2022-06-24
Added
Competent authorities designated under PSD2 must submit aggregated statistical data on payment fraud to the European Banking Authority via the European Central Bank, thereby exempting them from direct submission to the EBA. Submissions are required semi-annually, with deadlines of 30 June for the period ending 31 December and 31 December for the period ending 30 June. Data must be reported through EUCLID using the EBA Data Point Model, either via an Excel template generating XBRL-CSV or directly via XBRL-XML files. The decision enters into force immediately upon adoption on 24 June 2022.
EBA published 1 document in the last 30 days — get each new one by email the day it lands.
Decision of the European Banking
Authority EBA/DC/453 of 24 June 2022 concerning reporting of payment fraud data under the revised Payment Services Directive (PSD2) The Executive Director Having regard to (1) Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC 1 (the ‘EBA Regulation’), in particular Article 35 thereof, (2) Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market 2 (the 'PSD2'), in particular Article 96(6) thereof, (3) EBA Guidelines on fraud reporting under PSD2 (EBA/GL/2018/05), as amended by EBA/GL/2020/01 (the ‘EBA Guidelines on fraud reporting under PSD2’), (4) Decision EBA/DC/2020/335 of the EBA concerning the European Centralised Infrastructure of Data (EUCLID) (the ‘EUCLID decision’), Whereas:
(1) Competent authorities, as referred to in point (2) of Article 4 of the EBA Regulation, are required, in accordance with Article 35 of the EBA Regulation, to provide the EBA with all the necessary information, in specified formats, to carry out the tasks conferred on it. The EBA may also request information to be provided at recurring intervals and in specified formats or by way of comparable templates approved by the EBA. 1 OJ L331, 15.12.2010, p. 12 2 OJ L 337 23.12.2015, p. 35
2
(2) Article 96(6) of PSD2 requires payment service providers, as defined in Article 4(11) PSD2, to submit to their competent authorities statistical data on fraud relating to different means of payment. Also, the competent authorities under the PSD2 are required in turn to provide the EBA and the ECB with the same data in aggregated form. (3) The EBA Guidelines on fraud reporting under PSD2 require payment service providers to report to their competent authorities such data on a semi-annual basis, based on the applicable data breakdown(s) and validation rules set out in Annex 2 of the EBA Guidelines on fraud reporting under PSD2, and in accordance with the timelines and format set by the respective competent authorities. Competent authorities are required in turn to send the aggregated data to the EBA and the ECB within six months from the day after the end of the reporting period. (4) The EBA Guidelines on fraud reporting under PSD2 apply since 1 January 2019. In order to provide a streamlined submission of data and avoid double reporting burden for competent authorities to send data both to the EBA and the ECB, the EBA, the ECB and competent authorities agreed in 2019 on an ‘interim’ solution (envisaged to apply until the application date of the revised ECB Regulation on Payments Statistics), whereby each competent authority/National Central Bank would submit the data required under the PSD2 and the EBA Guidelines on fraud reporting under PSD2 only once, to the ECB and the ECB would subsequently share this data with the EBA, which would be based on a separate bilateral procedure. This ‘interim solution’ applied for the first six half-yearly reporting periods under the EBA Guidelines on fraud reporting under PSD2 (i.e. from January 2019 to December 2021). (5) The experience accumulated in the collection of data under the EBA Guidelines on fraud reporting under PSD2 during the said period has shown that there is a need to provide clearer expectations to all parties involved regarding both a minimum admissible level of data quality and specifications, and binding remittance dates for the submission of data to the EBA. (6) The EUCLID Decision, which applies to competent authorities as referred to in point (2) of
Article 4 of the EBA Regulation on fraud reporting under PSD2, states that the competent
authorities shall submit “all necessary data, record, file, statistics, document or numbers (…) to the EBA (…) on the basis of a Data Reporting Obligation” exclusively through EUCLID, except where the EBA has explicitly acknowledged, by Decision of the Executive Director, that the submission of data through other means is permitted. The Decision of the Executive Director shall also specify the other means that may be used for submission of such data and shall set out any technical specification necessary Furthermore, data on payment fraud is a Data Reporting Obligation, as defined in Article 1(c) of the EUCLID Decision, incumbent on competent authorities. (7) With a view to providing a streamlined submission of data and avoiding a burden of double reporting for competent authorities to both the EBA and the ECB, this decision allows for
3 data to be submitted by the relevant competent authorities via the ECB to the EBA. This is also the case for other data transmitted under the EUCLID decision, provided that the data submitted by the competent authorities is in accordance with the data breakdowns and validation rules set out by the EBA and in line with the format and timelines set out in the Decision. Has decided as follows:
Article 1 – Scope
This decision coversthe reporting to the EBA of aggregated statistical data on fraud from competent authorities designated under PSD2 in accordance with Article 96(6) of PSD2 and the EBA Guidelines on fraud reporting under PSD2.
Article 2 – Data to be reported
4 specifications provided by the EBA (including the EUCLID specifications mentioned in the EUCLID Decision and the validation rules set in the EBA Guidelines on fraud reporting under PSD2). Where the competent authorities cannot warrant this for a particular set of submitted data, the competent authorities shall draw the EBA’s attention thereto.
2. The EBA shall make the results of applied EBA validation rules available to the competent
authorities by 25 July and 25 January of each year.
3. In addition to the EUCLID specifications and the EBA validation rules published by the EBA, the
EBA may conduct additional quality checks of the data received to ensure consistency, which may then require revisions from the competent authorities.
4. Competent authorities shall submit the required data revisions to the EBA without undue delay.
Article 5 - Confidentiality and technical specifications
5
This Decision enters into force immediately.
Done at Paris, 24 June 2022
François-Louis Michaud
Executive Director
Read the rest free
Source: European Banking Authority — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from EBA
EBA published 1 document in the last 30 days. We email you each new one the day it's published.