[codicts-css-switcher id=”346″]

Global Law Experts Logo
psd3 psr estonia

PSD3 and the Payment Services Regulation in Estonia (2026): What Emis, Pis, Aisps and Pisps Must Change

By Global Law Experts
– posted 2 hours ago

Who this guide is for: compliance leads, general counsel, founders and CTOs at EMIs, PIs, AISPs and PISPs operating in or entering Estonia. It covers the expected PSD3/PSR changes and timelines, concrete authorisation and operational implications, Finantsinspektsioon expectations, and a practical remediation checklist you can act on now.

PSD3 PSR Estonia is a defining regulatory shift for every e-money institution, payment institution, account information service provider and payment initiation service provider licensed or seeking to operate under Estonian supervision. The European Commission’s third-generation payment services framework is designed to replace the Second Payment Services Directive (PSD2) with a combined package: a new Payment Services Directive (PSD3) and a directly applicable Payment Services Regulation (PSR). At the time of writing, the package is still moving through the EU legislative process, so its final text and application dates should be confirmed before firms fix project deadlines.

For firms overseen by Finantsinspektsioon, the Estonian Financial Supervision and Resolution Authority, the reform means reviewing authorisation scope, strong customer authentication, fraud handling, open-banking data access and outsourcing controls ahead of the eventual transition milestones. This guide translates the EU-level proposals into concrete steps for Estonia-licensed payment and e-money firms.

PSD3 and the Payment Services Regulation: what is changing vs PSD2

The most important structural change under the psd3 psr estonia framework is legal form. PSD2 is a directive (Directive (EU) 2015/2366), which each Member State transposed into national law, in Estonia primarily through the Payment Institutions and E-money Institutions Act, the text of which is available on Riigi Teataja. Directives leave room for divergence between jurisdictions. The proposed new package splits the rules: PSD3 would remain a directive governing authorisation and supervision, while the Payment Services Regulation would apply directly across all Member States, harmonising conduct, consumer protection, SCA and fraud rules without the need for national transposition.

For Estonian firms, this dual structure would have practical consequences. Authorisation, licensing conditions and supervisory powers would continue to flow through national law implementing PSD3, administered by Finantsinspektsioon. But much of the operational rulebook, how you authenticate customers, how you handle fraud, how you grant account access to third parties, would sit in the directly applicable Regulation, leaving less room for local interpretation. The European Commission has framed the reform around broad objectives that include strengthening consumer protection against fraud, improving the functioning of open banking, and levelling the competitive field between banks and non-bank payment providers.

Core PSD3 innovations relevant to Estonia

Several proposed innovations under the psd3 psr estonia package would require direct action from supervised firms:

  • Consolidated authorisation. The separate regimes for payment institutions and e-money institutions are brought closer together, with a more streamlined authorisation approach and clearer permitted-activity categories.
  • Enhanced fraud controls. Stronger obligations around transaction monitoring, IBAN-name matching and information sharing on fraud indicators.
  • Expanded reimbursement rights. Broader consumer entitlements to reimbursement in certain fraud scenarios, with defined liability allocation.
  • Improved open banking. Better-defined access interfaces, permission dashboards for customers and clearer obligations on account servicing providers.
  • Reinforced SCA. Refined strong customer authentication rules, including accessibility and inclusion considerations, supported by EBA technical standards.

What stays the same, continuity with PSD2

Not everything changes. The fundamental architecture of European payment regulation carries over from PSD2. The concept of regulated payment services, the licensing gateway operated by national competent authorities such as Finantsinspektsioon, safeguarding of customer funds, and the EU passporting mechanism all persist. Account information services and payment initiation services remain regulated activities. Strong customer authentication remains the cornerstone of the fraud-prevention regime, even as its detailed application is refined. Firms that built robust PSD2 compliance programmes are not starting from zero; the psd2 to psd3 transition is an upgrade and re-scoping exercise rather than a wholesale rebuild. The key discipline is mapping each existing control against the revised requirements to identify genuine gaps.

PSD3/PSR timeline and key milestones for Estonia

Understanding the psd3 estonia timeline is the first practical step for any compliance lead. The legislative package is expected to move from adoption at EU level into an application period, with transitional arrangements designed to give existing authorised firms a defined window to align. Because the Payment Services Regulation would apply directly, its operational provisions would take effect on the dates set out in the Regulation itself rather than on the date any Estonian implementing measure is passed. The PSD3 directive, by contrast, must be transposed into Estonian law before its national provisions apply.

Firms should therefore track two clocks: the EU-level application date for the directly applicable Regulation, and the national transposition and any transitional relief published on Riigi Teataja.

Because exact application dates are set at EU level and reflected in national measures, and because the package is not yet finalised, firms should confirm current dates directly against the European Commission payment services pages and Finantsinspektsioon guidance before locking project deadlines. What matters operationally is that preparation can begin now, and the firms that begin gap analysis early will face the least disruption.

EU adoption → national oversight: how Finantsinspektsioon is expected to act

Finantsinspektsioon is the national competent authority responsible for authorising and supervising payment institutions and e-money institutions in Estonia. Once the PSD3/PSR package applies, industry observers expect the supervisor to issue practical guidance and update its application and reporting expectations, mirroring its established approach under PSD2. Existing authorisations are not expected to be automatically extinguished; instead, transitional provisions typically allow already-authorised firms to continue operating while they demonstrate compliance with the new framework within a defined period. The likely practical effect is that Finantsinspektsioon will expect firms to submit updated documentation confirming that governance, safeguarding, SCA and fraud arrangements meet the revised standards.

Early engagement, including pre-notification correspondence, is a reliable way to avoid a rushed, contested review as any deadline approaches.

Firm-level project timelines: immediate to 6–12 months checklist

Regardless of the precise external deadline, firms can run their internal psd3 estonia timeline on a disciplined schedule:

  • 0–3 months. Commission a gap analysis mapping current permissions, controls and contracts against the anticipated PSD3/PSR requirements; assign an accountable owner.
  • 3–6 months. Remediate SCA and fraud-monitoring systems, review safeguarding arrangements, and scope any required licence amendment.
  • 6–12 months. Prepare amendment or notification documents for Finantsinspektsioon, update customer terms, complete staff training and finalise open-banking interface changes.

Authorisation and licensing changes under PSD3, what PIs and EMIs should consider

The authorisation dimension is where the psd3 psr estonia reforms will most directly affect a firm’s legal standing. PSD3 is expected to revisit the criteria for granting and maintaining a payment institution license Estonia holders rely on, and for the emi license Estonia e-money firms operate under. The proposed consolidation of the payment and e-money regimes means firms should not assume their existing permission scope maps cleanly onto the new categories. Some activities may be re-labelled; others may attract revised capital or safeguarding conditions. The correct starting point is a permission-by-permission review: list every regulated activity your firm currently performs, and confirm how each is likely to be treated under the new framework.

Capital and safeguarding are central to this review. PSD3 maintains the principle that customer funds must be protected, but firms should verify whether their safeguarding method, segregated accounts or an insurance/guarantee arrangement, continues to satisfy the revised expectations. Initial capital and own-funds requirements should be re-tested against the activities you intend to continue. Where the review reveals that your intended activity set falls outside your current authorisation, you may need to apply for an extended or new permission rather than a simple amendment.

When to notify Finantsinspektsioon vs when to apply for a new licence

A recurring practical question is whether a change requires a notification to Finantsinspektsioon or a fresh authorisation application. As a general rule, material changes to the nature, scope or scale of regulated activities, particularly adding a new payment service you are not currently authorised to provide, will require a new or extended authorisation, assessed against the full licensing criteria. Changes to governance, qualifying holdings, key function holders or outsourcing arrangements typically fall within the notification and prior-approval regime. Under the psd3 psr estonia framework, firms should treat any re-scoping triggered by new permitted-activity categories as a substantive matter warranting early dialogue with the supervisor, because misclassifying a change as a mere notification risks operating outside your permission.

Expected changes to governance, compliance function, and capital arrangements

PSD3 is expected to reinforce expectations on sound governance and internal control. Firms should confirm that the management body has clear accountability for payments compliance, that the compliance function has sufficient standing and resource, and that the risk framework explicitly addresses fraud, SCA failures and open-banking access. Documentation of these arrangements is what Finantsinspektsioon will assess. On capital, firms should refresh their own-funds calculations, stress the safeguarding arrangements against realistic volumes, and ensure that any insurance or comparable guarantee supporting the emi license Estonia or payment institution license Estonia permission remains valid and adequately sized. Where the firm relies on group support or outsourced functions, the governance file must show that responsibility and control remain with the licensed entity.

Practical checklist for licence amendment applications

  • Updated programme of operations reflecting revised permitted-activity categories.
  • Refreshed safeguarding description and evidence of the chosen method.
  • Recalculated own-funds and initial capital documentation.
  • Governance and organisational chart with named function holders.
  • Updated SCA, fraud-monitoring and business-continuity policies.
  • Revised outsourcing register and material contracts.

EMI vs PI vs AISP/PISP, obligations at a glance

The table below summarises how the main authorisation types compare on the dimensions most affected by the psd3 psr estonia reforms. It is a high-level orientation aid; confirm current thresholds and conditions against Finantsinspektsioon guidance and the applicable legal texts before relying on them.

Dimension EMI (e-money institution) PI (payment institution) AISP / PISP
Core activity Issuing e-money and providing payment services Executing payment services (transfers, acquiring, remittance) Account information (AISP) / payment initiation (PISP)
Initial capital Higher tier reflecting e-money issuance Tiered by permitted services AISP: professional indemnity insurance or comparable guarantee in place of minimum capital; PISP: lower capital tier
Safeguarding Required for funds received against e-money and payment services Required for payment service funds held AISP does not hold funds; PISP does not hold funds
Permitted activities Broadest, including e-money issuance Payment services only Narrow, service-specific
Passporting Yes, via EU passport Yes, via EU passport Yes, via EU passport
Anticipated PSD3 change Regime consolidation; safeguarding re-verification Revised permitted-activity categories; SCA and fraud rules Improved data-access rights and access-interface obligations

AISPs and PISPs: authorisation, API access and data sharing under PSD3

Open banking is one of the clearest areas of change under the psd3 psr estonia package. Account information service providers and payment initiation service providers depend on reliable access to customer accounts held at banks and other account servicing providers. PSD3 and the Regulation aim to reduce the friction that arose under PSD2 by tightening the obligations on account servicing providers to offer effective access, improving interface performance requirements, and giving customers clearer control through permission dashboards. For AISPs and PISPs already licensed or registered in Estonia, the core message is that regulated status persists, but the technical and contractual expectations around access are expected to become more prescriptive.

Authorisation scope and passporting for AISPs/PISPs in Estonia

AISPs and PISPs authorised or registered in Estonia should confirm that their permission continues to cover their actual services under the new categories. AISPs operating on a registration basis and PISPs operating under authorisation both benefit from the EU passport, allowing them to serve customers across the single market on the basis of their Estonian permission. During any transition, firms should verify that existing passport notifications remain accurate and that any host-state activity is correctly documented. Where a firm intends to expand from pure account information into payment initiation, that is a scope change likely to require an extended authorisation rather than a notification, and open banking estonia providers should plan the supervisory engagement accordingly.

Open banking technical and contractual requirements

On the technical side, the psd3 psr estonia rules are expected to place renewed emphasis on the quality and availability of access interfaces. Account servicing providers must ensure their interfaces perform to defined standards, and third parties must be able to identify themselves reliably and access only the data the customer has permitted. Firms should review their consent-capture flows so that customer permissions are explicit, granular and easy to withdraw, in line with the permission-dashboard concept. Contractually, AISPs and PISPs should confirm that their data-processing arrangements, liability allocation with account servicing providers and incident-handling procedures reflect the revised obligations. Documenting the technical access method and the consent lifecycle will be central to demonstrating open banking estonia compliance to Finantsinspektsioon.

SCA, fraud handling and customer protection, operational considerations

Strong customer authentication remains the operational heart of European payment security, and the psd3 psr estonia reforms are expected to refine rather than remove it. The European Banking Authority continues to publish guidelines and technical standards that shape how SCA is applied in practice, and firms should treat EBA material as the authoritative reference for the detail. The reforms place additional emphasis on accessibility, ensuring that authentication methods do not unfairly exclude vulnerable or disabled customers, alongside the existing requirement that at least two independent factors from knowledge, possession and inherence are combined for in-scope transactions.

Implementing SCA: technical, UX and third-party implications

Delivering strong customer authentication estonia compliance is as much a product and engineering challenge as a legal one. Firms should audit their authentication flows against current and anticipated expectations, confirm that applicable exemptions (such as low-value or transaction-risk-analysis exemptions) are being applied correctly and are properly evidenced, and test the customer experience to reduce friction without weakening security. Where authentication is delivered through a third party or an outsourced provider, the licensed firm remains accountable and must be able to demonstrate that the provider meets the standard. Accessibility should be built into the design so that alternative authentication routes exist for customers who cannot use a given factor.

Every exemption decision should be logged with a clear audit trail, because supervisors will expect to see the rationale.

Fraud handling, liability and reimbursement procedures

The Payment Services Regulation is expected to strengthen consumer protection by broadening the circumstances in which fraud victims are entitled to reimbursement and by clarifying how liability is allocated between the customer, the payment service provider and, in some scenarios, other parties. Firms should build clear internal procedures for triaging fraud claims, determining liability, and paying reimbursement within any required timeframes. Robust transaction monitoring and information sharing on fraud indicators are complementary obligations, better detection reduces both losses and disputes. Practically, firms should update their fraud policy, define reimbursement decision criteria, train frontline staff, and maintain records that show each claim was handled consistently.

The psd3 psr estonia regime rewards firms that can evidence a disciplined, documented approach to fraud and reimbursement.

Outsourcing, ICT risk and DORA overlap, what Estonian payment firms should address

Payment firms rarely operate every function in-house. Cloud hosting, authentication services, fraud tooling and account-access infrastructure are routinely outsourced, which means the psd3 psr estonia obligations interact directly with the Digital Operational Resilience Act (DORA) regime governing ICT risk for financial entities, which applies from 17 January 2025. Estonian payment institutions and e-money institutions should treat operational resilience and outsourcing governance as a single, integrated workstream rather than two disconnected compliance projects, because supervisors will assess them together.

Contractual clauses and supervisory notification to Finantsinspektsioon

Outsourcing of material or critical functions triggers both governance obligations and, in defined cases, prior notification to Finantsinspektsioon. Firms should maintain an accurate outsourcing register, and their contracts with providers should include the clauses supervisors expect: audit and access rights, sub-outsourcing controls, data-location and security commitments, service levels, exit and termination provisions, and cooperation with the competent authority. The licensed entity cannot delegate its regulatory responsibility, so contracts must preserve the firm’s ability to oversee and, if necessary, exit the arrangement. Where a critical function is being outsourced or materially changed, plan the supervisory notification early rather than treating it as a formality at the end of the project.

Operational resilience testing and incident reporting

Under the combined framework, firms must be able to detect, manage and report significant operational and security incidents. That means defined incident-classification criteria, escalation paths, tested response playbooks and clear reporting lines to Finantsinspektsioon within required timeframes. Periodic resilience testing, including scenario testing of key ICT systems and third-party dependencies, should form part of the annual control cycle so that the firm can evidence readiness rather than assert it.

Remediation roadmap and practical checklist for EMIs, PIs, AISPs and PISPs

The following remediation checklist converts the psd3 psr estonia considerations into accountable actions. Assign an owner and a target window to each item, and retain documentation for supervisory review.

  1. Permission mapping (Compliance lead), map current activities to the anticipated new categories.
  2. Gap analysis (Compliance/Legal), identify SCA, fraud, safeguarding and data-access gaps.
  3. Safeguarding re-verification (Finance), confirm method and adequacy.
  4. Own-funds recalculation (Finance), re-test capital against activities.
  5. SCA remediation (Engineering/Product), align authentication and exemptions.
  6. Fraud and reimbursement procedures (Risk), update policy and timelines.
  7. Open-banking interfaces (Engineering), meet access and consent standards.
  8. Outsourcing register and contracts (Legal/Procurement), refresh clauses.
  9. Incident reporting (Security), confirm classification and reporting lines.
  10. Governance documentation (Company secretary), update charts and accountabilities.
  11. Licence amendment or notification (Legal), prepare submissions for Finantsinspektsioon.
  12. Customer terms and training (Compliance), update disclosures and train staff.

Sample timeline: 0–3 months, 3–6 months, 6–12 months

Within the first three months, complete permission mapping, the gap analysis and safeguarding re-verification, and consider whether a notification or a new application is likely to be required. Between three and six months, remediate SCA and fraud systems, recalculate capital, refresh outsourcing contracts and prepare supervisory submissions. Between six and twelve months, finalise the amendment or notification for Finantsinspektsioon, update customer documentation, complete training, and finalise open-banking and incident-reporting changes. Firms entering the market for the first time should fold these steps into their initial authorisation project so that they launch aligned with the emerging psd3 psr estonia framework.

How Finantsinspektsioon is expected to supervise PSD3 compliance

Finantsinspektsioon supervises through a mix of authorisation review, ongoing reporting, desk-based analysis and, where warranted, on-site inspection. Under the psd3 psr estonia regime, industry observers expect supervisory attention to concentrate on fraud performance, SCA implementation, safeguarding adequacy and the quality of open-banking access. Non-compliance can expose firms to supervisory measures ranging from remediation demands to financial penalties and, in serious cases, restrictions on activity. The most effective posture is proactive engagement: submit clear, well-evidenced documentation, notify material changes early, and respond promptly to information requests. Firms that treat the supervisor as a partner in the transition, rather than a hurdle at the end of it, tend to experience smoother reviews. For tailored support, see our Licensing lawyers, Estonia team.

Conclusion and next steps

The psd3 psr estonia transition is a defined, time-bound compliance exercise once the framework is finalised, not an open-ended one. EMIs, PIs, AISPs and PISPs that begin preparing now, mapping permissions, closing SCA and fraud gaps, re-verifying safeguarding, tightening outsourcing controls and engaging Finantsinspektsioon early, will complete the transition with the least disruption and the strongest supervisory relationship. The firms that wait risk a rushed, contested review against a fixed deadline. Global Law Experts can support you with a targeted PSD3/PSR readiness audit, draft licence amendments, and pre-notification correspondence to Finantsinspektsioon, so your Estonian payment or e-money business is aligned with the new framework as it takes shape.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mark Gofaizen at Gofaizen & Sherle Fintech Lawyers, a member of the Global Law Experts network.

Sources

  1. European Commission, Payment services
  2. EUR-Lex, Directive (EU) 2015/2366 (PSD2)
  3. European Banking Authority
  4. Finantsinspektsioon, Estonian Financial Supervision and Resolution Authority
  5. Riigi Teataja, Estonian State Gazette
  6. Eesti Pank, Bank of Estonia

FAQs

Do AISPs and PISPs need new or updated authorisation under PSD3 in Estonia?
In most cases the existing regulated status of AISPs and PISPs is expected to continue, but firms must confirm that their permission maps onto any revised activity categories and that passport notifications remain accurate. A firm expanding from account information into payment initiation, or otherwise widening its scope, will generally need an extended authorisation rather than a simple notification. The safest approach is a permission review followed by early dialogue with Finantsinspektsioon.
PSD3 is expected to consolidate the payment institution and e-money institution regimes, revisit permitted-activity categories, and reinforce governance, safeguarding and capital expectations. Existing holders of a payment institution license Estonia permission should re-verify that their activities, safeguarding method and own-funds remain compliant, and should be prepared to file an amendment where the new categories change how their services are classified.
The package is still being finalised at EU level. The Payment Services Regulation would apply directly on the dates set out in the Regulation once adopted, while PSD3 must first be transposed into Estonian law before its national provisions take effect. Transitional arrangements are expected to allow already-authorised firms a defined window to align. Confirm the current psd3 estonia timeline against the European Commission payment services pages and Finantsinspektsioon guidance before fixing deadlines.
The psd3 psr estonia rules are expected to refine strong customer authentication with added emphasis on accessibility, broaden consumer reimbursement rights for certain fraud scenarios, and strengthen open-banking access obligations on account servicing providers. The European Banking Authority publishes the guidelines and technical standards that govern the detailed application of SCA, so firms should treat EBA material as the operational reference point.
Expect to provide an updated programme of operations, a safeguarding description with supporting evidence, recalculated own-funds and initial capital documentation, a governance and organisational chart with named function holders, updated SCA, fraud and business-continuity policies, and a current outsourcing register with material contracts. Complete, internally consistent documentation is a significant factor in a smooth review.
Supervisory measures can range from remediation demands to financial penalties and activity restrictions, depending on the severity of the breach. On passporting, firms should verify that host-state notifications remain accurate throughout any transition and update them where scope changes. Cross-border activity based on an out-of-date passport is a common and avoidable source of supervisory risk.
accounting requirements for srl italy
By Global Law Experts

posted 26 minutes ago

find family lawyer france
By Global Law Experts

posted 35 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

PSD3 and the Payment Services Regulation in Estonia (2026): What Emis, Pis, Aisps and Pisps Must Change

Send welcome message

Custom Message