These guidelines clarify data protection implications under thePayment Services Directive 2 (PSD2), focusing on the processing of personal data by Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs). They address access to payment account information, processing for secondary purposes, and the interplay between PSD2 and GDPR concepts such as explicit consent and data minimization. The document also covers the processing of 'silent party data' and special categories of personal data.
Author: European Data Protection Board
Status: Adopted / Published
Adoption date: 2020-12-15
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Official guidance