FB pixel

European Banking Authority sets conditions for PSD2 authentication compliance extension

 

The European Banking Authority (EBA) has agreed to allow conditional extensions of the deadline for implementing strong customer authentication (SCA) in accord with the EU’s Payment Services Directive Part 2 (PSD2), giving online vendors in Europe a way to remain compliant while finalizing their adoption of biometrics and other authentication factors.

The EBA published an opinion (PDF) on the elements of strong customer authentication, suggesting that the 18-month implementation period for the new regulations, which were adopted in 2015, has been sufficient to expect businesses to be able to comply. It also acknowledges, however, that online merchants and others who do not directly provide payment services themselves could face particular challenges.

Finextra reports that a recent survey from Stripe found just half of businesses expect to meet the compliance deadline, which could cost the online economy of Europe more than €50 billion.

The new PSD2 SCA rules require authentication processes to include inherence elements, which include physical and behavioral biometrics, possession elements, and knowledge elements, and the EBA opinion reviews the elements that may be compliant for each type.

The EBA now says that National Competent Authorities (CAs) can work with payment service providers and other stakeholders, including merchants, to give them limited extensions for migrating to compliant authentication approaches. Extensions are conditional on the payment service providers having a migration plan agreed to by their applicable CA, and the plan being carried out quickly.

The EBA plans to announce a new deadline for any party granted an extension to be compliant by.

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Face biometrics use cases outnumbered only by important considerations

With face biometrics now used regularly in many different sectors and areas of life, stakeholders are asking questions about a…

 

Biometric Update Podcast explores identification at scale using browser fingerprinting

“Browser fingerprinting is this idea that modern browsers are so complex.” So says Valentin Vasilyev, Chief Technology Officer of Fingerprint,…

 

Passkeys now pervasive but passwords persist in enterprise authentication

Passkeys are here; now about those passwords. Specifically, passkeys are now prevalent in the enterprise, the FIDO Alliance says, with…

 

Pornhub returns to UK, but only for iOS users who verify age with Apple

In the UK, “wanker” is not typically a term of endearment. However, the case may be different for Pornhub, which…

 

Europol operated ‘shadow’ IT systems without data safeguards: Report

Europol has operated secret data analysis platforms containing large amounts of personal information, such as identity documents, without the security…

 

EU pushes AI Act deadlines for high-risk systems, including biometrics

The EU has reached a provisional agreement on changes to the AI Act that postpone rules on high-risk AI systems,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events