February 2019
Total Page:16
File Type:pdf, Size:1020Kb
FEBRUARY 2019 Zopa CIO on PSD2 and customer relationships – Page 6 (Feature Story) Bulgaria passes GDPR amendments despite security concerns – Page 10 (News and Trends) GDPR and how a U.S. equivalent would look – Page 14 (Deep Dive) table of CONTENTS 03 WHAT’S INSIDE A look at the latest PSD2-related retail payment, data policy and compliance regulation news and developments 06 FEATURE STORY An interview with Didier Baclin, chief innovation officer for P2P loan company Zopa, on PSD2 and how it’s changing customer relationships 10 NEWS AND TRENDS The most recent PSD2 and GDPR trends, including how European businesses and consumers are responding to the regulations 14 DEEP DIVE An in-depth look into how other countries are reacting to PSD2 and GPDR, and how a U.S. equivalent could look 16 ABOUT Information on PYMNTS and Whitepages Pro ACKNOWLEDGMENT The PSD2 Tracker™ was done in collaboration with Whitepages Pro, and PYMNTS is grateful for the company’s support and insight. PYMNTS.com retains full editorial control over the findings presented, as well as the methodology and data analysis. 3 More European businesses are becoming compliant with the Revised Payment Services Directive (PSD2) and AROUND THE PSD2 AND GPDR WORLD General Data Protection Regulations (GDPR) by the week, but adherence isn’t without its challenges. Becoming Bulgaria is acting quickly to implement GPDR. The compliant with the European Union’s open banking country’s Parliament passed related amendments early ecosystem provides fraudsters with ample opportunities in 2019, but reservations remain about the associated to commit crime. security issues. As GDPR and PSD2 compliance become necessary in the EU, Bulgaria appears to be prioritizing Fifty-two percent of cyberattacks reported in the EU its citizens’ data protection and security. targeted firms that were subject to PSD2, meaning local businesses and payment providers will need to stay The spread of open banking across the EU is prompting on guard. That’s not to say that the directive has hit a businesses, payment providers and retailers to keep plateau, though. An increasing number of companies a closer eye on their compliance, too. Card network are now turning to PSD2-compliant application program Mastercard, in partnership with open banking solutions interfaces (APIs) that support payments. provider Konsentus, has added an identity and regulatory checking product to its suite of open banking services. These regulations aim to restore trust by giving The offering will review third parties looking for account consumers control of their data, but many in Europe access, and confirm that they are both legitimate and are still adjusting. Just 53 percent of those in the U.K. compliant with PSD2 and other European regulations. said they would give their banks their mobile phone numbers, which can put a damper on open banking Countries outside the European Union are also services. Under PSD2, many lenders and other financial experimenting with regulations similar to PSD2 and institutions (FIs) can use customers’ mobile numbers GDPR. South Africa is currently testing out open banking, to send them passcodes and other credentials. FIs will the concept that PSD2 introduced to Europe. Though it need to win their customers’ trust — and ensure them has yet to implement a similar regulation, the country’s that their data is not being misused — before they can willingness to change how it treats and interacts with utilize PSD2’s benefits, however. customer data speaks to PSD2’s global influence. © 2019 PYMNTS.com All Rights Reserved What’s Inside 4 As businesses and payment providers adhere to the ruling, they also need to be aware of accompanying regulations like EMV 3D Secure Authentication. The ruling takes effect in September, but it is currently With consumers and regulators both unclear whether EU retailers will be ready. Read more watching GDPR’s effects, is it likely that on this story and other global PSD2 developments in the the U.S. will pass a similar regulation? As Tracker’s News and Trends section (p. 10). such, how would that version look? MERCHANTS, CUSTOMERS AND FIs ARE CHANGING THEIR RELATIONSHIPS UNDER PSD2 “Following the [passing of the] GDPR, we expect this theme of ‘more transparency for the user on how their Merchants and companies are reevaluating how they data is being used and by whom’ to gather momentum, not just in the U.S. but [around] the globe. California is interact with each other as they become compliant leading the way in the U.S. with [the California Consumer with Europe’s PSD2 regulation. Data transparency Privacy Act], and Washington state is proposing a similar under the directive represents a unique opportunity law to GDPR, as well. Eventually, we expect a federal law to “level the playing field” between smaller companies will replace most of these state laws. and incumbent financial players, according to Didier The data entities covered will resemble the GDPR law, Baclin, chief innovation officer for person-to-person [including] most [personally identifiable information] (P2P) loan service Zopa. For this month’s Feature Story data with fundamental rights around transparency and choice, being informed and being ‘forgotten’ [as] the (p. 6), PYMNTS spoke with Baclin about increased data underpinnings... transparency, consumers’ changing role in open banking In the U.S., however, the thing to note is [that] industry- and how these relationships will continue to evolve specific regulations — such as HIPPA and [the] Gramm- in the future. Leach-Bliley Act laws — are already in place. These carve- outs for specific industries will happen and continue to have precedent. We also believe that, just like in the EU, DEEP DIVE: GDPR, PSD2 AND fraud prevention and similar exemptions will be carved POTENTIAL REGULATION IN THE U.S. out as well, given [that] the interests around the use of the data are aligned between the actual data subjects, EU-wide compliance with PSD2 and GDPR is growing, information controllers and processor entities. and the United States is taking notice. Support We suspect the U.S. laws will target businesses with for a similar regulation is gaining speed among commercial activity at a certain scale, only so that small government and industry experts in the country, which businesses do not have an onerous burden of complying is now considering implementing a similar regulation. with the law and stifling small business growth. Businesses that operate in Europe are already required Today, the engineering systems are not in place to fulfill to comply with GDPR and PSD2, but is there a need for these provisions and laws, so there will need to be a the law to be replicated in the U.S. — and, if so, would couple years lead-time so that business can update their it work? This Tracker’s Deep Dive (p. 14) takes a look at processes to handle the data and be in compliance once a new law is passed.” how such a U.S. regulation would look, and how it would affect consumers and businesses. SPENCER MCLAIN, vice president of Europe, the Middle East and Asia at Whitepages Pro © 2019 PYMNTS.com All Rights Reserved fast five 5 FACTS 75% Share of online EU retailers that are not aware of the payment security standard coming into 52% effect in September Portion of cyberattacks that targeted businesses subject to PSD2 from 2017 to 2018 80% Share of Dutch consumers that are currently 53% unaware of PSD2 Share of U.K. consumers who are willing to give banks their mobile numbers 87% Portion of schools that believe they are compliant with GDPR © 2019 PYMNTS.com All Rights Reserved 6 HOW PSD2 IS CHANGING Lending In The UK feature STORY © 2019 PYMNTS.com All Rights Reserved 7 feature STORY PSD2 launched in January 2018 and has been active “There’s always that question around data, and [if] people in the EU for a little over a year, meaning banks, are really going to share this type of data with [us],” merchants and customers are becoming used to it and Baclin said of the company’s products, which include a its accompanying GDPR data privacy law. They’re also new pre-loan income verification service developed in seeing their relationships with each other change. partnership with fellow U.K. company TrueLayer. “We saw that when there was a clear gain for customers — in Customers may be comfortable browsing the internet this case, having that frictionless experience — people or making financial transactions on their smartphones, are willing to go through and share their data with you.” but growing data safety concerns mean they don’t necessarily feel the same about sharing their phone SECURITY, VERIFICATION AND THE numbers or bank credentials. Additionally, third-party BENEFIT OF DATA providers and retail merchants are showing greater interest in how open banking- and PSD2-mandated data Bank data that was previously siloed became accessible transparency may give them a larger stake in customer to Zopa under PSD2, representing a beneficial relationships. opportunity for its customers. The company was one of the first to partake in the open banking ecosystem, and Signing up for a new financial product or service needs maintaining top-notch security was high priority as it to remain as convenient and secure as possible if third- worked toward a more seamless user experience, Baclin party providers want to gain the trust and loyalty of explained. A host of tools were used to make Zopa’s loan modern consumers, Didier Baclin, chief innovation officer application process simpler, and the overall experience of U.K.-based P2P loan provider Zopa, told PYMNTS in a ended up much different than it began. recent interview. “Traditionally, people would have had to upload a pay slip or some such information to prove that they indeed have © 2019 PYMNTS.com All Rights Reserved Feature Story 8 the salary that they declared, but using open banking … “The amount of data has increased, but it’s increased you can opt into the old way or the new way,” he said.