{"id":"circulars/cssf-18-704","title":"Circular CSSF 18/704","type":"circular","date":"2018-12-17","kind":"circular","html":"<p>Circular CSSF 18/704 is a CSSF circular, published 17 December 2018 and updated 1 January 2022. Subject: European Banking Authority (EBA) on major incident reporting under Directive (EU) 2015/2366 (PSD2), (EBA/GL/2017/10). It was repealed by <a href=\"/lhoft?page=circulars%2Fcssf-21-787\" class=\"wikiLink\" data-target=\"circulars/cssf-21-787\">Circular CSSF 21/787</a>.</p>\n<p>Legal basis: <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: Credit institutions, Payment institutions/electronic money institutions/AISPs, Specialised PFS, Support PFS.</p>\n<p>Keywords: Information security, Payment Service Provider (PSP), Payment services.</p>\n<h2>Text</h2>\n<p>In case of discrepancies between the French and the English text, the French text shall prevail.</p>\n<p>Luxembourg, 17 December 2018</p>\n<p>To all payment services providers</p>\n<p>Re: European Banking Authority Guidelines (“EBA”) on major incident reporting under Directive (EU) 2015/2366 (PSD2), (EBA/GL/2017/10)</p>\n<p>Ladies and Gentlemen, The purpose of this circular is: - to draw your attention to the Guidelines of the European Banking Authority (EBA) on the notification of major operational or security incidents (EBA/GL/2017/10 - “the Guidelines”) with which the CSSF commits to comply ; and - to provide details with regards to the reporting obligations of major operational or security incidents as provided by Article 105-2, paragraph (1) of the amended law of 10 November 2009 which provides that “payment service providers shall report major operational or security incidents to the CSSF without undue delay”; particularly concerning the notification process to the CSSF. 1. The Guidelines The Guidelines specify, in particular, the criteria for the classification of major operational or security incidents by payment services providers (hereafter “PSP”) as well as the format and procedures the latter should follow to communicate such incidents to the competent authority in the home Member State. The Guidelines apply to all incidents included under the definition of “major operational or security incident” which covers both external and internal events that could be either malicious or accidental. Circular CSSF 18/704</p>\n<p>The Guidelines apply also where the major operational or security incident originates outside the European union and affects the payment services provided by a PSP located in the European union either directly or indirectly. It is necessary to refer to the full text of the Guidelines concerning the definitions which are applicable, the classification of major operational or security incidents or any point related to the notification process. Annex 1 of the Guidelines contains the standard reporting templates to be used by the PSP.</p>\n<ol start=\"2\">\n<li>Technical instructions for the notification process to the CSSF The detailed technical instructions for sending the data related to the major operational or security incidents to the CSSF are laid down in Annex 1 of the present circular. 3. The deadlines for the notification to the CSSF PSP should submit an initial report to the CSSF within 4 hours from the moment the major operational or security incident was first detected. PSP should submit intermediate reports every time they consider that there is a relevant status update and, as a minimum, by the date for the next update indicated in the previous report (either the initial report or the previous intermediate report). PSP should deliver the final report to the CSSF within a maximum of 2 weeks after business is deemed back to normal. Reference should be made to the full text of the Guidelines concerning the timelines of the notification process. 4. Delegation of reporting obligations to a third party The delegation of reporting obligations of major operational or security incidents to a third party is not accepted. 5.</li>\n</ol>\n<p>Date of application</p>\n<p>This circular, by which the CSSF adopts the Guidelines, applies with immediate effect.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-18-704/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf18_704eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}