Agent · psd2-2015-2366-98
PSD2 artikel 98: Regulatory technical standards on authentication and communication
Structural tree: the article's own paragraphs, verbatim.
CELEX 32015L2366 · 2026-08-18 · Weight 59 · minimal-risk
OpenOpen reading. No metering is planned for this class.
- What this page is
- Agent, PSD2 artikel 98
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does PSD2 Article 98 require, and what outcome does the rule tree give?
PSD2 Article 98 is tested here by a deterministic rule tree of 14 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with Paragraph 1 applies, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32015L2366. The outcome is a machine classification, not a compliance decision.
PSD2 Article 98Checked against the publisher 2026-08-18Official text
- Paragraph 1 applies. 1. EBA shall, in close cooperation with the ECB and after consulting all relevant stakeholders, including those in the payment services market, reflecting all interests involved, develop draft regulatory technical standards addressed to payment service providers as set out in Article 1(1) of this Directive in accordance with Article 10 of Regulation (EU) No 1093/2010 specifying:
- Paragraph 2 applies. (a)
- Paragraph 3 applies. the requirements of the strong customer authentication referred to in Article 97(1) and (2);
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- in_scopeThe article applies to the situationboolean
- punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)
Rule tree
If: alla(in_scope = true, punkt = 1)
Paragraph 1 applies
1. EBA shall, in close cooperation with the ECB and after consulting all relevant stakeholders, including those in the payment services market, reflecting all interests involved, develop draft regulatory technical standards addressed to payment service providers as set out in Article 1(1) of this Directive in accordance with Article 10 of Regulation (EU) No 1093/2010 specifying:
Paragraph 1
If: alla(in_scope = true, punkt = 2)
Paragraph 2 applies
(a)
Paragraph 2
If: alla(in_scope = true, punkt = 3)
Paragraph 3 applies
the requirements of the strong customer authentication referred to in Article 97(1) and (2);
Paragraph 3
If: alla(in_scope = true, punkt = 4)
Paragraph 4 applies
(b)
Paragraph 4
If: alla(in_scope = true, punkt = 5)
Paragraph 5 applies
the exemptions from the application of Article 97(1), (2) and (3), based on the criteria established in paragraph 3 of this Article;
Paragraph 5
If: alla(in_scope = true, punkt = 6)
Paragraph 6 applies
(c)
Paragraph 6
If: alla(in_scope = true, punkt = 7)
Paragraph 7 applies
the requirements with which security measures have to comply, in accordance with Article 97(3) in order to protect the confidentiality and the integrity of the payment service users’ personalised security credentials; and
Paragraph 7
If: alla(in_scope = true, punkt = 8)
Paragraph 8 applies
(d)
Paragraph 8
If: alla(in_scope = true, punkt = 9)
Paragraph 9 applies
the requirements for common and secure open standards of communication for the purpose of identification, authentication, notification, and information, as well as for the implementation of security measures, between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers.
Paragraph 9
If: alla(in_scope = true, punkt = 10)
Paragraph 10 applies
2. The draft regulatory technical standards referred to in paragraph 1 shall be developed by EBA in order to:
Paragraph 10
If: alla(in_scope = true, punkt = 11)
Paragraph 11 applies
(a)
Paragraph 11
If: alla(in_scope = true, punkt = 12)
Paragraph 12 applies
ensure an appropriate level of security for payment service users and payment service providers, through the adoption of effective and risk-based requirements;
Paragraph 12
If: alla(in_scope = true, punkt = 13)
Paragraph 13 applies
(b)
Paragraph 13
If: alla(in_scope = true, punkt = 14)
Paragraph 14 applies
ensure the safety of payment service users’ funds and personal data;
Paragraph 14
If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.
The article text as read
- 11. EBA shall, in close cooperation with the ECB and after consulting all relevant stakeholders, including those in the payment services market, reflecting all interests involved, develop draft regulatory technical standards addressed to payment service providers as set out in Article 1(1) of this Directive in accordance with Article 10 of Regulation (EU) No 1093/2010 specifying:
- 2(a)
- 3the requirements of the strong customer authentication referred to in Article 97(1) and (2);
- 4(b)
- 5the exemptions from the application of Article 97(1), (2) and (3), based on the criteria established in paragraph 3 of this Article;
- 6(c)
- 7the requirements with which security measures have to comply, in accordance with Article 97(3) in order to protect the confidentiality and the integrity of the payment service users’ personalised security credentials; and
- 8(d)
- 9the requirements for common and secure open standards of communication for the purpose of identification, authentication, notification, and information, as well as for the implementation of security measures, between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers.
- 102. The draft regulatory technical standards referred to in paragraph 1 shall be developed by EBA in order to:
- 11(a)
- 12ensure an appropriate level of security for payment service users and payment service providers, through the adoption of effective and risk-based requirements;
- 13(b)
- 14ensure the safety of payment service users’ funds and personal data;
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32015L2366 art. 98, Regulatory technical standards on authentication and communication. ExploreWorld Legal, https://legal.exploreworldai.com/agent/psd2-2015-2366/artikel-98 (hämtad 2026-08-18, bevis sha256:f3ad081dc2a10849, bygge legal-2026-08-25).