The Payment Services Regulations 2017, implementing the EU’s revised Payment Services Directive (PSD2), apply from today.
Security obligations for payment service providers
- Regulation 98: maintain a framework of mitigation measures and control mechanisms for operational and security risks, and provide an annual risk assessment to the FCA.
- Regulation 99: notify the FCA of major operational or security incidents without undue delay.
- Regulation 100: strong customer authentication (multi-factor) for electronic payments and account access, with detailed technical standards to follow.
PSD2 also opens up access to payment accounts for authorised third-party providers, creating new interfaces that must be secured. Suppliers to payment firms should expect more detailed security requirements in contracts and due diligence.
Source: Payment Services Regulations 2017 (legislation.gov.uk)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.