{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/compliance",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/compliance)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-03",
    "fingerprint": "ewai:eu:e75645",
    "proof": "sha256:da5975cb8a27d4ba09396de75c96595af1d7989abdee4dc03fe44f06075d79e9",
    "jurisdiction": "eu",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "brand": {
    "product": "NovaCopilot",
    "platform": "ExploreWorldAI",
    "infrastructure": "ExploreWorld Legal",
    "infrastructure_url": "legal.exploreworldai.com",
    "legal_entity": "Valkiv Ventures AB",
    "permanent_url": "https://legal.exploreworldai.com/novacopilot",
    "source": "Source: NovaCopilot",
    "powered_by": "Powered by NovaCopilot",
    "license": "https://legal.exploreworldai.com/licensvillkor",
    "contact": "stig@valkiv.com"
  },
  "item": {
    "schema_version": "1.0.0",
    "id": "compliance:psd2:payment-service-provider",
    "act": {
      "id": "psd2",
      "slug": "psd2-2015-2366",
      "celex": "32015L2366",
      "name": "PSD2: Directive (EU) 2015/2366",
      "official_source": "https://eur-lex.europa.eu/eli/dir/2015/2366/oj",
      "consolidated": null,
      "in_force": "2016-01-12",
      "applies": "2018-01-13",
      "applies_kind": "transposition"
    },
    "role": "payment-service-provider",
    "obligations": [
      {
        "article": "73",
        "title": "Payment service provider’s liability for unauthorised payment transactions",
        "duty": "Refund the payer for an unauthorised payment transaction.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/psd2-2015-2366/artikel-73",
        "obligation_id": "obligation:eu:psd2-art-73-payment-service-provider",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:psd2-art-73-payment-service-provider",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 73",
          "title": "Payment service provider’s liability for unauthorised payment transactions",
          "paragraphs": [
            "1. Member States shall ensure that, without prejudice to Article 71, in the case of an unauthorised payment transaction, the payer’s payment service provider refunds the payer the amount of the unauthorised payment transaction immediately, and in any event no later than by the end of the following business day, after noting or being notified of the transaction, except where the payer’s payment service provider has reasonable grounds for suspecting fraud and communicates those grounds to the relevant national authority in writing. Where applicable, the payer’s payment service provider shall restore the debited payment account to the state in which it would have been had the unauthorised payment transaction not taken place. This shall also ensure that the credit value date for the payer’s payment account shall be no later than the date the amount had been debited.",
            "2. Where the payment transaction is initiated through a payment initiation service provider, the account servicing payment service provider shall refund immediately, and in any event no later than by the end of the following business day the amount of the unauthorised payment transaction and, where applicable, restore the debited payment account to the state in which it would have been had the unauthorised payment transaction not taken place.",
            "If the payment initiation service provider is liable for the unauthorised payment transaction, it shall immediately compensate the account servicing payment service provider at its request for the losses incurred or sums paid as a result of the refund to the payer, including the amount of the unauthorised payment transaction. In accordance with Article 72(1), the burden shall be on the payment initiation service provider to prove that, within its sphere of competence, the payment transaction was authenticated, accurately recorded and not affected by a technical breakdown or other deficiency linked to the payment service of which it is in charge.",
            "3. Further financial compensation may be determined in accordance with the law applicable to the contract concluded between the payer and the payment service provider or the contract concluded between the payer and the payment initiation service provider if applicable."
          ],
          "truncated": false,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32015L2366#art_73",
          "read_at": "2026-08-18",
          "sha256": "d15ffdb3354a05ec0edaf3405d08f98d1de9677d1b87425b6442d626202a2254",
          "complete": true,
          "completeness_note": "Hela artikeln, ordagrant."
        }
      },
      {
        "article": "95",
        "title": "Management of operational and security risks",
        "duty": "Manage operational and security risks of payment services.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/psd2-2015-2366/artikel-95",
        "obligation_id": "obligation:eu:psd2-art-95-payment-service-provider",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:psd2-art-95-payment-service-provider",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 95",
          "title": "Management of operational and security risks",
          "paragraphs": [
            "1. Member States shall ensure that payment service providers establish a framework with appropriate mitigation measures and control mechanisms to manage the operational and security risks, relating to the payment services they provide. As part of that framework, payment service providers shall establish and maintain effective incident management procedures, including for the detection and classification of major operational and security incidents.",
            "2. Member States shall ensure that payment service providers provide to the competent authority on an annual basis, or at shorter intervals as determined by the competent authority, an updated and comprehensive assessment of the operational and security risks relating to the payment services they provide and on the adequacy of the mitigation measures and control mechanisms implemented in response to those risks.",
            "3. By 13 July 2017, EBA shall, in close cooperation with the ECB and after consulting all relevant stakeholders, including those in the payment services market, reflecting all interests involved, issue guidelines in accordance with Article 16 of Regulation (EU) No 1093/2010 with regard to the establishment, implementation and monitoring of the security measures, including certification processes where relevant.",
            "EBA shall, in close cooperation with the ECB, review the guidelines referred to in the first subparagraph on a regular basis and in any event at least every 2 years.",
            "4. Taking into account experience acquired in the application of the guidelines referred to in paragraph 3, EBA shall, where requested to do so by the Commission as appropriate, develop draft regulatory technical standards on the criteria and on the conditions for establishment, and monitoring, of security measures.",
            "Power is delegated to the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.",
            "5. EBA shall promote cooperation, including the sharing of information, in the area of operational and security risks associated with payment services among the competent authorities, and between the competent authorities and the ECB and, where relevant, the European Union Agency for Network and Information Security."
          ],
          "truncated": false,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32015L2366#art_95",
          "read_at": "2026-08-18",
          "sha256": "997287200dc465b75c4c49fb224968697ca6863407946e93b2e33d4d05fb7930",
          "complete": true,
          "completeness_note": "Hela artikeln, ordagrant."
        }
      },
      {
        "article": "96",
        "title": "Incident reporting",
        "duty": "Report major operational or security incidents to the competent authority.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/psd2-2015-2366/artikel-96",
        "obligation_id": "obligation:eu:psd2-art-96-payment-service-provider",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:psd2-art-96-payment-service-provider",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 96",
          "title": "Incident reporting",
          "paragraphs": [
            "1. In the case of a major operational or security incident, payment service providers shall, without undue delay, notify the competent authority in the home Member State of the payment service provider.",
            "Where the incident has or may have an impact on the financial interests of its payment service users, the payment service provider shall, without undue delay, inform its payment service users of the incident and of all measures that they can take to mitigate the adverse effects of the incident.",
            "2. Upon receipt of the notification referred to in paragraph 1, the competent authority of the home Member State shall, without undue delay, provide the relevant details of the incident to EBA and to the ECB. That competent authority shall, after assessing the relevance of the incident to relevant authorities of that Member State, notify them accordingly.",
            "EBA and the ECB shall, in cooperation with the competent authority of the home Member State, assess the relevance of the incident to other relevant Union and national authorities and shall notify them accordingly. The ECB shall notify the members of the European System of Central Banks on issues relevant to the payment system.",
            "On the basis of that notification, the competent authorities shall, where appropriate, take all of the necessary measures to protect the immediate safety of the financial system.",
            "3. By 13 January 2018, EBA shall, in close cooperation with the ECB and after consulting all relevant stakeholders, including those in the payment services market, reflecting all interests involved, issue guidelines in accordance with Article 16 of Regulation (EU) No 1093/2010 addressed to each of the following:",
            "(a) payment service providers, on the classification of major incidents referred to in paragraph 1, and on the content, the format, including standard notification templates, and the procedures for notifying such incidents;",
            "(b) competent authorities, on the criteria on how to assess the relevance of the incident and the details of the incident reports to be shared with other domestic authorities.",
            "4. EBA shall, in close cooperation with the ECB, review the guidelines referred to in paragraph 3 on a regular basis and in any event at least every 2 years.",
            "5. While issuing and reviewing the guidelines referred to in paragraph 3, EBA shall take into account standards and/or specifications developed and published by the European Union Agency for Network and Information Security for sectors pursuing activities other than payment service provision.",
            "6. Member States shall ensure that payment service providers provide, at least on an annual basis, statistical data on fraud relating to different means of payment to their competent authorities. Those competent authorities shall provide EBA and the ECB with such data in an aggregated form."
          ],
          "truncated": false,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32015L2366#art_96",
          "read_at": "2026-08-18",
          "sha256": "f67274fa34a0deb585cd65b211e1ddb188dd3a94cd36cb4b4c9456617f3eaccc",
          "complete": true,
          "completeness_note": "Hela artikeln, ordagrant."
        }
      },
      {
        "article": "97",
        "title": "Authentication",
        "duty": "Apply strong customer authentication.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/psd2-2015-2366/artikel-97",
        "obligation_id": "obligation:eu:psd2-art-97-payment-service-provider",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:psd2-art-97-payment-service-provider",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 97",
          "title": "Authentication",
          "paragraphs": [
            "1. Member States shall ensure that a payment service provider applies strong customer authentication where the payer:",
            "(a) accesses its payment account online;",
            "(b) initiates an electronic payment transaction;",
            "(c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses.",
            "2. With regard to the initiation of electronic payment transactions as referred to in point (b) of paragraph 1, Member States shall ensure that, for electronic remote payment transactions, payment service providers apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.",
            "3. With regard to paragraph 1, Member States shall ensure that payment service providers have in place adequate security measures to protect the confidentiality and integrity of payment service users’ personalised security credentials.",
            "4. Paragraphs 2 and 3 shall also apply where payments are initiated through a payment initiation service provider. Paragraphs 1 and 3 shall also apply when the information is requested through an account information service provider.",
            "5. Member States shall ensure that the account servicing payment service provider allows the payment initiation service provider and the account information service provider to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user in accordance with paragraphs 1 and 3 and, where the payment initiation service provider is involved, in accordance with paragraphs 1, 2 and 3."
          ],
          "truncated": false,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32015L2366#art_97",
          "read_at": "2026-08-18",
          "sha256": "b11ba767a10d7dd1403f97d1c07f6652f07a9eb06bb43b03949f8b3a885374b4",
          "complete": true,
          "completeness_note": "Hela artikeln, ordagrant."
        }
      }
    ],
    "national_implementation": [
      {
        "jurisdiction": "SE",
        "sfs": "2010:751",
        "title": "Lag om betaltjänster",
        "short": "Betaltjänstlagen",
        "relation": "Genomför direktiv (EU) 2015/2366 (PSD2)",
        "official_text": "https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/_sfs-2010-751/",
        "law_graph": "https://legal.exploreworldai.com/api/public/v1/graph/law?act=betaltjanstlagen"
      }
    ],
    "read_at": "2026-08-31",
    "sha256": "6fe1e77d029f31bcde4fca57c4192910b01f34bd279796988175fa7d3f2c155f",
    "industries": [
      "banking"
    ],
    "freshness": {
      "index": 63,
      "readAt": "2026-08-31",
      "ageDays": 33,
      "cadenceDays": 30,
      "nextCheck": "2026-09-30",
      "state": "due",
      "stateLabel": "Omläsning inplanerad"
    },
    "stay_current": {
      "cursor": "MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg",
      "chain_hash": "b2e9562b24e7de637742b1660609c2d36eb107fbb6c5ca8041be4979b823290d",
      "changes": "https://legal.exploreworldai.com/api/public/v1/changes/cursor?after=MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg",
      "verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify?cursor=MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg&chain_hash=b2e9562b24e7de637742b1660609c2d36eb107fbb6c5ca8041be4979b823290d",
      "poll_after_seconds": 3600
    },
    "permanent_url": "https://legal.exploreworldai.com/api/public/v1/compliance?act=psd2-2015-2366&role=payment-service-provider",
    "method": "Skyldigheter ur registrets egna rader, artikel för artikel. Inget tolkas eller läggs till.",
    "official_text_coverage": {
      "quoted": 4,
      "total": 4
    },
    "content_kind_rule": "Endast source_text är lagens egen lydelse. duty är en kort sammanfattning, ej juristgranskad."
  },
  "explore": {
    "brand_source": "Source: NovaCopilot",
    "brand": {
      "product": "NovaCopilot",
      "platform": "ExploreWorldAI",
      "infrastructure": "ExploreWorld Legal",
      "infrastructure_url": "legal.exploreworldai.com",
      "legal_entity": "Valkiv Ventures AB",
      "permanent_url": "https://legal.exploreworldai.com/novacopilot",
      "source": "Source: NovaCopilot",
      "powered_by": "Powered by NovaCopilot",
      "license": "https://legal.exploreworldai.com/licensvillkor",
      "contact": "stig@valkiv.com"
    },
    "data_model": "https://legal.exploreworldai.com/api/public/v1/data-model",
    "relations": "https://legal.exploreworldai.com/api/public/v1/relations?id=compliance%3Apsd2-2015-2366%3Apayment-service-provider",
    "risk": "https://legal.exploreworldai.com/api/public/v1/risk?id=compliance%3Apsd2-2015-2366%3Apayment-service-provider",
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes/cursor",
    "partner_entries": "https://legal.exploreworldai.com/api/public/v1/partner-entry",
    "source": "Source: NovaCopilot"
  },
  "hash": "sha256:da5975cb8a27d4ba09396de75c96595af1d7989abdee4dc03fe44f06075d79e9",
  "version": "legal-2026-10-03",
  "expires": "2026-10-04T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-03+legal-2026-10-03+2026-10-03T18:14:58",
    "content_hash": "sha256:da5975cb8a27d4ba09396de75c96595af1d7989abdee4dc03fe44f06075d79e9",
    "revalidate_after": "2026-10-03T19:38:50.358Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/compliance",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}