Lex Browse everything How it works For developers

Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366

as it stood on 2023-07-25, permalink: /eu-eurlex/32018r0389/2023-07-25

2017-11-272023-09-12

3 versions · click any mark to read the law as it stood that day · the one you are reading

Point-in-time view as at 2023-07-25. This version has been superseded, it applied 2023-07-25 → 2023-09-11. Jump to the version in force today or see exactly what changed next.
Text included, per-article reading view. Deterministic extraction of the verbatim retrieved document; each article carries its own hash and anchor. © European Union, 1998-2026. Reuse permitted with attribution under Commission Decision 2011/833/EU. Consolidated texts have no legal effect; only acts published in the Official Journal are authentic.
Outline, 39 provisions

Article 1 Article 2 Article 3 Article 4 Article 5 Article 6 Article 7 Article 8 Article 9 Article 10 Article 10a Article 11 Article 12 Article 13 Article 14 Article 15 Article 16 Article 17 Article 18 Article 19 Article 20 Article 21 Article 22 Article 23 Article 24 Article 25 Article 26 Article 27 Article 28 Article 29 Article 30 Article 31 Article 32 Article 33 Article 34 Article 35 Article 36 Article 37 Article 38

CHAPTER I — GENERAL PROVISIONS

Article 1, Subject matter #art_1
Article 2, General authentication requirements #art_2
Article 3, Review of the security measures #art_3

CHAPTER II — SECURITY MEASURES FOR THE APPLICATION OF STRONG CUSTOMER AUTHENTICATION

Article 4, Authentication code #art_4
Article 5, Dynamic linking #art_5
Article 6, Requirements of the elements categorised as knowledge #art_6
Article 7, Requirements of the elements categorised as possession #art_7
Article 8, Requirements of devices and software linked to elements categorised as inherence #art_8
Article 9, Independence of the elements #art_9

CHAPTER III — EXEMPTIONS FROM STRONG CUSTOMER AUTHENTICATION

Article 10, Access to the payment account information directly with the account servicing payment service provider #art_10
Article 10a, Access to the payment account information through an account information service provider #art_10a
Article 11, Contactless payments at point of sale #art_11
Article 12, Unattended terminals for transport fares and parking fees #art_12
Article 13, Trusted beneficiaries #art_13
Article 14, Recurring transactions #art_14
Article 15, Credit transfers between accounts held by the same natural or legal person #art_15
Article 16, Low-value transactions #art_16
Article 17, Secure corporate payment processes and protocols #art_17
Article 18, Transaction risk analysis #art_18
Article 19, Calculation of fraud rates #art_19
Article 20, Cessation of exemptions based on transaction risk analysis #art_20
Article 21, Monitoring #art_21

CHAPTER IV — CONFIDENTIALITY AND INTEGRITY OF THE PAYMENT SERVICE USERS' PERSONALISED SECURITY CREDENTIALS

Article 22, General requirements #art_22
Article 23, Creation and transmission of credentials #art_23
Article 24, Association with the payment service user #art_24
Article 25, Delivery of credentials, authentication devices and software #art_25
Article 26, Renewal of personalised security credentials #art_26
Article 27, Destruction, deactivation and revocation #art_27

CHAPTER V — COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION / Section 1 — General requirements for communication

Article 28, Requirements for identification #art_28
Article 29, Traceability #art_29

CHAPTER V — COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION / Section 2 — Specific requirements for the common and secure open standards of communication

Article 30, General obligations for access interfaces #art_30
Article 31, Access interface options #art_31
Article 32, Obligations for a dedicated interface #art_32
Article 33, Contingency measures for a dedicated interface #art_33
Article 34, Certificates #art_34
Article 35, Security of communication session #art_35
Article 36, Data exchanges #art_36

CHAPTER VI — FINAL PROVISIONS

Article 37, Review #art_37
Article 38, Entry into force #art_38
Provenance and validity dates, identifier, hash
as of2023-07-25 → this version applied
valid2023-07-25 → 2023-09-11 publisher-asserted
typeREG_DEL Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)
languageen
published2023-07-25
lex_ideu-eurlex:32018r0389:2023-07-25
record sha25678a33d14fb3835d2102eba7cbc8ce3ec010ed2c46ca56b0e7083452ed8268c4e
New here? What am I looking at?

This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.

It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.

“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.

← previous version (2017-11-27)   what changed?   timeline   next version (2023-07-25) →

tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)