Our Expert in Estonia
No results available
Who this guide is for: compliance leads, general counsel, founders and CTOs at EMIs, PIs, AISPs and PISPs operating in or entering Estonia. It covers the expected PSD3/PSR changes and timelines, concrete authorisation and operational implications, Finantsinspektsioon expectations, and a practical remediation checklist you can act on now.
PSD3 PSR Estonia is a defining regulatory shift for every e-money institution, payment institution, account information service provider and payment initiation service provider licensed or seeking to operate under Estonian supervision. The European Commission’s third-generation payment services framework is designed to replace the Second Payment Services Directive (PSD2) with a combined package: a new Payment Services Directive (PSD3) and a directly applicable Payment Services Regulation (PSR). At the time of writing, the package is still moving through the EU legislative process, so its final text and application dates should be confirmed before firms fix project deadlines.
For firms overseen by Finantsinspektsioon, the Estonian Financial Supervision and Resolution Authority, the reform means reviewing authorisation scope, strong customer authentication, fraud handling, open-banking data access and outsourcing controls ahead of the eventual transition milestones. This guide translates the EU-level proposals into concrete steps for Estonia-licensed payment and e-money firms.
The most important structural change under the psd3 psr estonia framework is legal form. PSD2 is a directive (Directive (EU) 2015/2366), which each Member State transposed into national law, in Estonia primarily through the Payment Institutions and E-money Institutions Act, the text of which is available on Riigi Teataja. Directives leave room for divergence between jurisdictions. The proposed new package splits the rules: PSD3 would remain a directive governing authorisation and supervision, while the Payment Services Regulation would apply directly across all Member States, harmonising conduct, consumer protection, SCA and fraud rules without the need for national transposition.
For Estonian firms, this dual structure would have practical consequences. Authorisation, licensing conditions and supervisory powers would continue to flow through national law implementing PSD3, administered by Finantsinspektsioon. But much of the operational rulebook, how you authenticate customers, how you handle fraud, how you grant account access to third parties, would sit in the directly applicable Regulation, leaving less room for local interpretation. The European Commission has framed the reform around broad objectives that include strengthening consumer protection against fraud, improving the functioning of open banking, and levelling the competitive field between banks and non-bank payment providers.
Several proposed innovations under the psd3 psr estonia package would require direct action from supervised firms:
Not everything changes. The fundamental architecture of European payment regulation carries over from PSD2. The concept of regulated payment services, the licensing gateway operated by national competent authorities such as Finantsinspektsioon, safeguarding of customer funds, and the EU passporting mechanism all persist. Account information services and payment initiation services remain regulated activities. Strong customer authentication remains the cornerstone of the fraud-prevention regime, even as its detailed application is refined. Firms that built robust PSD2 compliance programmes are not starting from zero; the psd2 to psd3 transition is an upgrade and re-scoping exercise rather than a wholesale rebuild. The key discipline is mapping each existing control against the revised requirements to identify genuine gaps.
Understanding the psd3 estonia timeline is the first practical step for any compliance lead. The legislative package is expected to move from adoption at EU level into an application period, with transitional arrangements designed to give existing authorised firms a defined window to align. Because the Payment Services Regulation would apply directly, its operational provisions would take effect on the dates set out in the Regulation itself rather than on the date any Estonian implementing measure is passed. The PSD3 directive, by contrast, must be transposed into Estonian law before its national provisions apply.
Firms should therefore track two clocks: the EU-level application date for the directly applicable Regulation, and the national transposition and any transitional relief published on Riigi Teataja.
Because exact application dates are set at EU level and reflected in national measures, and because the package is not yet finalised, firms should confirm current dates directly against the European Commission payment services pages and Finantsinspektsioon guidance before locking project deadlines. What matters operationally is that preparation can begin now, and the firms that begin gap analysis early will face the least disruption.
Finantsinspektsioon is the national competent authority responsible for authorising and supervising payment institutions and e-money institutions in Estonia. Once the PSD3/PSR package applies, industry observers expect the supervisor to issue practical guidance and update its application and reporting expectations, mirroring its established approach under PSD2. Existing authorisations are not expected to be automatically extinguished; instead, transitional provisions typically allow already-authorised firms to continue operating while they demonstrate compliance with the new framework within a defined period. The likely practical effect is that Finantsinspektsioon will expect firms to submit updated documentation confirming that governance, safeguarding, SCA and fraud arrangements meet the revised standards.
Early engagement, including pre-notification correspondence, is a reliable way to avoid a rushed, contested review as any deadline approaches.
Regardless of the precise external deadline, firms can run their internal psd3 estonia timeline on a disciplined schedule:
The authorisation dimension is where the psd3 psr estonia reforms will most directly affect a firm’s legal standing. PSD3 is expected to revisit the criteria for granting and maintaining a payment institution license Estonia holders rely on, and for the emi license Estonia e-money firms operate under. The proposed consolidation of the payment and e-money regimes means firms should not assume their existing permission scope maps cleanly onto the new categories. Some activities may be re-labelled; others may attract revised capital or safeguarding conditions. The correct starting point is a permission-by-permission review: list every regulated activity your firm currently performs, and confirm how each is likely to be treated under the new framework.
Capital and safeguarding are central to this review. PSD3 maintains the principle that customer funds must be protected, but firms should verify whether their safeguarding method, segregated accounts or an insurance/guarantee arrangement, continues to satisfy the revised expectations. Initial capital and own-funds requirements should be re-tested against the activities you intend to continue. Where the review reveals that your intended activity set falls outside your current authorisation, you may need to apply for an extended or new permission rather than a simple amendment.
A recurring practical question is whether a change requires a notification to Finantsinspektsioon or a fresh authorisation application. As a general rule, material changes to the nature, scope or scale of regulated activities, particularly adding a new payment service you are not currently authorised to provide, will require a new or extended authorisation, assessed against the full licensing criteria. Changes to governance, qualifying holdings, key function holders or outsourcing arrangements typically fall within the notification and prior-approval regime. Under the psd3 psr estonia framework, firms should treat any re-scoping triggered by new permitted-activity categories as a substantive matter warranting early dialogue with the supervisor, because misclassifying a change as a mere notification risks operating outside your permission.
PSD3 is expected to reinforce expectations on sound governance and internal control. Firms should confirm that the management body has clear accountability for payments compliance, that the compliance function has sufficient standing and resource, and that the risk framework explicitly addresses fraud, SCA failures and open-banking access. Documentation of these arrangements is what Finantsinspektsioon will assess. On capital, firms should refresh their own-funds calculations, stress the safeguarding arrangements against realistic volumes, and ensure that any insurance or comparable guarantee supporting the emi license Estonia or payment institution license Estonia permission remains valid and adequately sized. Where the firm relies on group support or outsourced functions, the governance file must show that responsibility and control remain with the licensed entity.
The table below summarises how the main authorisation types compare on the dimensions most affected by the psd3 psr estonia reforms. It is a high-level orientation aid; confirm current thresholds and conditions against Finantsinspektsioon guidance and the applicable legal texts before relying on them.
| Dimension | EMI (e-money institution) | PI (payment institution) | AISP / PISP |
|---|---|---|---|
| Core activity | Issuing e-money and providing payment services | Executing payment services (transfers, acquiring, remittance) | Account information (AISP) / payment initiation (PISP) |
| Initial capital | Higher tier reflecting e-money issuance | Tiered by permitted services | AISP: professional indemnity insurance or comparable guarantee in place of minimum capital; PISP: lower capital tier |
| Safeguarding | Required for funds received against e-money and payment services | Required for payment service funds held | AISP does not hold funds; PISP does not hold funds |
| Permitted activities | Broadest, including e-money issuance | Payment services only | Narrow, service-specific |
| Passporting | Yes, via EU passport | Yes, via EU passport | Yes, via EU passport |
| Anticipated PSD3 change | Regime consolidation; safeguarding re-verification | Revised permitted-activity categories; SCA and fraud rules | Improved data-access rights and access-interface obligations |
Open banking is one of the clearest areas of change under the psd3 psr estonia package. Account information service providers and payment initiation service providers depend on reliable access to customer accounts held at banks and other account servicing providers. PSD3 and the Regulation aim to reduce the friction that arose under PSD2 by tightening the obligations on account servicing providers to offer effective access, improving interface performance requirements, and giving customers clearer control through permission dashboards. For AISPs and PISPs already licensed or registered in Estonia, the core message is that regulated status persists, but the technical and contractual expectations around access are expected to become more prescriptive.
AISPs and PISPs authorised or registered in Estonia should confirm that their permission continues to cover their actual services under the new categories. AISPs operating on a registration basis and PISPs operating under authorisation both benefit from the EU passport, allowing them to serve customers across the single market on the basis of their Estonian permission. During any transition, firms should verify that existing passport notifications remain accurate and that any host-state activity is correctly documented. Where a firm intends to expand from pure account information into payment initiation, that is a scope change likely to require an extended authorisation rather than a notification, and open banking estonia providers should plan the supervisory engagement accordingly.
On the technical side, the psd3 psr estonia rules are expected to place renewed emphasis on the quality and availability of access interfaces. Account servicing providers must ensure their interfaces perform to defined standards, and third parties must be able to identify themselves reliably and access only the data the customer has permitted. Firms should review their consent-capture flows so that customer permissions are explicit, granular and easy to withdraw, in line with the permission-dashboard concept. Contractually, AISPs and PISPs should confirm that their data-processing arrangements, liability allocation with account servicing providers and incident-handling procedures reflect the revised obligations. Documenting the technical access method and the consent lifecycle will be central to demonstrating open banking estonia compliance to Finantsinspektsioon.
Strong customer authentication remains the operational heart of European payment security, and the psd3 psr estonia reforms are expected to refine rather than remove it. The European Banking Authority continues to publish guidelines and technical standards that shape how SCA is applied in practice, and firms should treat EBA material as the authoritative reference for the detail. The reforms place additional emphasis on accessibility, ensuring that authentication methods do not unfairly exclude vulnerable or disabled customers, alongside the existing requirement that at least two independent factors from knowledge, possession and inherence are combined for in-scope transactions.
Delivering strong customer authentication estonia compliance is as much a product and engineering challenge as a legal one. Firms should audit their authentication flows against current and anticipated expectations, confirm that applicable exemptions (such as low-value or transaction-risk-analysis exemptions) are being applied correctly and are properly evidenced, and test the customer experience to reduce friction without weakening security. Where authentication is delivered through a third party or an outsourced provider, the licensed firm remains accountable and must be able to demonstrate that the provider meets the standard. Accessibility should be built into the design so that alternative authentication routes exist for customers who cannot use a given factor.
Every exemption decision should be logged with a clear audit trail, because supervisors will expect to see the rationale.
The Payment Services Regulation is expected to strengthen consumer protection by broadening the circumstances in which fraud victims are entitled to reimbursement and by clarifying how liability is allocated between the customer, the payment service provider and, in some scenarios, other parties. Firms should build clear internal procedures for triaging fraud claims, determining liability, and paying reimbursement within any required timeframes. Robust transaction monitoring and information sharing on fraud indicators are complementary obligations, better detection reduces both losses and disputes. Practically, firms should update their fraud policy, define reimbursement decision criteria, train frontline staff, and maintain records that show each claim was handled consistently.
The psd3 psr estonia regime rewards firms that can evidence a disciplined, documented approach to fraud and reimbursement.
Payment firms rarely operate every function in-house. Cloud hosting, authentication services, fraud tooling and account-access infrastructure are routinely outsourced, which means the psd3 psr estonia obligations interact directly with the Digital Operational Resilience Act (DORA) regime governing ICT risk for financial entities, which applies from 17 January 2025. Estonian payment institutions and e-money institutions should treat operational resilience and outsourcing governance as a single, integrated workstream rather than two disconnected compliance projects, because supervisors will assess them together.
Outsourcing of material or critical functions triggers both governance obligations and, in defined cases, prior notification to Finantsinspektsioon. Firms should maintain an accurate outsourcing register, and their contracts with providers should include the clauses supervisors expect: audit and access rights, sub-outsourcing controls, data-location and security commitments, service levels, exit and termination provisions, and cooperation with the competent authority. The licensed entity cannot delegate its regulatory responsibility, so contracts must preserve the firm’s ability to oversee and, if necessary, exit the arrangement. Where a critical function is being outsourced or materially changed, plan the supervisory notification early rather than treating it as a formality at the end of the project.
Under the combined framework, firms must be able to detect, manage and report significant operational and security incidents. That means defined incident-classification criteria, escalation paths, tested response playbooks and clear reporting lines to Finantsinspektsioon within required timeframes. Periodic resilience testing, including scenario testing of key ICT systems and third-party dependencies, should form part of the annual control cycle so that the firm can evidence readiness rather than assert it.
The following remediation checklist converts the psd3 psr estonia considerations into accountable actions. Assign an owner and a target window to each item, and retain documentation for supervisory review.
Within the first three months, complete permission mapping, the gap analysis and safeguarding re-verification, and consider whether a notification or a new application is likely to be required. Between three and six months, remediate SCA and fraud systems, recalculate capital, refresh outsourcing contracts and prepare supervisory submissions. Between six and twelve months, finalise the amendment or notification for Finantsinspektsioon, update customer documentation, complete training, and finalise open-banking and incident-reporting changes. Firms entering the market for the first time should fold these steps into their initial authorisation project so that they launch aligned with the emerging psd3 psr estonia framework.
Finantsinspektsioon supervises through a mix of authorisation review, ongoing reporting, desk-based analysis and, where warranted, on-site inspection. Under the psd3 psr estonia regime, industry observers expect supervisory attention to concentrate on fraud performance, SCA implementation, safeguarding adequacy and the quality of open-banking access. Non-compliance can expose firms to supervisory measures ranging from remediation demands to financial penalties and, in serious cases, restrictions on activity. The most effective posture is proactive engagement: submit clear, well-evidenced documentation, notify material changes early, and respond promptly to information requests. Firms that treat the supervisor as a partner in the transition, rather than a hurdle at the end of it, tend to experience smoother reviews. For tailored support, see our Licensing lawyers, Estonia team.
The psd3 psr estonia transition is a defined, time-bound compliance exercise once the framework is finalised, not an open-ended one. EMIs, PIs, AISPs and PISPs that begin preparing now, mapping permissions, closing SCA and fraud gaps, re-verifying safeguarding, tightening outsourcing controls and engaging Finantsinspektsioon early, will complete the transition with the least disruption and the strongest supervisory relationship. The firms that wait risk a rushed, contested review against a fixed deadline. Global Law Experts can support you with a targeted PSD3/PSR readiness audit, draft licence amendments, and pre-notification correspondence to Finantsinspektsioon, so your Estonian payment or e-money business is aligned with the new framework as it takes shape.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Mark Gofaizen at Gofaizen & Sherle Fintech Lawyers, a member of the Global Law Experts network.
posted 6 seconds ago
posted 2 minutes ago
posted 3 minutes ago
posted 8 minutes ago
posted 10 minutes ago
posted 12 minutes ago
posted 17 minutes ago
posted 17 minutes ago
posted 20 minutes ago
posted 25 minutes ago
posted 28 minutes ago
posted 33 minutes ago
No results available
Find the right Legal Expert for your business
Send welcome message