The strong customer authentication | FinTech online course #10

strong customer authentication | SCA | PayTechLaw | FinTech online course | sutthinon602

Strong Costumer Authentication (SCA) is a special form of authentication which is regulated in §§ 1 para. 24. 55 ZAG, which is based on Art. 97 PSD2. Authentication is used to check whether a person is also who he or she claims to be.

For electronic payment transactions, a SCA is required whenever the payer

  • accesses their payment account online,
  • initiates an electronic payment transaction, or
  • carries out, by means of remote access, an act involving the risk of payment fraud or other misuse.

Accordingly, the SCA obligation applies, for example, to credit card payments on the Internet or when accessing an online account. However, the obligation does not apply to payments by direct debit, even if the direct debit mandate is issued online. (Something different applies only to so-called e-mandates where the payer’s bank is involved in the issuing of the mandate). In fact, in the case of direct debit, the payment is initiated by the payee on the basis of the payer’s consent vis-à-vis the payee, their payment service provider or their own payment service provider. It is therefore not a payment transaction initiated by the payer.

The SCA requires at least two of the following elements to be applied:

  • “Knowledge”, in other words something that only the user knows,
  • “Possession”, i.e. something that only the user owns, or
  • “Inherence”, in other words something that is the user.

The elements used must be derived from different categories. Something that only the user knows can be a password or a PIN, for example. The category possession includes tokens and mobile phones. Ownership of the telephone can be proven, for example, by entering a transaction number (TAN) that was sent to the telephone by means of an SMS. The elements of the inherence category are personal or physical to the user, such as fingerprints or facial recognition..

A card payment in a shop can therefore be initiated, for example, with the card (possession element) and PIN (knowledge element).

But how come you do not always have to enter a PIN when paying by card in the supermarket? This is because the SCA is not necessary in all cases: Articles 10 to 20 of the Delegated Regulation (EU) 2018/389 on the Second Payment Services Directive (PSD2) provide for exemptions from the SCA obligation e.g. for

  • contactless payments,
  • unattended terminals for traffic and parking fees,
  • recipients deemed trustworthy by the payer, and
  • small value payments.

This means that a PIN does not have to be used for contactless card payments in the supermarket.

If the triggered electronic payment is a remote payment transaction, e.g. a transfer in online banking, the SCA must, according to Section 55 (2) ZAG, also be supplemented by a “dynamic link”, by means of which the payment transaction is linked to a concrete amount and the specific recipient. When sending a TAN by SMS, the payer must be informed, for example, of the amount and the payee for which this TAN is to apply. The TAN is then only valid for this one payment; any change to the payment data would invalidate the transmitted TAN.

Excluded from the requirement to apply SCA are payments for so-called MOTO orders, i.e. orders by mail order (letter, fax) and telephone.

 

LINK TO THE HOMEPAGE OF THE FINTECH ONLINE COURSE

 

Cover picture: Copyright © Adobe/ sutthinon602

 



By continuing, you accept our privacy policy.
You May Also Like
20. EU-Sanktionspaket gegen Russland: Was das für den Finanzsektor bedeutet 20th EU Sanctions Package against Russia: What It Means for the Financial Sector
Read More

20th EU Sanctions Package against Russia: What It Means for the Financial Sector

The EU’s 20th sanctions package against Russia increases the focus on sanctions circumvention via third countries, alternative payment channels and crypto structures. Banks, payment service providers and CASPs must strengthen their sanctions compliance with a stronger focus on payment flows, intermediaries and infrastructure risks.
Read More
Ist bei E-Geld ein Vertrag zwischen dem E-Geld-Herausgeber und der Akzeptanzstelle erforderlich? Is a contract between the e-money issuer and the merchant required for e-money?
Read More

Is a contract between the e-money issuer and the merchant required for e-money?

This article examines the European Commission’s controversial interpretation of Article 11(7) EMD2 regarding the definition of electronic money. It focuses on whether a contractual relationship between the e-money issuer and the accepting merchant is required for electronic money acceptance. The article concludes that Article 11(7) EMD2 does not establish a general contractual requirement for the acceptance of e-money.
Read More
Paris Blockchain Week 2026 – “The Bridge Between TradFi and Digital Assets”
Read More

Paris Blockchain Week 2026 – “The Bridge Between TradFi and Digital Assets”

Paris Blockchain Week 2026 highlighted the growing institutional adoption of digital assets. Under the theme “The Bridge Between TradFi and Digital Assets”, the event brought together leading players from traditional finance and the digital asset industry, focusing on tokenisation, stablecoins, MiCA and blockchain-based financial market infrastructures.
Read More