{"id":"circulars/cssf-19-720","title":"Circular CSSF 19/720","type":"circular","date":"2019-06-14","kind":"circular","html":"<p>Circular CSSF 19/720 is a CSSF circular, published 14 June 2019. Subject: Adoption of the Guidelines of the European Banking Authority on the conditions to benefit from an exemption from the contingency mechanism under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA &#x26; CSC) (EBA/GL/2018/07).</p>\n<p>Legal basis: Loi du 20 juillet 2018, <a href=\"/lhoft?page=laws%2F2009-11-10-n1\" class=\"wikiLink\" data-target=\"laws/2009-11-10-n1\">Law of 10 November 2009 on payment services and electronic money</a>.</p>\n<p>Relevant for: AISPs, Credit institutions, E-money institutions, Payment institutions, Payment institutions/electronic money institutions/AISPs.</p>\n<p>Keywords: Information and communications technology (ICT).</p>\n<h2>Text</h2>\n<p>Luxembourg, 14 June 2019</p>\n<p>To all payment services providers</p>\n<p>CIRCULAR CSSF 19/720 Re: Adoption of the Guidelines of the European Banking Authority on the conditions to benefit from an exemption from the contingency mechanism under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA &#x26; CSC) (EBA/GL/2018/07)</p>\n<p>Ladies and Gentlemen, The purpose of this circular is to draw your attention to the Guidelines of the European Banking Authority (“EBA”) on the conditions to benefit from an exemption from the contingency mechanism 1 under Article 33(6) of Regulation (EU) 2018/389 (RTS on SCA and CSC 2) (the “RTS”) - EBA/GL/2018/07 (the “Guidelines”) with which the CSSF commits to comply in its capacity as competent authority. The circular further provides in a formal way the instructions to submit an exemption request to the CSSF in line with the Guidelines, which were already indicated in a Communiqué 3 published on our website on 28 February 2019. As a reminder, the RTS will enter into force on 14 September 2019 4 and the Communiqué was published to urge those account servicing payment service providers (“ASPSPs”) which would like to obtain a contingency mechanism exemption as from that date, to submit their exemption request to the CSSF by no later than 1 May 2019. 1. The Guidelines As a reminder, the transposition of Directive (EU) 2015/2366 5 (“PSD2”) in Luxembourg through the Luxembourg law of 20 July 2018, amending the law of 10 November 2009 on payment services 6 (the “Law”), enshrined the right of account information service providers (“AISPs”), payment initiation service providers (“PISPs”) and card-based payment instrument 1</p>\n<p>Also called “fall back mechanism” Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication 3 <a href=\"https://www.cssf.lu/en/2019/02/obligations-regarding-strong-customer-authentication-and-common-andsecure-open-standards-of-communication-under-commission-delegated-regulation-eu-2018-389/\" target=\"_blank\" rel=\"noreferrer\">https://www.cssf.lu/en/2019/02/obligations-regarding-strong-customer-authentication-and-common-andsecure-open-standards-of-communication-under-commission-delegated-regulation-eu-2018-389/</a> 4 With the exception of paragraphs 3 and 5 of article 30, which apply from 14 March 2019 5 Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market, amending Directives 2002/65/EC, 2009/110/EC and 2013/36/EU and Regulation (EU) No 1093/2010, and repealing Directive 2007/64/EC 6 Law of 10 November 2009 on payment services, on the activity of electronic money institution and settlement finality in payment and securities settlement systems 2</p>\n<p>issuers (“CBPIIs” 7) (together also called “TPPs” 8) to access payment service user (“PSU”) payment account data held with account servicing payment service providers (“ASPSPs”), based on the PSU’s explicit consent. The RTS provide details on the new security requirements under PSD2 and regulate the access of TPPs to the PSU’s payment account data held with ASPSPs. These latter must offer at least one access interface to the former but are free to decide whether to establish such an interface by means of a so-called dedicated interface or by means of an adapted PSU interface. In accordance with Article 33(4) of the RTS, all ASPSPs that have opted to offer access via a dedicated interface are also required to implement a contingency mechanism, unless they receive an exemption from the CSSF in accordance with the four conditions set out under Article 33(6) of the RTS. The Guidelines further specify these four conditions to exempt an ASPSP from the obligation to set up the contingency mechanism. They also provide guidance on how competent authorities should consult the EBA for the purposes of the exemption in accordance with Article 33(6) of the RTS. 2.</p>\n<p>The text above is the opening of the document; the PDF carries the whole.</p>\n<p><a href=\"https://www.cssf.lu/en/Document/circular-cssf-19-720/\" target=\"_blank\" rel=\"noreferrer\">Document page</a>, <a href=\"https://www.cssf.lu/wp-content/uploads/cssf19_720eng.pdf\" target=\"_blank\" rel=\"noreferrer\">PDF</a>. Source: Commission de Surveillance du Secteur Financier (CSSF), reproduced with the CSSF's consent. The French text prevails.</p>"}