Connect with us

WINNING COMBINATION - SOFTSWISS develops innovative iGaming software products for online casino, sports betting, and beyond. Our products can be delivered as standalone solutions or combined into a single iGaming Platform.

The future of sports betting: BETBY sportsbook is focused on innovation through deep industry knowledge, state-of-the-art software & endless customization possibilities.

Compliance Updates

Fintech startups and banks face off on new rules over European payments and data access

Published

on

Reading Time: 5 minutes

A huge group of over 70 European fintech companies is sending caution that new EU rules on payments processing could unfairly pit them against large banks and ruin the industry if they are passed into law.

The rules that are a part of the European Union’s Payment Services Directive (PSD) would prohibit the practice of “screen scraping,” a usual practice applied by Fintechs to “scrape” display data from one application (like an online banking service) and display it on their own.

The fintech startups usually scrape data by logging into banking applications on account of their customers with sensitive data like passwords and PIN codes.

The 71 fintech firms argue in their manifesto that the prohibition on scraping is illogical and a backdoor method for traditional banks to claw back control as the Fintech revolution threatens to upend their business models.

However, banks are arguing that screen scraping is too dangerous and that customer data should only be accessible through bank-provided application programming interfaces (APIs) in the interest of customer security.

“The customer is in control of what can and cannot be shared with a third party, as the API is consent and permission-driven. Alternative technologies for sharing data exist, but are less robust and less secure than APIs,” said David Song, an EU affairs expert at UK Finance, a representation of over 300 firms providing banking, payments, and financial services in the United Kingdom.

Fintech companies, for their part, say that banks have an incentive to build semi-functional APIs that would tarnish fintech upstarts’ own quality of service and scare customers away from using their products, which at times compete directly with the services that banks offer to their clients.

“If we’re forced to use an API that doesn’t provide a good service, it will kill our business. We’ll have to use a low-quality interface that won’t meet our service needs and will drive customers away,” said Joan Burkovic of Bankin, a French fintech startup that helps customers manage their money and finances via an app that links to their existing bank accounts.

They also argue that a fallback option to screen scraping should necessarily be kept open in case a bank’s API fails.

“Without the fallback option, our business is effectively in the hands of banks. They’ll have full control over all the information they give to us and can even impose restrictions on how they send it. That goes entirely against the spirit of EU rules that guarantee technological neutrality for payments,” said Arturo González Mac Dowell, President & CEO of EuroBits, a payments aggregator headquartered in Spain.

Revised payment services directive

The European Union’s Payment Services Directive (PSD), originally passed in 2007, built a single market for cashless payments in Europe, making cross-border payments as easy and efficient for European consumers and businesses as domestic transfers.

It was revised in 2015 by the European Commission in part to promote more competition and digital innovation within the banking and payments sector.

Most importantly, the revised PSD (also known as PSD2) mandated that banks loosen their grip over customer account data and allow third parties to be able to access it with customers’ permission.

It is no secret that this will present a challenge to retail banks, who will lose their exclusive hold over customer data and be forced to innovate in both payments processing and customer data analytics, where many of their upstart competitors already have a significant lead.

“This presents banks with a challenge. At best, PSD2 puts at risk an important income stream for banks and at worst will relegate them to the status of a utility, acting as simple data holder,” said Jacqui Hatfield, former partner at the law firm Reed Smith, in an editorial for Banking Tech.

However, as is common practice in European financial regulation, a regulatory agency under the Commission’s authority was given the right to draft technical guidelines (such as the rules on screen scraping) that would come into effect after the general framework of the PSD2 was finalized and agreed among lawmakers.

The controversial ban on screen scraping was first tabled by the European Banking Authority, a London-based agency of the European Commission which has regulatory oversight over European banks, in February.

“The EBA is of the view that accessing accounts through screen scraping will no longer be allowed on the basis of a number of provisions under PSD2, especially the requirements on secure communication and on restrictions on [payments providers] in accessing data and information from accounts and transactions,” the agency said in its February proposal.

Banks agree.

“API-based solutions gain the benefits of device-based multi-factor authentication that is both safer and easy for consumers to use than typing codes into a form. Breach after breach has made clear that there is no such things as a ‘secure’ or ‘strong’ way to use passwords”, said the FIDO Alliance, an industry consortium of banks and payment services providers like Visa and MasterCard, in an open letter to EU lawmakers at the end of August.

The European Commission, which has final say over the proposed draft rules, has publicly disagreed with the EBA’s position and swooped in from above this summer to propose amendments to the guidelines, allowing for a “fall back” to screen scraping if banks’ APIs failed to provide fintech companies with reliable account data.

But in any case, the final rules will have to be vetted by both the European Parliament and finance ministers in the European Council, who have the right to veto them. It is expected by some that Council representatives from countries without a substantial fintech industry may push for a compromise between the Commission and EBA versions.

Why it matters for fintech startups

PSD2 falls into line with the Juncker Commission’s Digital Single Market strategy from 2014, in which it promised to break down barriers in the provision and sale of digital services and to ensure the free movement of data between consumers and companies in Europe.

The rules on digital payments are also envisaged to help break Europe’s longstanding dependency on bank finance. Many see the over-dominance of banks as an endemic problem to the growth of European capital markets and an important cause of the sovereign debt crises of 2010–2015.

However, the standoff on screen scraping suggests to some that large banks can still throw their weight around in lobbying EU laws aimed at increasing competition in financial services.

“The European Banking Authority has been behaving more like the European Banking Association on PSD2. It’s incredible that they haven’t met with any fintech companies at all to discuss their needs but are regularly taking meetings with banking associations on digital innovation,” said one fintech startup executive who declined to be named for the purposes of the article.

It has also shown that there is no single European rulebook dedicated to FinTech regulation, and is instead managed by a mix of national regulators and a constellation of institutions and agencies at the European level.

“It is striking to observe the large number of institutions currently commenting, regulating, drafting consulting, and exchanging ideas on fintech. There are already overlaps at European level, but more importantly there is already substantial regulatory divergence between EU countries,” wrote a team of three researchers from Brussels think-tank Bruegel for a discussion of EU finance ministers in Estonia this month.

However, it also pointed out that “in the European context, issues such as data privacy, cybersecurity, consumer protection and operational risks will be central importance for consumer acceptance.”

Still, the outstanding question is whether banks’ privacy concerns in the PSD2 are merely a Trojan horse to torpedo a nascent FinTech industry in Europe and to cling to their waning hold over customer account data.

“The bottom line is this: the Payment Services Directive 2 was designed in order to increase competition in the sphere of payments. Putting a ban screen scraping would undermine that principle”, said Nick Wallace of the Centre for Data Innovation.

The first parts of the PSD2 will come into force in all 28 Member States and the European Economic Area in January 2018. The Commission is expected to present its finalized set of rules on screen scraping in October or November, which will come into force 18 months after they are adopted by EU institutions.

Niji Narayan has been in the writing industry for well over a decade or so. He prides himself as one of the few survivors left in the world who have actually mastered the impossible art of copy editing. Niji graduated in Physics and obtained his Master’s degree in Communication and Journalism. He has always interested in sports writing and travel writing. He has written for numerous websites and his in-depth analytical articles top sports magazines like Cricket Today and Sports Today. He reports gaming industry headlines from all around the globe.

Advertisement
Advertisement

Advertisement

EveryMatrix at ICE 2025 in Barcelona: Explore advanced iGaming technologies and solutions, including Casino, Sports, Platform, Managed Services, and more. Visit EveryMatrix at stands 2G32, 5K10, and K36.

Advertisement

Launch your iGaming business swiftly and effortlessly with our comprehensive turnkey solutions

Trending (Top 7)

Discover the Magic of EuropeanGaming.eu – Your Gateway to the Gaming Universe

At the heart of the ever-evolving gaming and gambling industry lies EuropeanGaming.eu, a trailblazing online platform that has become the go-to destination for industry professionals, enthusiasts, and stakeholders. As part of HIPTHER, we’re redefining how the gaming world connects, informs, and inspires.

More Than News – A Hub of Insight and Innovation

Reaching over 300,000 readers monthly, EuropeanGaming.eu goes beyond headlines to deliver compelling stories, expert insights, and the latest industry news. From regulatory updates and compliance breakthroughs to the pulse-pounding world of esports and technological advancements, we provide comprehensive coverage of the topics that matter most:

  • Online and Land-Based Gaming
  • Betting and Esports
  • Regulatory and Compliance Updates
  • Cutting-Edge Technology in Gaming

Whether it’s daily news, exclusive interviews with industry leaders, in-depth event reports, or press releases that set the tone for the future, our content resonates with a global audience while maintaining a focus on Europe’s dynamic gaming market.

Bringing the Industry Together

Our impact doesn’t stop at digital content. EuropeanGaming.eu is a proud host of virtual meetups and industry-leading conferences that spark dialogue, foster collaboration, and drive innovation. Through detailed reports and live events, we create a space where operators, suppliers, regulators, and professional services come together to shape the future of gaming.

Why EuropeanGaming.eu?

At HIPTHER, we believe in empowering the gaming community with knowledge, connection, and opportunity. EuropeanGaming.eu embodies this spirit by serving as a one-stop resource for the latest trends, market developments, and global perspectives. Whether you’re an industry veteran, a rising operator, or a gaming enthusiast, this is where you find the stories that drive progress.

Get In Touch

Let’s shape the future of gaming together!


Copyright © 2015 - 2025
European Gaming is proudly part of HIPTHER. Registered in Romania under Proshirt SRL, Company Number: 2134306, EU VAT ID: RO21343605.
Office Address: Blvd. 1 Decembrie 1918 nr.5, Târgu Mureș, Romania

Join us as we celebrate a decade of delivering excellence and embrace the magic of what’s to come in 2025 and beyond!

We are constantly showing banners about important news regarding events and product launches. Please turn AdBlock off in order to see these areas.