Learning Objectives:

  • Understand the key regulatory frameworks governing digital banking.

  • Explain the provisions of PSD2, PSD3, and their implications for banks and fintechs.

  • Analyse the application of GDPR to digital banking and data protection.

  • Understand the impact of MiFID II and the EU AI Act on digital financial services.

1.1 Introduction to Digital Banking Regulation

The rapid digitalisation of financial services has necessitated a comprehensive regulatory framework to ensure consumer protection, financial stability, and market integrity. The LSBA’s Certified Professional in EU Digital Banking Laws programme identifies several key regulatory areas: “Introduction to EU Digital Banking Laws and Regulations,” “GDPR and Data Protection in Digital Banking,” “PSD2 and Open Banking Framework,” “Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) Compliance,” and “Cybersecurity and Risk Management in Digital Banking” . The University of Sussex module similarly covers “key aspects of the relevant regulations of the regulatory frameworks (PSD2, GDPR, Open Banking, MiFID, etc.)” .

The Manchester University module on Open Finance and Payment Technologies notes that students will “understand the fundamental rationales for regulation and how these apply to different financial technologies and be able to explain some of the different financial regulations (e.g. PSR, PSD2, etc.) and how they relate to data and information technology in payments and banking” . The HKIB syllabus covers “Open Banking and Open API” and “Worldwide development – UK, EU, Singapore, Australia, Japan and China” as core topics .

Key Regulatory Objectives:

  • Consumer Protection: The LSBA programme covers “Consumer Protection and Fair Practices in Digital Financial Services” as a core topic .

  • Financial Stability: Ensuring the stability of the financial system.

  • Market Integrity: The LSBA programme covers “Cross-Border Payment Regulations and SEPA Framework” and “E-Commerce and Digital Payment Systems in the EU” .

  • Data Protection: The LSBA programme covers “GDPR and Data Protection in Digital Banking” .

  • Innovation: The University of Sussex module covers “emerging technologies (Cloud Computing, Artificial Intelligence, Blockchain, Real-Time Payments etc.)” .

1.2 Payment Services Directives (PSD2 and PSD3)

PSD2 is the cornerstone of European payment services regulation. The LSBA programme covers “PSD2 and Open Banking Framework” as a core topic . The Manchester University module notes that students will “understand the fundamental rationales for regulation and how these apply to different financial technologies and be able to explain some of the different financial regulations (e.g. PSR, PSD2, etc.)” .

Key Provisions of PSD2:

  • Strong Customer Authentication (SCA): The ADGM Academy programme covers “security and risk management” as part of its Open Banking curriculum .

  • Open Banking Mandates: The HKIB syllabus covers “Open Banking and Open API” .

  • Third-Party Provider Access: The ADGM Academy programme covers “the roles of third-party providers within the Open Banking ecosystem” .

  • Consumer Protection: Enhanced consumer protection for electronic payments.

PSD3 Developments: The LSBA programme identifies “emerging trends and future of EU digital banking laws” as a core topic, reflecting the evolving nature of payment services regulation .

1.3 General Data Protection Regulation (GDPR)

The LSBA programme covers “GDPR and Data Protection in Digital Banking” as a core topic . The University of Sussex module covers “GDPR” as part of its regulatory frameworks curriculum . The Manchester University module covers data protection as part of its Open Finance curriculum .

Key GDPR Provisions for Digital Banking:

  • Lawful Basis for Processing: Ensuring a legal basis for processing personal data.

  • Data Subject Rights: The right to access, rectify, and delete personal data.

  • Data Protection by Design: The LSBA programme covers “Data Protection and Privacy” as core topics .

  • Breach Notification: Mandatory notification of data breaches.

  • Data Protection Impact Assessments (DPIAs): Required for high-risk processing activities.

1.4 MiFID II and the EU AI Act

The University of Sussex module covers “MiFID” as part of its regulatory frameworks curriculum . The LSBA programme covers “Emerging Trends and Future of EU Digital Banking Laws,” which includes the EU AI Act .

MiFID II Key Provisions:

  • Investor Protection: Transparency and suitability requirements.

  • Product Governance: Requirements for product design and distribution.

  • Research Unbundling: Separating research from execution costs.

EU AI Act Key Provisions:

  • Risk-Based Classification: The LSBA programme covers the EU AI Act as part of its emerging trends curriculum .

  • High-Risk AI Systems: Requirements for high-risk AI applications in finance.

  • Transparency and Explainability: Requirements for AI decision-making.

  • Prohibited AI Practices: Bans on certain AI practices that pose unacceptable risks.