What Is PSD2: Meaning and Implications for UK Businesses
  • Product News

What Is PSD2: Meaning and Implications for UK Businesses

If you take card payments every day, PSD2 already shapes how those payments work.

Standing for the (revised) Payment Services Directive 2, and in force in the EU since 13 January 2018, PSD2 brought major changes to consumer protection, payment security, and how banks share financial data.

In the following sections, we explain what PSD2 is, what it means for UK businesses in practice, and how the upcoming PSD3 reforms in the EU are likely to influence where UK payments regulation goes next.

What Is PSD2?

PSD2, or the Payment Services Directive 2, is the EU’s revised legal framework for payment services, replacing the original Payment Services Directive (PSD1) of 2007

Formally adopted by the European Parliament in 2015 and in force from 13 January 2018, PSD2 was designed to modernise a payments market that had moved on considerably from PSD1’s original scope.

PSD2’s main objectives are:

  • Consumer protection – stronger authentication requirements and clearer liability rules for unauthorised payments;
  • Competition and innovation in payments – opening up bank data to regulated third parties, giving rise to Open Banking;
  • A more integrated digital single market for payments across the European Economic Area (EEA).

Where PSD1 focused mainly on regulating traditional banks and payment providers, PSD2 widened the net to cover new categories of firms. For example, these include Account Information Service Providers and Payment Initiation Service Providers.

This is combined with the introduction of Strong Customer Authentication as a baseline security requirement across the industry.

Why Was PSD2 Introduced?

Why Was PSD2 Introduced?

PSD1 vs PSD2 comes down to one thing. PSD1 simply hadn’t kept pace with how people were actually paying for things. 

By the early 2010s, digital payments and fintech companies were growing quickly, and PSD1 had no real framework for services like account aggregation or third-party payment initiation.

Both of which had emerged organically without formal payment regulations behind them.

PSD2 was introduced to close that gap. It responded to:

  • The limitations of PSD1, which pre-dated mobile and app-based payments almost entirely;
  • The rise of fintech companies offering account aggregation, budgeting tools, and alternative ways to pay;
  • The need for stronger payment security, given rising card-not-present and online fraud;
  • The push for a more integrated payments market, so a payment service authorised in one EEA state could operate across all of them.

The result was a directive built specifically around financial technology innovation. It regulates the third-party providers reshaping the payments landscape, rather than trying to fit them into rules written for an earlier era.

Does PSD2 Apply to the UK?

Yes, PSD2 applies to the UK, with an important nuance. 

The UK implemented PSD2 before Brexit through the Payment Services Regulations 2017, which came fully into force on 13 January 2018. 

When the UK left the EU, this framework wasn’t repealed. It was “onshored” into UK law as retained EU legislation. The FCA remains the competent authority responsible for authorising and supervising payment service providers under it.

In practice, this means:

  • Most PSD2 principles remain in force in the UK, including Strong Customer Authentication and the regulated role of Account Information Service Providers and Payment Initiation Service Providers.
  • The FCA, alongside the Payment Systems Regulator, continues to oversee compliance, complaints, and authorisation of payment firms.
  • UK Open Banking continues to operate under its own domestic governance, building on the API standards originally created to meet PSD2’s requirements.
  • The UK and EU frameworks are starting to diverge, particularly now that the EU is replacing PSD2 with PSD3 and a new Payment Services Regulation (PSR) (reforms the UK isn’t bound by).

HM Treasury, the FCA, the Payment Systems Regulator and the Bank of England published a joint Payments Forward Plan in February 2026, setting out a UK-specific regulatory roadmap for 2026-2028. 

So while the UK isn’t following PSD3 directly, expect UK payment regulations to keep evolving in a broadly similar direction.

How PSD2 Changed the Payments Industry

PSD2’s biggest legacy is arguably Open Banking. 

Open Banking is all about the ability for customers to give regulated third parties secure, consent-based access to their account data and payment initiation, via standardised APIs rather than screen-scraping or shared passwords.

Alongside Open Banking, PSD2 reshaped the payment landscape through:

  • Strong Customer Authentication, requiring multi-factor authentication for most online and card transactions;
  • Regulated third-party providers, bringing account aggregators and payment initiation services fully within the payment regulations for the first time;
  • Greater competition, as banks were required to open up data access rather than controlling it exclusively;
  • Consumer control over financial data, since sharing is now permission-based and revocable rather than the default

These changes moved payment processing away from being solely the domain of banks and card networks, and towards a broader ecosystem of licensed providers working alongside them.

How PSD2 Works

At a mechanical level, PSD2 works by creating a regulated, consent-based bridge between banks (or other account-holding institutions) and third-party providers.

Here is how it works:

  • Banks and payment institutions hold customer accounts and, under PSD2, must expose secure APIs for regulated access to that data.
  • Third-party providers connect to those APIs once authorised or registered with the relevant regulator (the FCA, in the UK).
  • Customer consent is required before any data sharing or payment initiation can take place, and that consent can be withdrawn at any time.
  • Data sharing and payment initiation then happen directly between the bank and the third-party provider, without the customer needing to hand over their online banking password to a third party.

This is what makes PSD2 fundamentally different from earlier data-sharing methods. 

Access is granted deliberately, through regulated channels, rather than through credentials being shared informally.

Third-Party Providers Under PSD2

Two categories of third-party providers sit at the centre of PSD2, each authorised or registered separately depending on what they do.

Account Information Service Providers (AISPs)

AISPs let customers and businesses view financial data from multiple accounts in one place, without needing to log in separately to each bank. 

They’re typically used for:

  • Account aggregation – combining balances and transactions from several banks into a single dashboard;
  • Financial insights – analysing spending patterns, cash flow, and affordability;
  • Consumer use cases – budgeting apps, accounting software connections, and credit assessments that read account data directly rather than relying on manual statements.

Because AISPs only read data – they can’t move money – their regulatory burden focuses on data security and consent management rather than payment execution.

Payment Initiation Service Providers (PISPs)

PISPs do something different.

They initiate payments directly from a customer’s bank account, without the transaction passing through a card scheme.

  • Direct account-to-account payments – customers authorise a payment via their own online banking, rather than entering card details.
  • Merchant benefits – bank-to-bank payments can settle faster and typically cost less than card processing.
  • Payment initiation process – the PISP requests the payment, the customer confirms it through their bank’s own authentication step, and funds move directly.

For UK merchants, PISP-powered “Pay by Bank” style payments are becoming a genuine alternative to card payments at checkout, particularly for higher-value transactions where card fees add up.

Both AISPs and PISPs are required under PSD2 to hold Professional Indemnity Insurance, covering liabilities that could arise from unauthorised access or misuse of account information.

How PSD2 Affects Contactless Payments

How PSD2 Affects Contactless Payments

PSD2’s Strong Customer Authentication rules introduced transaction and cumulative spending thresholds for contactless card payments in the EU.

A single transaction above €50, or five consecutive contactless payments, or cumulative spending above €150 would all trigger a PIN prompt.

The UK adopted its own version of this model early on, using GBP thresholds rather than euros.

Most recently, this threshold is a £100 single transaction limit, with a cumulative cap of roughly £300 or five consecutive taps triggering a PIN request. 

However, UK rules have now moved beyond this fixed model. 

From 19 March 2026, the FCA removed the mandatory £100 contactless limit, giving banks and payment providers the flexibility to set their own transaction and cumulative limits, provided they maintain strong fraud controls. 

In practice, most major UK banks have said they’ll keep the existing £100/£300 structure in place for now, but the regulatory requirement for a single national limit no longer exists.

Considering this, UK contactless limits may start to vary more by provider over the next few years.

For UK businesses accepting contactless payments, this means that existing card terminals continue to work exactly as before. 

It also means that PIN prompts still protect customers from high fraud exposure and consumer protection for lost or stolen cards remains unchanged regardless of which limit a customer’s bank applies.

Benefits of PSD2 for Consumers

For everyday shoppers, PSD2 delivers several concrete benefits:

  • Better fraud protection, since SCA naturally reduces fraudulent card-not-present transactions;
  • Greater transparency around fees, providers, and how payment data is used;
  • More control over financial data, with consent-based sharing that can be revoked at any time;
  • Increased payment choice, as Open Banking-powered services and PISPs offer alternatives to traditional card payments.

Together, these add up to meaningfully stronger consumer rights in payments than existed before PSD2, particularly around transaction security and data access for third parties.

Get the perfect payment solution for your business

Enjoy 10% off your first order when you fill in the form below!

Benefits of PSD2 for Businesses

PSD2 isn’t only a consumer protection measure. It creates real commercial upside for merchants too:

  • Reduced fraud, thanks to SCA and multi-factor authentication, cutting down chargebacks tied to unauthorised transactions;
  • Better payment security, which supports regulatory compliance in payments and reduces the operational cost of handling disputes;
  • Open Banking opportunities, including cheaper, faster account-to-account payments via PISPs;
  • Improved customer trust, since PSD2-compliant checkouts signal that a business takes payment regulations seriously.

Furthermore, it creates room for more payment innovation. 

Open Banking access enables new products, from automated reconciliation tools to embedded finance features, that weren’t practical before.

How PSD2 Affects UK Businesses

For UK SMEs, PSD2 compliance shows up in a handful of practical places:

  • Accepting online payments – most checkouts now require an SCA step (commonly 3D Secure) for card payments above certain thresholds or risk levels.
  • Card payment compliance – your payment provider typically handles the technical SCA implementation, but you control the checkout experience around it.
  • Open Banking opportunities – UK businesses can now accept Pay by Bank-style payments via PISPs, often at a lower cost than card processing.
  • Working with payment providers – choosing a provider that keeps up with evolving payment regulations reduces your own compliance burden.
  • Customer authentication requirements – clear, consistent checkout messaging around SCA prompts helps reduce abandoned payments and false-positive fraud flags

A common misconception is that “the payment provider handles compliance, so I don’t need to think about it.” 

In reality, a business still controls checkout design, how failed authentications are communicated to customers, and how refunds and disputes are handled.

All of the above affect conversion rates as much as compliance. 

myPOS and similar UK payment providers build SCA and Open Banking capability directly into their card machines and online checkout tools. This means that businesses get PSD2-compliant payment processing without having to manage the underlying authentication infrastructure themselves.

What Is PSD3 And How It Builds On PSD2

PSD3 is the EU’s next iteration of payment services regulation, intended to refine PSD2 rather than replace its foundations. 

The European Parliament and Council reached a provisional political agreement on PSD3, alongside a new directly applicable Payment Services Regulation (PSR).

PSD3 focuses on:

  • Improving Open Banking frameworks, addressing API performance and reliability issues that have frustrated third-party providers since PSD2;
  • Stronger fraud prevention and consumer protection, particularly around authorised push payment (APP) fraud;
  • Better standardisation across EU member states, reducing the inconsistent implementation that has affected PSD2 in practice.

Crucially, the EU has split its new framework into two instruments.

These are PSD3 (a directive, transposed nationally) and the PSR (a regulation, directly applicable EU-wide), which is expected to reduce the kind of fragmented implementation that made PSD2 compliance harder for cross-border payment service providers.

Key Differences Between PSD2 And PSD3

The clearest distinctions between the two frameworks are:

  • Improved API performance and reliability – PSD3/PSR push for measurable service-level standards for Open Banking APIs, rather than PSD2’s more general requirement to provide access;
  • Enhanced fraud monitoring – stronger obligations around detecting and preventing authorised push payment fraud;
  • Clearer rules for third-party providers – merging payment institution and e-money institution licensing frameworks, simplifying authorisation for firms operating across both categories;
  • Stronger consumer rights – expanded reimbursement obligations where fraud results from inadequate provider safeguards.

Overall, dispute handling is improved, offering more consistent complaint and redress processes across member states

How PSD3 Will Impact Businesses And Payments

Although PSD3 doesn’t directly apply in the UK, its direction of travel matters for any UK business with EU customers, suppliers, or payment partners. 

It signals where UK payment regulations are likely heading. 

Expect:

  • More secure and seamless payments, as improved API standards make Open Banking connections more reliable;
  • Reduced fraud and chargebacks, driven by stronger fraud monitoring obligations;
  • Updated compliance requirements for UK-authorised payment institutions and e-money firms with EU-facing operations, which will need re-authorisation under PSD3’s merged licensing framework;
  • Continued growth of Open Banking, both in the EU under PSD3/PSR and in the UK under its own Payments Forward Plan (2026–2028);
  • Expansion of embedded finance, as clearer third-party provider rules make it easier for non-financial businesses to embed regulated payment features into their own products

Notably, on some fronts, the UK is already ahead of where PSD3 is heading.

The Payment Systems Regulator’s mandatory reimbursement scheme for authorised push payment fraud has been in force since October 2024, and the FCA’s supplementary safeguarding regime takes effect from 7 May 2026, tightening how customer funds are protected ahead of any wider legislative change.

Conclusion

PSD2 transformed how payments work.

For UK businesses, the practical reality hasn’t changed much since Brexit. Most PSD2 principles continue to apply through the Payment Services Regulations 2017, supervised by the FCA, even as the UK and EU frameworks start to take slightly different paths.

PSD3 is best understood as a refinement of PSD2, not a replacement of its core foundations. UK companies don’t need to comply with PSD3 directly, but keeping an eye on both the EU reforms and the UK’s own Payments Forward Plan will help you stay ahead of where payment regulations and customer expectations are heading next.

Frequently Asked Questions

Recurring payments may be exempt from Strong Customer Authentication (SCA) after the initial payment has been authenticated.

SCA usually requires customers to verify their identity using at least two authentication factors, such as a password, phone, or fingerprint.

Yes. One-click payments are still possible, although some transactions may require SCA depending on the circumstances.

If PSD2 and SCA requirements aren’t followed, payment providers or merchants may be liable for unauthorised transactions.

Payments under €30 may qualify for an SCA exemption, although banks can still request authentication in certain situations.

Most payment gateways have updated their systems to support PSD2, but you should ensure your provider is fully compliant with the latest requirements.

Related articles

myPOS Announces Its Most Modern and Durable Payment Machine Yet

myPOS Announces Its Most Modern and Durable Payment Machine Yet

  • Product News
6 Uses of QR Technologies in the Restaurant Industry

6 Uses of QR Technologies in the Restaurant Industry

  • Product News
The Versatile myPOS Go Combo is Here

The Versatile myPOS Go Combo is Here

  • Product News

Stay informed. Stay inspired.

Stay ahead of the game - sign up for the latest myPOS news, exclusive updates, and expert insights to boost your business!

Cookie

Select your cookie preference