EBA欧洲银行-Issues-VIII-to-XIII-raised-by-the-EBA-WG-on-APIs-_9页_359kb
报告摘要
EBA Summary of Responses to Issues VIII to XIII Raised by Participants of the EBA Working Group on APIs under PSD2
Core Content Overview
The European Banking Authority (EBA) has issued responses to several issues raised by participants of the Working Group on APIs under the second Payment Services Directive (PSD2). These responses focus on clarifying the legal and operational requirements for third-party providers (TPPs) and account servicing payment service providers (ASPSPs) when using APIs for payment account access and the use of eIDAS certificates.
Key Issues and EBA Responses
Issue VIII: Portability of 'Wide Usage' Data Between Member States
- Description: A participant asked whether data collected on a 3-month 'wide usage' period in one Member State by an ASPSP Group member could be used as evidence for the 'widely used' condition in another Member State for a different ASPSP in the same group, provided they use the same dedicated interface.
- EBA Response: The EBA addressed this through its Q&A tool (Q&A 4638, 26 April 2019), indicating that the data is not portable across Member States.
Issue IX: Passporting and eIDAS Certificates
- Description: A participant questioned whether ASPSPs must verify TPPs' authorization under free provision of services or the right of establishment, given that eIDAS certificates do not include passporting information.
- EBA Response: The EBA clarified that ASPSPs are not required to check for passporting or establishment rights, as the eIDAS certificate is the primary identification tool (Q&A 4432, 26 April 2019).
Issue X: Use of eIDAS Certificates During the Wide Usage Period Prior to 14.09.2019
- Description: A participant inquired if eIDAS certificates were mandatory during the 3-month wide usage period before 14 September 2019.
- EBA Response: The EBA responded through Q&A 4630 (26 April 2019), stating that the use of eIDAS certificates is not mandatory prior to the application date of the RTS on SCA&CSC.
Issue XI: Use of Agents and Outsourcing by TPPs
- Description: Participants raised concerns about whether ASPSPs should check the status of agents or outsourced providers used by TPPs.
- EBA Response: The EBA emphasized that TPPs must identify themselves using an eIDAS certificate, and the certificate must clearly indicate the principal TPP. ASPSPs are not legally required to check the status of agents, but they may do so if it does not create obstacles to service provision. The EBA also noted that TPPs remain liable for their agents' actions.
Issue XII: 'Widely Used' and 'Design to the Satisfaction of TPPs' Conditions
- Description: A participant argued that the EBA had weakened the requirements for TPPs in the exemption process.
- EBA Response: The EBA explained that it enhanced the involvement of TPPs in the exemption process. Guidelines include requirements for ASPSPs to provide feedback from TPPs and to ensure APIs meet all legal requirements, including the 'wide usage' condition based on the number of TPPs and successful requests.
Issue XIII: ASPSPs Relying on eIDAS Certificates
- Description: Market participants expressed concerns about potential mismatches between eIDAS certificate information and national/EBA registers, especially after revocation.
- EBA Response: The EBA clarified that ASPSPs are legally required to rely on eIDAS certificates for identification, and are not obligated to use other registers. However, they may perform additional checks if they do not create obstacles. NCAs are not required to update eIDAS certificates, but may do so voluntarily. The EBA also provided an annex listing which NCAs follow the revocation process.
Annex: List of NCAs That Will Follow the Revocation Process
| EU MS | Name of Authority | NCA Follows Process? |
|---|---|---|
| Austria | Austria Financial Market Authority | Yes |
| Belgium | National Bank of Belgium | Yes |
| Bulgaria | Bulgarian National Bank | Yes |
| Croatia | Croatian National Bank | Yes |
| Cyprus | Central Bank of Cyprus | No |
| Czech | Czech National Bank | No |
| Denmark | Danish Financial Supervisory Authority | No view expressed |
| Estonia | Estonia Financial Supervisory Authority | No view expressed |
| Finland | Finnish Financial Supervisory Authority | Yes |
| France | Prudential Supervisory and Resolution Authority | No |
| Germany | Federal Financial Supervisory Authority | No |
| Greece | Bank of Greece | Yes |
| Hungary | Central Bank of Hungary | No view expressed |
| Ireland | Central Bank of Ireland | No |
| Italy | Bank of Italy | No view expressed |
| Latvia | Financial and Capital Markets Commission | Yes |
| Lithuania | Bank of Lithuania | Yes |
| Luxembourg | Commission for the Supervision of Financial Sector | Yes |
| Malta | Malta Financial Services Authority | Yes |
| Netherlands | The Netherlands Bank | Yes |
| Poland | Polish Financial Supervision Authority | Yes |
| Portugal | Bank of Portugal | Yes |
| Romania | National Bank of Romania | No view expressed |
| Slovakia | National Bank of Slovakia | Yes |
| Slovenia | Bank of Slovenia | Yes |
| Spain | Bank of Spain | Yes |
| Sweden | Swedish Financial Supervision Authority | Yes |
| UK | Financial Conduct Authority | Yes |
Summary of EBA Positions
- The EBA provides clarifications and responses through its Q&A tool and opinions.
- ASPSPs are required to rely on eIDAS certificates for TPP identification.
- The EBA encourages TPPs to test and provide feedback on APIs to ensure quality and compliance.
- The use of eIDAS certificates is not mandatory prior to 14 September 2019.
- The EBA does not impose a legal obligation on ASPSPs to verify the status of TPP agents, but cautions against creating obstacles to service provision.
- NCAs may voluntarily update eIDAS certificates upon revocation, but are not legally required to do so.
- The EBA has enhanced the role of TPPs in the exemption process, ensuring their involvement and feedback.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载