National Bank (CNB)
The Czech National Bank acts as the central bank and unified supervisory authority of the Czech financial market under Act No. 6/1993 Coll.
- Luxembourg
Commission de Surveillance du Secteur Financier (CSSF)
The CSSF operates as the unified public supervisory authority for the Luxembourg financial centre, conducting prudential supervision and mar
- Netherlands
De Nederlandsche Bank (DNB)
De Nederlandsche Bank acts as the central bank of the Netherlands and integral member of the Eurosystem and ESCB, exercising prudential supe
- European Union
European Banking Authority (EBA)
The European Banking Authority is an independent EU agency that creates the European Single Rulebook for banking and payments, fosters super
- Estonia
Finantsinspektsioon (FI)
Finantsinspektsioon is Estonia's independent financial supervision and crisis resolution authority operating with autonomous responsibilitie
- Poland
Polish Financial Supervision Authority (KNF)
KNF ensures the proper functioning, stability, security, and transparency of the Polish financial market, safeguards public confidence in fi
- Latvia
Latvijas Banka (LB)
Latvijas Banka is the central bank of the Republic of Latvia and member of the Eurosystem, operating as the single integrated financial supe
- Malta
Malta Financial Services Authority (MFSA)
The Malta Financial Services Authority is the single autonomous financial regulator in Malta, entrusted with prudential and conduct supervis
- Slovakia
National Bank of Slovakia (NBS)
Národná banka Slovenska acts as the central bank and integrated financial supervisory authority of the Slovak Republic. It safeguards price
Upcoming changes
- PSD3 (COM(2023) 366) and the Payment Services Regulation (COM(2023) 367) are to replace this directive. The European Parliament's committee approved the text agreed with the Council on 5 May 2026; as of September 2026 the procedure still awaits formal adoption.3
- Conduct of business, open banking access, and Strong Customer Authentication rules currently in PSD2 will transfer to the directly applicable Payment Services Regulation (PSR, COM(2023) 367), introducing mandatory Confirmation of Payee verification across the EU.4
Sources
- eur-lex.europa.eu: TXT (32015L2366) · retrieved 2026-09-24
- eur-lex.europa.eu: TXT (02015L2366-20250117) · retrieved 2026-09-24
- oeil.europarl.europa.eu: procedure file · retrieved 2026-09-24
- eur-lex.europa.eu: TXT (52023PC0367) · retrieved 2026-09-24
Does PSD2 apply to your business?
Send us a short description of what you do. We tell you which obligations and licences follow from it, and what it takes to comply.
A free preliminary assessment: we check your business model against the licence before you spend on an application. We handle this licence and any other fintech licence, including jurisdictions the Atlas does not cover yet.