PSD2 / Openbanking
EU open banking
- What it is
- The European directive on payment services, the basis of open banking
- The main idea
- With your consent, third-party services can see account data and initiate payments
- What it protects
- Strong customer authentication for payments and log-ins
- Who benefits
- Those who use financial apps and account aggregators
- What to remember
- Access is granted with your consent and can be withdrawn
In plain words
PSD2 is the European directive on payment services on which open banking is built. Put simply: it allowed licensed third-party services, with your consent, to obtain information about your account and initiate payments on your behalf — through a secure connection to the bank.
The familiar conveniences grew out of this: apps that show all your accounts at different banks in one place, spending analysis services, paying directly from an account without a card. The second important part of the directive is strong customer authentication: confirming transactions with two factors, which is why payments and log-ins now require an extra confirmation.
There are two practical conclusions for the client. First: access to your account data is possible only with your explicit consent, and it can be withdrawn. Second: when connecting financial apps, look at the service’s licence and the scope of the permissions you grant — convenience should not turn into uncontrolled access to your financial picture.
Where you encounter it
What open banking gives
- Account information
- Transaction history
- Only with consent
- Initiated from the account
- No card fee
- Quick confirmation
- Strong authentication
- Licensing of services
- Withdrawal of consent
- The scope of permissions
- How long access lasts
- The list of connections
How to use it safely
- 01Check the service’s licence
- 02Read the scope of permissions
- 03Give consent deliberately
- 04Check the list of connections
- 05Withdraw access you no longer need
What you need to know
- Access to data is possible only with your consent
- Consent can be withdrawn at any time
- The service must be licensed
- Strong authentication is a mandatory requirement
- The rules apply in the EU and the EEA
Common mistakes
- Granting access to a service without checking its licence
- Not reading exactly which data are requested
- Forgetting to withdraw access from apps you no longer use
- Entering bank details on dubious websites
- Treating two-factor confirmation as an unnecessary formality
What this means for a BRIDGES client
We draw clients’ attention to digital hygiene when relocating: which services get access to your accounts and what permissions you grant. Your financial picture is sensitive data, especially while you are going through programme checks.
Frequently asked questions
01 /What is PSD2, in plain words?
The European directive on payment services. It allowed licensed services, with your consent, to see account data and initiate payments.
02 /Is it safe?
Access is possible only with your explicit consent, the service must be licensed, and transactions are confirmed with strong authentication. But you still need to check whom you are giving access to.
03 /Can access be withdrawn?
Yes. Consent can be withdrawn at any time — usually in the bank’s app, in the section on active connections.
04 /What is strong authentication?
Confirming a transaction with two independent factors — a password and a code from an app, for example. Because of it, payments require an extra step.
05 /Where do these rules apply?
In the European Union and the EEA countries. Outside them, approaches to open banking differ.
06 /Am I obliged to use such services?
No. It is an option, not a requirement. The bank works without any third-party apps being connected.
See also
Read next


This material has undergone editorial review by BRIDGES.
Getting used to European banking?
We will help you understand how accounts, payments and access work after the move.