Financial & Banking · European Union

PSD2 Explained for Consumers: Your Open Banking & Anti-Fraud Rights (and What PSD3 Will Change)

If your card details get cloned or someone steals your online banking credentials, it's a common fear that the bank will simply blame you for not protecting your data and leave you to absorb the loss. The Payment Services Directive (PSD2) — the law currently in force across the EU — exists specifically to prevent that outcome, and it's worth being precise about what applies today versus what's still on the way.

Important: PSD2 is the current law — PSD3 is not yet in force

You may see PSD2 and "PSD3" mentioned together as if they're interchangeable. They aren't, at least not yet. PSD3, alongside a new directly-applicable Payment Services Regulation (PSR), reached political agreement between the European Parliament and Council in late 2025, with formal texts expected to be published in the EU Official Journal sometime in 2026. But actual applicability isn't expected until roughly 2027-2028, following the standard transposition period for a directive. Until that happens, every consumer protection described below is governed by PSD2 as it stands today — not a future framework that hasn't taken effect.

Strong Customer Authentication (SCA) — the current shield

PSD2 introduced mandatory Strong Customer Authentication: transactions must generally be confirmed using two independent factors — something you know (a PIN), something you have (your phone or banking app), or something you are (fingerprint or face recognition). If a merchant processes a fraudulent charge without triggering SCA where it was required, liability generally shifts to the bank or merchant, not you.

The €50 liability cap

If your card is stolen or used fraudulently before you've had a reasonable chance to report it, your maximum legal liability is capped at €50. Anything taken above that must be refunded to you. Once you've notified your bank of the loss or theft, your liability for anything that happens afterward drops to zero.

The "value date" refund requirement

Report an unauthorised charge in writing as soon as you notice it, and explicitly invoke your rights under PSD2 as transposed into your country's national law. Banks are generally required to restore your funds by no later than the end of the following business day after you notify them — not weeks later, and not pending a lengthy internal investigation before you see your money back.

Open Banking — using third-party apps safely

PSD2 also underpins Open Banking: your right to use authorised third-party apps — budgeting tools, account aggregators — that access your transaction data securely via regulated APIs, with your explicit consent, rather than requiring you to hand over your actual banking password to a third party (a practice known as "screen scraping" that PSD2 was designed to phase out).

What PSD3/PSR will likely change, once it applies

The incoming framework is expected to strengthen fraud liability further — including provisions aimed at authorised push payment (APP) fraud, where victims are tricked into approving a transfer themselves — and to consolidate payment and e-money institution licensing. None of this is enforceable yet; treat any claim that PSD3 already grants you a specific right as premature until the Official Journal publication and national implementation are confirmed.

Sources