On 14 April 2021, Maria Raphael participated as a speaker at the 3rd Digital Banking & Payments Conference, “Responding to Change | Empowering Resilience”.

The conference examined the changing European banking and payments landscape, including new banking models, payment innovation, fintech, challenger banks and the expansion of financial services into increasingly digital and interconnected markets.

Maria Raphael, who at the time was Chair of the European Association of Data Protection Professionals (EADPP), delivered the presentation:

“The Interplay of the Second Payment Services Directive (PSD2) and the GDPR.”

Her contribution focused particularly on the data-protection questions created by two categories of payment services introduced under PSD2:

  • Payment Initiation Service Providers, or PISPs; and
  • Account Information Service Providers, or AISPs.

She also moderated a discussion between banking executives concerning customer and staff influence on B2B banking and new payments, including regulation, privacy, customer loyalty and mobile channels.

The presentation took place against the backdrop of a fundamental change in European payments.

PSD2 had opened payment-account infrastructure to new categories of regulated third-party providers.

At the same time, the GDPR imposed independent requirements governing the processing of the personal data accessed through those services.

The practical challenge was therefore not simply to comply with PSD2 or the GDPR separately.

It was to understand how both frameworks applied to the same payment-data ecosystem.

Responding to change in banking and payments

The 3rd Digital Banking & Payments Conference focused on the transformation of banking and payments through:

  • fintech;
  • challenger banks;
  • new payment services;
  • customer-centric technologies;
  • mobile channels;
  • innovative banking models;
  • and expansion of financial services into sectors such as retail, telecommunications, health and energy.

The event was held under the auspices and with the support of organisations including the Cyprus Deputy Ministry of Research, Innovation and Digital Policy, the Association of Cyprus Banks, the Cyprus Computer Society and EADPP.

The underlying theme was resilience in a financial sector undergoing rapid digital transformation.

For the data-protection discussion, that transformation raised an immediate question:

What happens when regulated access to payment accounts also involves extensive access to personal data?

PSD2 changed who could access payment-account data

PSD2 reshaped the European payments market by supporting new payment services and greater competition around payment accounts.

Two categories were particularly important to the presentation.

01 · PAYMENT INITIATION SERVICE PROVIDERS

A Payment Initiation Service Provider can initiate a payment order at the request of a payment-service user in relation to a payment account held with another payment service provider.

02 · ACCOUNT INFORMATION SERVICE PROVIDERS

An Account Information Service Provider can provide consolidated information concerning payment accounts held by a user with one or more payment service providers.

These services created opportunities for innovation and open banking.

They also created new flows of personal data between:

  • payment-service users;
  • account-servicing payment service providers;
  • PISPs;
  • AISPs;
  • and other participants in the payment ecosystem.

The question was therefore not simply whether a third-party provider was entitled to access an account under payments law.

It also needed to determine the conditions under which the personal data involved could lawfully be processed.

One of the most important principles in the PSD2/GDPR relationship is that a permission or requirement under payments legislation does not automatically determine the legal basis for processing personal data under the GDPR.

Payment-service providers therefore need to analyse the two regimes together.

The EDPB’s Guidelines 06/2020 on the interplay between PSD2 and the GDPR emphasise this distinction.

A provider may be permitted to access payment-account information under PSD2 while still needing to establish:

  • which GDPR legal basis applies;
  • whether the processing is necessary for the relevant service;
  • whether additional purposes are compatible;
  • and whether GDPR principles such as transparency and data minimisation are satisfied.

This is one of the central reasons the two frameworks cannot be implemented independently.

PSD2 uses the concept of “explicit consent” in relation to access to, processing and retention of personal data necessary for the provision of payment services.

That terminology can create confusion because the GDPR also uses the concept of consent as a legal basis for processing.

The EDPB clarified that the reference to explicit consent in PSD2 should not automatically be treated as a separate GDPR legal basis.

In the payment-services context, the GDPR legal basis may instead arise from another provision, such as processing necessary for performance of a contract, depending on the processing involved.

The correct analysis therefore requires payment-service providers to distinguish between:

  • the contractual and regulatory authorisation required to provide the payment service; and
  • the legal basis required under the GDPR for the related personal-data processing.

Open banking does not create unrestricted rights to reuse payment data

The availability of payment-account information through open-banking services does not mean that PISPs and AISPs can use that information without limitation.

The GDPR principles continue to apply.

Relevant questions include:

  • which data are necessary to provide the requested payment service;
  • whether further processing is compatible with the original purpose;
  • whether additional processing requires another legal basis;
  • how long data should be retained;
  • who receives the data;
  • and whether the user has been given appropriate transparency information.

A payment-data ecosystem can contain information capable of revealing significant aspects of an individual’s financial behaviour.

Data minimisation and purpose limitation are therefore particularly important.

Payment transactions can also contain data about people who are not the customer

Another important PSD2/GDPR issue concerns what the EDPB describes as “silent party data”.

A payment transaction can contain personal data relating to someone who is not the user of the PISP or AISP service.

For example, transaction information may identify:

  • the recipient of a payment;
  • the sender of funds;
  • counterparties;
  • or other individuals appearing in payment records.

Those individuals have not necessarily contracted with the third-party payment-service provider.

The processing of their personal data therefore requires its own GDPR analysis.

This illustrates why open banking cannot be understood solely through the contractual relationship with the customer who requested the service.

Access should be limited to the data necessary for the service

The GDPR principle of data minimisation is particularly significant where payment-service providers receive access to detailed account information.

The existence of technical access does not mean that every available field should automatically be collected, stored or reused.

A provider should be able to explain:

  • which account data it needs;
  • why those data are necessary;
  • how long they are retained;
  • whether the data are used for another purpose;
  • who receives them;
  • and how unnecessary access is prevented.

For AISPs and PISPs, privacy by design therefore needs to be reflected in the architecture of account access itself.

The EDPB Guidelines remain central to the PSD2/GDPR relationship

The European Data Protection Board adopted the final version of Guidelines 06/2020 on the interplay between PSD2 and the GDPR on 15 December 2020.

The Guidelines address matters including:

  • lawful grounds for processing;
  • further processing;
  • fraud prevention;
  • the relationship between PSD2 “explicit consent” and GDPR consent;
  • silent-party data;
  • special-category data;
  • data minimisation;
  • security;
  • transparency;
  • accountability;
  • and profiling.

Those issues provided important regulatory context for the 2021 conference presentation.

They also remain relevant today because PSD2 continues to operate while the EU completes the transition toward its next-generation payments framework.

EDPB Guidelines 06/2020 →


WHAT HAS CHANGED SINCE THE 2021 CONFERENCE?

The payments landscape has evolved significantly since the conference. PSD2 remains the current legislative framework, but the EU has agreed a major reform package that will eventually replace significant parts of it.

PSD2 is moving toward a new legislative architecture

On 28 June 2023, the European Commission proposed a major reform of the EU payments framework.

The package consists of:

  • a new Payment Services Directive, commonly referred to as PSD3; and
  • a directly applicable Payment Services Regulation, or PSR.

The proposed structure separates parts of the existing PSD2 framework between a Directive and a Regulation.

Broadly, the reform is intended to:

  • strengthen protection against payment fraud;
  • improve consumer protection;
  • support competition between banks and non-bank payment-service providers;
  • improve open banking;
  • strengthen enforcement;
  • and increase harmonisation across the European payments market.

The reform also incorporates the electronic-money framework more closely into the payments architecture.

The PSD3 / PSR reform has moved close to formal adoption

The European Parliament and the Council reached a provisional political agreement on the PSD3 / PSR package on 27 November 2025.

The final compromise texts were subsequently confirmed at Council level in April 2026.

As of September 2026, the legislative package has not yet been published in the Official Journal and should therefore not be described as fully enacted or applicable law.

PSD2 remains the operative payment-services framework.

The final compromise texts nevertheless provide a clear indication of the direction of the next-generation regime.

European Commission payment-services reform overview →

A new payments framework does not remove the GDPR layer

The shift from PSD2 toward PSD3 and the PSR does not remove the core issue discussed at the 2021 conference.

Payment services continue to involve extensive processing of personal data.

The European Data Protection Supervisor, commenting on the Commission’s reform proposals, again stressed the need to distinguish between:

  • permissions and requirements created by payments legislation; and
  • the legal basis required for processing personal data under the GDPR.

That is essentially the same regulatory intersection that existed under PSD2.

The legislative architecture may change.

The need to analyse payment regulation and data protection together remains.

The challenge is increasingly one of data governance, not simply account access

The original open-banking debate focused heavily on whether third-party providers could obtain access to payment accounts.

As the market has matured, the governance questions have become equally important.

Payment-service providers need to understand:

  • what data can be accessed;
  • for which purpose;
  • under which payment-services rule;
  • on which GDPR legal basis;
  • for how long;
  • whether further use is permitted;
  • which parties receive the information;
  • and how data-subject rights and transparency requirements are implemented.

For organisations providing payment services, data governance should therefore form part of product architecture rather than being added after technical integration is complete.

What remains relevant from the 2021 discussion

Although the European payments framework is moving toward a new generation of legislation, several principles from the 2021 presentation remain directly relevant.

Payment-service providers should still distinguish:

Regulatory permission

What does payments legislation permit or require the provider to do?

GDPR legal basis

What legal basis supports the associated processing of personal data?

Necessity

Which data are genuinely necessary to provide the service?

Further use

Can payment information be used for another purpose?

Third-party data

Does the transaction contain personal data relating to individuals who are not customers of the service?

Transparency

Do users understand what account information is accessed and how it will be used?

Technical access

Does the system architecture limit access and processing to what the service actually requires?

The terminology and legislative provisions may evolve.

The need to answer these questions does not.

Payments innovation and privacy regulation need to evolve together

The 2021 Digital Banking & Payments Conference reflected a period when open banking was rapidly changing the structure of European payments.

PSD2 had created new regulated actors and new ways of accessing payment-account information.

The GDPR required those new data flows to operate within a separate framework of lawful processing, transparency, minimisation and accountability.

Five years later, the payments legislation itself is again changing.

The PSD3 / PSR reform is intended to strengthen the European payments market and address problems identified during the PSD2 period.

But the core compliance lesson remains the same.

Innovation in payments creates data flows.

Those data flows need their own legal analysis.

For banks, fintechs, PISPs, AISPs and other payment-service providers, payments regulation and data-protection compliance therefore need to be designed together rather than treated as separate workstreams.