Our Expert in Austria
No results available
PSD3 PSR Austria is the regulatory shift that payments teams across the country can no longer defer, because the European Union’s proposed third Payment Services Directive and the directly applicable Payment Services Regulation are set to reshape how banks and fintechs contract with customers and agents. The new framework is intended to replace PSD2 with a combination of a directive (requiring national legislative change) and a regulation (applying automatically, without transposition), and that split alone changes how Austrian payment service providers must draft, amend and renegotiate their contractual estate.
For in-house counsel, compliance officers and product-legal leads at Austrian banks, payment institutions (PIs), electronic money institutions (EMIs) and fintechs, the practical question is no longer whether to act but which clauses to rewrite and when. This article maps the anticipated PSD3 PSR Austria obligations to concrete contract amendments, customer terms and conditions, agent and distributor agreements, liability allocation, strong customer authentication, disclosures and open banking API terms, with sample clause language and a roll-out checklist.
Every regulatory claim below should be cross-checked against the official texts on EUR-Lex and the supervisory guidance of the Austrian Financial Market Authority (FMA) before you finalise drafting, because the package is still progressing through the EU legislative process and its final text and dates are subject to change.
This guide is written for the people who own the contractual and compliance risk inside Austrian payment businesses:
The European Commission published its proposals for a PSD3 and a PSR in June 2023 as part of its wider review of the EU payments framework, with the stated aim of modernising and strengthening the rules first introduced under PSD2. At the time of writing the package remains under negotiation between the European Parliament and the Council and has not been finally adopted. Because the precise application dates depend on the final adopted texts and any transitional periods, Austrian teams should confirm effective dates against the official publications on EUR-Lex and the European Commission’s payment services pages rather than rely on secondary summaries.
The practical takeaway for Austrian PSPs is that contractual remediation is a multi-month exercise and should be planned backwards from the eventual application date once it is confirmed.
The two instruments, once adopted, will behave very differently in the Austrian legal order. The PSR, as an EU regulation, will apply directly in Austria from its date of application, without the need for a national transposition statute. PSD3, as a directive, will require Austria to adapt its national law, the measures that currently implement PSD2, principally the Zahlungsdienstegesetz 2018 (ZaDiG 2018), within the transposition window set by the directive. Compliance teams should monitor the Austrian Legal Information System (RIS) for the national implementing legislation and any amendments to existing payment services law, and the FMA’s guidance pages for supervisory expectations and notification requirements.
Once the final CELEX numbers for PSD3 and the PSR are published, cite the exact articles rather than working from the proposal text.
Direct applicability does not mean the PSR will operate in a vacuum. Austrian civil law, principally the Allgemeines Bürgerliches Gesetzbuch (ABGB), continues to govern contract formation, interpretation, the enforceability of limitation-of-liability clauses and consumer protection baselines (for example under the Konsumentenschutzgesetz, KSchG) that sit alongside the harmonised regime. In other words, a clause can be fully compliant with the PSR’s substantive payment rules yet still be vulnerable under Austrian rules on unfair terms or general contract law. The PSD3 PSR Austria analysis therefore has two layers: the harmonised EU obligations that apply directly, and the national law that determines how those obligations are packaged into enforceable contract terms.
Both must be satisfied for a customer T&C or agent agreement to stand up in practice.
The single most important structural change proposed relative to PSD2 is the division of the regime into two legal instruments. Under PSD2, nearly all the substantive rules sat in a directive that each Member State transposed, which produced divergence in how obligations were implemented across the Union. The proposed PSD3 PSR Austria framework separates the material: the PSR would carry the directly applicable conduct and operational rules, while PSD3 would govern matters that remain tied to national law, such as authorisation and the licensing architecture. This design is intended to reduce fragmentation and give PSPs operating across borders a more uniform rulebook.
For Austrian PSPs the regulation-versus-directive distinction has concrete drafting consequences. Where an obligation sits in the PSR, it will apply from the application date regardless of the state of Austrian implementing legislation, so customer-facing clauses that reflect PSR conduct rules can and should be aligned to the regulation directly. Where an obligation sits in PSD3, the exact wording of the national transposing law matters, and contract drafting may need to wait for or track the Austrian statute. A prudent approach is to prepare PSR-driven clauses in draft and build in a review trigger for PSD3-driven clauses once the national implementing measures appear in RIS.
Several areas remain anchored in Austrian law even under a harmonised regime. Civil liability mechanics, how damages are quantified, how indemnities are construed, and whether a liability cap is enforceable, are governed by Austrian contract law and judicial interpretation. Authorisation and ongoing supervision run through the FMA, whose guidance shapes what notifications are required and how agent oversight is assessed in practice. Consumer protection rules that pre-date the payments framework continue to apply to the extent they are not displaced by the harmonised regime.
The result is that a competent PSD3 PSR Austria contract review is never a pure copy-paste of EU text; it is a translation exercise that respects the Austrian legal environment in which the contract will be enforced.
| Topic | PSD2 (baseline) | PSD3 / PSR (proposed changes) |
|---|---|---|
| Legal form | Directive (transposed into national law) | PSD3 (Directive) + PSR (Regulation, directly applicable) |
| Scope | Payment services, PSP authorisation | Revised scope; clearer rules for AIS/PIS, strengthened consumer protections |
| Strong Customer Authentication (SCA) | EBA RTS; varying national approaches | Refined SCA obligations; clearer liability for SCA failures |
| Agent / distributor rules | Nationally implemented | More harmonised due diligence, oversight and liability allocation |
| Liability for unauthorised payments | PSP/customer split under PSD2 | Strengthened PSP obligations; further AISP/PISP liability clarifications |
| Open banking / APIs | PSD2 interfaces, varying implementations | More harmonised access and interface requirements |
Customer T&Cs are the most visible part of the PSD3 PSR Austria remediation, and the exercise is granular. A clause-by-clause review should start with definitions: the agreement must correctly describe payment initiation service providers (PISPs) and account information service providers (AISPs), the services they provide, and how the customer interacts with them. From there the review moves through the authentication process, the liability matrix for unauthorised transactions, notification and refund timelines, consent and consent-withdrawal mechanics, dispute resolution for billing errors, and the disclosure of fees and exchange rates. Each of these touchpoints maps to a specific obligation in the harmonised regime, and each needs wording that is both compliant and enforceable under Austrian law.
Strong customer authentication remains central to payment security, and the proposed PSD3 PSR Austria framework refines the obligations that PSD2 introduced. Your customer T&Cs should clearly set out when SCA applies, what the customer is required to do to complete authentication, and the circumstances in which an exemption may apply so that a transaction can proceed without a full authentication challenge. The European Banking Authority’s technical standards and guidance on SCA drive much of the detail here, and contract wording should remain consistent with those standards rather than paraphrasing them loosely.
Critically, the clause should allocate responsibility fairly: where the PSP fails to apply SCA when required, the regime places a stricter liability burden on the PSP, and the T&Cs should not attempt to contract around that outcome. Equally, the clause should spell out the customer’s own obligations, safeguarding credentials and devices, because those obligations feed into the liability analysis for unauthorised transactions.
The liability matrix is where the commercial and legal stakes are highest. Under the harmonised regime the PSP bears a heavier burden for unauthorised payments, particularly where it has not correctly applied strong customer authentication. Your T&Cs should contain a clear, structured liability clause that distinguishes between: transactions where SCA was correctly applied; transactions where SCA was not applied when it should have been; and transactions involving gross negligence or fraud on the customer’s side. The clause must also address the interaction with AISPs and PISPs, because the new framework clarifies how liability is allocated when a third-party provider is in the chain.
A common drafting error is to write a liability clause that is internally coherent but exceeds what Austrian law permits a PSP to shift onto a consumer; that error produces an unenforceable term and leaves the PSP exposed. The safer path is a layered clause that tracks the regime’s allocation and is tested against Austrian unfair-terms rules.
Customers are entitled to clear information on how and when refunds and reversals operate, and the PSD3 PSR Austria rules place a premium on transparent timeframes. Your T&Cs should state the circumstances in which a refund is available, the deadline by which the PSP will process it, and the information the customer must provide to trigger it. Where a transaction is reversed, the agreement should explain the mechanics and the timing so the customer is not left guessing. Vague or open-ended refund language is both a compliance risk and a dispute generator; precise, dated commitments reduce complaints and give the PSP a defensible position.
Open banking turns on consent, and the contract must make that consent architecture visible. Where an AISP accesses account information or a PISP initiates a payment, the customer’s consent is the legal gateway, and the T&Cs should explain what the customer is consenting to, how the data will be used, and how consent can be withdrawn. Open banking notices should be drafted so that consent is specific and revocable, and so that withdrawal is operationally effective, a right to withdraw that is not reflected in the PSP’s systems is a compliance gap waiting to be found.
These provisions sit at the intersection of the payments regime and data protection law (including the GDPR and the Austrian Datenschutzgesetz), and both should inform the drafting.
If customer T&Cs are the visible face of PSD3 PSR Austria compliance, agent and distributor agreements are where much of the hidden risk lives. The harmonised regime is expected to raise expectations around due diligence, ongoing oversight and liability allocation when a PSP uses agents or distributors to reach customers. For Austrian PSPs this means existing agent contracts, many of them drafted under the PSD2 regime, are likely to need substantive amendment rather than cosmetic updating. The drafting goal is an agreement that gives the PSP genuine control and visibility over the agent’s conduct while allocating liability in a way that is both commercially acceptable and enforceable.
Agent agreements should begin with a robust onboarding framework: the due diligence the PSP performs before appointing an agent, the information the agent must provide, and the conditions the agent must satisfy on an ongoing basis. Oversight is the recurring obligation, the PSP needs contractual rights to monitor the agent’s conduct, to require periodic reporting, and to inspect or audit where necessary. Termination rights deserve particular attention: the agreement should allow the PSP to terminate promptly where the agent breaches regulatory requirements, fails an audit, or triggers a supervisory concern, because the PSP remains answerable to the FMA for the agent’s conduct.
A weak termination clause leaves the PSP tied to a non-compliant agent, which is precisely the exposure the new regime is designed to reduce.
Liability allocation between PSP and agent is a negotiation, not a formality. Clearer allocation rules give PSPs a stronger basis to require indemnities for losses caused by agent breaches, but there are limits: a PSP cannot contract away its own regulatory responsibility, and an indemnity that purports to pass through all liability regardless of fault may be commercially and legally fragile. The practical drafting position is a calibrated liability clause supported by an indemnity for the agent’s own breaches, backed where appropriate by an insurance requirement so that the indemnity is more than a paper promise.
For agents of any scale, a minimum insurance obligation, covering professional and operational risks relevant to the payment activity, converts contractual liability into recoverable value.
Where agents or distributors access data or connect through interfaces, the agreement must impose clear security and service-level obligations. The harmonised access and interface requirements under the PSD3 PSR Austria framework are intended to give PSPs a standard to reference, and the contract should bind the agent to maintain availability, performance and security consistent with that standard. Security obligations should cover incident reporting, the agent must notify the PSP promptly of security incidents so the PSP can, in turn, meet its own notification duties to the FMA. A well-drafted agent agreement treats data access and API performance as measurable, auditable obligations rather than aspirational commitments.
The sample clauses below are starting points for the PSD3 PSR Austria remediation. They illustrate structure and intent; they are not a substitute for tailored drafting under Austrian law, and each should be reviewed by qualified counsel before use. Where a clause reflects a conduct rule, align the final wording to the PSR text on EUR-Lex and the relevant EBA guidance once adopted; where it touches enforceability, test it against Austrian contract and consumer law.
A workable SCA liability clause makes the allocation explicit. A baseline formulation provides that, where strong customer authentication is required and the PSP fails to apply it, the PSP bears liability for the resulting unauthorised transaction, save where the customer has acted fraudulently. A more detailed variant adds a tiered structure: full PSP liability where SCA was not applied; a defined customer exposure where SCA was applied correctly but the customer failed to safeguard credentials; and no customer liability once the customer has notified the PSP of a lost or compromised instrument. The advantage of the tiered variant is precision and defensibility; its drawback is complexity, so it must be drafted in plain enough terms to satisfy transparency expectations.
An agent indemnity clause should cover losses, claims and regulatory penalties arising from the agent’s breach of the agreement or of applicable payment rules. A balanced formulation provides that the agent indemnifies the PSP against losses caused by the agent’s own acts, omissions or regulatory breaches, with the indemnity supported by an obligation to maintain adequate insurance. A fallback negotiating position, often needed with larger agents, introduces a liability cap for certain categories of loss while preserving uncapped liability for fraud, wilful misconduct and regulatory breaches that expose the PSP to supervisory action. The cap makes the agreement commercially acceptable; the carve-outs preserve the PSP’s protection where it matters most.
Note that under Austrian law certain exclusions or limitations of liability (for example for intent or gross negligence) may be ineffective, so the drafting must respect those limits.
An API service-level clause should commit the counterparty to defined availability and performance levels consistent with the harmonised access and interface requirements, with reporting obligations and remedies for persistent underperformance. Pair the SLA with an audit right that allows the PSP to verify compliance, inspect relevant records, and require remediation within a defined period. Together these clauses turn open banking connectivity from an informal arrangement into an enforceable, measurable obligation, essential when the PSP remains accountable to the FMA for the overall service.
Contract remediation is only one workstream in a broader PSD3 PSR Austria programme, and it needs to be sequenced with product, technology and compliance changes. Treat the roll-out as a cross-functional project with a single owner and a backward-planned timeline anchored to the confirmed application date.
Engagement with the FMA is part of the programme, not an afterthought. Material changes to licences, to the use of agents, and to outsourcing arrangements can trigger notification obligations, and a prudent PSP identifies these early and engages the supervisor before implementing significant changes. Maintain a clear record of the contractual changes made, the rationale for liability and indemnity positions, and the provenance of any clause language, so that the PSP can demonstrate a considered compliance process if the FMA inspects. Recordkeeping is both a compliance obligation and the PSP’s best defence in a supervisory review.
When the drafting moves into negotiation, keep the commercial and regulatory priorities in view:
PSD3 PSR Austria is an upcoming compliance exercise that converts regulatory text into contract work: customer T&Cs, agent and distributor agreements, liability matrices, SCA clauses, refund disclosures and open banking terms are all likely to need revision, and the split between a directly applicable regulation and a transposed directive will dictate the sequence. The PSPs that move early, inventorying contracts, preparing PSR-driven clauses in draft and tracking the Austrian implementing law for PSD3-driven clauses, will reach the eventual application date with an enforceable, defensible contractual estate rather than a remediation backlog.
Treat the sample clauses here as a foundation, verify every obligation against the official sources once the texts are final, and run final drafts with qualified Austrian counsel before publication or signature.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Roman Hager at WMWP – Act Legal Austria, a member of the Global Law Experts network.
posted 6 minutes ago
posted 37 minutes ago
posted 37 minutes ago
posted 40 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message