2019-11-21
Added · Updated
Account information service providers are permitted to pursue other business activities, including additional payment services, financial services, or non-financial activities, subject to specific regulatory conditions. Providers must obtain an extension of their licence for other payment services and may require separate licensing from the Dutch Authority for the Financial Markets for financial services. Supervisory authorities can mandate the establishment of a separate entity if non-payment activities impair the institution's financial soundness or regulatory compliance. Additionally, providers may use account information for other business purposes only if the payment service user provides specific prior consent under the GDPR.
Q&A
Read aloud
Question:
Are account information service providers allowed to pursue other business activities, and if so, under what conditions?
Published: 21 November 2019
Answer:
Yes, under Article 18(1c) of PSD2, an account information service provider is also permitted to pursue business activities other than account information services.
Explanatory notes
An account information service provider may also provide one of the other seven payment services specified in Annex I to PSD2, with each service requiring an extension of the provider's licence. An account information service provider may also provide financial services (which may require a licence issued by the Dutch Authority for the Financial Markets – AFM), or business activities that are not at all related to financial service provision. The regulations themselves do not set any restrictions on the types of business activities pursued by payment service providers. The relevant supervisory authority may require the establishment of a separate entity for the payment services business, where the non-payment services activities of the payment institution impair or are likely to impair either the financial soundness of the payment institution or the ability of the competent authorities to monitor the payment institution’s compliance with all obligations laid down by PSD2 (Article 11(5)).
The EBA's Guidelines under Directive (EU) 2015/2366 (PSD2) on the information to be provided for the authorisation of payment institutions and e-money institutions and for the registration of account information service providers are important in the context of applications for a licence as an account service provider. This particularly applies to Guideline 4.2, which provides that applicants must indicate whether they intend to pursue any other business activities in the next three years, and provide a description of the type and expected volume of these activities. DNB will assess the viability of the business model of an account information service provider as an independent activity.
Question 2
Are account information service providers that also pursue other business activities also allowed to use the account information received with the payment service user's permission for these other business activities?
The answer is yes, but only if the payment service provider has provided GDPR consent specifically for this purpose. Pursuant to Article 67(2), under d and f, of PSD2 an account information service provider is not permitted to use information received in the context of the account information services specifically requested by the payment service user for any other purposes, in accordance with the requirements governing data protection. The payment service user must provide GDPR consent in advance if the account information service provider intends to use consolidated data for a purpose other than that for which the payment service user is entitled within the confines of the expressly requested account information service. The provisions of PSD2 then no longer apply. The payment service user does not necessarily have to receive the consolidated data that are to be used for other purposes.
Discover related articles
Q&A
Payment services
Banks
Payment institutions
Share:
Share on LinkedIn
Share on X
Share on Facebook
Share via Email
Interesting articles
Prudential rules do not hinder bank financing for EU priorities
17 July 2026
News item supervision
Europe faces historic investment challenges, in which banks will play an important financing role. Prudential requirements strengthen banks’ resilience, without posing a major obstacle to their financing. Unlocking more private finance requires better risk-sharing and deeper financial integration.
Read more Prudential rules do not hinder bank financing for EU priorities
News item supervision
17 July 2026
DNB Inhouse Day for the Dutch banking sector: financial crime supervision
16 July 2026
News item supervision
Following last year’s successful event, De Nederlandsche Bank (DNB) will again host an Inhouse Day for AML/CFT professionals in the Dutch banking sector. The event is designed to encourage dialogue and provide further insight into DNB’s AML/CFT supervision.
Read more DNB Inhouse Day for the Dutch banking sector: financial crime supervision
News item supervision
16 July 2026
Fine for ABN AMRO Bank N.V. for inadequate customer due diligence for high-risk customers
09 July 2026
Enforcement measures
De Nederlandsche Bank (DNB) imposed an administrative fine of €8.5 million on ABN AMRO Bank N.V. (ABN AMRO) on 6 July 2026 due to serious shortcomings in its anti-money laundering controls in the period from September 2023 through September 2024.
Read more Fine for ABN AMRO Bank N.V. for inadequate customer due diligence for high-risk customers
Enforcement measures
09 July 2026
De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’
25 June 2026
News item supervision
In the third edition of ‘Integrity Supervision in Focus’ (ISF), we share the key insights from our integrity supervision.
Read more De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’
News item supervision
25 June 2026
Necessary cookies
To ensure the proper operation of the website, De Nederlandsche Bank (DNB) uses functional cookies and analytics cookies, and has taken measures to ensure that these cookies have little or no impact on the privacy of website users.
Optional cookies
Some pages include embedded content from external websites. These websites may use proprietary (tracking) cookies. This allows third parties to track visitor statistics, show personalised content and display targeted ads, for example.
You can make your choice about allowing these optional cookies both when you first visit the website and when you navigate to a page with embedded content.