Europe's payment rules are being rebuilt around two connected laws. PSD3 is the proposed directive for authorisation and supervision of payment institutions. The Payment Services Regulation, or PSR, is intended to place many conduct and consumer-protection rules directly into one EU regulation.
The European Parliament and Council reached a provisional political agreement on 27 November 2025. Council records show that the agreement was confirmed by Coreper in April 2026 while the legal texts continued through the formal adoption process. That distinction matters: a political agreement is a major step, but organisations still need the final published text, application dates and national implementation details before treating every proposal as law in force.
Why split the rules into a directive and a regulation?
The package is intended to modernise PSD2, reduce inconsistent national interpretation and respond to payment fraud, open-banking problems and changes in the market.
What customers are likely to notice
Fraud prevention is at the centre of the reform. The negotiated texts address stronger cooperation between payment providers, clearer responsibilities and protection against newer forms of manipulation, including cases where a criminal tricks someone into authorising a transfer.
Better sharing and use of fraud-related information within legal safeguards.
More attention to whether the account name matches the intended recipient.
More reliable access and clearer rules for account-information and payment-initiation services.
Clearer information about charges, cash access and payment terms.
Updated access rules intended to improve the position of non-bank payment providers.
The exact protection in any individual case will depend on the final text and facts. Customers should still pause before approving an unexpected payment request and should contact their provider through a trusted channel.
What payment firms should do now
Waiting for the final application date does not mean doing nothing. The sensible work is to understand where existing processes depend on PSD2 and which parts are likely to change.
Identify products, entities, agents and technology providers affected by the package.
Document how suspicious payments, payee checks, warnings and reimbursement cases are handled.
Measure reliability, permissions, customer journeys and fallback arrangements.
Find clauses and data-sharing practices tied to current PSD2 language.
Assign an owner to track publication, transition periods, technical standards and national transposition.
The practical conclusion
PSD3 and PSR are no longer distant ideas, but they should not be described as fully applicable rules before formal adoption and the relevant dates. The direction is clear: more consistent supervision, stronger fraud protection and a better-functioning payments market. The implementation details will decide how much work that creates for each organisation.
This article provides general information, not legal advice.
