PSD2: The Bill on Payment Services in the Code of Economic Law

This post is also available in: Français (French) Nederlands (Dutch)

This bill partly transposes Directive 2015/2366/EU on payment services in the internal market (PSD2). The Directive aims to strengthen competition and innovation, taking account of market developments, while giving consumers a high level of protection across the Union. The prudential part having already been transposed by the Act of 11 March 2018, the government has now addressed the consumer-protection part, revising the Code of Economic Law and in particular its Book VII. The main changes concern the duty of information and transparency, liability, and the protection of personal data.

1. Duty of information and transparency

Payment-initiation service providers must communicate various information on intermediaries, representatives and competent supervisory authorities. Further information must be given after an order is initiated or received and after the transaction is executed: confirmation of successful initiation, a reference identifying the transaction, the amount, and any fees payable to the provider. It will be prohibited for the beneficiary to ask the payer to pay fees to the merchant for using any payment instrument: consumers can no longer be charged fees for debit and credit card transactions, including distance purchases. Information duties may be lightened for low-value operations. Rules on how initiation providers may access the payment account held by the account-servicing provider must be established to strengthen transparency.

2. Liability

Risk is placed mainly on operators, including payment initiators and account aggregators. A transaction is authorised only if the payer has consented to its execution, consent that may be given through the beneficiary or the initiation provider and withdrawn until the order becomes irrevocable. To obtain correction of an unauthorised or defective transaction, the user must notify the provider without delay on noticing it; the account-servicing provider makes the corrections at the user’s request. The payer’s provider must immediately refund the unauthorised amount, at the latest by the end of the next business day, unless it has good grounds to suspect fraud and notifies them in writing to the FPS Economy; in practice, this obligation will be very hard to meet. As to the burden of proof, it falls on the initiation provider’s intermediary to prove that a disputed initiated transaction was properly authenticated and recorded. On loss or theft, the payer bears losses from unauthorised transactions up to EUR 50 (instead of EUR 150 previously), and nothing in some cases; conversely, the payer bears all losses from his own fraud or from an intentional or grossly negligent breach of his obligations. Appropriate complaint procedures must be put in place, providers replying to all points within fifteen business days, with a possible extension.

Recent litigation confirms this functional view of the bank’s role: when executing a payment order, the bank acts as a payment service provider and owes no duty to warn about the underlying investment.

3. Protection of personal data

Book VII will provide that information to individuals on data processing, and the processing itself, must comply with the privacy legislation and the GDPR. Providers will access only the personal data necessary to perform their payment services (data minimisation) and will process and keep it only with the user’s explicit consent.

This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.

Comments are closed.

Up ↑

Discover more from Banking and Finance law in Belgium

Subscribe now to keep reading and get access to the full archive.

Continue reading