Open banking and PSD2 refer to the European Union’s framework for letting you share your bank account data with licensed third-party apps, and for letting those apps initiate payments on your behalf, without ever handing over your banking password. The framework is Directive (EU) 2015/2366, in force since 2018, which requires every bank in the EU to open its payment account infrastructure to authorized third parties through secure digital channels.1EUR-Lex. Directive (EU) 2015/2366 on Payment Services in the Internal Market The principle underneath it is simple: the data your account generates belongs to you, and your bank has to share it when you say so.
What PSD2 Requires of Your Bank
The core mandate is that banks must let authorized third parties access customer payment accounts that are available online, such as checking and current accounts, so those third parties can build competing financial products.1EUR-Lex. Directive (EU) 2015/2366 on Payment Services in the Internal Market Before PSD2, a fintech that wanted to consolidate balances across your different banks had no legal right to ask for the data. The directive created that right.
The law also requires each EU member state to maintain a public register of every authorized payment institution, its agents, and its branches.1EUR-Lex. Directive (EU) 2015/2366 on Payment Services in the Internal Market That register is your first line of defense. Before granting any app access to your accounts, you can check whether the company is actually licensed by looking it up in your national regulator’s list. Banks that refuse to open their infrastructure risk fines or loss of license.
The Three Types of Third Parties That Can Access Your Data
PSD2 does not create a single “open banking license.” It creates three distinct categories, and the differences matter because each one defines exactly what a company can and cannot do with your account.
Account Information Service Providers (AISPs)
An AISP is read-only. It pulls data from one or more of your payment accounts and consolidates it into a single view, letting you see balances and transactions from different banks in one place.2European Banking Authority. Clarification on Whether a Particular Business Model Type Constitutes the Provision of an Account Information Service as Defined by Article 4(16) of PSD2 Budgeting apps and personal finance dashboards typically hold this license. An AISP cannot request sensitive payment credentials like your PIN, and it has no authority to move money.1EUR-Lex. Directive (EU) 2015/2366 on Payment Services in the Internal Market
Payment Initiation Service Providers (PISPs)
A PISP can start a payment directly from your bank account, bypassing card networks. When you check out online and pick “pay by bank,” a PISP is usually handling the transfer.3Financial Conduct Authority. Account Information Service (AIS) and Payment Initiation Service (PIS) The restrictions are tight: a PISP cannot hold your funds at any point in the transaction, cannot store your sensitive payment data, and cannot alter the amount or recipient beyond what you authorized.1EUR-Lex. Directive (EU) 2015/2366 on Payment Services in the Internal Market
Card-Based Payment Instrument Issuers (CBPIIs)
A CBPII issues payment cards linked to an account held at a different bank. Under PSD2, it can ping your bank in real time to confirm whether enough funds are available to cover a purchase, but the bank only returns a yes-or-no answer. Your balance and account details stay private.
All three categories must register with their national competent authority before operating. AISPs and PISPs must also carry professional indemnity insurance or an equivalent guarantee as a condition of authorization, which protects you if a provider’s error causes financial loss.4European Banking Authority. EBA Publishes Final Guidelines on Professional Indemnity Insurance
Consent and Strong Customer Authentication
No third party touches your bank data without your explicit consent. PSD2 requires that both AISPs and PISPs get your clear, affirmative authorization before accessing, processing, or retaining any personal data, and they can only use data that is strictly necessary for the service you asked for.5European Data Protection Board. Guidelines 06/2020 on the Interplay of PSD2 and the GDPR The provider has to tell you exactly what it will access before you approve. You can revoke access at any time through your bank or the app.
To confirm you are actually the account holder, PSD2 requires Strong Customer Authentication (SCA). SCA needs at least two independent factors from three categories: something you know (a password or PIN), something you have (a phone or hardware token), and something you are (a fingerprint or facial scan).1EUR-Lex. Directive (EU) 2015/2366 on Payment Services in the Internal Market If either factor fails, the bank blocks the request. SCA applies whenever you access your payment account online, initiate an electronic payment, or perform any remote action that could expose you to fraud.
For ongoing access through an AISP, the original rules required your bank to re-verify your identity every 90 days. The European Banking Authority later extended the re-authentication window to 180 days.6European Banking Authority. EBA Publishes Final Report on the Amendment of Its Technical Standards on the Exemption to Strong Customer Authentication for Account Access That cuts friction for people who check budgeting apps daily while keeping long-term data sharing an active choice.
How Your Data Actually Moves
Before PSD2, third-party apps got at your bank data through screen scraping. The app logged in using your real username and password, pretending to be you. The app held your credentials, the bank could not tell it apart from a legitimate login, and you had no way to limit what it saw or did.
PSD2’s implementing regulation requires every bank offering online payment accounts to provide at least one secure interface through which licensed third parties can identify themselves and request data directly. Most banks built dedicated APIs for this. The API works as a controlled doorway. The third party sends a digital request for the specific data points you authorized, the bank verifies the requester’s identity using qualified electronic certificates tied to its regulatory license, and only then does the information move. At no point does the third party see your login credentials.7EUR-Lex. Commission Delegated Regulation (EU) 2018/389
Each request is limited to the exact scope you authorized. Once the bank fulfills the request, the connection closes. All communication is encrypted. The certificates the third party presents carry its authorization number, the name of its regulator, and its specific license type (AISP, PISP, or CBPII), so the bank can check in real time whether the requester is allowed to do what it is asking to do.
Who Pays When Something Goes Wrong
PSD2’s general rule puts liability for unauthorized transactions on the payment service provider, not you. If someone initiates a payment from your account without your authorization, the bank bears the loss. The exception is fraud or gross negligence on your part, such as deliberately sharing your credentials with a stranger or ignoring obvious signs that your account was compromised. Reporting a suspicious transaction quickly to your bank is what preserves the protection.
A Note on the U.S. Side
PSD2 is EU law. It does not govern accounts held at U.S. banks. The United States has been building a rough equivalent through the CFPB’s Section 1033 rule, finalized in late 2024, which would require U.S. financial institutions to share consumer data through APIs and prohibit screen scraping.8Federal Register. Required Rulemaking on Personal Financial Data Rights In July 2025, the CFPB itself moved to stay the rule while it initiates a new rulemaking to substantially revise it, and the court granted the stay. As of mid-2025, the rule remains on the books but is not being enforced, and its final form is uncertain. The U.S. framework also does not yet cover payment initiation, which PSD2 handles through PISPs.
What’s Changing: PSD3, the PSR, and FIDA
PSD2 has been in force since 2018, and its weaknesses are known. Because it was a directive rather than a regulation, each member state implemented it a little differently, which created uneven API quality, user experience, and enforcement. In June 2023, the European Commission proposed a replacement package: a new Payment Services Directive (PSD3) for licensing and authorization, plus a Payment Services Regulation (PSR) for conduct rules that apply directly across all member states without national transposition.9European Commission. Payment Services
The European Parliament and Council reached a provisional political agreement on the new framework on November 27, 2025.10European Parliament. Payment Services Regulation – Legislative Train Schedule Final texts are expected in the Official Journal in early-to-mid 2026, with the rules likely taking effect by late 2027 after an 18-to-21 month transition period. The main consumer-facing changes:
- Payment service providers must check that a payee’s name matches the account identifier before processing a payment. For impersonation fraud, where a scammer poses as a bank employee and tricks you into approving a payment, the provider must refund the full amount once you report it to the police and your bank.10European Parliament. Payment Services Regulation – Legislative Train Schedule
- National regulators gain authority to act immediately against banks whose APIs underperform.
- The separate Electronic Money Directive disappears. E-money institutions become a subcategory of payment institutions under PSD3 and must reapply for authorization.
- Consumers gain the right to access human customer support rather than being limited to chatbots.10European Parliament. Payment Services Regulation – Legislative Train Schedule
Separately, the Financial Data Access (FIDA) framework would extend open banking principles beyond payment accounts to a much wider set of financial products: mortgages, investment accounts, savings products, insurance policies, crypto assets, and creditworthiness data.11European Commission. Framework for Financial Data Access Health and life insurance data are excluded. FIDA is still working through the legislative process and has no final adoption date. If it passes, the same consent-based access model you already use for your checking account will reach almost everywhere you hold money.