PSD3 & PSR News Today: What’s Happening and What It Means for You
If you work in finance, fintech, or run a business that handles payments in Europe, PSD3 and PSR are two things you cannot afford to ignore right now.
The European Union is reshaping its entire payments rulebook. After years of living with PSD2, the EU is moving to a completely new framework. And it is bigger than most people realize.
This article gives you a clear, up-to-date picture of where PSD3 and PSR stand today, what the key changes are, and what you actually need to do about it.
No legal jargon. No fluff. Just the important stuff, explained clearly.
Quick Answer
What is the latest news on PSD3 and PSR?
The European Commission proposed PSD3 and the Payment Services Regulation (PSR) in June 2023. As of 2025, both are moving through the EU legislative process. PSD3 updates the licensing rules for payment firms. PSR replaces the conduct rules that were in PSD2 and becomes directly binding law across all EU member states. Full implementation is expected to take several years after formal adoption.
Table of Contents
- What Is PSD3?
- What Is PSR?
- PSD3 vs PSR: Understanding the Difference
- PSD3 vs PSD2: What Actually Changed
- Latest PSD3 and PSR Legislative News
- Key Changes That Matter Most
- Open Banking Under PSD3 and PSR
- Fraud Protection and Strong Customer Authentication
- Consumer Rights Under the New Framework
- Who Is Affected by PSD3 and PSR?
- PSD3 and PSR Implementation Timeline
- What Businesses Should Do Now
- Common Mistakes to Avoid
- Frequently Asked Questions
- Key Takeaways
What Is PSD3?
The Third Payment Services Directive is referred to as PSD3. It is the most recent version of the EU’s payment service provider licensing framework.
In 2007, the first Payment Services Directive was introduced. In 2015, PSD2 was implemented, bringing greater consumer safeguards, robust customer authentication, and open banking regulations. PSD3 currently expands upon that framework and resolves issues.
Since it is still a directive, EU members must incorporate it into their own national legislation. That is a crucial point. A directive, as opposed to a regulation, allows nations some latitude in how they carry out the regulations.
PSD3 concentrates on:
- Who is eligible to obtain a license as a payment institution?
- How bank infrastructure is accessed by non-bank payment companies
- Regulations pertaining to access to financial data
- Stricter guidelines for consumer protection
- Improved enforcement resources for national authorities
Consider PSD3 to be the structural layer. It establishes the scene. The operational layer is called PSR. It outlines exactly what you have to perform on a daily basis.
What Is PSR?
PSR stands for the Payment Services Regulation. This is brand new territory for EU payments law.
Previously, both the licensing rules and the conduct rules were bundled inside PSD2. The EU decided to split them. PSD3 handles licensing. PSR handles conduct.
The critical difference is the legal form. PSR is a regulation, not a directive. That means it applies directly in every EU member state without being rewritten into national law. The rules will be identical across the entire EU from day one.
PSR covers:
- Strong Customer Authentication (SCA) requirements
- Payment transaction liability between banks and customers
- Transparency obligations for payment firms
- Open banking API standards
- Refund rights for unauthorized and fraudulent payments
- Information requirements before and after a payment
For businesses operating across multiple EU countries, PSR is actually good news. Instead of dealing with 27 different versions of the same rule, there will be one version. Same rule, same wording, everywhere.
For a detailed legal breakdown of the PSR’s structure and what has changed in the legislative process,
[Morrison Foerster’s April 2025 analysis on PSD3 and PSR key developments]
is one of the most comprehensive resources available.
PSD3 vs PSR: Understanding the Difference
People often get confused because both came out at the same time and both deal with payments. Here is a simple breakdown.
| Feature | PSD3 | PSR |
|---|---|---|
| Type of law | Directive (needs national transposition) | Regulation (directly applicable) |
| Main focus | Licensing and access rules | Conduct and consumer rules |
| Applies to | Payment institutions | All payment service providers |
| Uniformity across EU | Varies by country | Same in every EU country |
| Replaces | PSD2 licensing provisions | PSD2 conduct provisions |
| Open banking rules | Sets access framework | Sets API and data standards |
The short version: PSD3 answers the question of who can operate as a payment firm. PSR answers the question of how they must behave.
Both work together. You cannot fully understand one without the other.
PSD3 vs PSD2: What Actually Changed
When PSD2 was released, it was a significant advancement. However, it had serious issues. Open banking APIs were unreliable, slow, and annoying. Rules for fraud culpability were ambiguous. Refunds were difficult for customers to get. It was difficult for third-party providers to obtain dependable bank access.
Most of the problems are resolved by PSD3 and PSR.
The biggest modifications are as follows:
A more robust framework for open banking
Open banking was promised by PSD2, but the experience was uneven. Banks created APIs that hardly adhered to the minimal requirements. The bar is raised by PSD3 and PSR.
According to the new regulations:
- Better open banking APIs must be offered by banks.
- Access rights for third-party suppliers are made obvious.
- Enforcement of API performance standards
Greater Liability for Fraud
The ambiguity of the fraud liability regulations under PSD2 was one of the main objections. When anything went wrong, banks and payment companies frequently disagreed about who was at fault.
PSR makes regulations more explicit. Banks are more responsible for preventing fraud. Refunds are more easily accessible to customers. There is a clearer definition of the burden of proof.
Enhanced Robust Customer Verification
Although SCA restrictions were in place under PSD2, users found them to be extremely frustrating. They were poorly implemented by many banks. Clumsy authentication procedures caused a lot of online transactions to fail.
In an effort to lower friction without compromising security, PSR modifies the SCA framework with more useful exemptions and clearer requirements.
Payment System Accessibility for Non-Bank Businesses
Under PSD2, payment institutions sometimes struggled to access payment systems because they had to go through banks that were also competitors. PSD3 improves direct access rights for payment institutions.
Financial Data Access Beyond Payments
PSD3 extends data access principles beyond payment account data. This connects to the EU’s broader Financial Data Access (FIDA) initiative, laying groundwork for a wider open finance ecosystem.
For a detailed breakdown of what these changes mean practically for your business, the
[Freshfields analysis on PSD3 and PSR] is worth reading.
Latest PSD3 and PSR Legislative News
The European Commission published the original PSD3 and PSR proposals on June 28, 2023.
Since then, the proposals have been working through the EU’s standard legislative process, which involves three institutions:
- The European Commission – drafted the proposals
- The European Parliament – reviewing and amending
- The Council of the EU – representing member state governments
Both the Parliament and the Council have been working through their own positions. Once each institution finalizes its position, they enter trilogue negotiations, where the three parties negotiate a final agreed text.
This process takes time. It is normal for major EU financial legislation to take two to four years from proposal to final adoption.
Once both texts are formally adopted:
- PSR would likely apply after an 18-month transition period
- PSD3 would need national implementation within roughly 18 months after that
The EU has signaled strong political will to move this forward. Payment modernization, fraud reduction, and open banking competitiveness are all priority issues.
Note for readers: Given how active this legislative process is, it is worth checking official EU sources and legal firm updates regularly for the latest status. The two external sources linked in this article both carry current information from established legal practices actively tracking this legislation.
Key Changes That Matter Most
Here is a focused summary of the changes with the highest practical impact.
1. PSR Becomes Directly Applicable Across All EU Countries
This is arguably the biggest structural change. Payment conduct rules become uniform EU-wide law. No more country-by-country variation in how SCA works or how fraud liability is interpreted.
Why it matters: Businesses operating in multiple EU countries will deal with one set of rules instead of 27 different national versions.
2. Banks Must Offer Better Open Banking APIs
API quality becomes regulated. Banks cannot continue offering low-quality interfaces that block third-party access.
Why it matters: Fintechs and third-party payment providers gain more reliable, predictable access to bank data.
3. Fraud Prevention Duty for Banks
Banks will carry a stronger duty to detect and prevent fraud at the point of payment.
Why it matters: Consumers get stronger protection. Banks face clearer liability when fraud slips through their systems.
4. Clearer SCA Exemptions
Payments below certain thresholds, low-risk transactions, and trusted payees can qualify for SCA exemptions under clearer rules.
Why it matters: Checkout friction decreases for low-risk payments. Conversion rates in e-commerce improve.
5. Improved Dispute Resolution
Both PSD3 and PSR include stronger out-of-court dispute resolution rights for consumers.
Why it matters: Customers have faster, cheaper ways to resolve payment disputes without going to court.
Open Banking Under PSD3 and PSR
Open banking is one of the central issues driving the PSD3 and PSR reform.
Under PSD2, open banking in Europe technically existed but underperformed expectations. The main reasons were:
- Banks were not required to provide high-quality APIs
- No performance standards were enforced
- Banks had little commercial incentive to make open banking easy
PSD3 and PSR change this by:
Setting API quality standards. Banks must now provide interfaces that meet minimum performance benchmarks. Downtime limits, response times, and reliability standards will be defined.
Removing fallback barriers. Under PSD2, banks could offer a fallback access method when their dedicated API failed. The rules around fallback are being tightened to prevent abuse.
Improving the dashboard experience. Consumers will get better visibility and control over which third-party apps have access to their payment data.
Extending financial data access. The new framework connects with the EU’s Financial Data Access (FIDA) initiative, which aims to expand open banking principles to mortgages, savings, and investment accounts.
This is a significant upgrade for the fintech sector. Companies that build on open banking infrastructure will have better, more reliable access than they did under PSD2.
If you follow technology and regulatory developments in financial services, our coverage of
[technology news today] tracks how these changes intersect with broader tech industry shifts.
Fraud Protection and Strong Customer Authentication
Fraud is a major driver behind both PSD3 and PSR.
Online payment fraud in Europe has continued to grow despite PSD2’s SCA requirements. The EU identified several weaknesses in the existing framework and moved to address them.
What Strong Customer Authentication Requires
SCA requires that payment authentication uses at least two of the following three factors:
- Something you know – a password or PIN
- Something you have – a phone or hardware token
- Something you are – a fingerprint or facial recognition
What Changed Under PSR
PSR keeps the core SCA framework but makes several improvements:
- Clearer definitions of each authentication factor
- More standardized exemptions (low-value payments, trusted merchants, corporate payments)
- Better rules on when banks can decline SCA-exempt transactions
- Stronger rules on who bears liability when SCA is bypassed
Fraud Liability Shifts
One of the most important fraud changes is clearer liability allocation.
Under PSD2, there were disputes about who was responsible when fraud happened. Was it the payer’s bank? The payee’s bank? The payment processor?
PSR brings cleaner rules. If a bank approves a fraudulent payment without proper SCA, the bank bears more of the liability. If the customer authorized the transaction willingly through authorized push payment (APP) fraud, the rules clarify how liability is shared between the sending and receiving bank.
This is a significant shift for banks. It creates a stronger financial incentive to invest in fraud detection.
Consumer Rights Under the New Framework
A fundamental component of both PSD3 and PSR is consumer protection.
Important consumer rights that are being reinforced include:
Refunds for unapproved payments are a right. Under PSR, you have a clearer and quicker right to a return if someone makes a payment without your consent and your bank is unaware of it.
improved pre-payment details. Businesses must provide you with more precise information about fees, exchange rates, and terms before you make a payment.
enhanced financial statements. Requirements for post-payment information are becoming increasingly uniform.
improved conflict resolution. Improved alternative dispute resolution procedures allow customers to settle grievances without going to court.
defense against exorbitant costs. Particularly at ATMs and points of sale, currency conversion fees must be transparent and upfront.
These are not dramatic changes for consumers who never have problems. But for anyone who has experienced payment fraud, unauthorized transactions, or confusing fees, the improvements are meaningful.
Who Is Affected by PSD3 and PSR?
The short answer: anyone involved in handling payments in the EU.
Payment Institutions and E-Money Institutions
These firms will need to review their licenses. PSD3 updates the licensing categories and requirements. Some existing licenses may need adjustment.
Banks and Credit Institutions
Banks face the biggest operational changes. They must improve open banking APIs, update fraud detection systems, and adapt liability frameworks.
Fintech Companies
Third-party payment providers and open banking fintechs benefit from better API access rights. But they also face updated compliance requirements.
E-commerce Businesses
Businesses selling online in Europe will be affected by SCA changes, refund rules, and transparency requirements. The changes are mostly positive, reducing unnecessary checkout friction.
Payment Processors and Acquiring Banks
Liability rules and SCA requirements directly affect how processors handle transaction authentication and dispute management.
Businesses Outside the EU
If your company processes payments from EU customers, sells to EU customers, or works with EU payment service providers, PSD3 and PSR affect you indirectly. You will need to comply where the EU customer leg of the transaction falls under EU jurisdiction.
PSD3 and PSR Implementation Timeline
This is the question everyone is asking. When does this actually kick in?
Here is the realistic picture based on where the legislative process stands.
| Stage | Status |
|---|---|
| Commission proposal published | June 2023 — Complete |
| European Parliament review | Ongoing through 2024-2025 |
| Council of EU review | Ongoing through 2024-2025 |
| Trilogue negotiations | Expected to conclude in 2025-2026 |
| Formal adoption | Likely 2025-2026 |
| PSR transition period (approx. 18 months) | Post-adoption |
| PSD3 national transposition period | Post-adoption |
| Full compliance expected | Approximately 2027-2028 |
These timelines are estimates. EU legislative processes can move faster or slower depending on political priorities and negotiation complexity.
What is clear is that the direction is set. Businesses waiting for the final text before starting compliance work will be starting very late.
What Businesses Should Do Now
You do not need to wait for the final text to start preparing.
The broad direction of PSD3 and PSR is clear. The major changes are well understood. Smart businesses are already mapping the impact on their operations.
Review Your Open Banking Infrastructure
If you rely on open banking APIs, assess your current integrations. API quality standards are going up. Identify any dependencies on low-quality bank APIs that may need to be replaced or upgraded.
Audit Your SCA Setup
Check whether your current SCA implementation matches what PSR is moving toward. If you have custom exemption logic, it may need updating.
Map Your Fraud Liability Exposure
Understand where fraud liability currently sits in your payment flows. When liability rules shift, knowing your current exposure helps you prepare.
Engage Your Legal and Compliance Teams
If you operate payment services in the EU, your legal team should already be tracking the trilogue negotiations. Identify who is responsible for PSD3/PSR compliance in your organization now, not later.
Watch the Legislative Process
Trilogue negotiations can produce final texts with last-minute changes. Stay close to trusted legal and regulatory sources for updates as they happen.
This kind of regulatory shift also intersects with broader trends in AI-driven financial services. Our coverage of
[AI news today] explores how artificial intelligence is changing compliance, fraud detection, and open banking simultaneously.
Common Mistakes to Avoid
Awaiting the Complete Text Before Taking Action
The main shifts are already evident. Companies will have a very short schedule if they wait for the final word before starting compliance activities.
Considering PSR and PSD3 as Distinct Problems
They collaborate. Gaps in compliance planning result from understanding one without the other.
Presuming PSD3 Is Covered by PSD2 Compliance
It doesn’t. Significant changes are being made to a number of regulations, including those pertaining to open banking API quality, SCA exemptions, and fraud responsibility. A system that complies with PSD2 does not necessarily comply with PSD3/PSR.
Underestimating the Needs for API Quality
Minimum-viable PSD2 APIs were developed by numerous banks and payment companies. Significant engineering effort may be necessary to meet the higher quality criteria under PSD3/PSR.
Ignoring Changes That Affect Consumers
Changes to refund rights and transparency rules affect customer-facing processes, not just backend infrastructure. Customer service, dispute resolution, and communications all need review.
Frequently Asked Questions
What is PSD3?
PSD3 is the Third Payment Services Directive. It is the EU’s updated framework for licensing payment firms and governing how they access payment systems and financial infrastructure. It replaces PSD2.
What is PSR in the context of EU payments?
PSR stands for Payment Services Regulation. It is a directly applicable EU regulation that covers conduct rules for payment service providers, including strong customer authentication, fraud liability, and consumer rights. It replaces the conduct parts of PSD2.
What is the difference between PSD3 and PSR?
PSD3 is a directive focused on licensing and structural rules. PSR is a regulation focused on conduct and consumer protection rules. PSD3 needs national implementation. PSR applies directly across all EU countries without national transposition.
When will PSD3 and PSR apply?
Full compliance is not expected until approximately 2027 or 2028, depending on when formal adoption concludes and how long the transition periods run. The legislative process is ongoing as of 2025.
Does PSD3 replace PSD2?
Yes. PSD3 and PSR together replace PSD2. PSD3 takes over the licensing and access rules. PSR takes over the conduct and consumer protection rules.
Who needs to comply with PSD3 and PSR?
Payment institutions, e-money institutions, banks, credit institutions, and any firm providing payment services to EU customers. Third-party providers and open banking fintechs are also covered.
How does PSR improve open banking?
PSR sets higher API quality standards that banks must meet, gives third-party providers stronger access rights, and creates better performance benchmarks for open banking interfaces.
Will PSD3 apply outside the EU?
PSD3 is EU law. But businesses outside the EU that process payments involving EU customers may be indirectly affected, particularly for transactions that touch EU-regulated payment service providers.
What happens to existing PSD2 licenses under PSD3?
PSD3 includes grandfathering provisions for existing licensed payment institutions. However, firms will need to review their licensing status and may need to update their licenses depending on what activities they carry out.
Is PSD3 relevant to the UK after Brexit?
The UK has its own separate Payment Services Regulations, which it retained after Brexit. PSD3 and PSR do not directly apply in the UK, but UK firms operating in the EU will still need to comply where their EU operations or EU customers are involved.
Key Takeaways
Here is the short version of everything covered in this article.
- PSD3 and PSR are the EU’s next generation of payments law. They replace PSD2 together.
- PSD3 is a directive covering licensing and access. PSR is a regulation covering conduct and consumer protection.
- PSR applies directly in all EU countries without national transposition. That is a fundamental change from PSD2.
- Open banking gets a serious upgrade. API quality standards become enforceable. Banks can no longer offer minimum-viable interfaces.
- Fraud liability rules become clearer. Banks carry stronger duties to prevent fraud and bear clearer liability when they fail.
- SCA rules are updated with more practical exemptions and cleaner standards.
- Consumer protections improve across refunds, transparency, and dispute resolution.
- Full implementation is not expected until approximately 2027-2028, but preparation should start now.
- Businesses should begin compliance mapping immediately. The direction is clear even before the final text arrives.
- Every payment firm in the EU is affected. Non-EU firms with EU customers or EU payment infrastructure exposure are also impacted indirectly.
PSD3 and PSR represent the most significant reform of EU payments law since PSD2 itself. Getting ahead of this change is not just good compliance practice. It is a competitive advantage.


