6 ms·
PSD2 – a directive that will change banking in Europe
- ptrptr 10y agoThis post was re-upped and is part of https://news.ycombinator.com/item?id=11662380 https://news.ycombinator.com/item?id=11662380 program. Full message I've received: We thought you might like to know that we put https://news.ycombinator.com/item?id=13921072 https://news.ycombinator.com/item?id=13921072 in the second-chance pool, so it will get a random placement on the front page sometime in the next 24 hours. This is part of an experiment in giving good HN submissions multiple chances at the front page. If you're curious, you can read about it at https://news.ycombinator.com/item?id=11662380 https://news.ycombinator.com/item?id=11662380 and other links there. And if you don't want these emails, sorry! Tell us and we won't do it again. Thanks for posting good stories to Hacker News, Daniel (moderator)
- djsumdog 10y agoThis seems backwards and terrible. Every other nation in the world allows direct person-to-person transfer between any bank. You put in your friend's name, BSB and account number into your phone in Australia and the next day they have money. In Germany, you have additional 1-time use TAN numbers. Only in the US must we use PayPal, Facebook or paper checks. In fact, paper checks are the only way to send money fee-free between banks. You can of course just display a check on a screen and have the other person take a photo of it with their phone, but that's still pretty ass backwards. Banking should allow direct transfer at the state level, without third parties or fees.
- scribu 10y agoIn the EU country where I'm from, you do pay a percentage fee each time you make a transfer to an account from a different bank.
- otheotheothe 10y agoWhere is that? SEPA room? In germany all SEPA transfers are free
- _pmf_ 10y agoThat's wrong.
- geff82 10y agoIt's not. Should I send you my business contract with a German bank?
- icebraining 10y ago"All transfer are free for my particular contract with a specific bank" is not the same as "In Germany all SEPA transfers are free". I don't pay for SEPA transfers either. But they're not all free in my country.
- _pmf_ 10y agoQuoting the SEPA-Wikipedia page: "Banks and payment institutions still have the option of charging a credit-transfer fee of their choice for euro transfers if it is charged uniformly to all EEA participants, banks or payment institutions, domestic or foreign." Which my bank does.
- germanier 10y agoCan you do both SEPA transfers and direct debit for free on that business account? If yes, I would be very interested. What's the name of this magical bank and do they take new customers?
- mantas 10y agoLithuanian there. SEPA (both intra-country and SEPA-wide) transfers cost money. FFS, even in-bank transfers cost money. €0.10-0.40, depending on transfer direction, bank and wether done online or in-person. But banks are happy to wave fees if you signup for a discount package (debit card + iban acc + free withdrawal + free transfers) or eligible for premium account for one reason or another.
- Tharkun 10y agoThat's simply not true. SEPA explicitly states that all SEPA transactions should cost the same amount of money. Either your bank is ripping you off, or you're not using SEPA. Clarification: that is to say for the same originating party. Different banks can charge whatever they like, but always the same amount for any SEPA payment, regardless of the target bank.
- icebraining 10y agoWhere does it say that? EC 924/2009 only says that the cost for a cross-border transfer must be the same as a corresponding national transfer, not that it must be a fixed amount. Furthermore, it leaves at the discretion of the national regular what a "corresponding transfer" means.
- shezi 10y agoWhat would be the difference between "the same" and "a fixed amount"? If it is "the same" for all transfers, would that not be a "fixed amount"?
- icebraining 10y agoIt's not the same for all transfers. It's the same for a cross-border transfer as for an equivalent national transfer. Meaning that they can charge a percentage of the transfer, rather than a fixed amount, as long as they charge the same percentage for a national transfer.
- mdekkers 10y agoHey, come and tell my bank in Cyprus. I am getting ripped off for literally hundreds of euros in fees every month on SEPA charges. I actually looked into this when they were finally forced to offer SEPA (still a hidden thing in their online banking) transfers, and I noticed they charge the same as for SWIFT. When I brought it up they said "if you make a big deal about it we will close your account"
- shezi 10y agoAnd that is partially why the thing in the article is so great: simply go to a German bank where there are no SEPA fees in the Euro area and be done with it. Lithuanian banks will realize at some point when their customers flee to other European countries.
- matt4077 10y agothat's already possible (single market etc.). It's just not widely used because people rarely trust banks without a local branch.
- wichert 10y agoI don't see anything in PSD2 that prevents direct person-to-person transfers between banks. SEPA (https://en.wikipedia.org/wiki/Single_Euro_Payments_Area#Charges https://en.wikipedia.org/wiki/Single_Euro_Payments_Area#Char... ) already requires banks to allow free transfers (with a few rare exceptions).
- sjtgraham 10y agoIn the UK you can do this and the payment is settled in the beneficiary's account within minutes.
- mantas 10y agoIn Lithuania all you need is IBAN number and receiver's name for in-country transfer. Money are pushed around 3x a day. It's more or less the same in whole SEPA area. Receiver's bank details (name + swift + address) are needed for international transfers though. I know for a fact that's all I needed to make payments to Poland and Germany. I received transfers from other EU countries with these credentials too.
- johansch 10y agoYou're not talking about the PSD2 thing in Europe, are you?
- dhfhduk 10y agoFWIW, there are services in the US that allow you to do this. I've done it with Wells Fargo, for instance. It might not be as standardized as in some other places, though, and I agree with your general frustration over the state of banking and financial transaction practices in the US.
- fergie 10y agoIts so strange that the US still uses checks.
- legulere 10y ago> AISP (Account Information Service Provider) are the service providers with access to the account information of bank customers. I do not see why I should entrust anybody but the bank with information about my wealth. This will get abused and I will probably get nudged into this, so that the company selling an unrelated product can sell my information. If you want to do a product using my banking data, then do a product using FinTS (https://en.wikipedia.org/wiki/FinTS https://en.wikipedia.org/wiki/FinTS) and not as a service that grabs my data to you. > PISP (Payment Initiation Service Provider) are the service providers initiating a payment on behalf of the user. No thanks! Direct debit and wire transfer work good enough. This probably will open the door to insecure payments without 2 Factor Authentication. > For banks, PSD2 poses substantial economical challenges. They are already under stress to provide low-cost bank accounts with the low interest rates of today. I am currently with a bank that I can trust (credit union) and I really do not see much of a need to change.
- javiercr 10y ago> I do not see why I should entrust anybody but the bank with information about my wealth. This will get abused and I will probably get nudged into this, so that the company selling an unrelated product can sell my information. Believe or not, many people (consumers) do this. For example: every Mint.com user
- sjtgraham 10y ago> No thanks! Direct debit and wire transfer work good enough. This probably will open the door to insecure payments without 2 Factor Authentication. PSD2 mandates "strong authentication", which is multi-factor, if the transaction is above 50 euros in value.
- matt4077 10y agoIn online payments, your choices in Europe are actually quite limited by this barrier to competitiveness: Wire transfers are usually free but take 1-3 days. Paypal and credit cards charge around 2%. This will enable processors to initiate and verify payments for a fraction of the costs. 2% can really add up as more and more commerce moves online.
- ivan_gammel 10y agoOnce the responsibilities for managing customers money will be spread between banks and fintech services, its possible that at some point the system will become too complicated to foresee potential risks (in this case it could be cyberattacks on infrastructure or instability of the banks due to the lower profits, increasing costs and faster money flows). As we know from our history, misunderstood risks may eventually lead to crisis. What are the guarantees that it won't happen in this case?
- dade_ 10y agoThe fact is that banks already use 3rd parties to provide new features and share data with them today. As I understand this post, it forces banks to allow 3rd parties that I can choose. Even if I choose not to use any of these services, the services my bank offer will need to be competitive for those that do. I think this sounds great as it also means that companies that do develop new products aren't going to have to resort to hacks to access client data or risk being locked out by the institution. Great post, I hadn't heard anything about this before, but I don't live in Europe.
- jslampe 10y agoI can appreciate the concerns some have voiced, but there's two main arguments for this approach. 1. It's better than what we have today. 2. PSD2 is standardizing and increasing access to financial data, making the entire ecosystem more competitive. Regarding #1: I understand the concerns regarding privacy and security, but this injects a whole new range of improvement that quite honestly we don't have today. Unlike many countries that have rendered their bank account number useless, the US has not. Today, we all provide our bank account numbers to a variety of companies (our jobs for salary, rent, etc.) via a direct credit or debit authorization form to a third party. The proliferation of Private Account Numberss in the digital age is exactly what's makes them such a high-value target for criminals. A digital authentication and authorization approach allows us to set parameters around authorization, rotate keys, create programmatic constraints, inject real-time security, and a number of other consumer controls (e.g. remove authorization for that annoying magazine company that charges me every month for that Better Homes and Gardens magazine I never ordered). This can all be done without providing the level of access we and banks provide on our behalf every day. Regarding #2: Banks are great at a number of things, like holding and securing our money. They're terrible at responding to market forces or consumer concerns. Instead, they use the mountains of red tape and regulation to fortify themselves from new market entrants. Greater, more open access to financial information levels the playing field; thus, increasing both innovation and better pricing for all. TL;DR - this is way better than what we have today.
- fsimoneschi3 10y agoSomething that is often overlooked about PSD2 is the introduction of a real liability model and explicit customer consent. What happens today is that account aggregators and payment initiation providers (this is true in US and EU) are operating in a gray area where transparency, consumer protection, and liability are either completely neglected or totally insufficient. PSD2 will create a clear regulatory framework, will introduce consumer protection, oversight from competent authorities and ultimately will create a transparent liability model for all the actors involved in the flow (data and payments). I think this is a great outcome for consumers and market competition. PSD2 is not perfect but is shaking the industry quite a lot. I'm working on TrueLayer (http://truelayer.com http://truelayer.com) which is a universal bank API platform in the context of PSD2. Email in profile if you want to chat about this topic.
- matthew_192 10y agoI often wonder if authors of PSD2 whitepapers ever read the text of the directive they're discussing. PSD2 is _not_ a carte blanche for every regulated PISP/AISP to consume Bank APIs for any arbitrary user. API access will be secured by the Account servicing PSP (ASPSP) security credentials. I.e. in order to initiate a payment the PISP will have to collect the users security credentials (password, mTAN or other OTP) issued by the ASPSP. Same goes for AISPs, where the customer must be initially authenticated with ASPSP credentials and then authenticate again after 90 days.
- sjtgraham 10y agoYes. Many of them do not read the directive let alone the RTS.
- nickonline 10y agoThere's still so many open questions though * How do I know the PISP/AISP is going to do what they say, how are they accredited? * If Spain has a very lax accreditation process then fraudulent PISP/AISP's will congregate there to scam other europeans - how do you stop this game of wack-a-mole when each country in the EU is defining their own system? * There's hugely complicated Strong Customer Authentication regulation that's just been released in draft adding complexity to an already complex system The problem is not _any_ arbitrary user that people are worried about, it's scams. If I approach 1000 people and 1 manage to scam one, I have access to all their financials
- Qantourisc 10y agoAnyone else wondering about potential security problems, and "hey where is my money" ? Now I didn't look into the protocol or security measures. But this has to be a risk.
- ErrantX 10y agoSo, the European Banking Authority (who wrote PSD2) have thought about this. The Directive mandates "Secure Customer Authentication" (SCA) which is pretty explicit about levels of security. It basically extends multi-factor authentication to all sorts of existing and new payment vectors. Here's a fun doc if you're interested: https://www.eba.europa.eu/documents/10180/1761863/Final+draft+RTS+on+SCA+and+CSC+under+PSD2+%28EBA-RTS-2017-02%29.pdf https://www.eba.europa.eu/documents/10180/1761863/Final+draf...
- mschuster91 10y ago> Some banks have already started making their APIs available. Examples hereof are the Danish Saxo Bank, that opened up for their APIs in September 201510 and Capital One, a UK based bank, that already now enables affiliates to benefit through their APIs. The article author is sadly uninformed on this one. In Germany, HBCI is employed since 2002 by 2000+ banks, approximately half of German banks (https://de.wikipedia.org/wiki/Homebanking_Computer_Interface https://de.wikipedia.org/wiki/Homebanking_Computer_Interface).
- matt4077 10y agoThe rather informed author is speaking of APIs using the the PSD2 standard, which serves a completely different purpose than HBCI. Of course ever bank everywhere has, for the last 20 years+, offered some way for their customers to interact via an API.
- mschuster91 10y ago> The rather informed author is speaking of APIs using the the PSD2 standard, which serves a completely different purpose than HBCI. Sorry, you're flat out wrong there. You can implement both an AISP and a PISP using HBCI. An AISP needs only a bank that supports HKKAZ/HKEKA transactions (aka, fetch transaction records). A PISP needs HKAOM/HKAUB/HKCCS (aka, initiate transfer transaction) transaction support from the bank. > Of course ever bank everywhere has, for the last 20 years+, offered some way for their customers to interact via an API. In most cases only for professional customers. HBCI (in Germany, though) changed the table as it was explicitly intended for private/small business owners.
- YeGoblynQueenne 10y ago>> banks’ monopoly on their customer’s account information (...) is about to disappear To clarify, this is presented as a good thing. Of course, my bank doesn't have a "monopoly" on my account information: that information is not a commodity. More so, it is definitely not something that I would ever want to have change hands and be traded around. I entrust my money to the bank, very grudgingly, because it's a convenience, but I definitely, very very definitely, do not want it to share any information about the services it provides to me with third parties. I really hope the article is misrepresenting the new directive, or that at the very least it will be a unique legistlative exception that somehow manages to provide adequate safeguards to my privacy, otherwise... OK, I don't know what, otherwise. This just sounds insanely stupid. In terms of protecting EU citizens' privacy it's a giant leap backwards.
- hopeless 10y agoIt's not about the banks selling your information but about you having (or giving) access to your information. For example, manually retyping my bank account transactions into my accounting software will hopefully become a thing of the past. And long overdue too!
- matt4077 10y agoHow about reading the first paragraph, or even the whole article? It means they need to provide API access to third parties upon your request. The idea is to disentangle services that currently are tied to a bank account. One example is online payment, where currently there are actually services in Europe that will ask you for your banking pin and tan to initiate and verify a wire transfer on your behalf – they actually use scripted browsers and even manually entry for this now. This does in no way change the data-protection requirements. They can not share your data with third parties without your consent beyond what is currently allowed.
- pjc50 10y agoThe potentially huge implication of this is the marginalising of existing payment processors. In theory it may be possible for merchants to directly get a payment from your bank by a mechanism a bit like OAuth. The underlying objective is the creation of a smooth and level market for payment services such that competition between European financial services companies increases, rather that being limited to banks which tend to be restricted to the country. Actual text of directive: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32015L2366 http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:320... See also http://www.thebunker.net/blog-psd2-is-a-disruptive-game-changer-and-success-depends-on-security-privacy-and-trust/ http://www.thebunker.net/blog-psd2-is-a-disruptive-game-chan... and https://www.out-law.com/en/articles/2015/january/key-features-of-psd2-and-what-they-mean-for-the-payments-industry/ https://www.out-law.com/en/articles/2015/january/key-feature... and https://www.starlingbank.com/explaining-psd2-without-tlas-tough/ https://www.starlingbank.com/explaining-psd2-without-tlas-to...
- AparnaC 10y agoPost PSD2, would a PSP be able to act as PISP and hold customer funds while acting as PISP since it already has authorisation to hold funds as PSP?