Retained EU Law SI 2018/389 United Kingdom

Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)

Status
In Force
Penalty ceiling
Regulated

Does it bind you?

Business-side roles with duties under this instrument.

Operator6

Other Acts binding the same actors

If a role above is yours, these are the other instruments that most often bind it.

Operator — also bound by 746 other Acts

What it requires

Regulations creating concrete business duties or carrying penalties, grouped as the instrument is structured. Titles link to the source text — blue means you’re leaving for legislation.gov.uk.

s.art030 General obligations for access interfaces Regulated
  • Provide and maintain a compliant access interface for third-party payment servicesOperator
s.art031 Access interface options Regulated
  • Provide payment service access via dedicated or existing interfaceOperator
s.art032 Obligations for a dedicated interface Regulated
  • Ensure your dedicated interface is available and performs as well as your customer-facing online bankingOperator
s.art033 Contingency measures for a dedicated interface Regulated
  • Have a fallback plan if your payment interface goes downOperator
s.art035 Security of communication session Regulated
  • Ensure security of communication sessions for payment servicesOperator
s.art036 Data exchanges Regulated
  • Provide equal data access, fund confirmation, and error notifications to third-party payment providersOperator
32 other provisions — procedural and definitional
s.art001 Subject matter
s.art002 General authentication requirements
s.art003 Review of the security measures
s.art004 Authentication code
s.art005 Dynamic linking
s.art006 Requirements of the elements categorised as knowledge
s.art007 Requirements of the elements categorised as possession
s.art008 Requirements of devices and software linked to elements categorised as inherence
s.art009 Independence of the elements
s.art010 Payment account information
s.art011 Contactless payments at point of sale
s.art012 Unattended terminals for transport fares and parking fees
s.art013 Trusted beneficiaries
s.art014 Recurring transactions
s.art015 Credit transfers between accounts held by the same natural or legal person
s.art016 Low-value transactions
s.art017 Secure corporate payment processes and protocols
s.art018 Transaction risk analysis
s.art019 Calculation of fraud rates
s.art020 Cessation of exemptions based on transaction risk analysis
s.art021 Monitoring
s.art022 General requirements
s.art023 Creation and transmission of credentials
s.art024 Association with the payment service user
s.art025 Delivery of credentials, authentication devices and software
s.art026 Renewal of personalised security credentials
s.art027 Destruction, deactivation and revocation
s.art028 Requirements for identification
s.art029 Traceability
s.art034 Certificates
s.art037 Review
s.art038 Entry into force

Duty extraction and severity labels are Guvnor’s analysis of the instrument, not the instrument itself. Always verify against the linked source text.