top of page

PSD3 and PSR: PSR brings non-regulated entities into the core of payment regulation (Part 4)

  • Writer: Sigita Zavišienė
    Sigita Zavišienė
  • Jun 11
  • 2 min read


The rules must be followed not only by regulated entities


The Payment Services Regulation (PSR) applies to services provided with the EU by PSPs. In addition, the PSR also applies to services provided within the EU by these entities:

  • Technical services providers

  • Operators of payments systems and payment schemes

  • E-communication services providers

  • Hosting services providers

  • Providers of very large online platforms and of very large online search engines

  • Original equipment manufacturers of mobile devices.


Technical services providers (e.g. Mambu)


Under the PSR, technical service providers must:

  • Follow contract termination rules (similar to PSPs)

  • Be liable for direct financial losses caused by failures related to SCA

  • Formalise outsourcing agreements when technical providers deliver and verify SCA elements

  • Ensure non-discriminatory access to payment technology

  • Comply with EBA technical standards on security, communication, and transaction monitoring.


Relevant Articles of the PSR: Articles 23(2), 58, 87, 88a, 89, 91 and 93 of the PSR.

 

Payment systems & schemes (e.g. Mastercard, VISA)


Key requirements:

  • Access rules must be objective, transparent, proportionate, and non-discriminatory

  • Participation may only be refused if the applicant poses a risk to the system

  • Restrictive membership rules and discrimination between participants are prohibited

  • Transparent fee structures (interchange, processing, and scheme fees)

  • Liability for failures affecting the application of the SCA

  • Strong personal data obligations


Relevant Articles of the PSR: 31, 31a, 58, 80, 91 and 93


Electronic communication providers (e.g. Telia, Tele2, Vodafone, Microsoft (Outlook))


Strong involvement in fraud prevention. Telcos and communication platforms must:

  • Implement measures to detect and prevent impersonation fraud (spoofed calls or emails)

  • Share fraud information with PSPs

  • Educate users on scams and reporting

  • Support public fraud awareness initiatives

  • Ensure fair and non-discriminatory access to mobile device features for secure payments


Relevant Articles of the PSR: 59, 59a, 84, 88a, 91 and 93


Hosting providers (e.g. Azure, AWS, Hostinger, Google Cloud)


Hosting providers must:

  • Cooperate with PSPs on fraud detection

  • Enable data sharing in case of suspicious activity

  • Ensure rapid fraud reporting and information exchange

  • Inform users about emerging scams

  • Compensate PSPs for losses resulting from illegal content that leads to fraud


Relevant Articles of the PSR: 59a, 78 and 91

 

Platforms & Search Engines (e.g. TikTok, Google, Facebook, Booking.com)


Requirements include:

  • Rapid cooperation and data sharing with PSPs to prevent fraud

  • Dedicated communication channels for fraud detection and alerts

  • User warnings and education about online scams

  • Verification of the financial advertisers

  • Transparency of the financial ads


Note: Direct supervision at EU level

Relevant Articles of the PSR: 59a, 59b, 84 and 89a


Device manufacturers (e.g. Apple, Samsung) Obligation include:


  • Provide fair, reasonable & non-discriminatory access to device features needed for secure payments

  • Ensure interoperability for PSPs and technical service providers

  • Limit restriction to strictly necessary security measures

  • Justify and document any limitations

  • Publish general conditions for interoperability and access


Relevant Article of the PSR: 88a


Need advice on PSD3/PSR requirements? Contact us: Sigita Zavišienė

bottom of page