Retained EU Law 2018 United Kingdom

Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)

At a glance

What's here

6 compliance obligations

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

s.art030

General obligations for access interfaces

  • Provide and maintain a compliant access interface for third-party payment services
s.art031

Access interface options

  • Provide payment service access via dedicated or existing interface
s.art032

Obligations for a dedicated interface

  • Ensure your dedicated interface is available and performs as well as your customer-facing online banking
s.art033

Contingency measures for a dedicated interface

  • Have a fallback plan if your payment interface goes down
s.art035

Security of communication session

  • Ensure security of communication sessions for payment services
s.art036

Data exchanges

  • Provide equal data access, fund confirmation, and error notifications to third-party payment providers
Browse 32 other sections — procedural / definitional / commencement
s.art001

Subject matter

s.art002

General authentication requirements

s.art003

Review of the security measures

s.art004

Authentication code

s.art005

Dynamic linking

s.art006

Requirements of the elements categorised as knowledge

s.art007

Requirements of the elements categorised as possession

s.art008

Requirements of devices and software linked to elements categorised as inherence

s.art009

Independence of the elements

s.art010

Payment account information

s.art011

Contactless payments at point of sale

s.art012

Unattended terminals for transport fares and parking fees

s.art013

Trusted beneficiaries

s.art014

Recurring transactions

s.art015

Credit transfers between accounts held by the same natural or legal person

s.art016

Low-value transactions

s.art017

Secure corporate payment processes and protocols

s.art018

Transaction risk analysis

s.art019

Calculation of fraud rates

s.art020

Cessation of exemptions based on transaction risk analysis

s.art021

Monitoring

s.art022

General requirements

s.art023

Creation and transmission of credentials

s.art024

Association with the payment service user

s.art025

Delivery of credentials, authentication devices and software

s.art026

Renewal of personalised security credentials

s.art027

Destruction, deactivation and revocation

s.art028

Requirements for identification

s.art029

Traceability

s.art034

Certificates

s.art037

Review

s.art038

Entry into force

Explore more

Browse legislation

Find other UK business legislation with related guidance.