Harmonizing open banking in the European Union: an analysis of PSD2 compliance and interrelation with cybersecurity frameworks and standards

Author:

Gounari Marianna,Stergiopoulos George,Pipyros Kosmas,Gritzalis Dimitris

Abstract

AbstractThis paper focuses on the security protocols enacted in banking transactions across the European Economic Area (EEA), as stipulated by the Second or Revised Payment Service Directive (commonly referred to as ‘PSD2’ or simply ‘the Directive’). The study aims to comprehensively analyse the implementation and efficacy of these security measures within the specified jurisdiction. The Directive incorporates fundamental rights and obligations that all stakeholders are compelled to adhere to and delineates specific security measures and standards that both traditional banking institutions and third-party providers (TPP) are mandated to implement. In particular, one of the cardinal mandates for banking and financial institutions under PSD2 is the obligation to facilitate third-party access to customer data via open application programming interfaces (API). While this open banking paradigm and the consequent proliferation of data sharing unquestionably bring about various advantages, such as enhanced consumer choice and market competition, they concurrently expose the financial ecosystem to a slew of potential security vulnerabilities and privacy risks. Upon conducting a comprehensive review of the security requirements and measures stipulated under PSD2 and a comparative analysis with essential cybersecurity frameworks and standards (NIS2, Cybersecurity Act, GDPR, ISO 27001:22 and PCI DSS), we have ascertained a discernible lack of harmonisation and clarity concerning the technical security specifications for its effective implementation. This lacuna substantiates the challenges banks face in fully grasping the extensive spectrum of compliance obligations mandated by PSD2. The aim of this research is to offer a valuable contribution to both the comprehension and the pragmatic deployment of security standards in the context of banking transactions, as regulated by the PSD2. The paper serves as a valuable resource for traditional banking institutions and relevant stakeholders by guiding them through the complexities of PSD2 implementation while also evaluating the effects of the security measures on transactional safeguards, data security, and the provision of payment services.

Funder

Athens University of Economics & Business

Publisher

Springer Fachmedien Wiesbaden GmbH

Reference69 articles.

1. Chishti S, Barberis J (2016) The FINTECH Book: The Financial. Technology (Handbook for Investors, Entrepreneurs and Visionaries. John Wiley & Sons)

2. Goldfarb A, Tucker C (2019) Digital Economics. J Econ Lit 57(1):3–43. https://doi.org/10.1257/jel.20171452

3. Directive (EU) 2015/2366of the European Parliament and of the Council of 25 November 2015on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC.

4. Directive (EU) 2007/64 of the European Parliament and of the Council of 13 November 2007on payment services in the internal market amending Directives 97/7/EC, 2002/65/EC and 2006/48/EC and repealing Directive 97/5/EC.

5. Khakan N, Mostafiz Najaf MIR (2021) Fintech firms and banks sustainability: Why cybersecurity risk matters? Int J Financial Eng. https://doi.org/10.1142/S2424786321500195

Cited by 1 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3