🎓 CoursesRisk & complianceIntermediate⏱ 60 min

Payment regulation: from PSD1 to the PSD3/PSR package. 7 chapters and a final quiz.

A one-hour course on why and how Europe regulates payments: PI and EMI status and licensing, what PSD2 introduced (open banking, SCA and its exemptions, liability under L. 133-18), the IFR interchange caps and brand choice, the 2024 instant payments regulation and Verification of Payee, and MiCA and DORA in brief. It then covers the PSD3/PSR package: what it changes, the 2026–2028 timeline, and the practical impact on a merchant or a fintech.

Chapter 1. Why regulate payments?

Payments are critical infrastructure. Every euro of wages, rent, or revenue moves through private systems (banks, card networks, PSPs), and a failure or abuse in any of them would have systemic effects. The market is also driven by strong network effects: the more widely a payment method is accepted, the more it gets used. Left alone, it drifts toward oligopoly. Payments are also a target for fraud at industrial scale. Since 2007, European regulation has pursued the same three objectives.

  • Protect: ring-fence customer funds (safeguarding), refund victims of unauthorized transactions, and require strong authentication.
  • Open up: break the banking monopoly (PI and EMI status), cap interchange fees, and force access to accounts (open banking) and to payment systems.
  • Secure the system as a whole: operational resilience (DORA), Eurosystem oversight of payment systems, and rules for crypto-assets used for payments (MiCA).
€1.2B
annual payment fraud in France in 2024 (a stable amount)
OSMP (Banque de France), 2025 report
0,053 %
card fraud rate in France in 2024, a record low
OSMP (Banque de France), 2025 report
€382M
fraud by manipulating the payer in 2024, or 32% of the total
OSMP (Banque de France), 2025 report

Who does what in European payment regulation

🇪🇺
Commission, Parliament, Council
They propose and adopt the legislation (directives and regulations): the PSDs, the IFR, the IPR, MiCA, DORA, and the PSD3/PSR package.
🏛️
EBA
The European Banking Authority drafts the regulatory technical standards (RTS, including those on SCA) and guidelines. It also maintains the registers of licensed firms.
🏦
ECB / Eurosystem
Oversees payment systems and schemes (TARGET, oversight of card and credit transfer schemes) and leads the digital euro project.
🇫🇷
ACPR and Banque de France
The ACPR licenses and supervises French PIs and EMIs. The Banque de France (France's central bank) oversees payment methods and runs the OSMP, its payment security observatory. The CNIL, France's data protection authority, covers personal data.

Directive or regulation: a difference that changes everything

A directive (PSD1, PSD2, the future PSD3) sets objectives that each member state transposes into national law; in France, into the Monetary and Financial Code. Timelines vary, and sometimes so do interpretations. A regulation (the IFR, the IPR, MiCA, DORA, the future PSR) is directly applicable across the EU, with no transposition. The same rules apply on the same timeline everywhere. The PSD3/PSR package makes exactly this shift. Most of the conduct rules move from the directive into a regulation, to end national divergence.

2007
DSP1
End of the banking monopoly: payment institutions are created, and SEPA gets its legal foundation.
2009
DME2
E-money institution status (Directive 2009/110/EC).
2015
IFR + PSD2
Interchange caps (Regulation 2015/751) and the second Payment Services Directive (2015/2366).
Sept. 2019
SCA
The RTS on strong authentication take effect (e-commerce migration completed in early 2021).
2022-2023
DORA and MiCA
Digital operational resilience and rules for crypto-assets.
2024
IPR
Instant Payments Regulation (2024/886): 2025 deadlines for the euro area.
Nov. 2025
PSD3/PSR agreement
Provisional political agreement between Parliament and Council on November 27, 2025; expected to apply around 2028.
🎯 Quick question
What is the fundamental difference between a directive (PSD2) and a regulation (the IFR, the future PSR)?