Payment Service Directive is a European law that gives you more control over your bank account and payment data

Payment Service Directive (often called PSD or PSD2) is a set of rules made by the European Union that controls how banks and payment companies handle your money and information. The main idea is straightforward: you should be able to see what's happening with your account, move your money to different banks more easily, and let other companies access your account information if you choose to — but only with your permission.

If you live in the EU, UK, or EEA countries (Iceland, Liechtenstein, Norway), these rules explore to your bank. If you live elsewhere, your bank may follow similar rules, but PSD2 is not legally required. The rules affect what your bank must do, not what you must do — but understanding them helps you know what rights you have.

Key Takeaways

  • Payment Service Directive is an EU law that requires banks to let you see your account data and move money between banks more easily.
  • The rules give you the right to let other companies (like budgeting apps or payment services) access your account information, but only if you give written permission first.
  • Banks must use strong security when you log in — usually a password plus a second step like a code sent to your phone — to protect your account from fraud.
  • You can switch banks without losing your payment history or having to update every company that pays you, because banks must help you move your information.

Why the rules exist: what changed

Before PSD2, banks kept tight control over customer data. If you wanted to use a budgeting app that could see your spending, or switch to a new bank, the process was slow and you had to do most of the work yourself. The EU created these rules to make banking more open and to let new companies compete with traditional banks.

The rules also came from real security problems. Banks were not always required to use strong security methods, so fraud was common. PSD2 set a minimum standard: banks must use strong customer authentication, which means you have to prove who you are in at least two different ways when you log in or make a large payment.

What "strong customer authentication" means for you

Strong customer authentication is the security step you may have noticed when your bank asks for your password and then sends you a code by text message. This is two-factor authentication — two different ways to prove you are who you say you are. One factor is something you know (your password), and the other is something you have (your phone) or something you are (your fingerprint).

Your bank must use this when you log in from a new device, when you make a payment over a certain amount, or when you change your account details. The exact amount varies by bank, but it is usually between €30 and €100. This slows down fraud because a thief would need both your password and your phone to get into your account.

Some banks let you skip the second step for small, regular payments to the same person — for example, your monthly rent to your landlord. This is called exemption, and your bank decides whether to offer it. You can usually turn this on or off in your account settings.

How third-party apps can access your account

One of the biggest changes PSD2 brought is the right to let other companies see your bank account information. These companies are called third-party providers, and they include budgeting apps, payment services, and loan companies. Under the old rules, they could not legally access your account data at all.

Now, if you want to use an app that tracks your spending across all your bank accounts, or a service that helps you move money between banks, you can give it permission. You do this by logging into the app and connecting your bank account — the app then asks your bank for permission, and your bank asks you to confirm. You are always in control: you can see which apps have access, and you can revoke permission at any time.

The catch is that the app must be registered and regulated. Your bank will only let a registered app access your account. This protects you from fake apps that pretend to be legitimate but are actually trying to steal your information.

Switching banks without losing your payment history

PSD2 requires banks to help you move your account information when you switch. This is called account information services. Your new bank can ask your old bank for a copy of your payment history, standing orders, and direct debits — the regular payments set up on your account.

You no longer have to manually tell every company that pays you (your employer, your benefits office) about your new account number. Instead, your new bank can get this information from your old bank and help you set up the same payments in the new account. The process still takes time — usually a few weeks — but the bank does the heavy lifting instead of you.

This matters most if you have many regular payments. If you are paid by direct deposit and have several bills on standing order, switching banks used to mean weeks of updating information and risking missed payments. Now your new bank handles most of it.

What PSD2 does not do

PSD2 does not protect you from your own mistakes. If you give your password to someone, or if you approve a payment you did not mean to make, the law does not automatically refund you. You have to report the problem to your bank quickly — usually within a few days — and the bank will investigate.

The rules also do not explore to cash. PSD2 covers electronic payments and account access, not money you withdraw from an ATM or hand over in person. And if you live outside the EU and EEA, your bank may not follow these rules at all, though many international banks do anyway because it is good practice.

Finally, PSD2 does not mean your bank has to offer every service. For example, your bank does not have to let third-party apps access your account if it has not built the technology to do so safely. But if it does offer the service, it must follow the PSD2 rules.

Frequently Asked Questions

Do I have to let apps access my bank account?

No. Giving permission to third-party apps is optional. You only grant access if you choose to use a service that needs it. You can revoke permission at any time in your bank's app or website.

Is it safe to let a budgeting app see my account?

If the app is registered with your country's financial regulator, yes — PSD2 rules require it to handle your data securely and not share it without your permission. Check your bank's list of approved apps before connecting. Never use an app your bank does not recognize.

What happens if I forget my password and my phone is lost?

Contact your bank when ready. Because strong authentication requires two factors, losing one of them locks you out. Your bank has a process to verify your identity another way (usually in person or by video call) so you can regain access. This takes longer than a normal login but protects your account from theft.

Can my bank refuse to switch my account information to another bank?

No. Under PSD2, your bank must provide your account information to your new bank if you request it. The process takes time, but the bank cannot refuse. If your bank is slow or unhelpful, you can complain to your country's financial regulator.

Does PSD2 explore if my bank is outside Europe?

Only if your bank operates in the EU or EEA. Banks based in the US, UK (post-Brexit), or other countries are not required to follow PSD2, though some do. Check your bank's terms to see what security and data-sharing rules it follows.