What Title III requires before signing
Title III of Directive (EU) 2015/2366 sets out the rules on transparency of conditions and information requirements for payment services. It determines what the provider gives its customer, when, in what form, and in what language, but it does not govern how a payment is executed. Title IV takes over from there and sets the rights and obligations attached to providing the service. The two titles are read together: the first fixes the information owed and the content of the contract, the second the rules for the transactions executed afterward. A framework contract clause that contradicts Title IV has no effect, because the directive requires full harmonization for most of its provisions. The text has applied since January 13, 2018, the deadline by which member states had to complete transposition.
A framework contract is one that governs the future execution of individual and successive payment transactions, and it may include an obligation to open a payment account. The definition covers checking accounts, cardholder agreements, the acceptance agreement a merchant signs with its provider, and subscriptions to a payment initiation service. A one-off payment made outside any such contract falls under a lighter information regime. The classification determines which information is owed and when it becomes due. It is assessed at sign-up, based on the purpose of the contract, not when a later dispute is examined.
Article 4 of the directive defines a durable medium. Any instrument qualifies if it lets the user store information addressed to them personally, access it later for an adequate period, and reproduce it unchanged. An online banking inbox meets that definition. That alone does not prove the information was provided, however, because the directive distinguishes providing information from merely making it available. In case C-375/15, known as BAWAG, the Court of Justice ruled on that distinction on January 25, 2017. Information placed in an electronic mailbox counts as provided only if the provider actively takes steps to bring the message’s existence and availability to the customer’s attention. Otherwise, it has merely been made available, and the customer has to go and look for it. The ruling concerned Directive 2007/64/EC, whose concepts of providing and making available were carried over into PSD2.
| Heading | Required content |
|---|---|
| 1. The provider | Name; geographic address of the head office and, where applicable, of the agent or branch established in the member state where the service is offered; relevant contact addresses; competent supervisory authority; public register of authorization and registration number. |
| 2. Use of the service | Main characteristics; the unique identifier the user must supply for a payment order to be executed correctly; form and procedure for giving and withdrawing consent; time of receipt of a payment order and any cut-off time; maximum execution time; option to agree spending limits; and, for a co-badged card, the rights under Article 8 of Regulation (EU) 2015/751. |
| 3. Charges, interest, and exchange rates | All charges payable to the provider, with a breakdown where relevant; applicable interest and exchange rates or the method for calculating them; the relevant date and reference index; and immediate application of changes in reference rates, if agreed. |
| 4. Communication | Agreed means of communication and related technical requirements; frequency and manner in which information is provided or made available; language of the contract and of communications; and a reminder of the right to obtain the contract terms at any time. |
| 5. Safeguards and corrective measures | Security measures the user must take; how to report loss or theft; secure procedure for alerting the customer in case of suspected fraud; conditions for blocking the instrument; the payer’s liability under Article 74, including the capped amount; time limit and procedure for reporting an unauthorized transaction; the provider’s liability under Articles 73 and 89; and refund conditions under Articles 76 and 77. |
| 6. Changes and termination | Tacit acceptance clause, if agreed; contract term; the user’s right to terminate and the related terms. |
| 7. Redress | Governing law and competent court, if a clause specifies them; out-of-court redress procedures available to the user under Articles 99 to 102. |
Information required by Title III is free: Article 40 prohibits charging for it. A provider may agree charges for additional or more frequent information, or for information sent by a means other than the one specified in the contract. Those charges must be reasonable and in line with the costs actually incurred. Throughout the relationship, the customer can ask to receive the framework contract terms and the Article 52 information on paper or another durable medium, free of charge. The burden of proving compliance with the information requirements, however, is not allocated the same way everywhere: Article 41 merely gives member states the option of placing it on the provider. The applicable rule therefore depends on each member state’s transposing law.
Changing and terminating: from two months’ notice to a free exit
Article 54 of the directive governs changes to a framework contract during its term and subjects them to a single notice period. Such changes are frequent: fee schedules evolve, limits change, and security requirements tighten. Any proposed change must be communicated no later than two months before its proposed effective date, in the same form required for pre-contractual information. The customer’s silence counts as acceptance only if the framework contract expressly says so. In that case, the provider must have told the customer two things: that acceptance will be presumed absent an objection, and that the customer may terminate free of charge at any time until the effective date.
Changes in interest and exchange rates are exempt from the notice period if two conditions are both met: the framework contract must allow for it, and the change must be based on a reference rate agreed between the parties. The customer is informed as soon as possible, unless another frequency has been agreed. A change more favorable to the customer applies without notice. The directive adds a neutrality requirement: changes must be implemented and calculated without discriminating between users. A schedule that passes on rate increases faster than decreases breaches it.
| Case | Rule | Reference |
|---|---|---|
| Termination by the user | At any time, subject to an agreed notice period of no more than one month. | Art. 55(1) |
| Cost of termination | Free, unless the contract has been in force for less than six months. Any charges must be appropriate and in line with costs. | Art. 55(2) |
| Termination by the provider | Allowed for an open-ended contract if the framework contract provides for it, with at least two months’ notice. | Art. 55(3) |
| Recurring charges | Payable pro rata up to termination. Charges paid in advance are refunded pro rata. | Art. 55(4) |
| Termination in response to a change | Free and immediate, at any time before the proposed change takes effect. | Art. 54(1) |
| More favorable national law | Member states may adopt provisions more favorable to the user. | Art. 55(6) |
The tacit acceptance clause has been challenged before the Court of Justice. In case C-287/19, known as DenizBank, decided on November 11, 2020, the Court declined to limit the clause to certain categories of customers or certain types of terms, since PSD2 imposes no such restriction. The Court added a caveat specific to consumer contracts: where the customer is a consumer, these provisions apply without prejudice to Directive 93/13/EEC on unfair contract terms. A broadly worded tacit acceptance clause can therefore still be reviewed by a national court for significant imbalance.
- Date and archive every version of the framework contract, with the date of communication, the channel used, and the customers it was sent to. A change that cannot be dated cannot be enforced against anyone.
- Notify actively when communicating through an online portal, with an alert that tells the customer a message has arrived.
- Make the exit window work in your systems, not just on paper. Free termination must function right up to the date the change takes effect.
- Keep reference rate changes separate from other changes. They follow a different regime and are not subject to the two-month notice period.
- Refund recurring charges paid in advance pro rata, without waiting for a claim. The obligation is set out in Article 55(4).
Execution: from time of receipt to funds availability
Execution of a payment transaction starts at the time the payment order is received, a concept the directive defines itself. The time of receipt is when the order reaches the payer’s provider. If that is not a business day, the order is deemed received on the next business day. The provider may set a cut-off time near the end of the business day, after which orders are also deemed received on the next business day. The cut-off time must be stated in the framework contract. A credit transfer entered at 11 p.m. on a Friday can therefore have its execution clock start on the following Monday, through the combined effect of the cut-off and the business-day rule, without any rule being broken.
| Transaction | Maximum time | Reference |
|---|---|---|
| Euro transaction within the EU, or domestic transaction in the currency of a non-euro member state | Payee’s provider’s account credited by the end of the following business day at the latest after receipt of the order | Art. 82(1) and Art. 83(1) |
| Paper-initiated payment order | One additional business day | Art. 83(1) |
| Intra-EU transaction outside the above scope | Same time limit unless the parties agree otherwise, and any agreed period may not exceed four business days | Art. 82(2) |
| Cash placed on a payment account, consumer | Funds available immediately after receipt, with a same-day value date | Art. 85 |
| Cash placed on a payment account, non-consumer | No later than the next business day after receipt | Art. 85 |
| Domestic transactions | A member state may impose a shorter time limit than the EU one | Art. 86 |
The value date is the reference date used to calculate interest on funds debited from or credited to a payment account. It is separate from the execution time and follows its own rules, of which there are three. The credit value date for the payee’s account can be no later than the business day on which the amount is credited to the account of the payee’s provider. The amount must be made available to the payee immediately after that credit, provided there is no currency conversion, or the conversion is between the euro and a member state currency or between two member state currencies. The debit value date for the payer’s account can be no earlier than the time the account is debited. These requirements also apply within a single provider: a transfer between two accounts it holds falls under the same regime.
The full amount of the transaction must reach the payee. The payer’s and payee’s providers transfer it without deducting any charges. There is a single exception, open only to the payee’s provider, which may agree with its customer to deduct its own charges before crediting the account. The full amount and the charges must then be shown separately in the information given to the payee. An acquiring fee netted from incoming funds is therefore lawful if it is agreed and itemized, whereas a deduction taken along the way by an intermediary provider is not (Directive (EU) 2015/2366, Article 81).
Liability for a non-executed or defectively executed transaction is allocated by a rule of evidence. The payer’s provider is liable to the payer unless it can prove that the payee’s provider received the amount. Once that is proven, liability shifts to the payee’s provider, which must make the amount available immediately. The payer’s provider must refund the non-executed or defectively executed transaction without undue delay and restore the account to the state it would have been in. Whatever the outcome, it must, on request, immediately try to trace the transaction and notify the customer of the result, free of charge. When the order goes through a payment initiation service provider, that provider bears the burden of proving that the order was received and recorded correctly, and it must immediately compensate the account servicing provider that issued the refund.
Charges: free by default, and surcharging largely shut down
Title IV makes everything related to information and correction free by default. The provider cannot charge the customer for meeting its information obligations or for the corrective and preventive measures the title requires. There are three named exceptions, and the list is exhaustive. First, refusing a payment order, where objectively justified, may be charged for if the framework contract says so. Second, revoking an order after the cut-off can also be charged for. Third, the provider may charge for recovering funds after the user supplied an incorrect unique identifier. Outside those three cases, any charge linked to a Title IV obligation is unlawful.
- Delivering pre-contractual and contractual information, and providing the framework contract terms on request at any time during the relationship. Articles 40 and 53.
- Refunding an unauthorized transaction and restoring the account to its previous state, value date included. Article 73.
- Tracing a non-executed or defectively executed transaction, whatever the outcome. Article 89.
- Reporting the loss, theft, misappropriation, or unauthorized use of an instrument. The reporting channel must be available at all times and free of charge; only replacement costs directly attributable to the instrument may be charged. Article 70.
- Proof of that report, which the provider must be able to give the customer on request for 18 months. Article 70.
Within the EU, the directive itself sets how charges are split between payer and payee. Where both providers are located in the EU, or where a single provider is involved and it is located there, the payee pays its own provider’s charges and the payer pays theirs. This split corresponds to the SHA charging option, which here derives from law rather than from the parties’ agreement, and no clause may depart from it. The OUR and BEN instructions, which put all charges on one party, therefore serve no purpose within that scope. They remain in use for payments to third countries, where the directive does not apply (Directive (EU) 2015/2366, Article 62(2)).
Surcharging means a payee charging the payer a fee for using a particular payment instrument. The rules come in three successive layers. The first permits the practice: the provider cannot prevent the payee from requesting a charge, offering a discount, or steering the payer toward one instrument over another. Any charge may not exceed the direct costs the payee incurs for that instrument. The second layer then removes most of the scope. Surcharging is prohibited on instruments whose interchange is capped by Chapter II of Regulation (EU) 2015/751, and on credit transfers and direct debits covered by Regulation (EU) No 260/2012. The third layer lets member states prohibit or limit surcharging further.
| Instrument | Interchange capped by Regulation (EU) 2015/751 | Surcharging allowed under PSD2 |
|---|---|---|
| Consumer debit card in a four-party scheme | Yes, 0.2% of the transaction value | No, prohibited by Art. 62(4) |
| Consumer credit or deferred debit card in a four-party scheme | Yes, 0.3% of the transaction value | No, prohibited by Art. 62(4) |
| Commercial card | No, excluded from Chapter II | Yes in principle, subject to national law and the direct-cost limit |
| Pure three-party scheme with no licenses granted to third parties | No, excluded from Chapter II | Yes in principle, same caveats |
| SEPA credit transfer and SEPA direct debit | Not applicable | No, prohibited by Art. 62(4) |
| Card issued outside the European Economic Area | No | Yes in principle, same caveats |
Information about charges must be given before the transaction is initiated, and the directive allows no exceptions. If the payee requests a charge or offers a discount for using a given instrument, it must inform the payer before initiation. The same rule applies when a provider or a third party requests the charge. The payer has to pay only if the full amount was disclosed beforehand. Currency conversion offered at an ATM, at the point of sale, or by the payee follows the same logic: whoever offers it must disclose all charges and the exchange rate applied (Directive (EU) 2015/2366, Articles 59 and 60).
Unauthorized transactions: refund first, investigate later
A payment transaction is authorized only if the payer has consented to its execution in the form agreed in the framework contract. Without that consent, the transaction is unauthorized, and Articles 71 to 74 apply. The payer’s provider refunds first and investigates afterward. That sequence sets the statutory regime apart from card network rules, where a dispute requires a reason code, opens a representment window, and may end in private arbitration.
The refund is due immediately, and no later than the end of the business day after the provider becomes aware of the transaction or is notified of it. The account is restored to the state it would have been in had the disputed transaction not taken place. The credit value date can be no later than the date of the disputed debit, which cancels out interest and any charges triggered by the resulting overdraft. There is one exception: the provider may delay the refund if it has grounds to suspect fraud by the payer, provided it communicates those grounds in writing to the competent national authority. A suspicion kept internal, without that communication, does not justify delaying the refund.
| Case | Who bears the loss | Reference |
|---|---|---|
| Lost, stolen, or misappropriated instrument; transactions before notification | The payer, up to €50 | Art. 74(1) |
| Loss, theft, or misappropriation the payer could not detect before the payment | The provider, unless the payer acted fraudulently | Art. 74(1) |
| Loss caused by an employee, agent, branch, or contractor of the provider | The provider | Art. 74(1) |
| Fraud by the payer, or intentional or grossly negligent failure to meet their obligations | The payer, with no cap | Art. 74(1) |
| Strong customer authentication not required by the payer’s provider | The payer’s provider, unless the payer acted fraudulently | Art. 74(2) |
| Payee or payee’s provider does not accept strong customer authentication | Whichever party failed to accept it, which must compensate the payer’s provider | Art. 74(2) |
| Transactions after the loss, theft, or misappropriation is reported | The provider, unless the payer acted fraudulently | Art. 74(3) |
| No reporting channel available at all times | The provider, unless the payer acted fraudulently | Art. 74(3) |
The €50 cap falls away in only three cases: fraud by the payer, intentional breach of their obligations, and gross negligence. Gross negligence drives most of the litigation, and the directive does not define it. The question is therefore argued before national courts, on the facts. Two elements frame how courts assess it. The alleged breach must concern an obligation under Article 69, which requires the customer to use the instrument in accordance with the agreed terms and to take reasonable steps to keep their personalized security credentials safe. The provider also has to prove the breach, without relying on the authentication record alone. Member states may also reduce the payer’s liability, taking into account the nature of the personalized security credentials and the specific circumstances. The threshold therefore varies from market to market.
The liability regime in Articles 71 to 74 is exclusive, which has direct consequences in litigation. In case C-337/20, decided on March 16, 2023, the Court of Justice barred a payment service user from invoking general contract liability law for facts already covered by the harmonized regime. Allowing a parallel claim would undo the allocation of liability the EU legislature intended. The Court made an exception for third parties: a guarantor is not a payment service user and keeps its general-law remedies. The ruling concerned Directive 2007/64/EC, whose relevant provisions were carried over into PSD2.
Complaints and ADR: two enforceable deadlines
Chapter 6 of Title IV requires a complaints procedure with fixed deadlines. Every provider must put in place and apply adequate and effective procedures for resolving complaints about the rights and obligations under Titles III and IV. The reply must be on paper or, if the parties agree, on another durable medium, and must address every point the customer raised. The deadline is 15 business days from receipt of the complaint.
Information about redress options has prescribed content and channels. The provider must inform the customer of at least one ADR (alternative dispute resolution) body competent for disputes under Titles III and IV. That information must be clear, comprehensive, and easily accessible on the provider’s website, if it has one, in its branches, and in the general terms and conditions of the contract. The provider must also explain how to get more information about that body and the conditions for using it. The procedures themselves fall under Directive 2013/11/EU on consumer ADR and are still organized country by country.
| Item recorded | What it proves |
|---|---|
| Date and channel through which the complaint was received | The 15-business-day clock starts on that date, and the provider must be able to prove it. |
| List of points raised by the customer | The reply must address every point, not just the main grievance. |
| Medium and date of the reply | The reply is due on paper, or on a durable medium if the parties agreed, within a deadline enforceable against the provider. |
| Reason for and date of any holding reply | A holding reply is valid only if it explains the reasons for the delay and gives the date of the final reply. |
| Record that the ADR body was disclosed | The Article 101 information requirement is proven case by case, not by a page on the website. |
| Authentication logs and technical evidence | The Article 72 burden of proof falls on the provider, even several months after the events. |
| Classification: authorized or unauthorized transaction | It determines the applicable regime, the refund deadline, and who bears the loss. |
A second route exists, separate from ADR. Article 99 requires member states to set up procedures for filing complaints with the competent authorities over alleged breaches of the directive. The European Banking Authority has issued guidelines harmonizing those national procedures, applicable since January 13, 2018 (EBA/GL/2017/13). National authorities also publish their own positions and recommendations, including the ACPR in France, BaFin in Germany, De Nederlandsche Bank in the Netherlands, and Banco de España in Spain. These documents do not carry the same legal weight everywhere, and they bind only their issuer’s market. The two routes can be combined: a complaint to the supervisor does not prevent the same facts from being taken to an ADR body.
Cross-border disputes have their own network. Since its creation in 2001, FIN-NET has linked the national out-of-court dispute resolution bodies for financial services across the European Economic Area, coordinated by the European Commission. A consumer in a dispute with a provider established in another member state contacts the body in their own country, which points them to the competent body. The network does not decide disputes. Its role is to identify the competent body, which is the first practical hurdle in cross-border redress.