2022-11-04
Added · Updated
The document requires Account Servicing Payment Service Providers (ASPSPs) that have developed dedicated Application Programming Interfaces (APIs) to correct two specific compliance gaps by 31 March 2023: ensuring the Payment Services User (PSU) name is provided via the API when available during direct access, and making 'card accounts' accessible to Third Party Providers (TPPs) on the same basis as direct interfaces. Failure to comply may result in the revocation of API contingency mechanism exemptions and administrative fines ranging from 10,000 to 5,000,000 euros for especially serious infractions.
Circular Letter No. CC/2022/00000026 Sent to: Credit Institutions, Payment Institutions and Electronic Money Institutions. Mod. 99999924/T – 01/14 Subject: RJSPME – Actions to ensure the continued compliance of interfaces dedicated to communication with third-party payment service providers
On 14 September 2019, Commission Delegated Regulation (EU) 2018/389 (RD 2018/389) of 27 November entered into force, which supplements Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November on payment services in the internal market (PSD2), as regards regulatory technical standards on strong customer authentication and common and secure open communication standards. PSD2 was transposed into the domestic legal order through the Legal Regime for Payment Services and Electronic Money (RJSPME), approved in annex to Decree-Law No. 91/2018 of 12 November.
According to Article 31 of RD 2018/389, in order to enable communication with third-party payment service providers (Third Party Providers – TPP), payment service providers that manage accounts (Account Servicing Payment Service Providers – ASPSP) may choose to develop a dedicated interface (Application Programming Interface – API) or, alternatively, allow TPPs to use the interface made available to customers when they access their accounts directly, duly adapted for this purpose (notably, homebanking and mobile applications).
The Bank of Portugal, as the national competent authority in this matter, has been monitoring the operation of the dedicated interfaces made available by ASPSPs and their compliance with the current regulatory framework, determining, whenever non-compliance with applicable technical requirements is detected, that actions be developed to resolve them (notably through Circular Letters CC/2020/00000045 and CC/2021/00000021).
Within the framework of the continuous monitoring actions conducted by the Bank of Portugal, two situations were identified related to: (i) the provision, in the API, of the names of payment services users (Payment Services User – PSU); and (ii) the provision, in the API, of “card accounts”.
i. Provision, in the API, of the names of payment services users
Taking into account the clarifications from the European Banking Authority (EBA), particularly in Q&A 2018_4081, it is the understanding of the Bank of Portugal that:
• For payment initiation services, if the PSU’s name is provided or made available to them by the ASPSP when the transaction is initiated directly by the PSU, this information must also be provided to the PSU when they use services from a PISP via the API, immediately after receipt of the payment order. This obligation stems from Article 36(1)(b) of RD 2018/389, which establishes that ASPSPs, immediately after receipt of the payment order, must “provide PISPs with the same information on the initiation and execution of the payment operation provided or made available to the PSU when the operation is initiated directly by the latter”.
• For account information services, the ASPSP must provide the PSU’s name when they access payment account information through an AISP via the API, if the same is made available to the PSU when accessing this information directly. Indeed, Article 36(1)(a) of RD 2018/389 establishes that ASPSPs must provide AISPs “with the same information on designated payment accounts and associated payment operations made available to the PSU when access to account information is directly requested, provided that this does not include sensitive payment data”. Article 4(32) of PSD2 establishes that, for the activities of PISPs and AISPs, the account holder’s name does not constitute sensitive payment data.
ii. Provision, in the API, of “card accounts”
In the understanding of the Bank of Portugal, the ASPSP must make available in the API the same information and enable the same operations that are offered in interfaces directly accessible by the PSU for “card accounts”.
Through Q&A_2019_4856, the EBA clarified that if an account where funds are covered by a credit line can be used to send and receive payment operations to and from third parties, and is accessible online, it must also be made available to TPPs, within the framework of common and secure communication, in accordance with Articles 65, 66 and 67 of PSD2 (respectively, Articles 105, 106 and 107 of RJSPME).
Under point (g) and point (ii) of Article 2 of RJSPME, respectively, a payment account is an account held in the name of one or more PSUs, which is used for the execution of payment operations, while a payment operation is the act, initiated by the payer or on their behalf, or by the payee, of depositing, transferring or withdrawing funds, regardless of any underlying obligations between the payer and the payee.
In the understanding of the Bank of Portugal, “card accounts” are payment accounts because they can be used for the execution of payment operations.
Given the above understanding, the Bank of Portugal establishes that ASPSPs that have chosen to develop an API must correct, if applicable, the situations identified above by the deadline of 31 March 2023.
If ASPSPs do not correct the indicated situations within the above-defined period, the Bank of Portugal may apply the current administrative offence regime and, in situations where it has granted an exemption from the API contingency mechanism, under Article 33(6) of RD 2018/389, revoke the same, in accordance with Article 33(7) of the same article.
It is further noted that violation of the rules regarding access to the payment account in the case of payment initiation services or account information services is, under points (z) and (aa) of Article 151 of RJSPME, considered an especially serious offence subject, in each case, to a fine ranging from 10,000 euros to 5,000,000 euros.
The Bank of Portugal, as the national competent authority in this matter, will take the necessary actions to ensure full compliance with the regulatory framework applicable to the APIs made available by ASPSPs.
More like this from BDP
BDP published 2 documents in the last 30 days. We email you each new one the day it's published.