What changes with PSD3 and the PSR: spoofing fraud, refunds, and transparency
The EU's updated payment framework splits its rules between a directive and a directly applicable regulation. Here is what it means for merchants, gateways, and consumers dealing with social engineering fraud.
The evolution of the payment regulatory framework in the European Union is entering a new stage with the legislative package set to replace PSD2. Unlike the 2015 reform, European lawmakers have divided the framework into two distinct instruments: the Payment Services Directive (PSD3) and the Payment Services Regulation (PSR). This distinction is far from cosmetic. While the directive requires transposition into national laws to govern the licensing and supervision of payment institutions, the regulation is directly and uniformly applicable across all EEA member states, eliminating fragmentation in day-to-day operations and consumer protection rules.
This structural change addresses fraud typologies that PSD2 failed to curb, clarifies liabilities between payment providers and merchants, and enhances transparency across processing costs.
Combating spoofing and social engineering fraud
Under PSD2, Strong Customer Authentication (SCA) significantly lowered fraud resulting from lost or stolen credentials in card payments. In response, criminal tactics pivoted toward social engineering. In spoofing fraud, perpetrators pose as employees of the customer's bank or public authorities, convincing victims to willingly authorize a transfer or validate a transaction.
Because these transactions involve explicit consent and technically satisfy two-factor authentication, existing rules frequently treated the payer as grossly negligent, leaving them with the financial loss. The PSR alters this dynamic:
- Payment service provider liability: If a customer falls victim to an attack where the fraudster impersonates the provider's official communication identity (such as spoofed phone numbers or genuine-looking email senders), the issuing institution must refund the total amount, unless it can prove intentional fraud by the consumer.
- Mandatory Verification of Payee: The requirement to cross-check the destination IBAN against the recipient account holder's name is extended across regular credit transfers. If a provider fails to flag a name mismatch before the user confirms the payment, the provider bears the financial loss if the transfer proves fraudulent.
- Cooperation across telecom and tech sectors: Telecommunications operators and digital platforms face increased coordination duties to prevent identity manipulation across phone networks and web services.
To see how these security layers operate in real checkout flows, you can read our guide on strong customer authentication (SCA) and 3D Secure.
Improvements to strong customer authentication and e-commerce
The PSR does not intend to create unnecessary friction for legitimate shoppers. Instead, it refines exemptions to maintain robust conversion rates while managing fraud effectively. Key adjustments include:
- Targeted exemptions: Clearer criteria allow acquirers and issuers to leverage transaction risk analysis (TRA) to skip the second factor without exposing the transaction flow to disproportionate fraud exposure.
- Merchant-initiated transactions (MIT): The framework clarifies recurring and variable charges where the cardholder is not present, preventing erroneous rejections on subscription billing after the initial authenticated transaction.
- Accessibility and inclusion: Authentication can no longer rely exclusively on smartphone applications. Issuers are required to provide accessible fallback methods—such as one-time passwords delivered via secure alternative channels or physical authenticators—so consumers without biometric hardware or compatible devices are not locked out.
Cost transparency and pre-authorization limits
Another core pillar of the regulation focuses on opaque pricing practices affecting consumers and merchants handling cross-border flows or pre-authorizations.
For currency conversions, payment providers must display a clear breakdown of the markup applied over the European Central Bank's benchmark foreign exchange rate before the transaction is authorized. Furthermore, in transactions where the final amount is unknown at the point of the initial hold—such as automated fuel pumps, car rentals, or hotel stays—the regulation caps the allowable hold amount and its duration. Issuers must immediately unblock surplus funds as soon as the merchant communicates the definitive charge.
Practical takeaway and technical preparation
The implementation of PSD3 and the PSR establishes a regulatory environment where security obligations are no longer placed disproportionately on end users. For payment platforms and digital merchants, this shift requires robust infrastructure capable of parsing advanced risk indicators, validating payee identity on transfers, and managing recurring subscription mandates reliably.
Following ongoing updates in payment regulations and adjusting technical integrations helps online businesses minimize disputes, avoid unnecessary chargebacks, and maintain checkout experiences aligned with European standards.
Building subscriptions?
Check the pricing and try the dashboard with sample data before integrating anything.