SlideShare a Scribd company logo
1 of 13
Download to read offline
Fintech Rebellion ?
“Screen-scraping” under PSD2
BANK
FINTECH
(R)EVOLUTION
MARIUSZ OŻGA
9th June 2017
Disclaimers
The opinions expressed in this article are the author's own and do not reflect the view
of the author’s employer (AliorBank).
The opinions expressed in this article do not constitute legal opinions and the author
shall not be deemed liable for any decisions undertaken assuming those opinions.
Legal framework & timeline
RTS
National regulation
Poland: Ustawa o zmianie ustawy
o usługach płatniczych
(projekt UC81)
Nov 2015
Jan 2018 ?
EU
Poland
3Q 2017 ?
SCA
CSC
1Q 2019 ?1Q 2018 ?you / we
are here
What do they want ? Who is rebelling ?
screen-scraping APIs
● direct access with credentials
transfer
● continue to use screen-scraping
● technologically proven
● protect fintechs business
models
● interface access, no credentials
transfer
● data protection and customers
security
● ban screen-scraping altogether
● provide countrywide standard
Current state of play: it’s not about Poland
effectively:
delay of RTS
Transition period, Art 109 of PSD2: explained by EC in 1 July RTS version
Western Europe:
screen-scraping
Poland:
screen-scraping banned
new law effectively not in
force right away?
IF screen-scraping stays
it will have an impact, but from 2019
SCA
Strong Customer Authentication - authentication based on the use of two or more
of the following elements:
● knowledge - ‘something only the user knows’ (eg. static password, code, PIN)
● ownership - ‘something only the user possesses’ (eg. token, mobile, smart card)
● inherence - ‘something the user is’ (eg. biometrics)
Items selected must be mutually independent, i.e. the breach of one does not
compromise the other. Procedure should be designed to protect confidentiality of
the authentication data.
A catalogue of notable exemptions: 90 days rule for AIS; contactless at POS;
parking fees; trusted beneficiaries; recurring transactions; same owner; low value;
corporate payments (+cards ?); risk analysis based.
Still valid when “direct access” applied.
When “direct access” applies
EC on RTS latest version as of 1 July:
“direct access” as a fallback scenario
as a result of
API inaccessibility
In other circumstances screen-scraping will not be allowed
30 secs rule
not delivering level of
performance/availability
performance rule
Direct access - appliance of rules
as of RTS, art 33
● PSP (TPP) needs to be identified (TTP access control
still valid)
● authentication procedures as for user
● PSP not allowed to access/store/process data for
purposes other than services requested by user
● documentation (logs) of data accessed shall be stored
and delivered to national authority (when asked)
● inform/justify to ASPSP (bank) & national authority
A number of outstanding issues
● who is entitled to determine and control the breach of
direct access appliance rules ?
● are TPPs allowed to ask their customers to share
credentials as preemptive measure (managing
expectations) ?
● how does it changes responsibilities of banks to protect
confidentiality of the authentication data ?
● how does that change responsibility for frauds ?
● does it apply to local API standards or banks alone ?
PolishAPI standard
set of
technological
standards
(Polish RTS):
compliance services
vs premium
countrywide
TPP access
control
(+blacklisting)
one-point
data entry access
(hub)
● no credential sharing
● voluntary participation for both banks and TPP
● customer opt-out possible
Bank strategies: battlegrounds vs cooperation
comply monetize
access
utilize
ext. data
Partner
ecosystem
business
model
API’s
PolishAPI
standards &
compliance
services
PolishAPI
standards,
compliance &
premium
services
PolishAPI
standards &
compliance
services; some
own APIs
PolishAPI
standards only;
amount of own
and specialized
APIs
compliant
only/fallback
(if required)
direct
access
compliance only monetize access
to data for extra
reve
bank as TPP (new
services/advice)
become ‘everyday
bank’; offer
non-financial services
with added value
compliant
only/fallback
(if required)
compliant
only/fallback
(if required)
compliant
only/fallback
(if required)
What do customers want ?
67%
willing to
share their data with
banks in return for new
benefits (Accenture)
93%
trust banks to keep
their money safe (EY)
User-experience: balance between utility and security
33%
customers of Polish banks
confirm utility as leading factor
for choosing finance
management tools
(PWC)
53%
happy for TPP initiating
payments on their
behalf (Accenture)
94%
stressed that any new
payment service at
least as secure as
method they use
(Accenture)
70%
would not trust TPP as
much as a bank with
their data (Accenture)
Thank you !
@MozgaOzga
Mariusz Ożga
BANK
FINTECH
(R)EVOLUTION

More Related Content

What's hot

PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropeTransUnion
 
[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...
[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...
[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...WSO2
 
INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17 INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17 Alessandra Gambrill - Guion
 
INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17 INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17 Alessandra Gambrill - Guion
 
The worrying fragility of PSD2
The worrying fragility of PSD2The worrying fragility of PSD2
The worrying fragility of PSD2Aden Davies
 
OpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking UpdateOpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking UpdateMikeLeszcz
 
Payments and transaction processing systems - Global and Indian Overview
Payments and transaction processing systems - Global and Indian OverviewPayments and transaction processing systems - Global and Indian Overview
Payments and transaction processing systems - Global and Indian OverviewAkshay Kaul
 
DBX Open Banking
DBX Open BankingDBX Open Banking
DBX Open BankingBase Camp
 
White Paper - Smart City | HashCash Consultants
White Paper - Smart City | HashCash ConsultantsWhite Paper - Smart City | HashCash Consultants
White Paper - Smart City | HashCash ConsultantsHashCash Consultants
 
Fraud detection in klarna
Fraud detection in klarnaFraud detection in klarna
Fraud detection in klarnaVaibhav Singh
 
Banking technology
Banking technologyBanking technology
Banking technologySarithapream
 
New innovations in banking industry
New innovations in banking industryNew innovations in banking industry
New innovations in banking industryHemanth Shenoy
 

What's hot (15)

PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in Europe
 
[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...
[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...
[WSO2Con EU 2017] Keynote: Digital Transformation in the Guise of a Regulatio...
 
INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17 INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by SOPRA BANKING - FinTech Belgium MeetUp 29/06/17
 
INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17 INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17
INSTANT PAYMENTS by BNPPF - FinTech Belgium MeetUp 29/06/17
 
bKash Business Case Study
bKash  Business Case StudybKash  Business Case Study
bKash Business Case Study
 
The worrying fragility of PSD2
The worrying fragility of PSD2The worrying fragility of PSD2
The worrying fragility of PSD2
 
OpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking UpdateOpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Foundation/Open Banking Workshop - Open Banking Update
 
Payments and transaction processing systems - Global and Indian Overview
Payments and transaction processing systems - Global and Indian OverviewPayments and transaction processing systems - Global and Indian Overview
Payments and transaction processing systems - Global and Indian Overview
 
An Introduction to Open Banking (PSD2)
An Introduction to Open Banking (PSD2)An Introduction to Open Banking (PSD2)
An Introduction to Open Banking (PSD2)
 
DBX Open Banking
DBX Open BankingDBX Open Banking
DBX Open Banking
 
From Payment to Digital Wallet
From Payment to Digital WalletFrom Payment to Digital Wallet
From Payment to Digital Wallet
 
White Paper - Smart City | HashCash Consultants
White Paper - Smart City | HashCash ConsultantsWhite Paper - Smart City | HashCash Consultants
White Paper - Smart City | HashCash Consultants
 
Fraud detection in klarna
Fraud detection in klarnaFraud detection in klarna
Fraud detection in klarna
 
Banking technology
Banking technologyBanking technology
Banking technology
 
New innovations in banking industry
New innovations in banking industryNew innovations in banking industry
New innovations in banking industry
 

Similar to Fintech rebellion: "screen-scraping" under PSD2

FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO Alliance
 
The Convergence Economy: Crypto Assets + Blockchain + IoT + AI
The Convergence Economy: Crypto Assets + Blockchain + IoT + AIThe Convergence Economy: Crypto Assets + Blockchain + IoT + AI
The Convergence Economy: Crypto Assets + Blockchain + IoT + AIOutlier Ventures
 
Conformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open BankingConformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open BankingWSO2
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service DirectiveLac Vuong
 
PSD2: Making it actionable
PSD2: Making it actionablePSD2: Making it actionable
PSD2: Making it actionableBackbase
 
WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2WSO2
 
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésLe monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésForums financiers de Wallonie
 
PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Bankingsenakafdo
 
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedPSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedTransUnion
 
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...Idan Tohami
 
Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?
Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?
Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?IRJET Journal
 
Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...
Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...
Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...WSO2
 
B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...
B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...
B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...Kullarat Phongsathaporn
 
Fintech Module 8 - Data, Analytics and Strategy
Fintech Module 8 - Data, Analytics and StrategyFintech Module 8 - Data, Analytics and Strategy
Fintech Module 8 - Data, Analytics and StrategyDrago Indjic
 
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...WSO2
 
figo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startupsfigo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech StartupsLars Markull
 
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...apidays
 
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...FinTechLabs.io
 

Similar to Fintech rebellion: "screen-scraping" under PSD2 (20)

FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in EuropeFIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe
 
The Convergence Economy: Crypto Assets + Blockchain + IoT + AI
The Convergence Economy: Crypto Assets + Blockchain + IoT + AIThe Convergence Economy: Crypto Assets + Blockchain + IoT + AI
The Convergence Economy: Crypto Assets + Blockchain + IoT + AI
 
Conformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open BankingConformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
Conformidade & Muito mais - Uma Demo da solução WSO2 Open Banking
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service Directive
 
PSD2: Making it actionable
PSD2: Making it actionablePSD2: Making it actionable
PSD2: Making it actionable
 
WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2
 
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésLe monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
 
PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Banking
 
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedPSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
 
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...
Open Banking / PSD2 & GDPR Regulations and How They Are Changing Fraud & Fina...
 
Open Banking beyond PSD2 in the EU
Open Banking beyond PSD2 in the EU Open Banking beyond PSD2 in the EU
Open Banking beyond PSD2 in the EU
 
Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?
Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?
Banks V/s P2P Transactions: Who will own the Future of Financial Transactions?
 
Radi IT Co-Payment Dep.pdf
Radi IT Co-Payment Dep.pdfRadi IT Co-Payment Dep.pdf
Radi IT Co-Payment Dep.pdf
 
Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...
Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...
Secure and Accelerated PSD2 Compliance with WSO2 Open Banking - A Technical D...
 
B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...
B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...
B11: Central IP & IT Court | FinTech: Legal and Regulatory Challenges (7 Aug ...
 
Fintech Module 8 - Data, Analytics and Strategy
Fintech Module 8 - Data, Analytics and StrategyFintech Module 8 - Data, Analytics and Strategy
Fintech Module 8 - Data, Analytics and Strategy
 
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
Agile and Adaptable Technology Platforms - Easing the Insanity of the Post PS...
 
figo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startupsfigo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startups
 
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...
APIdays Singapore 2019 - Global Open Banking Frameworks and Standards: Luca F...
 
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
 

Recently uploaded

Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignHenry Tapper
 
Quarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingQuarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingMaristelaRamos12
 
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...ranjana rawat
 
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex
 
Lundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfLundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfAdnet Communications
 
02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptx
02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptx02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptx
02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptxFinTech Belgium
 
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130Suhani Kapoor
 
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130  Available With RoomVIP Kolkata Call Girl Serampore 👉 8250192130  Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Roomdivyansh0kumar0
 
Booking open Available Pune Call Girls Shivane 6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Shivane  6297143586 Call Hot Indian Gi...Booking open Available Pune Call Girls Shivane  6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Shivane 6297143586 Call Hot Indian Gi...Call Girls in Nagpur High Profile
 
Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...
Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...
Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...makika9823
 
OAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptx
OAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptxOAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptx
OAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptxhiddenlevers
 
06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdf
06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdf06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdf
06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdfFinTech Belgium
 
The Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdfThe Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdfGale Pooley
 
Andheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot ModelsAndheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot Modelshematsharma006
 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...ssifa0344
 
Q3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast SlidesQ3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast SlidesMarketing847413
 
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...shivangimorya083
 
How Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingHow Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingAggregage
 

Recently uploaded (20)

Log your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaignLog your LOA pain with Pension Lab's brilliant campaign
Log your LOA pain with Pension Lab's brilliant campaign
 
Quarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of MarketingQuarter 4- Module 3 Principles of Marketing
Quarter 4- Module 3 Principles of Marketing
 
Commercial Bank Economic Capsule - April 2024
Commercial Bank Economic Capsule - April 2024Commercial Bank Economic Capsule - April 2024
Commercial Bank Economic Capsule - April 2024
 
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
(DIYA) Bhumkar Chowk Call Girls Just Call 7001035870 [ Cash on Delivery ] Pun...
 
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️call girls in  Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
call girls in Nand Nagri (DELHI) 🔝 >༒9953330565🔝 genuine Escort Service 🔝✔️✔️
 
Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024Bladex Earnings Call Presentation 1Q2024
Bladex Earnings Call Presentation 1Q2024
 
Lundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdfLundin Gold April 2024 Corporate Presentation v4.pdf
Lundin Gold April 2024 Corporate Presentation v4.pdf
 
02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptx
02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptx02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptx
02_Fabio Colombo_Accenture_MeetupDora&Cybersecurity.pptx
 
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
VIP Call Girls Service Dilsukhnagar Hyderabad Call +91-8250192130
 
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130  Available With RoomVIP Kolkata Call Girl Serampore 👉 8250192130  Available With Room
VIP Kolkata Call Girl Serampore 👉 8250192130 Available With Room
 
Booking open Available Pune Call Girls Shivane 6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Shivane  6297143586 Call Hot Indian Gi...Booking open Available Pune Call Girls Shivane  6297143586 Call Hot Indian Gi...
Booking open Available Pune Call Girls Shivane 6297143586 Call Hot Indian Gi...
 
Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...
Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...
Independent Lucknow Call Girls 8923113531WhatsApp Lucknow Call Girls make you...
 
OAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptx
OAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptxOAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptx
OAT_RI_Ep19 WeighingTheRisks_Apr24_TheYellowMetal.pptx
 
06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdf
06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdf06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdf
06_Joeri Van Speybroek_Dell_MeetupDora&Cybersecurity.pdf
 
The Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdfThe Economic History of the U.S. Lecture 18.pdf
The Economic History of the U.S. Lecture 18.pdf
 
Andheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot ModelsAndheri Call Girls In 9825968104 Mumbai Hot Models
Andheri Call Girls In 9825968104 Mumbai Hot Models
 
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
Solution Manual for Financial Accounting, 11th Edition by Robert Libby, Patri...
 
Q3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast SlidesQ3 2024 Earnings Conference Call and Webcast Slides
Q3 2024 Earnings Conference Call and Webcast Slides
 
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
Russian Call Girls In Gtb Nagar (Delhi) 9711199012 💋✔💕😘 Naughty Call Girls Se...
 
How Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of ReportingHow Automation is Driving Efficiency Through the Last Mile of Reporting
How Automation is Driving Efficiency Through the Last Mile of Reporting
 

Fintech rebellion: "screen-scraping" under PSD2

  • 1. Fintech Rebellion ? “Screen-scraping” under PSD2 BANK FINTECH (R)EVOLUTION MARIUSZ OŻGA 9th June 2017
  • 2. Disclaimers The opinions expressed in this article are the author's own and do not reflect the view of the author’s employer (AliorBank). The opinions expressed in this article do not constitute legal opinions and the author shall not be deemed liable for any decisions undertaken assuming those opinions.
  • 3. Legal framework & timeline RTS National regulation Poland: Ustawa o zmianie ustawy o usługach płatniczych (projekt UC81) Nov 2015 Jan 2018 ? EU Poland 3Q 2017 ? SCA CSC 1Q 2019 ?1Q 2018 ?you / we are here
  • 4. What do they want ? Who is rebelling ? screen-scraping APIs ● direct access with credentials transfer ● continue to use screen-scraping ● technologically proven ● protect fintechs business models ● interface access, no credentials transfer ● data protection and customers security ● ban screen-scraping altogether ● provide countrywide standard
  • 5. Current state of play: it’s not about Poland effectively: delay of RTS Transition period, Art 109 of PSD2: explained by EC in 1 July RTS version Western Europe: screen-scraping Poland: screen-scraping banned new law effectively not in force right away? IF screen-scraping stays it will have an impact, but from 2019
  • 6. SCA Strong Customer Authentication - authentication based on the use of two or more of the following elements: ● knowledge - ‘something only the user knows’ (eg. static password, code, PIN) ● ownership - ‘something only the user possesses’ (eg. token, mobile, smart card) ● inherence - ‘something the user is’ (eg. biometrics) Items selected must be mutually independent, i.e. the breach of one does not compromise the other. Procedure should be designed to protect confidentiality of the authentication data. A catalogue of notable exemptions: 90 days rule for AIS; contactless at POS; parking fees; trusted beneficiaries; recurring transactions; same owner; low value; corporate payments (+cards ?); risk analysis based. Still valid when “direct access” applied.
  • 7. When “direct access” applies EC on RTS latest version as of 1 July: “direct access” as a fallback scenario as a result of API inaccessibility In other circumstances screen-scraping will not be allowed 30 secs rule not delivering level of performance/availability performance rule
  • 8. Direct access - appliance of rules as of RTS, art 33 ● PSP (TPP) needs to be identified (TTP access control still valid) ● authentication procedures as for user ● PSP not allowed to access/store/process data for purposes other than services requested by user ● documentation (logs) of data accessed shall be stored and delivered to national authority (when asked) ● inform/justify to ASPSP (bank) & national authority
  • 9. A number of outstanding issues ● who is entitled to determine and control the breach of direct access appliance rules ? ● are TPPs allowed to ask their customers to share credentials as preemptive measure (managing expectations) ? ● how does it changes responsibilities of banks to protect confidentiality of the authentication data ? ● how does that change responsibility for frauds ? ● does it apply to local API standards or banks alone ?
  • 10. PolishAPI standard set of technological standards (Polish RTS): compliance services vs premium countrywide TPP access control (+blacklisting) one-point data entry access (hub) ● no credential sharing ● voluntary participation for both banks and TPP ● customer opt-out possible
  • 11. Bank strategies: battlegrounds vs cooperation comply monetize access utilize ext. data Partner ecosystem business model API’s PolishAPI standards & compliance services PolishAPI standards, compliance & premium services PolishAPI standards & compliance services; some own APIs PolishAPI standards only; amount of own and specialized APIs compliant only/fallback (if required) direct access compliance only monetize access to data for extra reve bank as TPP (new services/advice) become ‘everyday bank’; offer non-financial services with added value compliant only/fallback (if required) compliant only/fallback (if required) compliant only/fallback (if required)
  • 12. What do customers want ? 67% willing to share their data with banks in return for new benefits (Accenture) 93% trust banks to keep their money safe (EY) User-experience: balance between utility and security 33% customers of Polish banks confirm utility as leading factor for choosing finance management tools (PWC) 53% happy for TPP initiating payments on their behalf (Accenture) 94% stressed that any new payment service at least as secure as method they use (Accenture) 70% would not trust TPP as much as a bank with their data (Accenture)
  • 13. Thank you ! @MozgaOzga Mariusz Ożga BANK FINTECH (R)EVOLUTION