[codicts-css-switcher id=”346″]

Global Law Experts Logo
psd3 psr austria

Our Expert in Austria

  • GOLD

PSD3 and the Payment Services Regulation (PSR), Austria 2026: What Banks & Fintechs Must Change in Customer & Agent Contracts

By Global Law Experts
– posted 2 hours ago

PSD3 PSR Austria is the regulatory shift that payments teams across the country can no longer defer, because the European Union’s proposed third Payment Services Directive and the directly applicable Payment Services Regulation are set to reshape how banks and fintechs contract with customers and agents. The new framework is intended to replace PSD2 with a combination of a directive (requiring national legislative change) and a regulation (applying automatically, without transposition), and that split alone changes how Austrian payment service providers must draft, amend and renegotiate their contractual estate.

For in-house counsel, compliance officers and product-legal leads at Austrian banks, payment institutions (PIs), electronic money institutions (EMIs) and fintechs, the practical question is no longer whether to act but which clauses to rewrite and when. This article maps the anticipated PSD3 PSR Austria obligations to concrete contract amendments, customer terms and conditions, agent and distributor agreements, liability allocation, strong customer authentication, disclosures and open banking API terms, with sample clause language and a roll-out checklist.

Every regulatory claim below should be cross-checked against the official texts on EUR-Lex and the supervisory guidance of the Austrian Financial Market Authority (FMA) before you finalise drafting, because the package is still progressing through the EU legislative process and its final text and dates are subject to change.

Who this guidance is for and what you will get

This guide is written for the people who own the contractual and compliance risk inside Austrian payment businesses:

  • Who this is for. In-house counsel, compliance officers, and product and legal leads at Austrian banks, PIs, EMIs and fintechs.
  • What you will get. Austria-specific considerations under the proposed PSD3 and PSR, the contract provisions likely to need change, a negotiation and operational checklist, and sample clauses for customer T&Cs and agent agreements.
  • Recommended action. Treat the sample clauses as starting points; run final drafts with your Austrian legal counsel and engage your supervisory contacts at the FMA where material changes are involved.

Timeline and direct applicability of PSD3 PSR Austria

The European Commission published its proposals for a PSD3 and a PSR in June 2023 as part of its wider review of the EU payments framework, with the stated aim of modernising and strengthening the rules first introduced under PSD2. At the time of writing the package remains under negotiation between the European Parliament and the Council and has not been finally adopted. Because the precise application dates depend on the final adopted texts and any transitional periods, Austrian teams should confirm effective dates against the official publications on EUR-Lex and the European Commission’s payment services pages rather than rely on secondary summaries.

The practical takeaway for Austrian PSPs is that contractual remediation is a multi-month exercise and should be planned backwards from the eventual application date once it is confirmed.

Key dates and transposition for PSD3 PSR Austria

The two instruments, once adopted, will behave very differently in the Austrian legal order. The PSR, as an EU regulation, will apply directly in Austria from its date of application, without the need for a national transposition statute. PSD3, as a directive, will require Austria to adapt its national law, the measures that currently implement PSD2, principally the Zahlungsdienstegesetz 2018 (ZaDiG 2018), within the transposition window set by the directive. Compliance teams should monitor the Austrian Legal Information System (RIS) for the national implementing legislation and any amendments to existing payment services law, and the FMA’s guidance pages for supervisory expectations and notification requirements.

Once the final CELEX numbers for PSD3 and the PSR are published, cite the exact articles rather than working from the proposal text.

How the PSR interacts with Austrian law

Direct applicability does not mean the PSR will operate in a vacuum. Austrian civil law, principally the Allgemeines Bürgerliches Gesetzbuch (ABGB), continues to govern contract formation, interpretation, the enforceability of limitation-of-liability clauses and consumer protection baselines (for example under the Konsumentenschutzgesetz, KSchG) that sit alongside the harmonised regime. In other words, a clause can be fully compliant with the PSR’s substantive payment rules yet still be vulnerable under Austrian rules on unfair terms or general contract law. The PSD3 PSR Austria analysis therefore has two layers: the harmonised EU obligations that apply directly, and the national law that determines how those obligations are packaged into enforceable contract terms.

Both must be satisfied for a customer T&C or agent agreement to stand up in practice.

PSD3 vs PSR, what changes legally for PSD3 PSR Austria

The single most important structural change proposed relative to PSD2 is the division of the regime into two legal instruments. Under PSD2, nearly all the substantive rules sat in a directive that each Member State transposed, which produced divergence in how obligations were implemented across the Union. The proposed PSD3 PSR Austria framework separates the material: the PSR would carry the directly applicable conduct and operational rules, while PSD3 would govern matters that remain tied to national law, such as authorisation and the licensing architecture. This design is intended to reduce fragmentation and give PSPs operating across borders a more uniform rulebook.

Regulation versus directive, immediate effects

For Austrian PSPs the regulation-versus-directive distinction has concrete drafting consequences. Where an obligation sits in the PSR, it will apply from the application date regardless of the state of Austrian implementing legislation, so customer-facing clauses that reflect PSR conduct rules can and should be aligned to the regulation directly. Where an obligation sits in PSD3, the exact wording of the national transposing law matters, and contract drafting may need to wait for or track the Austrian statute. A prudent approach is to prepare PSR-driven clauses in draft and build in a review trigger for PSD3-driven clauses once the national implementing measures appear in RIS.

Where national law still matters

Several areas remain anchored in Austrian law even under a harmonised regime. Civil liability mechanics, how damages are quantified, how indemnities are construed, and whether a liability cap is enforceable, are governed by Austrian contract law and judicial interpretation. Authorisation and ongoing supervision run through the FMA, whose guidance shapes what notifications are required and how agent oversight is assessed in practice. Consumer protection rules that pre-date the payments framework continue to apply to the extent they are not displaced by the harmonised regime.

The result is that a competent PSD3 PSR Austria contract review is never a pure copy-paste of EU text; it is a translation exercise that respects the Austrian legal environment in which the contract will be enforced.

Topic PSD2 (baseline) PSD3 / PSR (proposed changes)
Legal form Directive (transposed into national law) PSD3 (Directive) + PSR (Regulation, directly applicable)
Scope Payment services, PSP authorisation Revised scope; clearer rules for AIS/PIS, strengthened consumer protections
Strong Customer Authentication (SCA) EBA RTS; varying national approaches Refined SCA obligations; clearer liability for SCA failures
Agent / distributor rules Nationally implemented More harmonised due diligence, oversight and liability allocation
Liability for unauthorised payments PSP/customer split under PSD2 Strengthened PSP obligations; further AISP/PISP liability clarifications
Open banking / APIs PSD2 interfaces, varying implementations More harmonised access and interface requirements

Required updates to customer terms and conditions

Customer T&Cs are the most visible part of the PSD3 PSR Austria remediation, and the exercise is granular. A clause-by-clause review should start with definitions: the agreement must correctly describe payment initiation service providers (PISPs) and account information service providers (AISPs), the services they provide, and how the customer interacts with them. From there the review moves through the authentication process, the liability matrix for unauthorised transactions, notification and refund timelines, consent and consent-withdrawal mechanics, dispute resolution for billing errors, and the disclosure of fees and exchange rates. Each of these touchpoints maps to a specific obligation in the harmonised regime, and each needs wording that is both compliant and enforceable under Austrian law.

Strong Customer Authentication, mandatory clauses and exemptions

Strong customer authentication remains central to payment security, and the proposed PSD3 PSR Austria framework refines the obligations that PSD2 introduced. Your customer T&Cs should clearly set out when SCA applies, what the customer is required to do to complete authentication, and the circumstances in which an exemption may apply so that a transaction can proceed without a full authentication challenge. The European Banking Authority’s technical standards and guidance on SCA drive much of the detail here, and contract wording should remain consistent with those standards rather than paraphrasing them loosely.

Critically, the clause should allocate responsibility fairly: where the PSP fails to apply SCA when required, the regime places a stricter liability burden on the PSP, and the T&Cs should not attempt to contract around that outcome. Equally, the clause should spell out the customer’s own obligations, safeguarding credentials and devices, because those obligations feed into the liability analysis for unauthorised transactions.

Liability allocation for unauthorised payments and SCA failures

The liability matrix is where the commercial and legal stakes are highest. Under the harmonised regime the PSP bears a heavier burden for unauthorised payments, particularly where it has not correctly applied strong customer authentication. Your T&Cs should contain a clear, structured liability clause that distinguishes between: transactions where SCA was correctly applied; transactions where SCA was not applied when it should have been; and transactions involving gross negligence or fraud on the customer’s side. The clause must also address the interaction with AISPs and PISPs, because the new framework clarifies how liability is allocated when a third-party provider is in the chain.

A common drafting error is to write a liability clause that is internally coherent but exceeds what Austrian law permits a PSP to shift onto a consumer; that error produces an unenforceable term and leaves the PSP exposed. The safer path is a layered clause that tracks the regime’s allocation and is tested against Austrian unfair-terms rules.

Refunds, reversals and timeframe disclosures

Customers are entitled to clear information on how and when refunds and reversals operate, and the PSD3 PSR Austria rules place a premium on transparent timeframes. Your T&Cs should state the circumstances in which a refund is available, the deadline by which the PSP will process it, and the information the customer must provide to trigger it. Where a transaction is reversed, the agreement should explain the mechanics and the timing so the customer is not left guessing. Vague or open-ended refund language is both a compliance risk and a dispute generator; precise, dated commitments reduce complaints and give the PSP a defensible position.

Data use, consents and open banking notices

Open banking turns on consent, and the contract must make that consent architecture visible. Where an AISP accesses account information or a PISP initiates a payment, the customer’s consent is the legal gateway, and the T&Cs should explain what the customer is consenting to, how the data will be used, and how consent can be withdrawn. Open banking notices should be drafted so that consent is specific and revocable, and so that withdrawal is operationally effective, a right to withdraw that is not reflected in the PSP’s systems is a compliance gap waiting to be found.

These provisions sit at the intersection of the payments regime and data protection law (including the GDPR and the Austrian Datenschutzgesetz), and both should inform the drafting.

Agent and distributor agreements, new duties and drafting points

If customer T&Cs are the visible face of PSD3 PSR Austria compliance, agent and distributor agreements are where much of the hidden risk lives. The harmonised regime is expected to raise expectations around due diligence, ongoing oversight and liability allocation when a PSP uses agents or distributors to reach customers. For Austrian PSPs this means existing agent contracts, many of them drafted under the PSD2 regime, are likely to need substantive amendment rather than cosmetic updating. The drafting goal is an agreement that gives the PSP genuine control and visibility over the agent’s conduct while allocating liability in a way that is both commercially acceptable and enforceable.

Delegation, onboarding, oversight and termination rights

Agent agreements should begin with a robust onboarding framework: the due diligence the PSP performs before appointing an agent, the information the agent must provide, and the conditions the agent must satisfy on an ongoing basis. Oversight is the recurring obligation, the PSP needs contractual rights to monitor the agent’s conduct, to require periodic reporting, and to inspect or audit where necessary. Termination rights deserve particular attention: the agreement should allow the PSP to terminate promptly where the agent breaches regulatory requirements, fails an audit, or triggers a supervisory concern, because the PSP remains answerable to the FMA for the agent’s conduct.

A weak termination clause leaves the PSP tied to a non-compliant agent, which is precisely the exposure the new regime is designed to reduce.

Liability, indemnities and insurance expectations

Liability allocation between PSP and agent is a negotiation, not a formality. Clearer allocation rules give PSPs a stronger basis to require indemnities for losses caused by agent breaches, but there are limits: a PSP cannot contract away its own regulatory responsibility, and an indemnity that purports to pass through all liability regardless of fault may be commercially and legally fragile. The practical drafting position is a calibrated liability clause supported by an indemnity for the agent’s own breaches, backed where appropriate by an insurance requirement so that the indemnity is more than a paper promise.

For agents of any scale, a minimum insurance obligation, covering professional and operational risks relevant to the payment activity, converts contractual liability into recoverable value.

Data access, API SLAs and security obligations

Where agents or distributors access data or connect through interfaces, the agreement must impose clear security and service-level obligations. The harmonised access and interface requirements under the PSD3 PSR Austria framework are intended to give PSPs a standard to reference, and the contract should bind the agent to maintain availability, performance and security consistent with that standard. Security obligations should cover incident reporting, the agent must notify the PSP promptly of security incidents so the PSP can, in turn, meet its own notification duties to the FMA. A well-drafted agent agreement treats data access and API performance as measurable, auditable obligations rather than aspirational commitments.

Practical redlines and sample clauses for PSD3 PSR Austria contracts

The sample clauses below are starting points for the PSD3 PSR Austria remediation. They illustrate structure and intent; they are not a substitute for tailored drafting under Austrian law, and each should be reviewed by qualified counsel before use. Where a clause reflects a conduct rule, align the final wording to the PSR text on EUR-Lex and the relevant EBA guidance once adopted; where it touches enforceability, test it against Austrian contract and consumer law.

SCA failure clause, sample and variants

A workable SCA liability clause makes the allocation explicit. A baseline formulation provides that, where strong customer authentication is required and the PSP fails to apply it, the PSP bears liability for the resulting unauthorised transaction, save where the customer has acted fraudulently. A more detailed variant adds a tiered structure: full PSP liability where SCA was not applied; a defined customer exposure where SCA was applied correctly but the customer failed to safeguard credentials; and no customer liability once the customer has notified the PSP of a lost or compromised instrument. The advantage of the tiered variant is precision and defensibility; its drawback is complexity, so it must be drafted in plain enough terms to satisfy transparency expectations.

Agent liability and indemnity clause

An agent indemnity clause should cover losses, claims and regulatory penalties arising from the agent’s breach of the agreement or of applicable payment rules. A balanced formulation provides that the agent indemnifies the PSP against losses caused by the agent’s own acts, omissions or regulatory breaches, with the indemnity supported by an obligation to maintain adequate insurance. A fallback negotiating position, often needed with larger agents, introduces a liability cap for certain categories of loss while preserving uncapped liability for fraud, wilful misconduct and regulatory breaches that expose the PSP to supervisory action. The cap makes the agreement commercially acceptable; the carve-outs preserve the PSP’s protection where it matters most.

Note that under Austrian law certain exclusions or limitations of liability (for example for intent or gross negligence) may be ineffective, so the drafting must respect those limits.

API SLA and audit right clause

An API service-level clause should commit the counterparty to defined availability and performance levels consistent with the harmonised access and interface requirements, with reporting obligations and remedies for persistent underperformance. Pair the SLA with an audit right that allows the PSP to verify compliance, inspect relevant records, and require remediation within a defined period. Together these clauses turn open banking connectivity from an informal arrangement into an enforceable, measurable obligation, essential when the PSP remains accountable to the FMA for the overall service.

Operational and compliance checklist for the roll-out

Contract remediation is only one workstream in a broader PSD3 PSR Austria programme, and it needs to be sequenced with product, technology and compliance changes. Treat the roll-out as a cross-functional project with a single owner and a backward-planned timeline anchored to the confirmed application date.

Internal change plan, legal, product and operations

  • Legal review. Inventory every affected contract, customer T&Cs, agent and distributor agreements, outsourcing and API agreements, and map each to the relevant PSD3 or PSR obligation once the texts are finalised.
  • Product impact. Assess how authentication flows, refund processes and consent journeys must change, and align the contract wording to the actual product behaviour.
  • Technology changes. Update SCA flows, implement or update access/interface standards, and build operationally effective consent-withdrawal functionality.
  • Agent remediation. Reissue or amend agent contracts to reflect the new oversight, liability and security obligations.
  • Customer communications. Prepare clear notices explaining changes to T&Cs, with sufficient lead time and consistent with the change-of-terms procedures applicable under the framework.
  • Training and audit. Train staff on the new obligations and schedule internal audits to verify implementation.

Supervisory notifications and recordkeeping

Engagement with the FMA is part of the programme, not an afterthought. Material changes to licences, to the use of agents, and to outsourcing arrangements can trigger notification obligations, and a prudent PSP identifies these early and engages the supervisor before implementing significant changes. Maintain a clear record of the contractual changes made, the rationale for liability and indemnity positions, and the provenance of any clause language, so that the PSP can demonstrate a considered compliance process if the FMA inspects. Recordkeeping is both a compliance obligation and the PSP’s best defence in a supervisory review.

What to negotiate with partners and agents

When the drafting moves into negotiation, keep the commercial and regulatory priorities in view:

  • Liability caps and carve-outs. Agree caps where commercially necessary, but preserve uncapped liability for fraud, wilful misconduct and regulatory breaches, bearing in mind Austrian limits on excluding liability for intent and gross negligence.
  • Insurance. Require a minimum insurance level proportionate to the payment activity and the agent’s size.
  • Audit frequency. Secure audit rights with a cadence that reflects the risk, not a one-off entitlement.
  • Subcontracting. Control the agent’s ability to subcontract, and ensure obligations flow down.
  • Exit mechanics. Negotiate clean termination and transition provisions, including who holds the risk on legacy payments.
  • Transitional liability. Address liability for transactions that straddle the old and new regimes.

Conclusion and next steps for PSD3 PSR Austria compliance

PSD3 PSR Austria is an upcoming compliance exercise that converts regulatory text into contract work: customer T&Cs, agent and distributor agreements, liability matrices, SCA clauses, refund disclosures and open banking terms are all likely to need revision, and the split between a directly applicable regulation and a transposed directive will dictate the sequence. The PSPs that move early, inventorying contracts, preparing PSR-driven clauses in draft and tracking the Austrian implementing law for PSD3-driven clauses, will reach the eventual application date with an enforceable, defensible contractual estate rather than a remediation backlog.

Treat the sample clauses here as a foundation, verify every obligation against the official sources once the texts are final, and run final drafts with qualified Austrian counsel before publication or signature.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Roman Hager at WMWP – Act Legal Austria, a member of the Global Law Experts network.

Sources

  1. European Commission, Payment services
  2. EUR-Lex (EU law portal)
  3. European Banking Authority (EBA)
  4. Austrian Legal Information System (RIS)
  5. Austrian Financial Market Authority (FMA)
  6. Oesterreichische Nationalbank (OeNB)
  7. Österreichischer Rechtsanwaltskammertag (Austrian Bar / ÖRAK)
  8. University of Vienna, Faculty of Law

FAQs

When will PSD3 and the PSR start applying in Austria?
The PSD3 and PSR package was proposed by the European Commission in 2023 and remains under negotiation; it has not yet been finally adopted. Once adopted, the PSR will apply directly in Austria from its stated application date, and PSD3 will require national implementing measures within its transposition window. Because the exact dates depend on the final adopted texts, confirm them against EUR-Lex and the European Commission’s payment services pages, and monitor RIS and the FMA for Austrian notices.
PSD3 is a proposed directive that Austria would transpose into national law, chiefly covering authorisation and licensing matters, while the PSR is a proposed regulation that would apply directly without transposition and carry most of the conduct and operational rules. For PSD3 PSR Austria compliance, this means PSR-driven clauses can be prepared to align with the regulation, whereas PSD3-driven clauses should track the Austrian implementing legislation.
Customer T&Cs are likely to need updated definitions for AISPs and PISPs, revised strong customer authentication clauses, a restructured liability matrix for unauthorised payments and SCA failures, clearer refund and reversal timeframes, and transparent consent and consent-withdrawal provisions for open banking. Each change must be both compliant with the harmonised regime and enforceable under Austrian law.
The harmonised regime is expected to raise expectations on due diligence, ongoing oversight, audit and termination, and to clarify how liability is allocated between PSP and agent. Austrian PSPs should expect to amend existing agent agreements to add stronger onboarding, monitoring and incident-reporting duties, calibrated indemnities and insurance requirements, and prompt termination rights for regulatory breaches.
Material changes to licences, agents and outsourcing arrangements can trigger notification obligations to the FMA under the applicable Austrian framework. The prudent course under PSD3 PSR Austria is to identify notifiable changes early and engage the supervisor before implementing significant contractual or structural changes, keeping clear records of the changes and their rationale.
No. A PSP cannot contract away its own regulatory responsibility, and a clause that attempts to pass through all liability regardless of fault may be unenforceable under Austrian law and inconsistent with supervisory expectations. The workable position is a calibrated liability allocation supported by indemnities and insurance, with carve-outs that preserve protection for fraud and regulatory breaches.
The sample clauses in this article are starting points only. They must be tailored to Austrian law, aligned to the final PSD3 and PSR texts once adopted, and reviewed by qualified counsel before use. Enforceability depends on the surrounding contract, the applicable consumer protection rules and the specific commercial context.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

PSD3 and the Payment Services Regulation (PSR), Austria 2026: What Banks & Fintechs Must Change in Customer & Agent Contracts

Send welcome message

Custom Message