PSD2 & Strong Customer Authentication

The Second Payment Services DirectiveClosed PSD2 is an EU Directive which sets requirements for firms that provide payment services. It introduces a number of requirements around how firms treat their customers and handle their complaints, and the data they must report to the FCA. (PSD2), is an European Union (EU) Directive which sets requirements for firms that provide payment services. It aims to improve consumer protection, make payments safer and more secure. PSD2 came into force on 13th January 2018, with some individual countries within the EU having extensions until 20221. PSD2 introduced some new requirements for card issuers and processors, such as:

  • The requirement for Strong Customer Authentication (SCA) on all e-commerce and contactless payments unless specific exemptions apply.

  • The requirement for Dynamic SCA Linking - verifying that the details in an authentication session match the details in the subsequent payment authorisation

PSD2 rules are issued by the European Banking Authority (EBA)Closed The EBA is an independent EU Authority which works to ensure effective and consistent prudential regulation and supervision across the European banking sector..

Strong Customer Authentication (SCA)

The EBA states that for a transaction to be Strong Customer Authenticated (SCA), at least two of the following must be verified during the transaction:

Thredd currently considers all 3D Secure transactions as SCA3. If the 3D Secure transaction is considered as SCA, Thredd automatically flags the possession and knowledge tests in the EHI GPS_POS_Data field. See PSD2 Transaction Status.

PSD2 Dynamic Linking

PSD2 Dynamic SCA Linking requires that the details provided in a 3D SecureClosed 3D Secure (3-domain structure), also known as a payer authentication, is an authentication process involving the issuer’s authentication service provider (e.g., Cardinal or Apata) to pre-authenticate the cardholder. This process happens before the Authorisation is sent by the merchant Acquirer, and the critical details from the 3D-secure response are included in the Authorisation message to enable the issuer to prove that 3D-secure authentication was obtained. authentication session matches the details that were provided during the transaction authorisation. For example, matching of the authorised amount to the authenticated amount, and matching of the merchant name.

Thredd can do this matching. Alternatively, you can perform matching using details provided in transaction messages sent from the Thredd External Host Interface (EHI)Closed The External Host Interface provides a facility to enable exchange of data between Thredd and external systems via our web services. All transaction data processed by Thredd is transferred to the External Host side via EHI in real time. For certain types of transactions, such as Authorisations, the External Host can participate in payment transaction authorisation. to your systems. For more information, see the EHI Guide > Transaction Matching - Authentications and Authorisations.

SCA Exemptions

All transactions must have Strong Customer Authentication (SCA), unless they meet one of the following European Banking Authority (EBA) exemptions:

Article

Description of SCA Exemption

Article 11

Contactless transaction of up to EUR 50.00, and cumulatively not exceeding EUR 150.00 or 5 transactions.

Article 12

Paying a transport or parking fare at an unattended terminal.

Article 13

The receiver of funds is a trusted beneficiary, or this is a recurring payment transaction (but not the first instance of).

Article 14

The sender and receiver of funds are the same person.

Article 15

E-commerce transaction of up to EUR 30.00, and cumulatively not exceeding EUR 100.00 or 5 transactions.

Article 16

E-commerce transaction classified as low-risk (as defined in the Article).

 

The specific transaction limits (i.e., frequency and amount) may vary per country. Please check with your Issuer or country financial regulator for details. These limits can be set at your Thredd card Product level. See PSD2 Product Settings.

Transactions where the PSD2 rules do not apply

The PSD2 rules do not apply to the following types of transactions:

To understand the end-to-end transaction flow and Thredd checks related to PSD2, see PSD2 Transaction Checks.

Find out more about the PSD2 Regulations

Below are links to additional information about the PSD2 and SCA regulations.