# PSD2: Directive (EU) 2015/2366 on payment services in the internal market

Source page: https://protegra.io/licensing/laws/eu-psd2-2015-2366/

Directive (EU) 2015/2366 (PSD2) is the European Union directive governing payment services, electronic transactions, and open banking across the internal market. It establishes the licensing frameworks for fully authorised payment institutions, registered account information service providers (AISPs), and small payment institutions under national exemption regimes, defining core prudential capital, customer safeguarding, and Strong Customer Authentication requirements.

## At a glance

| Official title | Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC [1] |
| --- | --- |
| English title | Directive (EU) 2015/2366 on payment services in the internal market |
| Citation | Directive (EU) 2015/2366 |
| Jurisdiction | European Union (applies in every EU/EEA state) |
| Type | directive |
| Adopted | 2015-11-25 |
| In force from | 2016-01-12 |
| Status | in force |

## Full text

**Official full text:** [Directive (EU) 2015/2366 on payment services in the internal market (PDF, en)](https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:02015L2366-20250117) [2] · 988 KB · file checked 2026-09-24 · consolidated version of 2025-01-17

Official page: [eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32015L2366) [1]

## Summary

Directive (EU) 2015/2366 (PSD2) establishes the European Union regulatory framework for payment services and electronic payments within the internal market. It applies to payment service providers across the EEA, including payment institutions, credit institutions, electronic money institutions, and post office giro institutions. The directive creates three licensing statuses: fully authorised payment institutions, registered account information service providers (AISPs), and small payment institutions operating under optional national exemption regimes. Key obligations include maintaining initial capital between EUR 20,000 and EUR 125,000 depending on services offered, and holding ongoing own funds under one of three supervisory calculation methods (Methods A, B, or C). Institutions handling client funds must segregate them in designated accounts or back them with comparable insurance guarantees. PSD2 opens the payment ecosystem by requiring account servicing payment service providers to grant non-discriminatory access to payment initiation service providers (PISPs) and AISPs without contractual friction. It also mandates Strong Customer Authentication (SCA) to combat fraud and sets prior regulatory approval thresholds for qualifying holding acquisitions.

Summary written by the Atlas from the official text; the law itself prevails.

## Main articles

- **Art. 1**: Categorises payment service providers into credit institutions, electronic money institutions, post office giro institutions, payment institutions, ECB, national central banks, and public authorities.
- **Art. 5**: Specifies comprehensive documentation required for payment institution authorisation, including business plan, governance, risk controls, ICT resilience arrangements, and anti-money laundering mechanisms.
- **Art. 6**: Requires prior written notification to competent authorities before acquiring or disposing of qualifying holdings crossing the 20%, 30%, or 50% capital or voting rights thresholds.
- **Art. 7**: Mandates initial capital of EUR 20,000 for money remittance, EUR 50,000 for payment initiation services, and EUR 125,000 for other core payment services.
- **Art. 8**: Requires payment institutions to maintain ongoing own funds at least equal to initial capital or calculated own funds under Article 9, preventing group double-counting.
- **Art. 9**: Defines three supervisory methods (A, B, C) for calculating ongoing own funds based on fixed overheads, transaction volume, or gross revenue indicators.
- **Art. 10**: Obliges institutions to safeguard user funds by segregation in separate credit institution accounts, investment in secure low-risk assets, or comparable insurance guarantees.
- **Art. 11**: Sets statutory conditions for granting payment institution authorisation, ensuring robust governance, sound management, and effective supervisory oversight across all Member States.
- **Art. 13**: Governs conditions under which competent authorities may withdraw authorisation, including non-use within 12 months, irregular procurement, or threats to payment system stability.
- **Art. 18**: Authorises payment institutions to provide ancillary services and credit linked to payments from own funds, strictly forbidding deposit-taking or holding non-payment accounts.
- **Art. 28**: Establishes the EU passporting regime, enabling authorised payment institutions to provide cross-border services or establish branches across Member States via regulator notifications.
- **Art. 32**: Allows Member States to exempt small payment institutions with monthly transactions under EUR 3 million from full authorisation, without EU passporting rights.
- **Art. 33**: Exempts account information service providers from capital requirements, replacing them with professional indemnity insurance while granting full cross-border passporting rights.
- **Art. 35**: Requires payment system operators to provide objective, non-discriminatory, and proportionate access rules to payment service providers, preventing unjustified access barriers.
- **Art. 36**: Mandates credit institutions to provide payment institutions with payment account access on an objective, non-discriminatory, and proportionate basis with motivated refusal reasons.
- **Art. 66**: Establishes payer rights to use payment initiation services and requires account servicing providers to facilitate payment initiation without requiring contractual agreements.
- **Art. 67**: Guarantees rights to use account information services, requiring account servicing providers to share account data securely and without discrimination based on explicit user consent.
- **Art. 97**: Mandates strong customer authentication for online account access, electronic payment initiation, and remote actions with fraud risks, requiring dynamic transaction linking.
- **Art. 103**: Requires Member States to enact effective, proportionate, and dissuasive penalties for infringements and permits public disclosure of imposed administrative sanctions.
- **Art. 109**: Provides transitional grandfathering arrangements allowing existing payment institutions licensed under Directive 2007/64/EC to continue activities while transitioning to PSD2.
- **Art. 114**: Formally repeals Directive 2007/64/EC (PSD1) with effect from 13 January 2018, replacing references in Union law according to the correlation table.
- **Art. 115**: Sets the national transposition deadline and date of application as 13 January 2018, with deferred application for specific technical security standards.

## Licences it governs

- [EMI · LithuaniaElectronic money institution licence for non-limited activityLB · capital EUR 350,000](https://protegra.io/licensing/licences/emi/lithuania/)
- [PI · Czech RepublicAccount Information Service Provider authorisation (povolení k činnosti správce informací o platebním účtu)CNB](https://protegra.io/licensing/licences/payment-institution/czech-republic-aisp/)
- [PI · Czech RepublicSmall-scale Payment Service Provider authorisation (povolení k činnosti poskytovatele platebních služeb malého rozsahu - PPSMR)CNB](https://protegra.io/licensing/licences/payment-institution/czech-republic-small-scale/)
- [PI · Czech RepublicPayment Institution licence (povolení k činnosti platební instituce)CNB](https://protegra.io/licensing/licences/payment-institution/czech-republic/)
- [PI · GermanyAccount information service provider registration (Registrierung als Kontoinformationsdienstleister nach § 34 ZAG)BaFin](https://protegra.io/licensing/licences/payment-institution/germany-aisp/)
- [PI · GermanyPayment institution licence (Erlaubnis zur Erbringung von Zahlungsdiensten nach § 10 ZAG)BaFin](https://protegra.io/licensing/licences/payment-institution/germany/)
- [PI · EstoniaPayment institution operating with an exceptionFI](https://protegra.io/licensing/licences/payment-institution/estonia-exception/)
- [PI · EstoniaOperating licence as a payment institutionFI](https://protegra.io/licensing/licences/payment-institution/estonia/)
- [PI · SpainEntidad de pago (EP) / Payment institution authorizationBdE](https://protegra.io/licensing/licences/payment-institution/spain/)
- [PI · IrelandAccount Information Service Provider RegistrationCBI](https://protegra.io/licensing/licences/payment-institution/ireland-aisp/)
- [PI · IrelandPayment Institution AuthorisationCBI](https://protegra.io/licensing/licences/payment-institution/ireland/)
- [PI · LithuaniaPayment institution licence for restricted activityLB](https://protegra.io/licensing/licences/payment-institution/lithuania-restricted/)
- [PI · LithuaniaPayment institution licenceLB](https://protegra.io/licensing/licences/payment-institution/lithuania/)
- [PI · LuxembourgPayment institution authorisationCSSF](https://protegra.io/licensing/licences/payment-institution/luxembourg/)
- [PI · LatviaRegistered payment institutionLB](https://protegra.io/licensing/licences/payment-institution/latvia-registered/)
- [PI · LatviaAuthorised payment institution licenceLB](https://protegra.io/licensing/licences/payment-institution/latvia/)
- [PI · MaltaAccount information service provider registrationMFSA](https://protegra.io/licensing/licences/payment-institution/malta-aisp/)
- [PI · MaltaPayment institution licenceMFSA](https://protegra.io/licensing/licences/payment-institution/malta/)
- [PI · NetherlandsExempt payment service provider registration (Vrijstelling betaaldienstverlener)DNB](https://protegra.io/licensing/licences/payment-institution/netherlands-exempt/)
- [PI · NetherlandsPayment institution licence (Vergunning betaalinstelling)DNB](https://protegra.io/licensing/licences/payment-institution/netherlands/)
- [PI · PolandAccount Information Service Provider registration (dostawca świadczący wyłącznie usługę dostępu do informacji o rachunku - AISP)KNF](https://protegra.io/licensing/licences/payment-institution/poland-aisp/)
- [PI · PolandNational Payment Institution licence (krajowa instytucja płatnicza - KIP)KNF](https://protegra.io/licensing/licences/payment-institution/poland-kip/)
- [PI · PolandSmall Payment Institution registration (mała instytucja płatnicza - MIP)KNF](https://protegra.io/licensing/licences/payment-institution/poland-mip/)
- [PI · SlovakiaPayment institution licence (povolenie na poskytovanie platobných služieb bez obmedzenia rozsahu)NBS](https://protegra.io/licensing/licences/payment-institution/slovakia/)

## Regulators that apply it

- [GermanyFederal Financial Supervisory Authority (BaFin)BaFin operates as Germany's unified federal financial supervisor under the Federal Ministry of Finance, supervising credit institutions, fin](https://protegra.io/licensing/regulators/bafin-germany/)
- [SpainBank of Spain (BdE)Banco de España is Spain's national central bank and banking supervisor, operating as an integral part of the European System of Central Ban](https://protegra.io/licensing/regulators/banco-de-espana/)
- [LithuaniaBank of Lithuania (LB)The Bank of Lithuania operates as the central bank of the Republic of Lithuania and member of the Eurosystem, conducting integrated prudenti](https://protegra.io/licensing/regulators/bank-of-lithuania/)
- [IrelandCentral Bank of Ireland (CBI)The Central Bank of Ireland serves the public interest by maintaining monetary and financial stability while ensuring that the financial sys](https://protegra.io/licensing/regulators/central-bank-of-ireland/)
- [Czech RepublicCzech National Bank (CNB)The Czech National Bank acts as the central bank and unified supervisory authority of the Czech financial market under Act No. 6/1993 Coll.](https://protegra.io/licensing/regulators/cnb-czechia/)
- [LuxembourgCommission de Surveillance du Secteur Financier (CSSF)The CSSF operates as the unified public supervisory authority for the Luxembourg financial centre, conducting prudential supervision and mar](https://protegra.io/licensing/regulators/cssf-luxembourg/)
- [NetherlandsDe Nederlandsche Bank (DNB)De Nederlandsche Bank acts as the central bank of the Netherlands and integral member of the Eurosystem and ESCB, exercising prudential supe](https://protegra.io/licensing/regulators/dnb-netherlands/)
- [European UnionEuropean Banking Authority (EBA)The European Banking Authority is an independent EU agency that creates the European Single Rulebook for banking and payments, fosters super](https://protegra.io/licensing/regulators/eba/)
- [EstoniaFinantsinspektsioon (FI)Finantsinspektsioon is Estonia's independent financial supervision and crisis resolution authority operating with autonomous responsibilitie](https://protegra.io/licensing/regulators/finantsinspektsioon-estonia/)
- [PolandPolish Financial Supervision Authority (KNF)KNF ensures the proper functioning, stability, security, and transparency of the Polish financial market, safeguards public confidence in fi](https://protegra.io/licensing/regulators/knf-poland/)
- [LatviaLatvijas Banka (LB)Latvijas Banka is the central bank of the Republic of Latvia and member of the Eurosystem, operating as the single integrated financial supe](https://protegra.io/licensing/regulators/latvijas-banka/)
- [MaltaMalta Financial Services Authority (MFSA)The Malta Financial Services Authority is the single autonomous financial regulator in Malta, entrusted with prudential and conduct supervis](https://protegra.io/licensing/regulators/mfsa-malta/)
- [SlovakiaNational Bank of Slovakia (NBS)Národná banka Slovenska acts as the central bank and integrated financial supervisory authority of the Slovak Republic. It safeguards price](https://protegra.io/licensing/regulators/nbs-slovakia/)

## Upcoming changes

- PSD3 (COM(2023) 366) and the Payment Services Regulation (COM(2023) 367) are to replace this directive. The European Parliament's committee approved the text agreed with the Council on 5 May 2026; as of September 2026 the procedure still awaits formal adoption. [3]
- Conduct of business, open banking access, and Strong Customer Authentication rules currently in PSD2 will transfer to the directly applicable Payment Services Regulation (PSR, COM(2023) 367), introducing mandatory Confirmation of Payee verification across the EU. [4]

## Sources

1. [eur-lex.europa.eu: TXT (32015L2366)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32015L2366): retrieved 2026-09-24
2. [eur-lex.europa.eu: TXT (02015L2366-20250117)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02015L2366-20250117): retrieved 2026-09-24
3. [oeil.europarl.europa.eu: procedure file](https://oeil.europarl.europa.eu/oeil/en/procedure-file?reference=2023/0209(COD)): retrieved 2026-09-24
4. [eur-lex.europa.eu: TXT (52023PC0367)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52023PC0367): retrieved 2026-09-24

Last verified 2026-09-24 · Author: Danil Marmysh · Reviewed by Anastasia Sidorenkova · © Protegra. Data: CC BY 4.0, cite "Protegra Licensing Atlas". Not legal advice.
