2017-09-22

Added · Updated

Additional rules applying to current licence holders wishing to remain active under PSD2

Payment institutions must meet stricter operational and IT requirements, including strong customer authentication, secure data storage, and systems for reporting operational and security incidents to DNB. They are subject to more extensive reporting obligations, such as submitting annual statistical fraud data and notifying DNB of major incidents for escalation to the ECB and EBA. Owners of qualifying holdings representing 10% or more of shares or voting rights must obtain a declaration of no-objection from DNB, while the European Central Bank maintains a register for up-to-date notifications and central points of contact.

De Nederlandsche Bank logo

Netherlands

De Nederlandsche Bank

Click to view thumbnail

Factsheet

Read aloud

PSD2 lays down rules with respect to sound and ethical operational management, and also introduces new obligations for license holders.

Published: 22 September 2017

The most important changes for current licence holders ensuing from PSD2, EBA RTS and guidelines, are as follows:

Operational and IT requirements

(PSD2 Articles 95-98, RTS 4 and Guidelines 3 and 5) A payment institution must be meet stricter requirements concerning the effective management of operational processes and operational and security risks, and internal and external information requirements. Requirements for payment institutions in this respect include ensuring that data are protected from unauthorised access or processing, strong customer authentication, and secure communication and data storage. Payment institutions must also ensure the availability of data and electronic data processing. They must have systems in place for the classification and reporting of operational and security incidents, as well as a process to report major incidents to DNB.

Reporting requirements

(PSD2 Article 96 and Guidelines 1 and 5) Under PSD2, payment institutions are subject to more extensive reporting requirements. This includes the obligation to report major incidents to DNB, which DNB must then report to the ECB and EBA. Payment institutions must also submit to the supervisory authority on a regular basis, and at least annually, statistical data about fraud.

Notifications

(PSD2 Article 15, RTSs 1, 2, 3 and 5) The EBA maintains a register with notifications. Payment institutions must provide notifications that are up to date. If a payment institution uses several agents for each Member State, the payment institution must designate and manage a Central Point of Contact (CPC). The host supervisory authority has far-reaching powers to request information from the registered agent. See the fact sheet [LINK] on outgoing notifications for more information.

Qualifying holdings

(PSD2 Article 6) PSD2 lays out rules for holdings in a payment institution. The implementation of this provision in Dutch law is aligned as far as possible with existing requirements for declarations of no-objection (DNOs) under the Dutch Financial Supervision Act (Wet op het financieel toezicht – Wft) (Sections 3:95, 3:102(1) and 3:103(1)). As a result, owners of a direct or indirect qualifying holding in a licensed payment institution must have a DNO, which means that owners of holdings that represent 10% or more of shares or voting rights must hold a DNO from DNB.

Definition of payment transaction and calculation of own funds requirement The definition of a payment transaction will remain unchanged for all elements in Title II of PSD2, including the method for calculating own funds under method B.

In due course, the method for calculating the own funds requirement, and the definition of the payment volume parameter in that calculation, will be agreed upon at a European level. Depending on the outcome, the own funds requirement may go up. We will make information available as soon as we have it.

Discover related articles

Factsheet

Market access

Payment institutions

Share:

Share on LinkedIn

Share on X

Share on Facebook

Share via Email

Interesting articles

De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’

25 June 2026

News item supervision

In the third edition of ‘Integrity Supervision in Focus’ (ISF), we share the key insights from our integrity supervision.

Read more De Nederlandsche Bank publishes ‘Integrity Supervision in Focus 2026’

News item supervision

25 June 2026

DNB email on technical adjustments

25 June 2026

News item supervision

This week, you may receive an email from De Nederlandsche Bank (DNB). This email concerns technical adjustments required to continue corresponding with DNB by email.

Read more DNB email on technical adjustments

News item supervision

25 June 2026

Update FATF-warning lists June 2026

23 June 2026

News item supervision

FATF released an update of its ‘grey’ and ‘black’ lists.

Read more Update FATF-warning lists June 2026

News item supervision

23 June 2026

Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach

03 June 2026

News item supervision

Payment fraud has a significant impact on society. We therefore consider the management of external payment fraud to be an important topic, as secure and reliable payment systems are central to our public mandate, as emphasised in our Payments Strategy 2026-2028.

Read more Banks and payment institutions are actively combating payment fraud but could adopt a more targeted approach

News item supervision

03 June 2026

Necessary cookies

To ensure the proper operation of the website, De Nederlandsche Bank (DNB) uses functional cookies and analytics cookies, and has taken measures to ensure that these cookies have little or no impact on the privacy of website users.

Optional cookies

Some pages include embedded content from external websites. These websites may use proprietary (tracking) cookies. This allows third parties to track visitor statistics, show personalised content and display targeted ads, for example.

You can make your choice about allowing these optional cookies both when you first visit the website and when you navigate to a page with embedded content.