Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ
    • Magazines▾
      • Global Banking & Finance Review Magazine Issue 79
      • Global Banking & Finance Review Magazine Issue 78
      • Global Banking & Finance Review Magazine Issue 77
      • Global Banking & Finance Review Magazine Issue 76
      • Global Banking & Finance Review Magazine Issue 75
      • Global Banking & Finance Review Magazine Issue 73
      • Global Banking & Finance Review Magazine Issue 71
      • Global Banking & Finance Review Magazine Issue 70
      • Global Banking & Finance Review Magazine Issue 69
      • Global Banking & Finance Review Magazine Issue 66
    Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Home > Finance > Why PSD2 still applies to the UK even after Brexit
    Finance

    Why PSD2 still applies to the UK even after Brexit

    Why PSD2 still applies to the UK even after Brexit

    Published by Jessica Weisman-Pitts

    Posted on November 1, 2021

    Featured image for article about Finance

    Britain might have left the EU at the end of 2020, but it’s still subject to a variety of European regulations in areas like financial services, data protection and technology.

    Payment Services Directive 2 (PSD2) is one of those. Brought into effect in September 2019, among other things PSD2 creates a framework for banks to share personal account information directly with other regulated providers in order to foster the development of new services and products for bank customers. PSD2 was also introduced with the aim of rationalising financial transactions across European borders and protecting online payments.

    It demands Strong Customer Authentication (SCA) for transactions which basically means Multi-Factor Authentication (MFA) for customers. PSD2 also requires Common and Secure Communication (CSC) which involves the use of two distinct certificates to protect transactions. The Qualified Certificate for Website Authentication (QWAC) is used to protect data in peer-to- peer communications as well as to identify who controls the endpoints involved. The Qualified Certificate for Electronic Seals (QSealC) is meant to protect data and documents and confirm their legal origin.

    Although the UK left the European Union on December 31st 2020, PSD2 still applies to a great extent. In fact, sovereignty isn’t even the main issue – the UK government has adopted PSD2 into national law to bring the country in-line with its neighbouring supra-national bloc.

    The UK government has done the same with several landmark pieces of EU regulation. In the run up to Brexit, the UK’s Information Commissioner’s Office (ICO) stated clearly that the UK would be complying with the General Data Protection Regulation (GDPR), whether it was in or out of the European Union. Though the UK is not formally under EU jurisdiction any longer, it is still subject to an act of law called the “UK GDPR” which mirrors the principles, rights and obligations of the GDPR. This is largely because GDPR compliance is the price of doing business for anyone who wants to use the data of European citizens.

    Similarly, a “UK eIDAS” has been created tailoring the contents of the European eIDAS Regulation which governs the use of Qualified Trust Service Providers for legally-valid electronic signatures, among other things.

    Whether the UK is in or out of the European Union, it is likely to be subject to European regulations especially when it comes to privacy and data protection. That’s not just true for the UK, but many other non-EU countries. The EU standards for implementing technical aspects of PSD2 were even widened as “Open Banking” standards precisely so the UK and other countries or regions might adopt them more readily.

    This is less a question of state sovereignty than it is a confirmation of certain facts of modern life. This is about inexorable digital transformations all over the globe and the security of data in a world that gets more deeply connected by the day.

    On the 31st of December 2020, the UK officially left the European Union, but it did so amid the tumult of a global pandemic.

    The pandemic has deepened our reliance on online transactions as well as the security of those transactions. Furthermore, it has accelerated the world’s digital migration at breakneck speed. Governments and companies are now doubling down on digital transformations with the introduction of mass remote work and the new centrality of electronic identities in the form of vaccine passports. Business and connected technology pays less and less heed to national borders by the day and the pandemic spurred that process on.

    Regulations like PSD2 are becoming ever more crucial to underpin these digital transformations and it may mean that not just the UK – but many other countries – will have to comply with EU regulations in some way.

    The GDPR is useful as a representative example. When it was introduced in 2018 it brought in hefty fines for companies who failed to protect personal data and issued injunctions about how organisations should collect, protect and store that data. Critically, the regulation applies not just within European borders, but wherever the data of a European citizen is being processed. The EU is the largest trading bloc in the world and there are few organisations which would want to refuse the opportunity to do business there. Now, countries around the world are drafting data protection legislation which largely mirrors the statues of the GDPR.

    PSD2, like the GDPR, may soon be adopted – at least in spirit – by other non-EU countries if not for the thoroughness of its regulations, then for the undeniable attraction of the European market.

    These kinds of developments are irresistible to nation states – who want to protect citizens and companies from threats that don’t pay heed to borders. They can only do that by working in parallel with other countries. To that end, regulations like PSD2, GDPR or eIDAS may have been built for the EU, but are profoundly informing if not directly inspiring technological regulation all over the world.

    Britain might have left the EU at the end of 2020, but it’s still subject to a variety of European regulations in areas like financial services, data protection and technology.

    Payment Services Directive 2 (PSD2) is one of those. Brought into effect in September 2019, among other things PSD2 creates a framework for banks to share personal account information directly with other regulated providers in order to foster the development of new services and products for bank customers. PSD2 was also introduced with the aim of rationalising financial transactions across European borders and protecting online payments.

    It demands Strong Customer Authentication (SCA) for transactions which basically means Multi-Factor Authentication (MFA) for customers. PSD2 also requires Common and Secure Communication (CSC) which involves the use of two distinct certificates to protect transactions. The Qualified Certificate for Website Authentication (QWAC) is used to protect data in peer-to- peer communications as well as to identify who controls the endpoints involved. The Qualified Certificate for Electronic Seals (QSealC) is meant to protect data and documents and confirm their legal origin.

    Although the UK left the European Union on December 31st 2020, PSD2 still applies to a great extent. In fact, sovereignty isn’t even the main issue – the UK government has adopted PSD2 into national law to bring the country in-line with its neighbouring supra-national bloc.

    The UK government has done the same with several landmark pieces of EU regulation. In the run up to Brexit, the UK’s Information Commissioner’s Office (ICO) stated clearly that the UK would be complying with the General Data Protection Regulation (GDPR), whether it was in or out of the European Union. Though the UK is not formally under EU jurisdiction any longer, it is still subject to an act of law called the “UK GDPR” which mirrors the principles, rights and obligations of the GDPR. This is largely because GDPR compliance is the price of doing business for anyone who wants to use the data of European citizens.

    Similarly, a “UK eIDAS” has been created tailoring the contents of the European eIDAS Regulation which governs the use of Qualified Trust Service Providers for legally-valid electronic signatures, among other things.

    Whether the UK is in or out of the European Union, it is likely to be subject to European regulations especially when it comes to privacy and data protection. That’s not just true for the UK, but many other non-EU countries. The EU standards for implementing technical aspects of PSD2 were even widened as “Open Banking” standards precisely so the UK and other countries or regions might adopt them more readily.

    This is less a question of state sovereignty than it is a confirmation of certain facts of modern life. This is about inexorable digital transformations all over the globe and the security of data in a world that gets more deeply connected by the day.

    On the 31st of December 2020, the UK officially left the European Union, but it did so amid the tumult of a global pandemic.

    The pandemic has deepened our reliance on online transactions as well as the security of those transactions. Furthermore, it has accelerated the world’s digital migration at breakneck speed. Governments and companies are now doubling down on digital transformations with the introduction of mass remote work and the new centrality of electronic identities in the form of vaccine passports. Business and connected technology pays less and less heed to national borders by the day and the pandemic spurred that process on.

    Regulations like PSD2 are becoming ever more crucial to underpin these digital transformations and it may mean that not just the UK – but many other countries – will have to comply with EU regulations in some way.

    The GDPR is useful as a representative example. When it was introduced in 2018 it brought in hefty fines for companies who failed to protect personal data and issued injunctions about how organisations should collect, protect and store that data. Critically, the regulation applies not just within European borders, but wherever the data of a European citizen is being processed. The EU is the largest trading bloc in the world and there are few organisations which would want to refuse the opportunity to do business there. Now, countries around the world are drafting data protection legislation which largely mirrors the statues of the GDPR.

    PSD2, like the GDPR, may soon be adopted – at least in spirit – by other non-EU countries if not for the thoroughness of its regulations, then for the undeniable attraction of the European market.

    These kinds of developments are irresistible to nation states – who want to protect citizens and companies from threats that don’t pay heed to borders. They can only do that by working in parallel with other countries. To that end, regulations like PSD2, GDPR or eIDAS may have been built for the EU, but are profoundly informing if not directly inspiring technological regulation all over the world.

    Related Posts
    Hogan Lovells and Cadwalader plan merger to create law firm with $3.6 billion in revenue
    Hogan Lovells and Cadwalader plan merger to create law firm with $3.6 billion in revenue
    Pirelli says 99.3% of 500 million euro bond converted, diluting Sinochem and Camfin stakes
    Pirelli says 99.3% of 500 million euro bond converted, diluting Sinochem and Camfin stakes
    ECB policymakers see steady rates next year but cut not off table, sources say
    ECB policymakers see steady rates next year but cut not off table, sources say
    Britain names Christian Turner as ambassador to the US
    Britain names Christian Turner as ambassador to the US
    Trump administration imposes sanctions on two more ICC judges
    Trump administration imposes sanctions on two more ICC judges
    Norway reaches 2026 fisheries agreement with Russia, cod quota at lowest level since 1991
    Norway reaches 2026 fisheries agreement with Russia, cod quota at lowest level since 1991
    Ukraine-US fund approves investment policies as it eyes first projects in 2026
    Ukraine-US fund approves investment policies as it eyes first projects in 2026
    VW management to continue cost cutting
    VW management to continue cost cutting
    Parliament of Swiss canton Fribourg votes to ban mobile phones at school
    Parliament of Swiss canton Fribourg votes to ban mobile phones at school
    Italy economy minister denies interfering in MPS's bid for Mediobanca
    Italy economy minister denies interfering in MPS's bid for Mediobanca
    Eni and BlackRock's GIP take joint control of carbon capture unit
    Eni and BlackRock's GIP take joint control of carbon capture unit
    Bank of England's Bailey sees inflation near 2% target by May
    Bank of England's Bailey sees inflation near 2% target by May

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    More from Finance

    Explore more articles in the Finance category

    Italian judge drops Genoa dam case against Webuild CEO

    Italian judge drops Genoa dam case against Webuild CEO

    ECB's Lagarde 'fully confident' EU will agree reparation loan plan for Ukraine

    ECB's Lagarde 'fully confident' EU will agree reparation loan plan for Ukraine

    ECB keeps rates unchanged, turns more positive on economy

    ECB keeps rates unchanged, turns more positive on economy

    Austria's top court rules Meta's ad model illegal, orders overhaul of user data practices in EU

    Austria's top court rules Meta's ad model illegal, orders overhaul of user data practices in EU

    Salzgitter takes legal action against Thyssenkrupp over HKM joint venture

    Salzgitter takes legal action against Thyssenkrupp over HKM joint venture

    Lovable valued at $6.6 billion in latest funding round as AI coding demand surges

    Lovable valued at $6.6 billion in latest funding round as AI coding demand surges

    Israel, Germany sign $3.1 billion contract expansion for Arrow air defence system

    Israel, Germany sign $3.1 billion contract expansion for Arrow air defence system

    Britain imposes more sanctions on Russia's energy sector

    Britain imposes more sanctions on Russia's energy sector

    Asked about NATO, Zelenskiy says Ukraine should not change its constitution

    Asked about NATO, Zelenskiy says Ukraine should not change its constitution

    Equals Money | Railsr partners with Okta to secure AI-driven payments

    Equals Money | Railsr partners with Okta to secure AI-driven payments

    France drafts in army for cattle vaccination to defuse farmer protests

    France drafts in army for cattle vaccination to defuse farmer protests

    Russia orders Russian Railways to sell $2.4 billion Moscow Towers to pay debts, three sources say

    Russia orders Russian Railways to sell $2.4 billion Moscow Towers to pay debts, three sources say

    View All Finance Posts
    Previous Finance PostCAN TECH-FUELLED COMPASSIONATE COLLECTIONS CALM THE TIDAL WAVE OF DEBT?
    Next Finance PostCOP26: World will try again to avert climate disaster