6 ms·
The EU has been making some good moves in opening up the payment services industry through regulation. The biggest example is the PSD2 regulations passed in 201
by aedron 7y ago
The EU has been making some good moves in opening up the payment services industry through regulation. The biggest example is the PSD2 regulations passed in 2015[1]. Among many other things, this law requires banks in the EU to expose APIs into their systems, that allow third parties to make transfers to and from the bank's accounts, only subject to proper customer authentication and AML compliance. This essentially lets third parties build universal payment services on top of existing banking infrastructure.
> The law highlights the growing desire in Germany for tighter regulation of U.S. technology companies.
No, this highlights that the EU is willing and able to regulate markets to keep them open to all participants.
Looking forward to laws opening up this sector even more.
[1] https://en.wikipedia.org/wiki/Payment_Services_Directive#Revised_Directive_on_Payment_Services_(PSD2) https://en.wikipedia.org/wiki/Payment_Services_Directive#Rev...
- DavideNL 7y agoI agree, this is a great development. Hope to see the same in other EU countries.
- cprecioso 7y agoPSD2 is great, but as far as I remember, it doesn't make banks have a common basic API, every bank can implement it wildly differently. Next step is something like OpenBanking in the UK which does ask for common APIs.
- grenoire 7y agoThe next step is unfortunately not coming up anytime soon. They made account information and payment initiation service provider (AISP and PISP respectively) licensing mandatory to connect with banks, but most banks don't even have their APIs production-ready in time! Rabobank (Dutch) quoted to us the end of 2020 for their 'official' connection platform, but the requirements have been made legally binding in September...
- giancarlostoro 7y agoI was thinking about how much I would love it here in the US if I could have a one stop banking app for all my balances that isnt selling them to Facebook or something sketchy. I think open APIs would be the only way I would trust it. If I had the app source it would work for me. Even if I only have it for bigger banks I just want less apps and more uniformity.
- davchana 7y agoI am an Indian in US & I love my UPI app for Indian banking needs. Before that, I had to use multiple banks' apps. Many of those would randomly want to verify me by sending an SMS to Indian 1800 number, impossible from my Indian Sim card while in roaming in US. Now I just use PhonePe. Two banks, One Credit Card. Inter transfers, Card Payment, Bill Payments, Phone Recharges, Sending money to others, all from within one app. *No affiliation, just a happy customer.
- Longhanks 7y agoThe PSD2 is extremely user hostile. In fact, it's so universally hated that Switzerland's banks (not in the EU) have called it an "experiment at the customer's cost, creating dangerous confusion while undermining the security of customer's data" (https://www.swissbanking.org/de/themen/digitalisierung/open-banking-und-standardisierte-schnittstellen-api-1/payment-service-directive-psd2 https://www.swissbanking.org/de/themen/digitalisierung/open-...). As a EU citizen myself that now has to live with an incredibly disrupting online banking experience, I am more than unhappy with the EU's regulations.
- tpush 7y agoDo you have any concrete criticisms? How is the online banking experience "incredibly disrupting"?
- carstenhag 7y agoThe current PSD2 implementation at most banks is just terribly annoying. On things which require authentication every 90 days (like checking the balance via api), almost all banks require one after every attempt/api call. Even worse: Many banks don't support their app's 2FA for the api calls, but instead the old tan lists. (ING does this AFAIK)
- dvfjsdhgfv 7y ago> As a EU citizen myself that now has to live with an incredibly disrupting online banking experience How so? For most people PSD2 means 2F auth not just for money transfers but also for login, which is quite good for security in general, although of course won't help in all cases (like SIM swap).
- WA 7y agoBecause some banks (Consorsbank for example), take this to an extreme and ask you to 2FA all the time for every login. I used to refresh several bank accounts several times per day through a third party app (MoneyMoney) on the Mac. This worked pretty flawlessly until September. Now, I have to take out my phone and 2FA all the things in three different apps. Of course, partially, Consorsbank is to blame here, because they fucked this up. Other banks have more customer-friendly interpretations on how often you have to 2FA (like once per month). Only thing I noticed: I used to automatically fetch transactions through a HBCI interface with the open source software AqBanking on a VPS. This doesn't work anymore, because you need to register this software somewhere. So not sure how this is connected to PSD2 exactly. I assume the requirements for HBCI got tightened.
- C1sc0cat 7y agoAh just like the changes to merchant card fees worked so well for the citizens (cost me about (£15 -£20 a month) And the card companies just invented new fees for merchants so they don't see much of an advantage.
- Roark66 7y agoYes, PSD2 is good, but I'm wondering why they didn't go further and mandate something like UK's Open Banking. The difference is that currently in EU banks are forced to expose a banking API, but every bank can have their own API. While in UK there is one API standard that banks are supposed to allow to be used. So writing an app for EU one has to deal with tens (if not hundreds) of bank-specific implementations while in UK one is all that's needed.
- grenoire 7y agoThank you for pointing this out. Recently I've been talking to many different banks and payment service providers in the Netherlands, and it's absolutely crazy how little specification there is to the technical end of things. It's effectively an auditorium of hundreds of banks and PSPs across Europe, shouting at each other over how they want to (or not want to) do this one specific thing. It has not helped by any means with the ton of technical debt they had, because now everybody's just winging it and being minimally PSD2 compliant. We still don't have a standardised OAuth (or OAuth-styled) access to banks, and it doesn't look like PSD2 is helping anybody out beyond the "yeah, like, just make the data accessible without scraping, thanks!"
- em-bee 7y agothere are two sides of that coin. while a standard API is nice, it also prevents evolution and improving APIs. you don't really want to lock in a specific API by law. that will work well for a few years, but then it will more likely hinder innovation, rather than support it.
- intarga 7y agoThe real result of this is aggregators appearing, which present a unified interface to all banks, hiding the implementation details under their own interface. i.e https://www.neonomics.io/ https://www.neonomics.io/
- Shivetya 7y agoHaving banks have an API is far different than telling Apple to share access to how the interface with those APIs. If anything it probably is a push by state actors who hope their intelligence services can use the hooks to circumvent the security Apple and even Android users have from their devices. Apple is not preventing you from using a bank or accessing your funds in that bank, they are just offering up a new secure means to do so. Your bank still has to play along. Now if Apple was exclusive then we would have an issue So by this logic, anyone who has a device which supports NFC payments and can load an app from a third party must allow access to methods the hardware performs the handshake/connection? So why not just say all parts of the phone must be fully exposed, why not demand that apps can make the phone calls? I have two major issues with these demands. First being it simply is more likely a means for state actors to have more opportunities for back doors violating the trust people put into their devices. the second is what is to prevent every damn bank and store from demanding you only use their app because you know that will happen.
- Despegar 7y ago>If anything it probably is a push by state actors who hope their intelligence services can use the hooks to circumvent the security Apple and even Android users have from their devices. It's not anything cloak-and-dagger like that. It's really just politicians leaning in on the side of their banks in a commercial negotiation with Apple.
- Terretta 7y agoIt’s the question whether the device “is” the wallet or the bank’s app “is” the wallet. I think for reasons similar to what grandparent mentions, I prefer it be the device, like the hardware btc wallets. Regulations shouldn’t crack open a toaster, and shouldn’t crack open a PDA.
- FabHK 7y ago> No, this highlights that the EU is willing and able to regulate markets to keep them open to all participants. Exactly. I find it absurd that credit card companies can charge between 1.5% and 3.5% in merchant fees. Some 2%+ of the retail volume goes to credit card companies! (Who then turn around and give a small fraction of it back to their more savvy and rich customers via miles or points, while charging their poorer or less organised customers horrendous late fees and interest.) The German Girocard debit card system charges merchants at most 0.2%, an order of magnitude less. That's the way it should be.
- ericmay 7y agoWell, on the other hand if such a system was implemented in the US, prices would stay the same. For me as an end user I don’t care if Wal-Mart eats those fees or Visa does, except I get a credit card where, as you say, I get points and whatnot to keep using. There is also nothing stopping companies in the US from either implementing a super low-cost system, or just only accepting cash. I think CC have critical adoption in the US, and nothing but legislation would remove them - it’s a zero sum game. If I stop using a card I don’t get points and pay the same price for products. I don’t know all of the details of the German Girocard, seems like it’s a good product potentially, but would need some more info. In the US, if someone scams my debit card I am out of cash until it’s recovered. How does it work in this case for this card? I would also like to challenge the notion that prices should be X, just because someone is perceived as a middleman. Prices should be (excluding healthcare) whatever people are willing to pay. It’s equivalent to someone complaining about mobile app developers costing a certain amount of money and just saying that’s the way it should be. Companies put a lot of money, time, and development into building the infrastructure and products, so they should be free to charge what the market will bear for these types of products.
- lotsofpulp 7y ago> Well, on the other hand if such a system was implemented in the US, prices would stay the same. For me as an end user I don’t care if Wal-Mart eats those fees or Visa does, except I get a credit card where, as you say, I get points and whatnot to keep using. There is no reason prices would stay the same, unless there was collusion between all the retailers. And neither Walmart nor Visa eat the fees. Anyone not earning credit card rewards eat the fees. Also, money transfer infrastructure is just as important as healthcare. As is water, electricity, and transportation. I’m assuming you wouldn’t want the electric or gas company to charge what the market will bear when it’s -10C outside for a few weeks.