EBA欧洲银行-Fifth-set-of-issues-raised-by-EBA-WG-on-APIs_7页_400kb
报告摘要
EBA Responses to API Working Group Issues XXI to XXVI under PSD2
Core Content Overview
The European Banking Authority (EBA) has provided responses to several issues raised by participants in the EBA Working Group on APIs under the second Payment Services Directive (PSD2). These responses aim to clarify legal and technical requirements related to the use of APIs in payment services, particularly concerning the contingency mechanism, eIDAS certificates, and data access.
Main Issues and EBA Responses
Issue XXI: Machine-readability of the central register of the EBA under PSD2
- Topic: Clarification of data fields and properties in the JSON file of the EBA central register.
- Description: Participants requested a document to clarify the structure of the JSON file containing EBA central register data.
- EBA Response:
- The EBA agrees that such clarification is beneficial.
- On 5 August 2019, a document specifying the data properties of the JSON file was published.
- The document is available on the right-hand side of the EBA webpage.
Issue XXII: Measurement of response times of the dedicated interface
- Topic: Clarification of what constitutes response time for the contingency mechanism under Guideline 2.3.
- Description: Participants questioned whether the time for Strong Customer Authentication (SCA) or TPP authorisation verification should be included in response time calculations.
- EBA Response:
- The EBA clarified that response time includes the time taken to check the authorisation/registration of TPPs, specifically the TPP’s eIDAS certificate.
- This is in accordance with Article 34(1) of the RTS (Delegated Regulation 2018/389).
- The question on SCA inclusion was answered in Q&A 4661 (9 August 2019), which states that SCA time should not be included in response time calculations.
Issue XXIII: Contingency mechanism in Art. 33(4) RTS – Identification of TPPs through “guestbooks”
- Topic: Whether using a “guestbook” method for TPP identification is compliant with the RTS.
- Description: Some participants proposed a method where TPPs register in a “guestbook” with eIDAS certificates before accessing the ASPSP’s systems.
- EBA Response:
- The EBA does not consider this method compliant with the RTS.
- Identification of TPPs must be based on qualified certificates (QSealCs/QWACs) under Article 34(1) RTS.
- The guestbook method does not allow ASPSPs to verify TPP identity at the time of access, which violates Article 66(3)(d) PSD2 and Article 66(2)(c) PSD2.
- The method also lacks a legal basis in PSD2 or RTS.
Issue XXIV: Contingency mechanism in Art. 33(4) RTS – Data that can be accessed
- Topic: Whether ASPSPs need to limit data access by TPPs via the contingency mechanism.
- Description: Participants asked if ASPSPs must restrict data access when using the contingency mechanism.
- EBA Response:
- The RTS do not require ASPSPs to limit data access under the contingency mechanism, except for sensitive payment data.
- Article 36.1(a) RTS specifies that ASPSPs should provide the same information to AISPs as is available to the PSU when directly requesting access, excluding sensitive payment data.
- Sensitive payment data is defined in Article 4(32) PSD2 as data that can be used for fraud.
- Account owner name and account number are not considered sensitive.
- ASPSPs are not required to limit data access unless specified by the RTS or GDPR.
Issue XXV: Documentation of the contingency mechanism in Art. 33(4) RTS
- Topic: Whether ASPSPs are required to document the contingency mechanism and by when.
- Description: TPPs expressed concerns about the lack of documentation and unclear SCA procedures for contingency access.
- EBA Response:
- Article 33(1) RTS requires ASPSPs to include a strategy and plans for contingency measures in the design of the dedicated interface.
- Article 33(2) RTS mandates communication plans to inform TPPs about system restoration and alternative options.
- Article 33(5) RTS requires ASPSPs to ensure TPPs can be identified and rely on authentication procedures.
- The RTS do not specify a deadline for documentation, but ASPSPs are expected to provide this documentation before the implementation of the contingency mechanism.
- This documentation is necessary to ensure smooth service continuity and transparency for TPPs.
Issue XXVI: Availability of, and reliance on, eIDAS certificates under Art. 34 RTS
- Topic: Concerns about the difficulty in obtaining eIDAS certificates from QTSPs.
- Description: TPPs raised issues regarding the unavailability of eIDAS certificates (QWACs and QSealCs) for testing ASPSP production interfaces.
- EBA Response:
- The EBA acknowledges that uncertainty about the "authorisation number" in Article 34(2) RTS contributed to delays in certificate issuance.
- In O&A 4679, the EBA clarified that the "authorisation number" includes national identification numbers used by NCAs.
- To provide additional clarity, the EBA published technical documents on 31 July 2019:
- A document with identification numbers used in EBA registers.
- Two documents with NCA abbreviations and CA email addresses for notification exchange with QTSPs.
- These documents support paragraph 32 of the EBA Opinion on eIDAS certificates and help ensure timely revocation of certificates when authorisations are withdrawn.
Key Information
- The EBA does not provide legally binding interpretations, only informational guidance.
- Machine-readable formats and eIDAS certificate standards are essential for API compliance and stakeholder understanding.
- Response time calculations under the contingency mechanism include TPP authentication checks but exclude SCA time.
- The contingency mechanism requires TPP identification using eIDAS certificates, and non-compliant methods like "guestbooks" are not acceptable.
- Data access during contingency is not restricted unless involving sensitive payment data.
- Documentation of contingency mechanisms is required but not time-bound.
- The availability and use of eIDAS certificates are crucial for compliance, and the EBA has taken steps to improve clarity and facilitate certificate issuance.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载