2021-04-30
Added · Updated
Payment Account Service Providers (ASPSPs) that have developed dedicated APIs must correct identified non-compliances, including missing payment instruments, authentication flow obstacles, and missing authentication methods, by 30 September 2021. Failure to comply may result in the application of the current regulatory offense regime and the revocation of any granted API contingency mechanism exemptions. Violations regarding account access for payment initiation and account information services are classified as particularly serious offenses, subject to fines ranging from 10,000 to 5,000,000 euros.
Circular Letter No. CC/2021/00000021 Sent to: Credit Institutions, Payment Institutions, and Electronic Money Institutions. Mod. 40000375/T – 01/14 Subject: RJSPME – Supervisory actions to ensure the removal of obstacles to the provision of services by third-party payment service providers
The Commission Delegated Regulation (EU) 2018/389 of 27 November 2017, which supplements Directive (EU) 2015/2366 of 25 November 2015 on payment services in the internal market (PSD2), as regards regulatory technical standards on strong customer authentication and on common and secure open standards of communication, entered into force on 14 September 2019. PSD2 was transposed into Portuguese law by Decree-Law No. 91/2018 of 12 November, which approved the Legal Regime for Payment Services and Electronic Money (RJSPME).
Thus, since 14 September 2019, payment service providers that manage payment accounts (Account Servicing Payment Service Providers – ASPSPs) must provide communication interfaces compatible with the requirements established in RJSPME and Delegated Regulation (EU) 2018/389 that allow common and secure communication with third-party payment service providers (TPP1).
According to Article 31 of Delegated Regulation (EU) 2018/389, ASPSPs may choose to develop a dedicated interface (Application Programming Interface – API) or, alternatively, allow TPPs to use the interface provided directly to duly adapted customers for this purpose (notably home banking and mobile applications).
With the aim of standardizing the monitoring of compliance with the requirements applicable to the APIs provided for in paragraph 3 of Article 32 of Delegated Regulation (EU) 2018/389, the European Banking Authority (EBA) published, on 4 June 2020, the “Opinion on obstacles under Article 32(3) of the RTS on SCA and CSC”, which identified situations that could be considered obstacles to the provision of payment services by TPPs when communicating with ASPSPs via an API.
Taking into account the clarifications provided by the EBA through the aforementioned Opinion and the information collected within the scope of monitoring actions carried out, the Bank of Portugal, as the competent national authority in this matter, issued, on 9 July 2020, Circular Letter CC/2020/00000045.
This Circular Letter signaled a set of situations identified in the Portuguese market that constitute obstacles to the provision of services by TPPs when communicating with ASPSPs via an API and established the respective deadlines for their correction.
On 18 February 2021, despite recognizing that competent national authorities had taken measures to ensure that ASPSPs under their supervision were in compliance with Delegated Regulation (EU) 2018/389, the EBA noted that many of the obstacles had not yet been removed, thereby impeding the promotion of innovation and competition advocated by PSD2. With a view to ensuring supervisory convergence in the context of the European Union, the EBA published, on that date, the “Opinion of the European Banking Authority on supervisory actions to ensure the removal of obstacles to account access under PSD2”, which stipulated a deadline of 30 April 2021 for competent national authorities to take new supervisory measures leading to the elimination of existing obstacles to the provision of payment services by TPPs.
Based on the monitoring carried out regarding the progress of ASPSPs in eliminating the obstacles identified in Circular Letter CC/2020/00000045, the Bank of Portugal considers that situations remain to be resolved, namely those related to:
i. Failure to provide, in the API, all payment instruments offered in channels for direct access by payment service users; ii. Existence of obstacles in user authentication flows; iii. Failure to provide, in the API, all authentication methods offered in channels for direct access by payment service users (via “app-to-app redirection” or “decoupled” method).
In this regard, the Bank of Portugal establishes that ASPSPs that have chosen to develop an API must correct the aforementioned non-compliances by the deadline of 30 September 2021.
If ASPSPs do not correct the signaled situations within the aforementioned deadline, the Bank of Portugal may apply the current regulatory offense regime and, in situations where it has granted an exemption from the API contingency mechanism, under paragraph 6 of Article 33 of Delegated Regulation (EU) 2018/389, revoke the same, in accordance with paragraph 7 of the same article.
It is further noted that the violation of rules regarding access to payment accounts in the case of payment initiation services and account information services is, under letters z) and aa) of Article 151 of RJSPME, considered a particularly serious offense, subject, in each case, to a fine ranging from 10,000 euros to 5,000,000 euros.
The Bank of Portugal, as the competent national authority in this matter, will take the necessary actions to ensure full compliance of the APIs provided by ASPSPs with the applicable regulatory framework, in order to promote a secure and innovative payment market.
1 Account Information Service Providers (AISP), Payment Initiation Service Providers (PISP), and Payment Service Providers that issue card-based payment instruments (CBPII).