MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
PSD2 is the revised European Payment Services Directive, in force in the Netherlands since early 2019. The biggest change: banks must grant third parties access to payment account data—with the explicit consent of the customer and only to parties with a valid license. This opens up new services but entails strict requirements regarding consent and privacy, which are supervised by the Dutch Data Protection Authority (AP) and the Dutch Central Bank (DNB).
PSD2 (Payment Service Directive 2) is the successor to PSD1, the directive that introduced SEPA, among other things. Since its entry into force in early 2019, there have been significant changes: for instance, the deductible for the loss of a debit card and surcharges for credit card payments in online shops have been abolished. In addition, PSD2 offers new opportunities for entrepreneurs — subject to conditions.
Third parties gain access to payment accounts
The most important change is that banks are required to grant third parties access to the payment account, provided that conditions are met. The customer must give their consent for this, and that consent is valid for a maximum of ninety days. Furthermore, the party granted access must hold a valid license.
For example, a mortgage advisor can provide targeted advice based on an overview of income and expenses, or an app can offer a comprehensive overview of all accounts. Such access also entails (privacy) risks — and that is why the rules are strict.
Explicit consent is required
To protect the consumer, he must give the third party explicit consent. The Dutch Data Protection Authority (AP) has previously indicated the requirements that such consent must meet: free, unambiguous, specific, and informed.
- Tacit consent or a pre-ticked box is not permitted.
- Because consent must be freely given, the consumer must also always be able to withdraw it.
- The consent is specific: only for a specific processing and a specific purpose. The data may never be used for any other purpose.
Both the Dutch Data Protection Authority (AP) and De Nederlandsche Bank (DNB) supervise this. The Consumers' Association also conducts annual checks on providers of PSD2 services and has its own hotline; the association sees the benefits (more competition and innovation) but also points out the risks.
Don't forget the GDPR
Payment service providers, like all organizations that process personal data, must comply with the GDPR : have a valid legal basis, provide clear information, and properly secure the data.
Frequently Asked Questions
Do I need a license for PSD2 services?
Yes. Anyone wishing to access payment account data as a third party requires a valid license and must meet strict requirements, with supervision by the DNB and the AP.
How long is a customer's consent valid?
Permission for access is valid for a maximum of ninety days and must be renewed thereafter. Furthermore, the customer can withdraw the permission at any time.
May I use PSD2 data for marketing?
No, not without further ado. The consent is specific to a particular purpose; use for another purpose, such as marketing, is in principle not permitted.
Getting started with PSD2?
For PSD2 services, you need not only a license but also the right documentation and a comprehensive consent and privacy approach. The legal experts at MKB Juristen can help you. View our expertise in privacy and data protection or schedule an intake meeting .