(1) The payment service provider is required to apply strong customer authentication where the payer
1. accesses its payment account online;
2. initiates an electronic payment transaction;
3. carries out any action, through a remote channel, that may imply a risk of payment fraud or other abuses. In the case referred to in the first sentence, a payment service provider must have adequate security measures to protect the confidentiality and integrity of payment service users' personalised security credentials.
(2) Where the electronic payment transaction under subsection (1), first sentence, no. 2, is a remote electronic payment transaction, the payment service provider must apply strong customer authentication that includes elements that dynamically link the transaction to a specific amount and a specific payee.
(3) Subsection (1), second sentence, and subsection (2) also apply where payments are initiated through a payment initiation service provider. Subsection (1) also applies where information is requested through an account information service provider.
(4) The account servicing payment service provider must allow the payment initiation service provider and the account information service provider to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user under subsection (1) and, in cases involving a payment initiation service provider, also under subsection (2).
(5) Further details of the requirements and procedures for strong customer authentication, including any exemptions from its application, and of the requirements for security measures for the confidentiality and integrity of personalised security credentials, are governed by the delegated act under Article 98 of Directive (EU) 2015/2366.
Home› Payment Services› ZAG-EN
Part 10 · Common Provisions for All Payment Service Providers › Chapter 4 · Strong Customer Authentication › Section 55
Strong Customer Authentication
←→ also move between sections