All articles Fintech & Banking

PSD2 explained simply: what really changes if you sell online

You don't need a banking law degree. You need to know three things, and this article gives you exactly those.

PSD2 explained simply: what really changes if you sell online

PSD2 is one of those acronyms everyone cites and few really explain, maybe because the official text of the directive is written in language that discourages anyone who isn't a banking lawyer. But the practical consequences for anyone selling online are few and concrete. Let's look at them directly.

What PSD2 is, in one sentence

It's the European payment services directive that introduced two main changes: strong customer authentication (3D Secure/SCA) on almost every card payment, and mandatory access to bank accounts for authorised third-party providers (the technical foundation of open banking).

What it concretely means for your checkout

You're required to support strong customer authentication for most card transactions: your payment gateway has to handle it, it's not optional.

Specific exemptions exist (very low-value transactions, already-authorised recurring payments) that, if handled well by your provider, reduce extra verification requests without breaching the regulation.

The other half of PSD2: open banking

The directive requires banks to provide access to their customers' account data and payment functionality to authorised third-party providers, if the customer explicitly consents.

This has made possible services like account-to-account payments, which bypass the card networks entirely, often with lower fees for the merchant.

What will change with PSD3

The next regulation, currently being rolled out at European level, aims to further strengthen fraud protection and simplify certain technical aspects of third-party access to bank data.

For anyone selling online, the practical advice stays the same: choose a payment provider that keeps its infrastructure aligned with regulation, so they manage the changes, not you.

Key takeaways
  • PSD2 requires strong customer authentication on almost every card payment.
  • The same directive is the legal foundation of open banking and account-to-account payments.
  • Certain exemptions reduce extra verification requests, if your gateway handles them correctly.
  • PSD3 will further strengthen security and rules on bank data access.
Mistakes to avoid
  • Using a gateway that doesn't correctly handle PSD2 exemptions, increasing unnecessary verifications.
  • Thinking PSD2 is only about security and not also about new opportunities like open banking.
  • Not keeping up with the regulatory changes coming with PSD3.

Frequently asked questions

Does PSD2 only apply to sales in Europe?

It applies to payments where both the card issuer and the merchant's payment service provider are in the European Economic Area. Transactions with non-EU cards may follow different rules.

What happens if I don't comply with the strong authentication requirement?

Issuing banks can decline non-compliant transactions, directly affecting your payment approval rate and, therefore, your sales.

Is open banking mandatory for my e-commerce?

No, offering it as a payment method is a business choice, not an obligation. PSD2 requires banks to enable it technically, not merchants to offer it.

A provider that keeps up to date, so you don't have to

Daevon keeps its infrastructure aligned with European payment regulation at all times, including PSD2 exemptions.

Keep reading