On 29 January 2021, the Kemp Little team joined Deloitte Legal. Click here to view the press release.

As of 30 January 2021, Kemp Little LLP ceased to operate as a firm of solicitors and practice law and ceased to be regulated and authorised by the Solicitors Regulation Authority.

Kemp Little LLP has been re-named KL Heritage LLP.

If you are looking to contact a specific individual to seek legal advice or in respect of any other business relationship, please contact Deloitte Legal.

If you are seeking to contact the old Kemp Little LLP in relation to a previous business relationship or matter, please get in touch with KL Heritage LLP.

For enquiries relating to Kemp Little technology products and training portal, please email deloittelegal@deloitte.co.uk

 


 

Kemp Little is a trade name used under licence by KL Heritage LLP (formerly Kemp Little LLP, registered number OC300242 and VAT number 182 8854 65).

On 29 January 2021, the Kemp Little team joined Deloitte Legal.  As of 30 January 2021, Kemp Little ceased to operate as a firm of solicitors and practice law. From this date Kemp Little ceased to be authorised and regulated by the Solicitors Regulation Authority and is being re-named KL Heritage LLP.

All references to Kemp Little herein are references to KL Heritage LLP, which used to carry on business in that name.

KL Heritage LLP is not connected to or associated with Deloitte Legal or Deloitte LLP in any capacity.

 

Kemp Little
  • Looking for someone?
  • Email us
  • Search
MENU MENU
Insights overview

Financial regulation · 29 November 2017 · Chris Hill · Jake Ghanty

PSD2 – Delegated Regulation: technical standards and communication

What has happened? Firms who are within scope of the second Payment Services Directive ((EU) 2015/2366) (“PSD2”) now have – at long last – some… Read more

more content below

What has happened?

Firms who are within scope of the second Payment Services Directive ((EU) 2015/2366) (“PSD2”) now have – at long last – some clarity around PSD2’s strong customer authentication (“SCA”) requirements, following the European Commission’s adoption on 27 November 2017 of a Delegated Regulation and Annex with regard to the regulatory technical standards (“RTS”) on SCA and common and secure open standards of communication (“CSC”) (C(2017) 7782).

What are the key points?

The key points relate to continuing access by payment service providers to payment service users’ payment account information held by banks and an optional corporate exemption from certain SCA requirements.

Some detail

The journey to this point has not been easy and it is not clear whether the final RTS will answer all outstanding questions around SCA. The RTS were drafted initially by the European Banking Authority (“EBA”) further to its mandate under PSD2 to specify the requirements for SCA (under Article 98) and related exemptions, security measures for payment service users’ credentials and CSC for payment service providers.

The RTS met with initial disapproval from the European Commission, which drafted a letter in May 2017 setting out its intention to make a number of amendments. The most controversial of these was the Commission’s proposed requirement that Account Servicing Payment Service Providers (“ASPSPs”) (banks typically) provide access to the customer interface for Account Information Service Providers (“AISPs”) and Payment Initiation Service Providers (“PISPs”) if the dedicated interface is not available. In other words, screen-scraping would still need to be provided even if a bank’s dedicated interface for AISPS and PISPs fails; this is in order to ensure continuity to payment service users (end customers) of the services provided by AISPs and PISPs. In June 2017, the EBA responded with an Opinion letter, setting out its objections, including its objection to permitting screen-scraping in this way.

The Commission’s adoption of the RTS includes some substantive amendments reflecting the Commission’s original position. The first is the addition of a further exemption from SCA to cover electronic payment transactions that are performed through dedicated payment processes used by corporates, where the appropriate level of security is achieved through other means than the authentication of a particular individual. This exemption would be subject to the approval of each national competent authority.

The Commission’s second amendment to the RTS relates to “screen-scraping”. Here, the Commission promotes a compromise position (or perhaps a punt). The Commission maintains that banks should permit a fall-back mechanism if the dedicated interface fails: “it is necessary  to  provide,  subject  to  strict  conditions,  a  fall-back  mechanism  that  will  allow  such  providers  to  use  the  interface  that  the  account  servicing   payment   service   provider   maintains   for   the   identification   of,   and  communication   with,   its  own  payment  service   users.” (C(2017) 7782 final (Recital 24))

Having said that, the Commission has also decided that national competent authorities may exempt banks from being required to provide such a fall-back mechanism, provided the dedicated interface meets certain criteria. In other words, it’s back to the FCA. This means that ASPSPs, AISPs and PISPs could face different SCA requirements depending upon which Member State they are operating in.

What happens next?

Although PSD2 applies from 13 January 2018, the RTS apply 18 months after the date that the Delegated Regulation enters into force, which will be the date of its publication in the Official Journal of the EU. This means that the RTS should apply from around Q3/Q4 2019, assuming the necessary approval by the European Parliament and the Council is granted.

The Commission’s adoption of the RTS has several implications for payment service providers. Payment service providers now know they have until around Q3/Q4 2019 to ensure that their systems comply with the security measures in Articles 65, 67 and 97 of PSD2 (transposed in the UK under Part 7 of the Payment Services Regulations 2017) concerning SCA, bearing in mind that those provisions in Articles 65, 67 and 97 that do not relate to SCA will apply from the implementation of PSD2 13 January 2018.

  • Share this blog

  • Twitter
  • Facebook
  • Linkedin

Need to talk about this?

Chris HillChris Hill

Jake GhantyJake Ghanty

Get in touch

Sign up for our newsletters

  • Share this Blog

  • Twitter
  • Facebook
  • Linkedin

Other stuff you might like

  1. UK’s Gaming Industry – what are the key considerations and how can Kemp Little help?
  2. Webinar: PSD3: An EPA webinar in partnership with Kemp Little
  3. Living with the competition? You might have to tell your boss | Financial News
The hottest topics in technology
  • Adtech & martech
  • Agile
  • Artificial intelligence
  • EBA outsourcing
  • Brexit
  • Cloud computing
  • Complex & sensitive investigations
  • Connectivity
  • Cryptocurrencies & blockchain
  • Cybersecurity
  • Data analytics & big data
  • Data breaches
  • Data rights
  • Digital commerce
  • Digital content risk
  • Digital health
  • Digital media
  • Digital infrastructure & telecoms
  • Emerging businesses
  • Financial services
  • Fintech
  • Gambling
  • GDPR
  • KLick DPO
  • KLick Trade Mark
  • Open banking
  • Retail
  • SMCR
  • Software & services
  • Sourcing
  • Travel
close
The hottest topics in technology
  • Adtech & martech
  • Agile
  • Artificial intelligence
  • EBA outsourcing
  • Brexit
  • Cloud computing
  • Complex & sensitive investigations
  • Connectivity
  • Cryptocurrencies & blockchain
  • Cybersecurity
  • Data analytics & big data
  • Data breaches
  • Data rights
  • Digital commerce
  • Digital content risk
  • Digital health
  • Digital media
  • Digital infrastructure & telecoms
  • Emerging businesses
  • Financial services
  • Fintech
  • Gambling
  • GDPR
  • KLick DPO
  • KLick Trade Mark
  • Open banking
  • Retail
  • SMCR
  • Software & services
  • Sourcing
  • Travel
Kemp Little

Lawyers
and thought leaders who are passionate about technology

Expand footer

Kemp Little

138 Cheapside
City of London
EC2V 6BJ

020 7600 8080

hello@kemplittle.com

Services

  • Commercial technology
  • Consulting
  • Disputes
  • Intellectual property
  • Employment
  • Immigration

 

  • Sourcing
  • Corporate
  • Data protection & privacy
  • Financial regulation
  • Private equity & venture capital
  • Tax

Sitemap

  • Our people
  • Insights
  • Events
  • About us
  • Contact us
  • Cookies
  • Privacy
  • Terms of use
  • Complaints
  • Debt recovery charges

Follow us

  • Twitter
  • LinkedIn
  • FlightDeck
  • Sign up for our newsletters

Kemp Little LLP is a limited liability partnership registered in England and Wales (registered number OC300242) and is authorised and regulated by the Solicitors Regulation Authority. Its registered office is 138 Cheapside, London EC2V 6BJ. The SRA Standards and Regulations can be accessed by clicking here.

  • Cyber Essentials logo
  • LORCA logo
  • ABTA Partner+ logo
  • Make Your Ask logo
  • FT Innovative Lawyers 2019 winners logo
  • Law Society Excellence Awards shortlisted
  • Legal Business Awards = highly commended
  • Home
  • Our people
  • Services
    • Business restructuring and reorganisation
    • Commercial technology
    • Consulting
    • Corporate
    • Data protection & privacy
    • Digital content & reputation risk
    • Disputes
    • Employment
    • Financial regulation
    • Immigration
    • Innovation
    • Intellectual property
    • Private equity & venture capital
    • Sourcing
    • Tax
    • Travel
  • Resources
  • Insights
  • Covid 19: Your Business Continuity
  • Events
  • About us
    • Who we are
    • Our social responsibilities
    • Our partnerships
    • Join us
  • Contact us
  • FlightDeck
  • Sign up for our newsletters
  • Follow us
    • Twitter
    • LinkedIn
close
close
close

Send us a message

Fill in your details and we'll be in touch soon

[contact-form-7 id="4941" title="General contact form"]
close

Sign up for our newsletter

I would like to receive updates and related news from Kemp Little *

Please select below any publications that you would like to receive:

Newsletters

close

Register for future event information

[contact-form-7 id="4943" title="Subscribe to future events"]
close
close
Generic filters
Exact matches only

Can't remember their name? View everyone

  • Home
  • Our people
  • Services
    • Business restructuring and reorganisation
    • Commercial technology
    • Consulting
    • Corporate
    • Data protection & privacy
    • Digital content & reputation risk
    • Disputes
    • Employment
    • Financial regulation
    • Immigration
    • Innovation
    • Intellectual property
    • Private equity & venture capital
    • Sourcing
    • Tax
    • Travel
  • Resources
  • Insights
  • Covid 19: Your Business Continuity
  • Events
  • About us
    • Who we are
    • Our social responsibilities
    • Our partnerships
    • Join us
  • Contact us
  • FlightDeck
  • Sign up for our newsletters
  • Follow us
    • Twitter
    • LinkedIn