Publications and events

EMA responds to EBA Consultation on Passporting under PSD2

EMA responds to EBA Consultation on Passporting under PSD2

See the EBA consultation details here.

The EMA has responded to the EBA’s consultation on regulatory technical standards (RTS) on the framework for cooperation and exchange of information between competent authorities for passport notifications under PSD2. These draft RTS set out templates for passporting, services passporting, agent passporting, and establishment passporting. They also set out a template for distributor passporting. These templates could have a significant impact on PSPs passporting to other EU Member States, including where any services are outsourced to another EU Member State.

The EMA’s response welcomes the standardisation of passporting notifications, as this may improve efficiencies for both regulators and firms. However, there are a number of concerns raised by the EMA in the response.

PSD2 provides for two types of passporting to be undertaken. These are based on the principle of mutual recognition set out in the Treaty of the European Union (“Treaty”). The first is freedom to offer services and the second is the right of establishment. However, the draft format conflates these concepts by requiring one form for both. Not only is this unhelpful from an administrative perspective, but it may result in Member State authorities treating passport entities as established entities. The EMA has accordingly proposed:
– that two forms are used – one for passporting under Freedom of Services, and one for Freedom of Establishment
– a separate, third form should be used for the outsourcing of services
– a definition of “distributor” would help distinguish between agents and distributors in terms of operation and legal responsibilities.


Read the EMA response here.

EMA responds to EBA Consultation on Passporting under PSD2 Read More »

EMA response to FCA Guidance consultation on outsourcing to the cloud

EMA response to FCA Guidance consultation on outsourcing to the cloud

Read about FCA’s consultation here.

The EMA responded to the FCA’s recent consultation on the use of cloud IT service providers This is of significant interest for many Fintechs and innovative PSPs who rely on such outsourcers to deliver many important functions. The FCA draft guidance in a number of areas (i.e. Legal and regulatory considerations, Effective access to Systems Data, Access to business premises) will likely have a significant impact on existing outsourcerrelationships. Based on the current draft, it is likely that many existing service contracts would have to be re-negotiated and possibly terminated with the financial service providers bearing additional costs and corresponding impact on existing operations.

The EMA’s response calls on the FCA to take into account current technology trends and market dynamics when drafting the Final Guidance on this topic. Currently, many regulated firms have limited negotiating leverage to introduce any changes to the standard service delivery agreements offered by the large, reputable cloud IT service providers.

The EMA’s response suggests that instead the Guidance focus on:
(1) additional criteria for a regulated firm to consider when establishing a cloud-service outsourcer due diligence process, and
(2) setting up a robust service review & monitoring framework; for example ensuring a service provided by a cloud-based outsourcer meets agreed key performance indicators (“KPIs”).

Read the EMA response here.

EMA response to FCA Guidance consultation on outsourcing to the cloud Read More »

3rd International Conference on E-money, Cards and Payments

3rd International Conference on E-money, Cards and Payments

3rd International Conference on E-money, Cards and Payments held on 18 – 19 May 2016 at the Lindner Hotel Gallery Central, Bratislava, Slovakia.


Dr Qazi Jalisi, Senior legal adviser for the Electronic Money Association took part in a discussion on “Payments Evolution/Revolution – payment technology for banks and alternative service providers of today and 10 years in the future”. He also gave a presentation on anti-money laundering.

Dr Qazi Jalisi in a panel discussion at 3rd Int'l conference on e-money, cards and paymentsRead more about the conference here.

3rd International Conference on E-money, Cards and Payments Read More »

EMA response to EBA Discussion Paper on security requirements of PSD2

The EMA has responded to the EBA’s discussion paper on strong customer authentication and secure communication under PSD2. This discussion paper asks for views from stakeholders regarding a number of topics that the EBA proposes to address in the regulatory technical standards it will develop to support compliance with the PSD2 security requirements (including the practicalities around strong customer authentication, dynamic linking of customer authentication with individual transaction information and secure intra-PSP communication).

The EMA’s response:
– raises concerns regarding the minimum 10-month time gap between the time PSD2 comes into force and the earliest date that the EBA RTS may be implemented;
– calls for a risk- and principles-based approach rather than delving into prescriptive detail or producing exhaustive lists of security controls/transaction types;
– expresses concern about the negative consequences of an EU standard that is overly prescriptive or diverges significantly from global standards, as many EMA members operate outside the EU;
– calls for the definition of a governance framework (used to assess compliance of individual solutions/products) with the RTS.

The EMA response also requests:
– further clarification around the category of payment activities that might benefit from the ‘risk-based’ exemption frjaneom the requirement to complete strong customer authentication (SCA): Many online account access interactions (i) do not expose sensitive payment data or payment user credentials and (ii) cannot be used to alter existing account settings; thus, they do not give rise to payment fraud risks.
– a flexible approach with regards to the requirements to ‘dynamically link’ each payment with information about the payee and payment amount, as this will introduce significant friction to the user experience with little benefit in terms of security of payment transaction.

Read the EMA response here.


EMA response to EBA Discussion Paper on security requirements of PSD2 Read More »

EMA response on Extension of data-gathering powers

EMA response to HMRC on Extension of data-gathering powers

Read about HMRC’s consultation here.

The EMA has responded to HMRC’s consultation on draft legislation intended to tackle the ‘hidden economy’ of tax avoidance by extending their powers to gather bulk data on transactions by customers of electronic PSPs and business intermediaries. This would give HMRC the legal power to require electronic PSPs (ePSPs) and business intermediaries to report bulk transaction data on their customers on a regular (annual, quarterly or potentially monthly) basis.

The EMA has two main concerns in relation to the draft legislation. Firstly, whilst the intention is only to capture income received in the course of business, the current legal drafting would not preclude HMRC from requesting bulk data related to certain consumer accounts as well as business accounts. Secondly, there is no intention of collecting equivalent data from other PSPs, such as banks. We believe that not only would this have a negative impact on consumer trust in relation to ePSP accounts by raising data privacy concerns, it would place ePSPs at a disadvantage to other PSPs such as banks, who would not be required to provide equivalent information.

On that basis, the EMA’s response proposes amendments to the legislation in several areas:
1. A narrowing of the defintion of electronic PSP
2. A narrowing of the types of payment transactions that can be captured
3. A narrowing of the type of payment recipient whose transaction data can be captured
4. A clarification that merchant acquirers should be excluded, as they are already covered under existing powers.

Read the EMA response here.

EMA response on Extension of data-gathering powers Read More »

EMA response to EBA on SDD EDD

Read about the European Supervisory Authorities’ Joint consultation here.

The EMA has responded to the European Supervisory Authorities’ Joint consultation on risk factors and simplified and enhanced customer due diligence as under 4MLD. The EMA welcomed the format of the draft guidance, which set out an initial section with generic guidance followed by sector-specific guidance.

The response highlights a number of points:

– the guidance around the treatment of Politically Exposed Persons (PEPs) is overly complex, and risks excluding PEPs from financial services as the cost of maintaining their accounts may outweigh any commercial benefit for providers.
– the guidance for around correspondent banking relationships could lead to the conclusion that banks have to take steps to “know their customer’s customer”, which will exacerbate de-risking, a phenomenon that has had a negative impact on the e-money and money service business sectors in recent years
– several detailed comments around risk factors that indicate higher or lower risk in the e-money sector.

Read the EMA response here.

EMA response to EBA on SDD EDD Read More »

EMA 2015 conference sound bites from Payvision

EMA 2015 conference – The impact of payment regulatory changes in Europe

The 5th Electronic Money Association conference (EMA) took place in October 2015, in Brussels. The bi-annual event facilitates a two-way conversation between regulators and EMA members on the upcoming legislative changes in European Economic Area (EEA), such as the Revised Directives on Payment Services (PSD2) and Fourth Money Laundering Directive (4MLD).

View the EMA 2015 conference sound bites from Payvision here.

Share your comments on LinkedIn or tweets on the EMA twitter account where you can find more video footage from the EMA conference.




EMA 2015 conference sound bites from Payvision Read More »

Meet Thaer Sabri, the EMA CEO at Money 20/20 Europe

Money 20/20 Europe, held between 4-7 April 2016 in Copenhagen, Denmark

Start registering for the World’s largest FinTech event before 13 November to get your next fix using EMA200 code to save €200!

Don’t miss the chance to meet there Dr Thaer Sabri, the EMA CEO! He will be representing the Electronic Money Association (EMA) in a panel on innovative payments in a complex regulatory environment.


Read more here about the event.

Meet Thaer Sabri, the EMA CEO at Money 20/20 Europe Read More »

PSD2 Newly regulated services

One of PSD2’s most contested provisions during the negotiation process related to “third party payment service providers”, later redefined as (i) Payment Initiation Service Providers (PISPs) and (ii) Account Information Service Providers (AISPs).

These are not new services, but they will now be subject to regulation for the first time, and through regulation could achieve the stability to enable a new wave of innovation based on the additional functionality.

PISPs include providers such as Sofort and Trustly, and also bank-led initiatives such as the Dutch iDEAL. They essentially enable a user to initiate a payment transaction from their own bank account, to the bank account of the merchant, over existing banking networks. PISPs add value by facilitating the payment from the merchant’s checkout, populating the payment instruction page with transaction and payee data.

AISPs on the other hand include Yodlee as well as Intuit’s Mint; both offer services that enable users to aggregate data from different financial services providers using . This is done by logging into a user’s account and “scraping” the relevant data, and doing so again for the various financial products: bank accounts, loan accounts, credit cards etc. The user is then able to review their financial information at a single location; and more significantly, may be offered tools to analyse the data, compare prices, make suggestions on service providers and perhaps be offered additional products – all tailored to the user’s specific needs.

During the negotiation process, banks proposed that PISPs and AISPs enter into legal contracts with “account servicing payment service providers” (ASPSPs)- such as banks, before they could access users’ accounts. This might have also created a framework for cost sharing or for fees to be applied. This was rejected by legislators who feared it would act as a barrier to take-up, and set out provisions for unencumbered access wherever there was an online banking interface. Similarly, legislators provided that ASPSPs could not prohibit customers from using their ASPSP account authentication credentials with third party service providers.

PSD2 has also tasked the EBA with developing regulatory technical standards on “secure open standards of communication” between the various parties. This falls short of mandating an API, and was welcomed by PISPs who feared that the development of more detailed specifications could be used as a proxy for limiting bank account and information access.

There are benefits for customers generally, but also for payment service providers looking to offer new payment products. The first is in lowering the cost of funding for these products. E-money issuers for example have an acquiring cost associated with enabling consumers to purchase e-money and funding their accounts or prepaid cards. Direct bank transfers would lessen dependence on debit and credit card funding, lowering the cost of acquiring, and in turn enabling more competitive consumer and merchant fees.

Secondly, and as trailed within PSD2 text, the Commission foresees the migration of these services to the physical world. PISPs could issue “debit cards” linked to users’ own bank accounts, triggering payments over the banking network, and bypassing card schemes. This could save on interchange and other card related fees, but will of course be subject to the PISPs’ own fees.

AISP services have a distinct appeal. They have the potential of concentrating value and creating a single reference point for users. Aggregating user data, mining this information, providing users with tools to better understand their finances, and presenting money saving choices and offers, perhaps in a PSP agnostic environment, have the potential to build consumer trust and to provide a gateway to financial services.

The article “PSD2 Newly regulated services” was written by Dr Thaer Sabri, EMA CEO

PSD2 Newly regulated services Read More »