| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | AA | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | The current version of the Law of Ukraine "On Payment Services | Amendments and updates | Comments | ||||||||||||||||||||||||
2 | English | Ukrainian | Ukrainian | English | |||||||||||||||||||||||
3 | LAW OF UKRAINE | ЗАКОН УКРАЇНИ | |||||||||||||||||||||||||
4 | On Payment Services | Про платіжні послуги | |||||||||||||||||||||||||
5 | Article 24. Activities of a Technological Operator Technological payment service operator (hereinafter referred to as the technological operator) - a legal entity that provides processing, clearing services, or performs operational, informational and other technological functions related to the provision of payment services, without attracting funds for payment transactions to its account; | Стаття 24. Діяльність технологічного оператора | Стаття 24. Діяльність технологічного оператора | ||||||||||||||||||||||||
6 | |||||||||||||||||||||||||||
7 | 1. A legal entity has the right to carry out activities as a technological operator in Ukraine only after its inclusion in the Register in the manner determined by the regulatory acts of the National Bank of Ukraine, unless otherwise provided by this Law. | 1. Юридична особа має право здійснювати в Україні діяльність з надання послуг технологічного оператора лише після включення її до Реєстру в порядку, визначеному нормативно-правовими актами Національного банку України, якщо інше не передбачено цим Законом. | |||||||||||||||||||||||||
8 | |||||||||||||||||||||||||||
9 | Banks have the right to carry out activities as a technological operator in Ukraine on the basis of a banking license without inclusion in the Register. | Банки мають право здійснювати в Україні діяльність з надання послуг технологічного оператора на підставі банківської ліцензії без включення до Реєстру. | |||||||||||||||||||||||||
10 | |||||||||||||||||||||||||||
11 | The functions of a technological operator do not include the provision of non-financial payment services. | До функцій технологічного оператора не належить надання нефінансових платіжних послуг. | Технологічний оператор має право здійснювати в Україні діяльність з надання нефінансових платіжних послуг після включення його до Реєстру як надавача нефінансових платіжних послуг. | A technological operator has the right to carry out activities in Ukraine for the provision of non-financial payment services after its inclusion in the Register as a provider of non-financial payment services. | The proposed amendments to Article 24 and 53 of the Ukrainian Payment Services Law aim to address two key issues: Clarify the scope of a technological operator's activities: The current law provides a somewhat contradictory description of a technological operator's functions, particularly in relation to their ability to act as Payment Initiation Service Providers (PISPs) and Account Information Service Providers (AISPs). The amendments seek to clarify whether technological operators are prohibited from acting as PISPs and AISPs or whether these functions are simply not explicitly included within their scope of activities. Enable technological operators to act as hubs: Market participants in Ukraine are interested in utilizing hub services while also providing PISP and AISP services. Technological operators are particularly well-suited to perform hub functions, and experience in other countries (as well as the absence of such prohibitions in PSD2) suggests that combining hub and SAS (PISPs and AISPs) services within a single legal entity should be permitted. The proposed amendment to Article 53, Section 10, aims to address this issue. Benefits of the Amendments The proposed amendments are expected to bring several benefits to the Ukrainian payment services industry: Enhanced clarity and consistency: By clarifying the scope of a technological operator's activities, the amendments will provide greater certainty for market participants and reduce the risk of legal disputes. Increased innovation and competition: Enabling technological operators to act as hubs will foster innovation and competition in the market, leading to a wider range of services and potentially lower prices for consumers. Alignment with international standards: The amendments will bring Ukrainian payment services legislation closer to international standards, such as PSD2, further facilitating cross-border payments and promoting the integration of the Ukrainian market into the global financial ecosystem. | ||||||||||||||||||||||
12 | |||||||||||||||||||||||||||
13 | Article 53. General Provisions | Стаття 53. Загальні положення | |||||||||||||||||||||||||
14 | |||||||||||||||||||||||||||
15 | 1. Account Servicing Payment Service Providers shall, in accordance with the procedure established by the National Bank of Ukraine, ensure the possibility of continuous real-time access to accounts (except for correspondent bank accounts and the payment service provider's settlement account) of their users to banks and other payment service providers that have been granted the right to provide non-financial payment services (hereinafter referred to as third-party payment service providers in this Article). | 1. Надавачі платіжних послуг з обслуговування рахунку зобов’язані у порядку, встановленому Національним банком України, забезпечувати можливість постійного доступу в режимі реального часу до рахунків (крім кореспондентських рахунків банку та розрахункового рахунку надавача платіжних послуг) своїх користувачів банкам та іншим надавачам платіжних послуг, що отримали право на надання нефінансових платіжних послуг (далі у цій статті - сторонні надавачі платіжних послуг). | |||||||||||||||||||||||||
16 | |||||||||||||||||||||||||||
17 | Access to the account is carried out through the interaction of the information systems of the account servicing payment service provider and the third-party payment service provider. | Доступ до рахунку здійснюється шляхом взаємодії інформаційних систем надавача платіжних послуг з обслуговування рахунку та стороннього надавача платіжних послуг. | |||||||||||||||||||||||||
18 | |||||||||||||||||||||||||||
19 | {The first part of Article 53 was supplemented by the second paragraph in accordance with the Law No. 2888-IX of 12.01.2023} | {Частину першу статті 53 доповнено абзацом другим згідно із Законом № 2888-IX від 12.01.2023} | |||||||||||||||||||||||||
20 | |||||||||||||||||||||||||||
21 | 2. In order to ensure the right to access the user's account, as provided for in the first part of this Article, the account servicing payment service provider shall obtain the user's consent before granting such access. The user's consent is granted in respect of: | 2. Для забезпечення права на доступ до рахунку користувача, передбачений частиною першою цієї статті, надавач платіжних послуг з обслуговування рахунку зобов’язаний перед наданням такого доступу отримати згоду користувача. Згода користувача надається щодо: | |||||||||||||||||||||||||
22 | |||||||||||||||||||||||||||
23 | the specific third-party payment service provider to whom he/she grants consent for access; | 1) конкретного стороннього надавача платіжних послуг, якому він надає згоду на доступ; | |||||||||||||||||||||||||
24 | |||||||||||||||||||||||||||
25 | the specific account to which he/she grants consent for access; | 2) конкретного рахунку, згоду на доступ до якого він надає; | |||||||||||||||||||||||||
26 | |||||||||||||||||||||||||||
27 | the specific non-financial payment service to which he/she grants his/her consent, and the specific amount of information about the account and the user of such account. | 3) конкретної нефінансової платіжної послуги, на яку він надає свою згоду, та конкретного обсягу інформації щодо рахунку і користувача такого рахунку. | |||||||||||||||||||||||||
28 | |||||||||||||||||||||||||||
29 | The user's consent may be obtained by the account servicing payment service provider from the user through the respective third-party payment service provider with which the user has contractual relations. | Згода користувача може бути отримана надавачем платіжних послуг з обслуговування рахунку від користувача через відповідного стороннього надавача платіжних послуг, який має договірні відносини з таким користувачем. | |||||||||||||||||||||||||
30 | The user's consent is granted with the use of strong user authentication, which is carried out by the account servicing payment service provider. The user's consent is valid for the periods established by the regulatory acts of the National Bank of Ukraine regarding strong authentication, except in cases of its revocation by the user earlier. | Надання згоди користувача здійснюється із застосуванням посиленої автентифікації користувача, яку проводить надавач платіжних послуг з обслуговування рахунку. Згода користувача діє протягом строків, встановлених нормативно-правовими актами Національного банку України щодо посиленої автентифікації, крім випадків відкликання її користувачем раніше. | |||||||||||||||||||||||||
31 | |||||||||||||||||||||||||||
32 | Before obtaining or simultaneously with obtaining the user's consent, the account servicing payment service provider shall obtain the user's permission to disclose information that constitutes banking secrecy, commercial secrecy, and the secrecy of the payment service provider. Such user's permission may be obtained by the account servicing payment service provider from the user through the respective third-party payment service provider with which the user has contractual relations. | Надавач платіжних послуг з обслуговування рахунку перед отриманням або одночасно з отриманням згоди користувача зобов’язаний отримати дозвіл користувача на розкриття інформації, що містить банківську таємницю, комерційну таємницю, таємницю надавача платіжних послуг. Такий дозвіл користувача може бути отриманий надавачем платіжних послуг з обслуговування рахунку від користувача через відповідного стороннього надавача платіжних послуг, який має договірні відносини з таким користувачем. | Згода користувача має включати дозвіл на розкриття інформації, що містить банківську таємницю, комерційну таємницю, таємницю надавача платіжних послуг в частині надання користувачу послуг отримання відомостей з рахунків, ініціювання платіжної операції та бути підтвердженою фактом виконання посиленої автентифікації користувача. | User consent must include permission to disclose information containing banking secrecy, commercial secrecy, and payment service provider secrecy in the part of providing the user with services for obtaining account information, initiating a payment transaction, and be confirmed by the fact of SCA. | The current version of the Law requires that banking secrecy, commercial secrecy, and payment service provider secrecy be disclosed before obtaining user consent. This means that users must first be informed about the types of confidential information that will be disclosed before they can agree to its disclosure. Additionally, the current Law requires the use of QES to confirm user consent for disclosing confidential information. The proposed amendments aim to address these inefficiencies by combining the consent and disclosure processes and using SCA as the primary method of consent confirmation. This approach is expected to make the consent process more streamlined, user-friendly, and less administratively burdensome. Overall, the proposed amendments represent a positive step towards improving the user experience and promoting the adoption of digital financial services in Ukraine. | ||||||||||||||||||||||
33 | |||||||||||||||||||||||||||
34 | {Частина друга статті 53 в редакції Закону № 2888-IX від 12.01.2023} | ||||||||||||||||||||||||||
35 | {Part two of Article 53 as amended by the Law No. 2888-IX of 12.01.2023} | ||||||||||||||||||||||||||
36 | 3. The procedure for obtaining the user's permission to disclose information that constitutes banking secrecy, commercial secrecy, and the secrecy of the payment service provider, as well as the procedure for actions in case of granting and withdrawing consent by the user, are determined by the agreement between the user and the account servicing payment service provider, taking into account the requirements established by the National Bank of Ukraine. The procedure for providing the third-party payment service provider with the user's consent and withdrawing such consent is determined by the agreement between the user and the respective third-party payment service provider, taking into account the requirements established by the National Bank of Ukraine. | 3. Порядок надання дозволу користувача на розкриття інформації, що містить банківську таємницю, комерційну таємницю, таємницю надавача платіжних послуг, а також порядок дій у разі надання та відкликання згоди користувачем визначаються договором між користувачем та надавачем платіжних послуг з обслуговування рахунку з урахуванням вимог, встановлених Національним банком України. Порядок надання сторонньому надавачу платіжних послуг згоди користувача та відкликання такої згоди визначається договором між користувачем та відповідним стороннім надавачем платіжних послуг з урахуванням вимог, встановлених Національним банком України. | 3. Порядок надання сторонньому надавачу платіжних послуг згоди користувача та відкликання такої згоди визначається договором між користувачем та відповідним стороннім надавачем платіжних послуг з урахуванням вимог, встановлених Національним банком України. З відкликанням згоди користувача одночасно відкликається дозвол на розкриття інформації, що містить банківську таємницю, комерційну таємницю, таємницю надавача платіжних послуг, а в разі відкликання дозволу на розкриття інформації, що містить банківську таємницю, комерційну таємницю, таємницю надавача платіжних послуг - згода користувача. Відкликання згоди користувача та дозволу на розкриття інформації, що містить банківську таємницю, комерційну таємницю, таємницю надавача платіжних послуг користувача через надавача платіжних послуг з обслуговування рахунку може здійснюватися із застосуванням посиленої автентифікації користувача. | 3. The procedure for providing consent to a third-party payment service provider and withdrawing such consent is determined by the agreement between the user and the respective third-party payment service provider, taking into account the requirements established by the National Bank of Ukraine. Upon the withdrawal of the user's consent, the permission for the disclosure of information containing banking secrecy, commercial secrecy, and payment service provider secrecy is simultaneously withdrawn, and in the event of the withdrawal of permission for the disclosure of information containing banking secrecy, commercial secrecy, and payment service provider secrecy, the user's consent is withdrawn. The withdrawal of the user's consent and permission for the disclosure of information containing banking secrecy, commercial secrecy, and payment service provider secrecy by the user through the account servicing payment service provider can be carried out with the use of enhanced user authentication. | Aim of the Amendments: These amendments aim to streamline and clarify the process of user consent for sharing financial data with third-party payment service providers (TPPs). Changes Introduced: Previously, the user's consent for data sharing and permission for disclosing confidential information (banking secrecy, commercial secrecy, and payment service provider secrecy) were treated as separate entities. The amendments now link these concepts. Granting consent to a TPP automatically grants permission to disclose the necessary information, and vice versa. Withdrawing consent also withdraws permission. This creates a clear and unified approach to user authorization for data sharing. Impact of the Amendments: Prevents Conflicting Situations: By linking consent and permission, the amendments eliminate the possibility of users having conflicting authorizations. This reduces the risk of users filing claims against account servicing payment service providers (ASPSPs) due to inconsistencies. Enhanced User Control: Users have a clear understanding of what they are consenting to when they allow TPP access. Reduced Regulatory Risk: ASPSPs are less likely to face regulatory issues due to unclear authorization processes. Additional Notes: The amendments highlight the National Bank of Ukraine's (NBU) role in establishing specific requirements for user consent procedures. The text mentions the possibility of using SCA for withdrawing consent and permission through the ASPSP. This suggests a focus on strong authentication methods to ensure user security when revoking access. Overall, these amendments simplify the process of user consent for data sharing with TPPs. They promote user clarity and control, while also mitigating potential risks for both users and ASPSPs. | ||||||||||||||||||||||
37 | |||||||||||||||||||||||||||
38 | The user's consent may be withdrawn by the user through a third-party payment service provider or through the account servicing payment service provider. | Згода користувача може бути відкликана користувачем через стороннього надавача платіжних послуг або через надавача платіжних послуг з обслуговування рахунку. | |||||||||||||||||||||||||
39 | |||||||||||||||||||||||||||
40 | The account servicing payment service provider shall ensure that the facts of granting/withdrawing the user's consent are recorded in its own information system. | Надавач платіжних послуг з обслуговування рахунку зобов’язаний забезпечити фіксування у власній інформаційній системі фактів надання/відкликання згоди користувача. | |||||||||||||||||||||||||
41 | |||||||||||||||||||||||||||
42 | An additional request for consent, confirmed by strong user authentication, is carried out by the account servicing payment service provider exclusively in case of suspicion of unauthorized access. | Додатковий запит згоди, підтвердженої посиленою автентифікацією користувача, проводиться надавачем платіжних послуг з обслуговування рахунку виключно у разі наявності підозри вчинення несанкціонованого доступу. | |||||||||||||||||||||||||
43 | {Part three of Article 53 as amended by the Law No. 2888-IX of 12.01.2023} | {Частина третя статті 53 в редакції Закону № 2888-IX від 12.01.2023} | |||||||||||||||||||||||||
44 | Account Servicing Payment Service Provider Information Panel The account servicing payment service provider must provide the payment service user with an information panel integrated into its user interface (mobile application, other forms of remote communication) for monitoring and managing the consents granted by the payment service user for the purpose of obtaining the account information service and initiating a payment transaction. The information panel must: Provide the payment service user with an overview of each consent granted, including: a) The legal name (trademarks, if any) of the service provider to which access has been granted; b) The user's account to which access has been granted; c) The purpose of the consent; d) The validity period of the consent; e) The categories of data that are transferred. f) The date and time the payer granted consent to perform a payment transaction, which is confirmed by the fact of the user's strong authentication; Allow the user to revoke or create a new consent for a specific account information provider, initiate a payment transaction; Store and provide the user with access to information about consents that have been revoked or expired for two years. The account servicing payment service provider must ensure that the information panel is easy to find in its user interface and that the information displayed on the information panel is accurate, reliable and easily understandable for the user. | Надавач платіжних послуг з обслуговування рахунку повинен надати користувачеві платіжних послуг інформаційну панель, інтегровану в його інтерфейс користувача (мобільний застосунок, інші форми дистанційної комунікації) для моніторингу та керування згодами, наданими користувачем платіжних послуг для цілей отримання послуги з отримання відомостей з рахунків, ініціювання платіжної операції. Інформаційна панель повинна: 1) надавати користувачеві платіжної послуги огляд кожної наданої згоди, включаючи: а) юридичну назву (торговельні марки за наявності) надавача послуги, якому надано доступ; б) обліковий запис користувача, до якого було надано доступ; в) мета згоди; г) термін дії згоди; д) категорії даних, які передаються. е) дату та час надання платником згоди на виконання платіжної операції, що підтверджено фактом виконання посиленої автентифікації користувача; 2) дозволяти користувачеві відмінити або створити нову згоду для певного надавача послуги з отримання відомостей з рахунків, ініціювання платіжної операції; 3) зберігати та надавати доступ користувачу до інформації про згоди, які були відкликані або термін дії яких закінчився, протягом двох років. Надавач платіжних послуг з обслуговування рахунку, повинен забезпечити, що інформаційну панель легко знайти в його інтерфейсі користувача, а інформація, яка відображається на інформаційній панелі, була точною, достовірною та легко зрозумілою для користувача. | To enhance customer experience (CX) and user experience (UX) in consent management, requirements are being introduced for ASPSPs. It is also clarified that for payments, consent is confirmed by the fact of conducting SCA, the date and time of which is recorded in the consent management interface. | ||||||||||||||||||||||||
45 | |||||||||||||||||||||||||||
46 | 4. Before granting a third-party payment service provider access to the user's account, the account servicing payment service provider shall verify the authorization of the activity of such third-party payment service provider for the respective payment service in accordance with the procedure established by the National Bank of Ukraine (hereinafter - verification of information in the Register). | 4. Перед наданням сторонньому надавачу платіжних послуг доступу до рахунку користувача надавач платіжних послуг з обслуговування рахунку зобов’язаний перевірити авторизацію діяльності такого стороннього надавача платіжних послуг щодо відповідної платіжної послуги у порядку, встановленому Національним банком України (далі - перевірка відомостей у Реєстрі). | 4. Перед наданням сторонньому надавачу платіжних послуг доступу до рахунку користувача надавач платіжних послуг з обслуговування рахунку зобов’язаний перевірити авторизацію діяльності такого стороннього надавача платіжних послуг щодо відповідної платіжної послуги у порядку, встановленому Національним банком України. | ||||||||||||||||||||||||
47 | |||||||||||||||||||||||||||
48 | The account servicing payment service provider is prohibited from providing access to the user's account to third-party payment service providers that have not passed the verification of information in the Register. | Надавачу платіжних послуг з обслуговування рахунку заборонено надавати доступ до рахунку користувача стороннім надавачам платіжних послуг, які не пройшли перевірку відомостей у Реєстрі. | Надавачу платіжних послуг з обслуговування рахунку заборонено надавати доступ до рахунку користувача стороннім надавачам платіжних послуг, які не пройшли перевірку авторизації діяльності. | ||||||||||||||||||||||||
49 | |||||||||||||||||||||||||||
50 | 5. The account servicing payment service provider is prohibited from providing access to users' accounts to third-party payment service providers in case of non-fulfillment/non-compliance with the conditions for access provided for by this Law. | 5. Надавачу платіжних послуг з обслуговування рахунку заборонено надавати доступ до рахунків користувачів стороннім надавачам платіжних послуг у разі невиконання/невідповідності умов надання доступу, визначених цим Законом. | |||||||||||||||||||||||||
51 | |||||||||||||||||||||||||||
52 | The account servicing payment service provider shall be liable for damages caused to the user in case of non-compliance with the conditions for access to the account, in accordance with the legislation. | Надавач платіжних послуг з обслуговування рахунку несе відповідальність за шкоду, заподіяну користувачу в разі недотримання ним умов надання доступу до рахунку, відповідно до законодавства. | |||||||||||||||||||||||||
53 | |||||||||||||||||||||||||||
54 | 6. The granting by the account servicing payment service provider of access to users' accounts to third-party payment service providers does not require the establishment of contractual relations between such payment service providers. | 6. Надання надавачем платіжних послуг з обслуговування рахунку доступу до рахунків користувачів стороннім надавачам платіжних послуг не потребує встановлення договірних відносин між такими надавачами платіжних послуг. | 6. Надання надавачем платіжних послуг з обслуговування рахунку доступу до рахунків користувачів стороннім надавачам платіжних послуг не потребує встановлення договірних відносин між такими надавачами платіжних послуг, якщо відповідна послуга та умови її надання (обсяг, частота тощо) є обов'язковими для всіх надавачів платіжних послуг з обслуговування рахунку, та має надаватися на безоплатній основі. Доступ сторонніх надавачів платіжних до послуг, які надаються на платній основі не є обовʼязковим, і не може бути передумовою надання послуг, що надаються надавачем платіжних послуг з обслуговування рахунку на безоплатній основі. | 6. Access to user accounts by account servicing payment service providers (PSPs) to third-party PSPs does not require the establishment of contractual relationships between such PSPs, if the relevant service and its terms of provision (volume, frequency, etc.) are mandatory for all ASPSPs and must be provided free of charge. Access of third-party PSPs to services provided on a paid basis is not mandatory and cannot be a prerequisite for the provision of services provided by the ASPSP free of charge. | Purpose of the Amendments The amendments clarify the rules around open banking services and the relationships between account servicing payment service providers (ASPSPs) and third-party payment service providers (TPPs). The key points are as follows: Open banking services can be either free or paid. ASPSPs are free to offer open banking services on a paid or unpaid basis. Regulated open banking services are mandatory and must be provided free of charge. If an open banking service is regulated by the National Bank of Ukraine (NBU), then ASPSPs are required to offer it free of charge to TPPs. This means that TPPs do not need to have a contract with an ASPSP in order to access these services. ASPSPs cannot require TPPs to sign a contract for paid services if the TPP only wants to use free regulated services. ASPSPs cannot force TPPs to sign a contract for paid services if the TPP only wants to use the free regulated open banking services. Explanation The original text simply stated that ASPSPs do not need to have a contract with TPPs to provide them with access to user accounts. However, it did not clarify whether open banking services could be paid or unpaid, or whether regulated open banking services were mandatory. The amendments address these issues by explicitly stating that open banking services can be either free or paid, and that regulated open banking services are mandatory and must be provided free of charge. This is to ensure that TPPs have access to the information they need to provide innovative financial services to their customers, without being forced to pay for services they do not need. | ||||||||||||||||||||||
55 | |||||||||||||||||||||||||||
56 | 7. Provision of information to the user on their accounts by third-party payment service providers is carried out on the basis of a service agreement. | 7. Надання користувачу сторонніми надавачами платіжних послуг інформації за його рахунками здійснюється на підставі договору про надання послуг. | |||||||||||||||||||||||||
57 | |||||||||||||||||||||||||||
58 | 8. The National Bank of Ukraine determines the conditions for access of third-party payment service providers to user accounts, the procedure for granting and withdrawing user consent, and mandatory requirements for methods of protection and exchange of information between users, account servicing payment service providers and third-party payment service providers in the process of accessing user accounts. | 8. Національний банк України визначає умови доступу сторонніх надавачів платіжних послуг до рахунків користувачів, порядок надання та відкликання згоди користувача та обов’язкові вимоги до способів захисту та обміну інформацією між користувачами, надавачами платіжних послуг з обслуговування рахунку та сторонніми надавачами платіжних послуг у процесі доступу до рахунків користувачів. | 8. Національний банк України визначає строки та умови доступу сторонніх надавачів платіжних послуг до рахунків користувачів фізичних осіб, фізичних осіб підприємців або юридичних осіб (зокрема перелік операцій, які є обов’язковими для виконання надавачами платіжних послуг з обслуговування рахунку у разі надходження запиту від користувача через стороннього надавача платіжних послуг та особливості виконання таких операцій ), перелік користувачів, до рахунків яких надається такий доступ, порядок надання та відкликання згоди користувача та обов’язкові вимоги до способів захисту та обміну інформацією між користувачами, надавачами платіжних послуг з обслуговування рахунку та сторонніми надавачами платіжних послуг у процесі доступу до рахунків користувачів. | 8. The National Bank of Ukraine determines the terms and conditions for access of third-party payment service providers to the accounts of individuals, sole proprietors, or legal entities (including the list of transactions that are mandatory for account servicing payment service providers to perform in the event of a request from the user through a third-party payment service provider and the specifics of performing such transactions), the list of users to whose accounts such access is granted, the procedure for granting and withdrawing user consent, and mandatory requirements for methods of protection and exchange of information between users, account servicing payment service providers, and third-party payment service providers in the process of accessing user accounts. | Purpose of the Amendments The amendments to the Ukrainian Payment Services Law (the "Law") aim to address two main concerns: Concerns regarding the National Bank of Ukraine's (NBU) mandate: The NBU believes it lacks the authority to differentiate and delay the implementation of open banking services for different types of customers (individuals, sole proprietors, and legal entities). The NBU is concerned that initiating legislative changes to obtain such a mandate could be interpreted as non-compliance of Ukrainian payment legislation with the PSD2 Directive, potentially complicating negotiations between Ukraine and the EU in the context of Ukraine's EU accession framework. Concerns regarding the readiness of the Ukrainian open banking market: Ukrainian open banking market participants do not intend to launch open banking services for legal entities by the deadline specified in the transitional provisions of the Law (August 1, 2025). This is due to the complexities of Strong Customer Authentication (SCA) for legal entities. The Open API Group, which represents 95% of Account Servicing Payment Service Providers (ASPSPs) and develops the Ukrainian open banking specification based on BG specs ver. 2.0, does not plan to submit a specification for NBU approval that includes legal entity account access services. Addressing the Concerns The amendments, in conjunction with changes to the Law's transitional provisions, establish a regulatory framework that: Eliminates the requirement to implement services for accessing different types of accounts simultaneously: This allows for a phased implementation approach, prioritizing the rollout of open banking services for individuals and sole proprietors. Empowers the NBU to postpone the implementation of services for legal entities: This provides flexibility to address the specific challenges of SCA for legal entities and ensure a smooth and secure implementation. | ||||||||||||||||||||||
59 | 9. Надавач платіжних послуг з обслуговування рахунку має право відмовити сторонньому надавачу платіжних послуг в доступі до рахунку користувача з об’єктивно виправданих та належним чином підтверджених законних підстав (неправомірний доступу до рахунку користувача, ініціювання неакцептованих, помилкових, неналежних платіжних операцій тощо). Надавач платіжних послуг з обслуговування рахунку має повідомити стороннього надавача платіжних послуг про відмову в доступі до рахунку та вказати причини. Така інформація має бути надана, якщо це можливо до того, як у доступі буде відмовлено, і не пізніше, ніж одразу після цього, якщо надання такої інформації не загрожує об’єктивно виправданим міркуванням безпеки або заборонено законодавством України. | 9. The account servicing payment service provider has the right to refuse a third-party payment service provider access to a user's account on objectively justified and duly confirmed legal grounds (unauthorized access to the user's account, initiation of unauthorized, erroneous, or improper payment transactions, etc.). The account servicing payment service provider must notify the third-party payment service provider of the refusal of access to the account and indicate the reasons. Such information must be provided, if possible, before access is denied, and no later than immediately thereafter, if the provision of such information does not jeopardize objectively justified security considerations or is prohibited by the legislation of Ukraine. | Purpose: These amendments aim to establish a balance between: Account security and user control: Ensuring account servicing payment service providers (ASPSPs) have the authority to protect user accounts from unauthorized access and fraudulent activity. Key Points: Right to Refuse Access: ASPSPs gain the right to deny access to TPSPs on objectively justified and documented legal grounds. This empowers ASPSPs to act against malicious actors attempting unauthorized access, initiating fraudulent transactions, or causing other security concerns. Transparency and Notification: Whenever access is denied, ASPSPs are obligated to inform the TPSP and explain the reasons for refusal. This promotes transparency and allows TPSPs to address the issue or appeal the decision. Timing of Notification: Ideally, the notification should happen before access is denied. However, immediate notification after the denial is also acceptable if security concerns or Ukrainian law prevent it. This ensures the TPSP is promptly informed and can take corrective actions. | ||||||||||||||||||||||||
60 | {Частина восьма статті 53 в редакції Закону № 2888-IX від 12.01.2023} | ||||||||||||||||||||||||||
61 | 10. На підставі договорів та відповідно до цього Закону діяльність з організації електронної взаємодії надавачів платіжних послуг із іншими надавачами та користувачами мають право здійснювати технологічні оператори. Надавачі фінансових, нефінансових платіжних послуг, технологічні оператори повинні вживати заходів щодо забезпечення безпеки інформації під час зазначеної електронної взаємодії та використовувати інформацію виключно для надання послуг задіяним особам. | 10. Technological operators have the right to carry out activities on the organization of electronic interaction of payment service providers with other providers and users on the basis of contracts and in accordance with this Law. Providers of financial and non-financial payment services, technological operators must take measures to ensure the security of information during such electronic interaction and use the information exclusively for the provision of services to the involved persons. | The proposed amendments to Article 24 and Article 53 part 10 of the Ukrainian Payment Services Law aim to address two key issues: Clarify the scope of a technological operator's activities: The current law provides a somewhat contradictory description of a technological operator's functions, particularly in relation to their ability to act as Payment Initiation Service Providers (PISPs) and Account Information Service Providers (AISPs). The amendments seek to clarify whether technological operators are prohibited from acting as PISPs and AISPs or whether these functions are simply not explicitly included within their scope of activities. Enable technological operators to act as hubs: Market participants in Ukraine are interested in utilizing hub services while also providing PISP and AISP services. Technological operators are particularly well-suited to perform hub functions, and experience in other countries (as well as the absence of such prohibitions in PSD2) suggests that combining hub and SAS (PISPs and AISPs) services within a single legal entity should be permitted. The proposed amendment to Article 53, Section 10, aims to address this issue. Benefits of the Amendments The proposed amendments are expected to bring several benefits to the Ukrainian payment services industry: Enhanced clarity and consistency: By clarifying the scope of a technological operator's activities, the amendments will provide greater certainty for market participants and reduce the risk of legal disputes. Increased innovation and competition: Enabling technological operators to act as hubs will foster innovation and competition in the market, leading to a wider range of services and potentially lower prices for consumers. Alignment with international standards: The amendments will bring Ukrainian payment services legislation closer to international standards, such as PSD2, further facilitating cross-border payments and promoting the integration of the Ukrainian market into the global financial ecosystem. | ||||||||||||||||||||||||
62 | Article 54. Provision of payment initiation services | Стаття 54. Надання послуги з ініціювання платіжної операції | |||||||||||||||||||||||||
63 | |||||||||||||||||||||||||||
64 | 1. A payer has the right to engage a payment initiation service provider (PISP) to initiate a payment transaction, except for initiating a payment transaction from a bank's correspondent account or a payment service provider's (PSP) payment account. | 1. Платник має право залучити для ініціювання платіжної операції (крім ініціювання платіжної операції з кореспондентського рахунку банку та розрахункового рахунку надавача платіжних послуг) надавача платіжних послуг з ініціювання платіжної операції. | |||||||||||||||||||||||||
65 | |||||||||||||||||||||||||||
66 | . A payment initiation service is not provided if the payer's account is not accessible in real time. | 2. Послуга з ініціювання платіжної операції не надається, якщо до рахунку платника немає доступу в режимі реального часу. | |||||||||||||||||||||||||
67 | |||||||||||||||||||||||||||
68 | 3. When providing payment initiation services, a payment initiation service provider (PISP) is obliged to: | 3. Надавач послуг з ініціювання платежу під час надання послуг з ініціювання платіжної операції зобов’язаний: | |||||||||||||||||||||||||
69 | |||||||||||||||||||||||||||
70 | . Ensure the non-accessibility of users' individual account information to any other parties except the user and the payment service provider that provided it to the user, and its transmission by the payment initiation service provider only through secure communication channels, taking into account the requirements of this Law. | 1) забезпечити недоступність індивідуальної облікової інформації користувачів будь-яким іншим сторонам, крім користувача та надавача платіжних послуг, який надав їх користувачу, та передавання їх надавачем послуг з ініціювання платіжної операції лише захищеними каналами зв’язку з урахуванням вимог цього Закону; | |||||||||||||||||||||||||
71 | |||||||||||||||||||||||||||
72 | 2. Ensure the provision of any other information about the user obtained during the provision of the payment initiation service only to the recipient and only with the consent of the user. | 2) забезпечити надання будь-якої іншої інформації про користувача, отриманої під час надання послуги з ініціювання платіжної операції, лише отримувачу та лише за згодою користувача; | |||||||||||||||||||||||||
73 | |||||||||||||||||||||||||||
74 | 3. Identify itself to the account servicing payment service provider each time a payment transaction is initiated and ensure secure information exchange with the account servicing payment service provider, payer, and recipient only through secure communication channels, taking into account the requirements of this Law. | 3) щоразу під час ініціювання платіжної операції ідентифікувати себе перед надавачем платіжних послуг з обслуговування рахунку та забезпечувати безпечний обмін інформацією з надавачем платіжних послуг з обслуговування рахунку, платником та отримувачем лише захищеними каналами зв’язку з урахуванням вимог цього Закону. | |||||||||||||||||||||||||
75 | |||||||||||||||||||||||||||
76 | 4. During the provision of payment initiation services, the payment initiation service provider (PISP) shall not: | 4. Під час надання послуг з ініціювання платіжної операції надавач послуг з ініціювання платіжної операції не має права: | |||||||||||||||||||||||||
77 | |||||||||||||||||||||||||||
78 | (a) receive or hold any funds from the user in connection with the payment transaction; | 1) отримувати чи утримувати з користувача будь-які кошти у зв’язку з платіжною операцією; | |||||||||||||||||||||||||
79 | |||||||||||||||||||||||||||
80 | (b) store any sensitive payment data of the user; | 2) зберігати будь-які вразливі платіжні дані користувача; | 2) зберігати будь-які вразливі платіжні дані користувача з метою, не пов’язаною з наданням послуги; | store any sensitive payment data of the user for a purpose not related to the provision of the service; | Purpose of the amendment: The amendment clarifies that PISPs are only prohibited from storing sensitive payment data for purposes that are not related to the provision of payment initiation services. This means that PISPs can still store sensitive payment data for purposes that are necessary for providing the service, such as authenticating the user, initiating payments, or complying with regulatory requirements. Rationale for the amendment: The original requirement was overly broad and could have been interpreted to prohibit PISPs from storing any sensitive payment data, even for legitimate purposes. This would have been impractical and could have hindered the ability of PISPs to provide their services. The amended requirement provides more clarity and flexibility for PISPs while still protecting the security of sensitive payment data. It allows PISPs to store sensitive payment data for purposes that are necessary to provide the service, while prohibiting them from storing such data for other purposes that could pose a risk to the user's security. Examples of legitimate purposes for storing sensitive payment data: Authenticating the user: PISPs may need to store sensitive payment data, such as card numbers or CVVs, in order to verify the identity of the user and prevent unauthorized access to their accounts. Initiating payments: PISPs may need to store sensitive payment data, such as account numbers and routing numbers, in order to initiate payments on behalf of the user. Complying with regulatory requirements: PISPs may be required to store sensitive payment data for a certain period of time in order to comply with anti-money laundering (AML) and know-your-customer (KYC) regulations. | ||||||||||||||||||||||
81 | |||||||||||||||||||||||||||
82 | (c) request from the user any information not related to the provision of the payment initiation service; | 3) запитувати у користувача будь-яку інформацію, не пов’язану з наданням послуги з ініціювання платіжної операції; | |||||||||||||||||||||||||
83 | |||||||||||||||||||||||||||
84 | (d) change the amount or any other parameters of the payment instruction. | 4) змінювати суму або будь-які інші параметри платіжної інструкції. | |||||||||||||||||||||||||
85 | |||||||||||||||||||||||||||
86 | 5. Upon the payer's consent to execute a payment transaction in accordance with this Law, the account servicing payment service provider (ASPSP) shall: | 5. За умови надання платником згоди на виконання платіжної операції згідно з цим Законом надавач платіжних послуг з обслуговування рахунку зобов’язаний: | 5. Після надання платником згоди на виконання платіжної операції, що підтверджено фактом виконання посиленої автентифікації користувача, надавач платіжних послуг з обслуговування рахунку зобов’язаний: | 5. After the payer has given their consent to the execution of a payment transaction, which is confirmed by the fact of the user's strong authentication, the account servicing payment service provider (PSP) shall: | Purpose of the amendment: The amendment clarifies that the payer's consent to execute a payment transaction must be obtained and recorded in a way that is secure and auditable. It also specifies that strong customer authentication (SCA) can be used to confirm the payer's consent. Rationale for the amendment: The original requirement was vague and did not provide enough guidance on how PSPs should obtain and record the payer's consent. This could have led to inconsistent and insecure practices, and it could have made it difficult for payers to dispute unauthorized transactions. The amended requirement provides more clarity and security for both payers and PSPs. It requires PSPs to obtain the payer's consent in a way that is clear and verifiable, and it allows them to use SCA to confirm the payer's consent. This will help to prevent unauthorized transactions and make it easier for payers to resolve disputes. Additional considerations: The definition of "consent" is not explicitly defined in the current version of the law. This means that there is some uncertainty about what exactly constitutes valid consent. The amended requirement does not address this issue directly, but it does provide a more specific way for PSPs to obtain and record consent, which may help to reduce the risk of disputes. SCA is a strong indicator of the payer's intent to execute a payment transaction. This means that it can be used to confirm the payer's consent in a secure and reliable way. The amended requirement explicitly allows PSPs to use SCA to confirm consent, which is a positive step. Using information about executed payment transactions in consent management can provide users with greater transparency and understanding of their consent history. This can help them to identify and dispute any unauthorized transactions. The amended requirement does not specifically mandate the use of this information, but it does not prohibit it either. PSPs should consider using this information to improve the user experience and protect their customers. | ||||||||||||||||||||||
87 | |||||||||||||||||||||||||||
88 | (a) carry out secure information exchange with the payment initiation service provider (PISP) only through secure communication channels in compliance with the requirements of this Law; | 1) здійснювати безпечний обмін інформацією з надавачем послуг з ініціювання платежу лише захищеними каналами зв’язку з дотриманням вимог цього Закону; | |||||||||||||||||||||||||
89 | |||||||||||||||||||||||||||
90 | (b) immediately upon receipt of a payment instruction from the PISP, provide (or make available) to it all available information about the initiation of such payment transaction and its execution; | 2) негайно після отримання платіжної інструкції від надавача послуг з ініціювання платіжної операції надати (або зробити доступною) йому всю доступну інформацію про ініціювання такої платіжної операції та її виконання; | |||||||||||||||||||||||||
91 | |||||||||||||||||||||||||||
92 | (c) execute payment instructions provided through the PISP on the same terms and conditions as payment instructions provided directly by the payer, including in terms of processing time, execution priority, or fees for the provision of services. | 3) виконувати платіжні інструкції, надані через надавача послуг з ініціювання платіжної операції, на тих самих умовах, що й платіжні інструкції, надані безпосередньо платником, зокрема в частині строків оброблення, пріоритету виконання або стягнення плати за надання послуг. | |||||||||||||||||||||||||
93 | |||||||||||||||||||||||||||
94 | Article 55. Provision of Account Information Services | Стаття 55. Надання послуги з надання відомостей з рахунків | |||||||||||||||||||||||||
95 | |||||||||||||||||||||||||||
96 | 1. A user has the right to engage an account information service provider (AISP) to obtain account information from accounts opened by the user with other account servicing payment service providers (ASPSPs). | 1. Користувач має право залучити надавача послуг з надання відомостей з рахунків для отримання відомостей з рахунків, відкритих користувачем в інших надавачів платіжних послуг з обслуговування рахунку. | |||||||||||||||||||||||||
97 | |||||||||||||||||||||||||||
98 | 2. An account information service is not provided if the user's account is not accessible in real time. | 2. Послуга з надання відомостей з рахунків не надається, якщо до рахунку користувача немає доступу в режимі реального часу. | |||||||||||||||||||||||||
99 | |||||||||||||||||||||||||||
100 | 3. An AISP: | 3. Надавач послуг з надання відомостей з рахунків: | |||||||||||||||||||||||||