(1) A person who intends to provide payment services in Germany on a commercial basis or on a scale requiring a commercially organised business undertaking, without being a payment service provider within the meaning of section 1(1), first sentence, nos. 2 to 5, requires a written or electronic licence from BaFin. Beyond the provision of payment services, the licence covers
1. the provision of operational and closely related ancillary services; ancillary services are the ensuring of the execution of payment transactions, foreign exchange transactions, services for ensuring data protection and data storage and processing, and safe custody services, insofar as this does not consist of accepting deposits;
2. the operation of payment systems in accordance with section 57;
3. business activities that do not consist in the provision of payment services, having regard to the applicable Union law and the relevant national law in each case.
(2) The licence application must contain the following particulars and evidence:
1. a description of the business model, from which the nature of the intended payment services in particular is apparent;
2. a business plan comprising a budget forecast for the first three financial years, demonstrating that the applicant has adequate and proportionate systems, resources and procedures to operate soundly;
3. evidence that the applicant possesses the initial capital required under section 12, no. 3, as well as, for payment initiation services and account information services, evidence of the safeguarding of professional liability under the conditions of sections 16 and 36;
4. a description of the measures taken to comply with the safeguarding requirements under section 17;
5. a description of the governance arrangements and internal control mechanisms of the applicant, including administrative, risk-management and accounting procedures, together with arrangements for the use of ICT services under Regulation (EU) 2022/2554, demonstrating that these governance arrangements, control mechanisms and procedures are proportionate, appropriate, sound and adequate;
6. a description of the procedures in place to monitor, handle and follow up security incidents and security-related customer complaints, including an incident-reporting mechanism which has regard to the reporting obligations under Chapter III of Regulation (EU) 2022/2554;
7. a description of the process in place to file, monitor, track and restrict access to sensitive payment data;
8. a description of business continuity arrangements, including a clear identification of critical operations, effective ICT business continuity policies and plans, ICT response and recovery plans, and a procedure to test regularly the adequacy and efficiency of such plans under Regulation (EU) 2022/2554;
9. a description of the principles and definitions applied for the collection of statistical data on performance, transactions and fraud;
10. a description of the security policy, including a detailed risk assessment of the payment services provided and a description of the security control and mitigation measures taken to protect payment service users adequately against the risks identified, including fraud and the unlawful use of sensitive and personal data;
11. a description of the internal control mechanisms which the applicant has put in place to comply with the requirements of sections 27 and 53;
12. a description of the applicant's organisational structure, where applicable including a description of the intended use of agents and branches and of the on-site and off-site checks which the applicant undertakes to carry out on them at least annually, together with a description of outsourcing arrangements and a description of its participation in a national or international payment system;
13. the names of the holders of a significant holding, the amount of their holding and evidence that they meet the requirements to be imposed in the interest of ensuring the sound and prudent management of the applicant; section 2c(1), fourth sentence of the Banking Act applies correspondingly;
14. the names of managers and, insofar as the undertaking pursues, in addition to the provision of payment services, other business activities, the names of the persons responsible for the management of the applicant's payment services business;
15. where applicable, the names of the statutory auditors of the annual financial statements and of the consolidated financial statements;
16. the legal form and the articles of association or partnership agreement of the applicant;
17. the address of the applicant's head office or registered office. Together with the documents under the first sentence, nos. 4 to 6 and 12, the applicant must submit a description of its audit arrangements and organisational arrangements for taking all reasonable steps to protect the interests of its users and to ensure continuity and reliability in the performance of the payment services it provides. The description of the security policy under the first sentence, no. 10 must state how a high degree of technical security and data protection is ensured by those measures; this also applies to any software and IT systems used by the applicant or by the undertakings to which the applicant outsources all or part of its activities. The application must contain evidence that the persons named in the first sentence, no. 14, are reliable and have adequate theoretical and practical knowledge and skills, including management experience, to provide payment services. The applicant must appoint at least two managers; for undertakings of small size, one manager is sufficient. BaFin may, in an individual case, require further particulars and evidence in relation to the information under the first to fifth sentences, insofar as this appears necessary for it to perform its statutory tasks.
(3) BaFin informs the applicant, within three months of receipt of the application or, where the application is incomplete, within three months of the submission of all the particulars necessary for the decision, whether the licence is granted or refused. Where, within twelve months of receipt of the application by BaFin, notwithstanding BaFin's request to complete the application within one month, sufficient particulars or documents enabling BaFin to decide on the application are still not available, the application must be refused.
(4) BaFin may grant the licence subject to conditions that must remain within the scope of the purpose pursued by this Act. Within that purpose it may also restrict the licence to individual payment services. Where the payment institution simultaneously pursues other business activities, BaFin may require it to spin off those activities or to establish a separate undertaking for its payment services business, where those activities impair, or could impair, the payment institution's financial soundness or the possibilities for its examination.
(5) The payment institution must without delay notify BaFin of every materially and structurally significant change in the factual or legal circumstances, insofar as it affects the accuracy of the particulars and evidence submitted under subsection (2).
(6) BaFin must publish the granting of the licence in the Federal Gazette.
(7) Insofar as a licence under subsection (1) is required for the provision of payment services, entries may be made in public registers only once the licence has been proven to the registration court.
(8) The Federal Ministry of Finance is authorised to issue, by statutory instrument not requiring the consent of the Bundesrat, in agreement with the Deutsche Bundesbank, more detailed provisions on the type, scope and form of the application documents provided for under this provision. The Federal Ministry of Finance may transfer the authorisation, by statutory instrument, to BaFin, on condition that the statutory instrument is issued in agreement with the Deutsche Bundesbank. The leading associations of the institutions must be heard before the statutory instrument is issued. The Federal Office for Information Security must be heard insofar as the security of information technology systems is concerned.
(9) Subsections (1) to (7) also apply where, in the course of a conversion under section 305, section 320 or section 333 of the Conversion Act, a legal person carrying on business subject to licensing under subsection (1) transfers its legal seat from abroad to Germany.
Home› Payment Services› ZAG-EN
Part 2 · Licence; Holders of Significant Holdings › Chapter 1 · Licence › Section 10
Licence for Providing Payment Services; Authorisation to Issue Statutory Instruments
←→ also move between sections