Payment regulation: from PSD1 to the PSD3/PSR package. 7 chapters and a final quiz.
A one-hour course on why and how Europe regulates payments: PI and EMI status and licensing, what PSD2 introduced (open banking, SCA and its exemptions, liability under L. 133-18), the IFR interchange caps and brand choice, the 2024 instant payments regulation and Verification of Payee, and MiCA and DORA in brief. It then covers the PSD3/PSR package: what it changes, the 2026–2028 timeline, and the practical impact on a merchant or a fintech.
Explain the three purposes of payment regulation (protecting funds, competition, security) and the role of each authority: the Commission, the EBA, the ECB, and the ACPR
Tell payment institution and e-money institution status apart: licensing, initial capital, safeguarding of funds, and the European passport
Master what PSD2 introduced: open banking (AISP/PISP), strong authentication and its quantified exemptions, and the liability regime of articles L. 133-18 to L. 133-24
Apply the Interchange Fee Regulation (IFR): the 0.2% and 0.3% caps, brand choice on co-badged cards, and itemized fee billing
Chapter 1. Why regulate payments?
Payments are critical infrastructure. Every euro of wages, rent, or revenue moves through private systems (banks, card networks, PSPs), and a failure or abuse in any of them would have systemic effects. The market is also driven by strong network effects: the more widely a payment method is accepted, the more it gets used. Left alone, it drifts toward oligopoly. Payments are also a target for fraud at industrial scale. Since 2007, European regulation has pursued the same three objectives.
Protect: ring-fence customer funds (safeguarding), refund victims of unauthorized transactions, and require strong authentication.
Open up: break the banking monopoly (PI and EMI status), cap interchange fees, and force access to accounts (open banking) and to payment systems.
Secure the system as a whole: operational resilience (DORA), Eurosystem oversight of payment systems, and rules for crypto-assets used for payments (MiCA).
€1.2B
annual payment fraud in France in 2024 (a stable amount)
OSMP (Banque de France), 2025 report
0,053 %
card fraud rate in France in 2024, a record low
OSMP (Banque de France), 2025 report
€382M
fraud by manipulating the payer in 2024, or 32% of the total
OSMP (Banque de France), 2025 report
Who does what in European payment regulation
🇪🇺
Commission, Parliament, Council
They propose and adopt the legislation (directives and regulations): the PSDs, the IFR, the IPR, MiCA, DORA, and the PSD3/PSR package.
🏛️
EBA
The European Banking Authority drafts the regulatory technical standards (RTS, including those on SCA) and guidelines. It also maintains the registers of licensed firms.
🏦
ECB / Eurosystem
Oversees payment systems and schemes (TARGET, oversight of card and credit transfer schemes) and leads the digital euro project.
🇫🇷
ACPR and Banque de France
The ACPR licenses and supervises French PIs and EMIs. The Banque de France (France's central bank) oversees payment methods and runs the OSMP, its payment security observatory. The CNIL, France's data protection authority, covers personal data.
Directive or regulation: a difference that changes everything
A directive (PSD1, PSD2, the future PSD3) sets objectives that each member state transposes into national law; in France, into the Monetary and Financial Code. Timelines vary, and sometimes so do interpretations. A regulation (the IFR, the IPR, MiCA, DORA, the future PSR) is directly applicable across the EU, with no transposition. The same rules apply on the same timeline everywhere. The PSD3/PSR package makes exactly this shift. Most of the conduct rules move from the directive into a regulation, to end national divergence.
2007
DSP1
End of the banking monopoly: payment institutions are created, and SEPA gets its legal foundation.
2009
DME2
E-money institution status (Directive 2009/110/EC).
2015
IFR + PSD2
Interchange caps (Regulation 2015/751) and the second Payment Services Directive (2015/2366).
Sept. 2019
SCA
The RTS on strong authentication take effect (e-commerce migration completed in early 2021).
2022-2023
DORA and MiCA
Digital operational resilience and rules for crypto-assets.
2024
IPR
Instant Payments Regulation (2024/886): 2025 deadlines for the euro area.
Nov. 2025
PSD3/PSR agreement
Provisional political agreement between Parliament and Council on November 27, 2025; expected to apply around 2028.
🎯 Quick question
What is the fundamental difference between a directive (PSD2) and a regulation (the IFR, the future PSR)?
Chapter 2. From PSD1 to PSD2: PI and EMI status and licensing.
Before 2007, you had to be a bank to collect funds on behalf of others. PSD1 (Directive 2007/64/EC, transposed in France in 2009) created payment institution (PI) status. The license is lighter, in proportion to a payments business that takes no deposits and extends no credit. The second E-Money Directive, EMD2 (2009/110/EC), did the same for electronic money with e-money institution (EMI) status. Europe's PSPs, wallets, and neobanks grew on this foundation; PSD2 (Directive 2015/2366, in effect since January 13, 2018) then expanded and tightened it.
PIs and EMIs are not covered by deposit insurance. In exchange, customer funds must be safeguarded: held in a segregated account at a credit institution, or covered by insurance or an equivalent guarantee. That keeps them out of creditors' reach if the PSP fails. Safeguarding breaches are among the most common grounds for ACPR sanctions, and the PSD3 package tightens these requirements further by requiring firms to spread safeguarded funds across several banks.
Exemptions, agents, and passporting
Limited network: cards usable only within a restricted network (a retailer's gift card, a fuel card) are exempt from licensing, but must be notified above €1 million in annual volume.
Commercial agent: an intermediary that negotiates for only one of the two parties can be exempt. Marketplaces long relied on this loophole until PSD2 closed it, which is why so many marketplaces now safeguard their funds with third-party PIs and EMIs.
Agents and distributors: a PI can operate through registered agents, and an EMI through distributors, with the principal institution fully liable.
European passport: a license obtained in one member state lets a firm operate across the EU and EEA, either cross-border or through a branch. That explains the rise of Luxembourg, Lithuania, and Ireland as hubs.
PSD2 also tightened ongoing requirements: governance, the AML/CFT program, systems security (reporting of major incidents), and fraud reporting to the ACPR and the EBA. A license brings permanent supervision; it is not a one-time formality.
🎯 Quick question
What is the minimum initial capital required for an e-money institution (EMI)?
Chapter 3. Open banking and strong authentication: the core of PSD2.
PSD2's most radical change is access to accounts (XS2A). Account-holding banks (ASPSPs) must open access to payment accounts without a prior contract and free of charge. Two new regulated types of firm benefit: payment initiation service providers (PISPs, art. 66) and account information service providers (AISPs, art. 67). The RTS require secure access interfaces (APIs). In practice, their uneven quality remains the Achilles' heel of European open banking, and the PSD3/PSR package aims to fix it.
Payment initiation (PIS): paying by bank transfer on a merchant's website
Customer
Chooses “pay by bank transfer” at checkout
Selects their bank
➜
PISP
Prepares the transfer order and redirects to the bank
Amount and payee prefilled (dynamic linking)
➜
Bank (ASPSP)
Authenticates the customer with SCA
Banking app, biometrics, or OTP
➜
Bank (ASPSP)
Executes the transfer (often SCT Inst)
Funds irrevocable within seconds
➜
PISP
Confirms initiation to the merchant
The merchant can ship
SCA: two factors and dynamic linking
Strong customer authentication (SCA) requires at least two factors from different categories: knowledge (a password or PIN), possession (an enrolled phone, a card), and inherence (biometrics). Remote payments also require dynamic linking: the authentication code is cryptographically bound to the amount and the payee, so any change invalidates it. SCA has applied since September 14, 2019 (RTS 2018/389) and was fully enforced for e-commerce in early 2021.
Exemption
Limit
Key condition
Low-value remote payment
30 €
Cumulative €100 or 5 consecutive transactions without SCA
Contactless in store
50 €
Cumulative €150 or 5 consecutive transactions without SCA
Transaction risk analysis (TRA)
100 € / 250 € / 500 €
Fraud rate of the PSP applying the exemption at or below 0.13%, 0.06%, or 0.01%, respectively
Trusted beneficiaries
None
Allowlist the customer manages with their bank
Fixed-amount recurring transactions
None
SCA on the first transaction, exempt thereafter
Corporate payments (dedicated protocols)
None
Secure protocols reserved for business payers (lodged cards, treasury transfers)
Transit fares and parking machines
None
Unattended terminals dedicated to these uses
SCA exemptions under the RTS
Don't confuse exemptions with transactions that are out of scope for SCA: MOTO payments (mail order or telephone order), one-leg-out transactions (issuer or acquirer outside the EEA), anonymous cards, and above all MITs (merchant-initiated transactions). The merchant initiates an MIT under a mandate, such as a variable-amount subscription. SCA is required when the mandate is set up, not on each payment.
⚠️
Liability under the French Monetary and Financial Code
L. 133-18: when an unauthorized transaction is reported, the refund must be immediate, and no later than the end of the next business day, unless the bank has documented grounds to suspect the customer of fraud. L. 133-19: the cardholder's liability is capped at €50 for a lost or stolen card used before it was reported, and falls to €0 if the bank did not require SCA. L. 133-24: the customer has 13 months to report an unauthorized transaction. SCA is not just a UX constraint. It decides who bears the fraud loss.
🎯 Quick question
An acquirer wants to exempt transactions up to €500 from SCA through TRA. What fraud rate must it maintain?
Chapter 4. The Interchange Fee Regulation (IFR): caps and brand choice.
Interchange is the fee the acquirer pays the issuing bank on every card payment, and it is passed on to the merchant in the MSC. After 15 years of litigation over its anticompetitive effects, Regulation (EU) 2015/751 (the IFR) capped it for consumer cards. The caps have applied since December 9, 2015, and the business rules (brand choice, itemized billing) since June 9, 2016.
0,2 %
interchange cap on consumer debit cards
Regulation (EU) 2015/751, art. 3
0,3 %
interchange cap on consumer credit cards
Regulation (EU) 2015/751, art. 4
June 9, 2016
business rules take effect: brand choice, unblending, limits on honor-all-cards
The caps do not covercommercial cards (business and corporate), three-party schemes such as American Express when they use no third-party issuers, or cards issued outside the EEA. Interchange on commercial cards is often 3 to 5 times higher. Interregional transactions are capped separately, through commitments by Visa and Mastercard, at 1.15% to 1.5% online.
Article 8: co-badging and brand choice
Nearly every French payment card is co-badged CB + Visa or CB + Mastercard (CB, or Cartes Bancaires, is France's domestic card scheme). The IFR bars schemes from imposing a brand. So the merchant sets the default brand on its terminal or payment page, often CB, which has historically had competitive fees. But the consumer keeps the right to choose the other brand for any transaction. This “routing” is a real cost lever for French merchants. The same battle is now playing out online in wallets, where Apple Pay has opened up a choice between CB, Visa, and Mastercard.
Article 9: the end of opaque bundled pricing (unblending)
By default, the acquirer must offer fees broken down by card category and brand: interchange, scheme fees, and its own margin. A merchant can explicitly request a single “blended” rate. Together with the caps, unblending pushed large merchants toward Interchange++ pricing, which passes interchange cuts straight through to them. The honor-all-cards rule is also limited: accepting a brand's debit cards no longer obliges a merchant to accept its credit or commercial cards.
⚠️
The blind spot: scheme fees
The IFR caps interchange but not the network fees (scheme fees) that Visa and Mastercard charge. European merchant federations have documented steep increases since 2016, to the point that the Commission reopened the issue in its IFR review and through investigations into the international schemes' fees. Keep this in mind when renegotiating any acquiring contract.
🎯 Quick question
What interchange cap does the IFR set for a consumer debit card?
Chapter 5. The 2024 Instant Payments Regulation: instant transfers for everyone, plus VoP.
SEPA Instant Credit Transfer is an EPC scheme launched in 2017. Funds are credited irrevocably in under 10 seconds, 24/7. Yet SCT Inst long remained a niche product, often priced at a premium; it still accounted for only 10% of credit transfers sent in France in 2024. Regulation (EU) 2024/886, the Instant Payments Regulation (IPR), which entered into force on April 8, 2024, makes it mandatory and brings its price into line with standard transfers.
January 9, 2025
Mandatory reception (euro area)
Every euro area PSP that offers credit transfers must be able to receive SCT Inst, may not charge more for instant transfers than for standard ones, and switches to daily sanctions screening of its customer base (instead of screening each transaction).
October 9, 2025
Mandatory sending + VoP
Mandatory sending of SCT Inst, and Verification of Payee on all SEPA credit transfers.
January 9, 2027
Outside the euro area: reception
PSPs in member states outside the euro area must be able to receive SCT Inst in euros.
July 9, 2027
Outside the euro area: sending
The sending requirement extends to PSPs outside the euro area.
Verification of Payee: the name is checked before every transfer
Since October 9, 2025, before executing a credit transfer (instant or standard), the payer's bank queries the payee's bank to check that the name entered matches the IBAN. There are three possible answers: match, close match (the actual name is displayed), or no match. The payer can still proceed, but does so with a warning. The service is free, and businesses sending bulk transfer files can opt out. It targets fraud using fake bank details and fake suppliers, the core of the €382 million in manipulation fraud recorded in France in 2024.
10 s
maximum time to credit an SCT Inst, 24/7, 365 days a year
EPC SCT Inst scheme
10 %
share of credit transfers sent as instant payments in France in 2024, and growing fast
OSMP (Banque de France), 2025 report
Oct. 9, 2025
VoP mandatory on all SEPA credit transfers in the euro area
Regulation (EU) 2024/886
The IPR also fixes a long-standing asymmetry. It amends the Settlement Finality Directive to give PIs and EMIs direct access to designated payment systems. The Eurosystem opened TARGET to nonbank PSPs in 2025. Fintechs can now settle their flows without relying entirely on a sponsor bank.
🔑
Why it matters strategically for merchants
An instant transfer priced like a standard one and protected by VoP becomes a credible rail for collecting payments: bill payments, immediate refunds, marketplace payouts. The same rail underpins Wero, the European wallet from EPI. For merchants, it offers an account-to-account alternative to cards, with no interchange.
🎯 Quick question
What becomes mandatory for euro area PSPs on October 9, 2025?
Chapter 6. MiCA and DORA in brief: stablecoins and digital resilience.
MiCA: crypto-assets come within the scope of regulation
The MiCA regulation (Markets in Crypto-Assets, (EU) 2023/1114) is the world's first comprehensive framework for crypto-assets. For payments, the key part concerns stablecoins. Tokens backed by a single official currency are e-money tokens (EMTs) and can only be issued by a credit institution or a licensed EMI. Legally, a regulated euro stablecoin is tokenized electronic money, redeemable at par at any time. Tokens backed by a basket of assets (ARTs) have their own regime, with caps on their use for payments when they are not denominated in euros.
June 30, 2024
Titles III and IV apply
The ART and EMT regime takes effect. Circle becomes the first licensed issuer (as an EMI in France) for USDC and EURC.
December 30, 2024
CASP regime takes effect
A single crypto-asset service provider (CASP) license, passportable across the EU.
June 30, 2026
French transition period ends
Firms registered as PSANs (France's former crypto-asset service provider status) must now hold a CASP license (grandfathering ends by July 1, 2026, at the latest, depending on the member state).
DORA: digital operational resilience
The DORA regulation ((EU) 2022/2554), in effect since January 17, 2025, sets a common resilience baseline against IT risk. It covers nearly all financial entities: banks, PIs, EMIs, insurers, and CASPs. Payment chains are directly affected, since an outage at a PSP or a critical cloud provider is now a regulated event.
ICT risk management: governance and a map of critical assets and functions, under the direct responsibility of the management body.
Incidents: major ICT incidents are classified and reported to the supervisor within harmonized deadlines.
Resilience testing: a testing program, up to threat-led penetration testing (TLPT) for significant firms.
ICT third-party risk: a register of information on all IT vendor contracts, mandatory contract clauses, and exit strategies.
Oversight of critical providers: major vendors (especially cloud providers) designated as “critical third-party providers” come under the direct oversight of the European authorities, with the first designations made in 2025.
ℹ️
Why cover these two regulations in a payments course?
MiCA anchors stablecoins in e-money law. Any payment project using EMTs (marketplace settlement, international transfers) requires an EMI or banking license. DORA governs whether payment acceptance chains stay available at all. PSP–merchant contracts now include business continuity, reversibility, and incident reporting requirements that stem from the regulation.
🎯 Quick question
Under MiCA, who can issue an e-money token (a stablecoin backed by a single currency)?
Chapter 7. The PSD3/PSR package: key changes, timeline, and impact.
Proposed by the Commission on June 28, 2023, the package revising PSD2 has two parts. The PSD3 directive now focuses on the licensing and supervision of payment institutions. The PSR (Payment Services Regulation), which applies directly, takes over all the conduct rules: SCA, open banking, transparency, and fraud. A third proposal, FIDA, on financial data access, or “open finance,” is following its own legislative track. After the provisional political agreement of November 27, 2025, formal adoption is expected in 2026.
🪪
Single PI license
EMI status is folded in. E-money becomes a service provided by payment institutions, and existing firms will have to reapply for a license during the transition period.
🔓
Open banking 2.0
Mandatory, high-performing dedicated interfaces (no more fallback mechanism), a list of prohibited obstacles, and dashboards at the bank where customers can view and revoke account access permissions.
🛡️
Stronger fraud prevention
IBAN/name verification for all transfers (already brought in by the IPR), fraud data sharing between PSPs, transaction monitoring, and customer education obligations.
📞
Spoofing fraud
A new refund right. A victim manipulated by a fraudster impersonating their bank (a spoofed phone number or sender ID) can be refunded, subject to conditions (a police report, and no gross negligence).
💶
Access to cash
Merchants will be able to hand out cash without a purchase (cashback capped at a few dozen euros), and independent ATM operators will no longer need a full license.
🏦
PSPs' right to a bank account
Banks will have to justify any refusal or closure of an account held by a PI or fintech, and PIs get broader access to payment systems, building on the IPR.
Spoofing: the clearest sign of how fraud has shifted
SCA sharply reduced “technical” fraud, so fraudsters now target people instead. In France, manipulation fraud accounted for 32% of fraud losses by value in 2024 (OSMP). But a victim who approves a transaction under manipulation has legally “authorized” the payment, so the L. 133-18 refund does not apply. The PSR opens a targeted exception: when the fraudster posed as the bank itself (phone spoofing, a spoofed text message), the PSP will have to refund the victim. The balance was fine-tuned during the trilogue, and the final published text sets the exact conditions.
June 28, 2023
Commission proposal
PSD3 + PSR package (with FIDA on a separate track).
April 23, 2024
Parliament position
First reading adopted before the European elections.
November 27, 2025
Provisional political agreement
Parliament–Council compromise on PSD3 and the PSR in the trilogue.
May 5, 2026
ECON committee approval
The compromise text is approved; formal adoption is expected in late 2026 (Parliament's plenary vote is provisionally scheduled for December 14, 2026), followed by publication in the Official Journal of the EU.
By 2028
In force
The PSR applies 21 months after entry into force (27 months for payee verification), and PSD3 must be transposed within the same 21 months, for an operational switchover expected in the second half of 2028 at the earliest.
Practical impact for merchants
Credit transfers and A2A: instant transfers at standard prices plus VoP create payment rails that compete with cards (Wero, open banking payment initiation) and belong in your checkout strategy.
Supplier workflows: VoP becomes part of outgoing payment processes (any change to a supplier's bank details now triggers a check).
PSP contracts: the 2026–2028 wave of relicensing is a natural window to renegotiate (pricing, DORA clauses, reversibility).
Cash: cashback without a purchase becomes a local service stores can offer.
Practical impact for fintechs
Relicensing: a full application must be filed again (governance, safeguarding across several banks, an orderly wind-down plan, DORA compliance). Start preparing as soon as the text is published.
E-money: no more need for dual PI and EMI status, which simplifies things for wallets and issuers.
Access to infrastructure: direct access to payment systems and a right to a bank account, with reasons required for any refusal, mean less dependence on sponsor banks.
New obligations: VoP, fraud data sharing, and open banking permission dashboards are all product projects to budget for in 2027–2028.
🔑
The course in a nutshell
Twenty years of European regulation have opened up the market (PSD1 and PSD2), capped costs (the IFR), mandated security (SCA, DORA), and modernized the rails (the IPR, MiCA). The PSD3/PSR package, expected to apply around 2028, unifies licensing and shifts the battle to manipulation fraud. Start preparing your licensing, VoP, and customer journeys now.
🎯 Quick question
In the package revising PSD2, why are the conduct rules (SCA, open banking, fraud) in the PSR rather than in PSD3?