{"id":2310,"date":"2019-09-16T16:36:29","date_gmt":"2019-09-16T16:36:29","guid":{"rendered":"https:\/\/work2.dossetenta.com\/lupicino\/2019\/09\/16\/enhanced-client-authentication-sca-with-online-payments\/"},"modified":"2022-08-30T08:31:57","modified_gmt":"2022-08-30T07:31:57","slug":"enhanced-client-authentication-sca-with-online-payments","status":"publish","type":"post","link":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/","title":{"rendered":"Enhanced Client Authentication (SCA) with online payments"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p>On September 11th, we learned of <em>Banco de Espa\u00f1a<\/em>\u2019s decision to extend the period ending on the 14th to comply with the obligations of <strong>Delegated Regulation 2018\/389<\/strong>. <em>Banco de Espa\u00f1a<\/em> (<em>BdE<\/em>) is thus making use of the extraordinary power granted by the European Banking Authority (EBA) to national authorities, permitting them to grant limited additional time and work with Payment Service Providers (PSPs) on the application of Enhanced Client Authentication (SCA) in electronic payments. <em>BdE<\/em> has not set an end date or duration for the additional time and will focus on reviewing plans submitted by PSPs.<\/p>\n<p>The Internal Market Payment Services Directive 2015\/2366, more commonly known as <strong>PSD2<\/strong>, aims to foster competition and innovation, protect consumers and strengthen security requirements for online payments. The Directive is complemented by the delegated Regulation on technical regulatory standards for enhanced customer authentication (SCA) and common and secure open communication standards (CSCs).<\/p>\n<p>The SCA is a double-verified security authentication protocol that EBA established as part of the <strong>Technical Regulatory Standards<\/strong> (RTS) developed by PSD2 (which gave rise to the Delegated Regulation). This protocol has become the main stumbling block for the implementation of PSD2. SCA is considered to be a fundamental element in the development of what is known as Open Banking.<\/p>\n<p>The PSD2 updates the regulations established with the PSD1 and introduces a regulation of payment services that were being provided in the market but were actually outside the scope of the PDS1, such as the payment initiation service (PIS) and the account information service (AIS), provided by so-called <strong>Third Party Providers<\/strong> (TPP). Until the entry into force of the PSD2 and the delegated Regulation, the provision of these services implied making use, through the technique known as \u201cscreen scraping\u201d, of the same credentials for access to the services of the payment account holder himself, which implies a high security risk.<\/p>\n<p>In line with the PDS2 mandate, the EBA started work on the definition of Technical Regulatory Standards (RTS), in cooperation with the ECB, applicable to PIS and AIS service providers. The definition of these standards has been complex and focused on the definition of the SCA and the CSC. The final result has been the Delegated Regulation. PSD2 and <strong>enhanced customer authentication<\/strong> therefore signify new rules that change the way payment service providers identify their customers.<\/p>\n<p>Reinforced customer authentication processes serve to determine that a customer is who he claims to be. SCA will require payment service providers to verify that identity using at least two data independent of each other, known as authentication factors. These factors have been classified into three groups:<\/p>\n<p>&#8211; <strong>Knowledge<\/strong>: that which only the client knows.<\/p>\n<p>&#8211; <strong>Possession<\/strong>: that which only the client has.<\/p>\n<p>&#8211; <strong>Inherence<\/strong>: that which the client is.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center;\">Enhanced client authentication on PSD2<\/p>\n<p>Source: Banco de Espa\u00f1a<\/p>\n<p>&nbsp;<\/p>\n<p>Another aspect of the regulation to consider is the obligation for Payment Service Providers to develop open programming interfaces (APIs) so that TPPs providing any type of service, PIS or AIS, can communicate with them.<\/p>\n<p>All these issues are regulated in the <strong>Royal Decree-Law 19\/2018<\/strong> which partially transposes the PSD2 into Spanish law.<\/p>\n<p>Finally, we must not forget other regulations to take into account, such as <strong>Regulation (EU) 2016\/679<\/strong> on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95\/46\/EC, since what is involved is personal data and therefore agreements with payment service users may be necessary.<\/p>\n<p>We must pay attention to the specific deadline that the BOE grants, but in any case we must work to meet the requirements as soon as possible<a href=\"#_ftnref1\" name=\"_ftn1\"><\/a><\/p>\n<hr \/>\n<p>Authors: Sergio Mu\u00f1oz<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; On September 11th, we learned of Banco de Espa\u00f1a\u2019s decision to extend the period ending on the 14th to comply with the obligations of Delegated Regulation 2018\/389. Banco de Espa\u00f1a (BdE) is thus making use of the extraordinary power granted by the European Banking Authority (EBA) to national authorities, permitting them to grant limited&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1483,1754],"tags":[],"class_list":["post-2310","post","type-post","status-publish","format-standard","hentry","category-newsletters-en","category-articulo-de-opinion-en"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Enhanced Client Authentication (SCA) with online payments | Lupicinio<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Enhanced Client Authentication (SCA) with online payments | Lupicinio\" \/>\n<meta property=\"og:description\" content=\"&nbsp; On September 11th, we learned of Banco de Espa\u00f1a\u2019s decision to extend the period ending on the 14th to comply with the obligations of Delegated Regulation 2018\/389. Banco de Espa\u00f1a (BdE) is thus making use of the extraordinary power granted by the European Banking Authority (EBA) to national authorities, permitting them to grant limited...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/\" \/>\n<meta property=\"og:site_name\" content=\"Lupicinio\" \/>\n<meta property=\"article:published_time\" content=\"2019-09-16T16:36:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-08-30T07:31:57+00:00\" \/>\n<meta name=\"author\" content=\"dossetenta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mercedes Olmedo Couceiro\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Enhanced Client Authentication (SCA) with online payments | Lupicinio","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/","og_locale":"en_US","og_type":"article","og_title":"Enhanced Client Authentication (SCA) with online payments | Lupicinio","og_description":"&nbsp; On September 11th, we learned of Banco de Espa\u00f1a\u2019s decision to extend the period ending on the 14th to comply with the obligations of Delegated Regulation 2018\/389. Banco de Espa\u00f1a (BdE) is thus making use of the extraordinary power granted by the European Banking Authority (EBA) to national authorities, permitting them to grant limited...","og_url":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/","og_site_name":"Lupicinio","article_published_time":"2019-09-16T16:36:29+00:00","article_modified_time":"2022-08-30T07:31:57+00:00","author":"dossetenta","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Mercedes Olmedo Couceiro","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/#article","isPartOf":{"@id":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/"},"author":{"name":"dossetenta","@id":"https:\/\/lupicinio.com\/en\/#\/schema\/person\/dd5e6be799e68269529f63681729fc6f"},"headline":"Enhanced Client Authentication (SCA) with online payments","datePublished":"2019-09-16T16:36:29+00:00","dateModified":"2022-08-30T07:31:57+00:00","mainEntityOfPage":{"@id":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/"},"wordCount":615,"publisher":{"@id":"https:\/\/lupicinio.com\/en\/#organization"},"articleSection":["Newsletters","Opinion Article"],"inLanguage":"en-US"},{"@type":["WebPage","ItemPage"],"@id":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/","url":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/","name":"Enhanced Client Authentication (SCA) with online payments | Lupicinio","isPartOf":{"@id":"https:\/\/lupicinio.com\/en\/#website"},"datePublished":"2019-09-16T16:36:29+00:00","dateModified":"2022-08-30T07:31:57+00:00","breadcrumb":{"@id":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/lupicinio.com\/en\/enhanced-client-authentication-sca-with-online-payments\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/lupicinio.com\/en\/"},{"@type":"ListItem","position":2,"name":"Enhanced Client Authentication (SCA) with online payments"}]},{"@type":"WebSite","@id":"https:\/\/lupicinio.com\/en\/#website","url":"https:\/\/lupicinio.com\/en\/","name":"Lupicinio","description":"Abogados Internacionales","publisher":{"@id":"https:\/\/lupicinio.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/lupicinio.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/lupicinio.com\/en\/#organization","name":"Lupicinio International Law Firm","url":"https:\/\/lupicinio.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/lupicinio.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/lupicinio.com\/wp-content\/uploads\/2021\/10\/lupicinio-e1634641574720.png","contentUrl":"https:\/\/lupicinio.com\/wp-content\/uploads\/2021\/10\/lupicinio-e1634641574720.png","width":325,"height":104,"caption":"Lupicinio International Law Firm"},"image":{"@id":"https:\/\/lupicinio.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/lupicinio.com\/en\/#\/schema\/person\/dd5e6be799e68269529f63681729fc6f","name":"dossetenta","sameAs":["https:\/\/lupicinio.com"],"url":"https:\/\/lupicinio.com\/en\/lawyer\/mercedes-olmedo\/"}]}},"_links":{"self":[{"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/posts\/2310","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/comments?post=2310"}],"version-history":[{"count":2,"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/posts\/2310\/revisions"}],"predecessor-version":[{"id":10656,"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/posts\/2310\/revisions\/10656"}],"wp:attachment":[{"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/media?parent=2310"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/categories?post=2310"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lupicinio.com\/en\/wp-json\/wp\/v2\/tags?post=2310"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}