PSD2
The European Union directive governing electronic payments that introduced open banking access and mandatory strong customer authentication.
Definition
PSD2, the Second Payment Services Directive, is the EU legal framework for payment services that has applied across the EEA since 2018. Two of its most consequential elements are open banking, which requires banks to let licensed third parties access account information and initiate payments with the customer's consent, and Strong Customer Authentication, which mandates two-factor verification for most electronic payments. Together these reshaped online checkout: they enabled account-to-account payment initiation and forced wider adoption of authentication steps like 3-D Secure. The UK retained an equivalent regime after leaving the EU, and other regions have modelled similar open-banking rules.
Worked example
Because of PSD2, a customer paying by card is stepped up to a 3-D Secure challenge, while an open-banking provider can initiate a bank transfer once the customer consents in their banking app.
Why it matters
For learners, PSD2 explains why European checkouts ask for extra verification and how bank-based payments became possible. For professionals, PSD2 compliance drives authentication design, decline management, and open-banking product strategy.
Related
Note: PSD2 applies in the EU/EEA; the UK operates a retained equivalent, and successor rules (such as PSD3 proposals) are in progress.