Don’t do SECURITY. Do business SECURELY.

PSD2 arrives: Payment Services Regulations 2017 apply

The Payment Services Regulations 2017, implementing PSD2 in the UK, now apply, with new security and incident reporting obligations.

The Payment Services Regulations 2017, implementing the EU’s revised Payment Services Directive (PSD2), apply from today.

Security obligations for payment service providers

  • Regulation 98: maintain a framework of mitigation measures and control mechanisms for operational and security risks, and provide an annual risk assessment to the FCA.
  • Regulation 99: notify the FCA of major operational or security incidents without undue delay.
  • Regulation 100: strong customer authentication (multi-factor) for electronic payments and account access, with detailed technical standards to follow.

PSD2 also opens up access to payment accounts for authorised third-party providers, creating new interfaces that must be secured. Suppliers to payment firms should expect more detailed security requirements in contracts and due diligence.

Source: Payment Services Regulations 2017 (legislation.gov.uk)

This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.

More insights