Payment Services Regulation (PSR) – between consumer protection and due diligence

14 July 2026 | Knowledge, News, The Right Focus

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Strengthened obligations for payment service providers

The PSR provides for a significant expansion of the obligations of payment service providers, covering both organisational and technological aspects. Financial institutions will be required to implement both more advanced transaction monitoring mechanisms and systems designed to detect high-risk transactions.

Particular emphasis has been placed on combating fraud involving manipulation, social engineering and the unauthorised impersonation of payment service provider staff. Consequently, banks will be required to continuously improve the security of their communication channels and to respond without delay to any indications that may suggest an attempted fraud.

Liability for unauthorised transactions

Despite the strengthening of user protection standards, the draft PSR does not introduce the principle of strict liability on the part of payment service providers for the consequences of all unauthorised transactions. The final form of the regulation in fact departs from earlier concepts that envisaged a far-reaching transfer of the risk of such transactions to financial institutions.

Whilst the regulation does maintain the principle of prompt reimbursement of the amount of an unauthorised transaction – by the end of the next business day at the latest, following the date on which the transaction is identified or a report is received – it significantly expands the list of exceptions to this rule. Under the proposed provisions, a provider may refuse to refund funds where it has objectively justified grounds to suspect that the user acted intentionally or with gross negligence, in particular with regard to the protection of the payment instrument or authentication credentials. At the same time, the bank is required to justify its refusal and to inform the user of the available means of redress.

This approach to liability reflects a desire to strike a balance between the interests of the consumer and the need to prevent abuse on the part of users as well.

Spoofing – a new basis for liability of payment service providers

The PSR also introduces significant provisions regarding so-called spoofing, i.e. situations involving the impersonation of specific entities and the misleading of a user as to the identity of the sender of a communication.

The draft limits the liability of payment service providers to cases in which the perpetrator directly impersonates a given financial institution. Automatic liability is excluded, however, in situations where the fraudster impersonates other entities operating outside the regulatory scope of the PSR. The right to a refund is available to the consumer only on condition that they promptly report the incident to both the provider and the police, and the provider has 15 business days in which to issue a refund or provide a reasoned refusal.

This solution takes into account the complexity of the modern digital environment, in which fraudulent schemes frequently involve multiple independent communication channels and entities beyond the control of a single payment service provider.

Shared responsibility in the digital ecosystem

A noteworthy development is the expansion of the range of entities involved in combating financial fraud. The PSR provides for an obligation of cooperation between payment service providers, digital platforms and telecommunications service providers. These entities will be required to respond to reports of fraudulent activity and to take measures aimed at eliminating it.

One example of such provisions is the obligation for the payee’s bank to verify, free of charge, that a bank account number (IBAN) matches the payee’s name or business name, and subsequently to inform the payer’s payment service provider of the result of that verification. This information is then passed to the person initiating the transfer by their own provider before that person is offered the opportunity to authorise the transaction. Importantly, this obligation covers all types of transfers, i.e. both standard credit transfers and instant credit transfers.

The extension of the scope of shared responsibility reflects the regulatory direction of building a comprehensive security framework covering the entire digital services ecosystem.

The importance of user due diligence

Despite a significant increase in the level of regulatory protection, the PSR makes clear that the security of payment transactions cannot be ensured solely through the actions of financial institutions. The behaviour of the user and adherence to basic precautionary principles remain of key importance.

The draft Regulation explicitly underlines the importance of education and the raising of awareness regarding the risks associated with the use of payment services. Users should in particular:

  • Verify the authenticity of communications and contact channels
  • Protect their authentication credentials
  • Avoid making decisions under pressure
  • Use only reliable communication channels

Failure to exercise due diligence may result in a reduction in the scope of protection afforded by the applicable provisions.

The PSR as part of the new payments market architecture

The PSR forms part of a broader legislative package that also includes the PSD3 Directive, the aim of which is to create a new, more coherent legal framework for the payment services market in the European Union that is adapted to the digital reality.

The new rules will be directly applicable in all Member States, which will contribute to further market harmonisation and to the standardisation of user protection standards.

The PSR should be viewed as an attempt to strike a balance between enhancing security and maintaining user accountability for their own actions. The Regulation strengthens the obligations of financial institutions and expands anti-fraud mechanisms, whilst stopping short of introducing a model of full and unlimited liability on the part of payment service providers.

Questions? Contact us

Latest Knowledge

NIS2 and the National Cybersecurity System Act in transport: what you need to do before October 2026

The amended Act on the National Cybersecurity System (UKSC) has been in force since 3 April 2026. For transport sector undertakings, this means a specific compliance timeline, including an obligation to register with the National Cybersecurity System (KSC) registry by 3 October 2026. Failure to do so may result in substantial financial penalties, coupled with the risk of personal liability for senior management. Not every undertaking, however, automatically falls within the scope of the new regime. Read on to find out whether your organisation is affected and what you need to do before the deadline for preparation.

Family foundations: the government has done the maths and presented the bill

Three years. That’s how long we’ve been waiting for what the Council of Ministers had seen in the data from the outset – and has now disclosed in its review of the Family Foundation Act. The document not only diagnoses the problems, but also previews substantial changes to rules that founders and their advisers treated as settled and stable. And therein lies a problem that goes far beyond tax matters. If the rules of the game are changed while the game is being played, there can be neither planning stability nor trust in the law. It is no coincidence that one of the greatest concerns among entrepreneurs considering setting up a foundation is not the level of taxation, but the stability of the legal framework – which today is once again being called into question.

What the new swiss franc act means for banks

We now have a new Act on Special Measures for the Adjudication of Cases Concerning Loan Agreements Denominated in or Indexed to the Swiss Franc. The provisions come into force 14 days after publication. So now is a good time to look at what lies ahead and what banks should be doing today.

New draft Pay Transparency Act – what has changed since December 2025?

A second version of the draft act on strengthening the application of the right to equal pay for equal work or work of equal value between men and women has now been published. It refines procedures and deadlines and introduces a new supervisory body. We have already discussed the changes affecting the recruitment stage and the three pillars of the forthcoming pay transparency framework, noting that Poland will miss the EU transposition deadline of 7 June 2026. Now, we take a closer look at the further changes, new developments and risks that have emerged in the latest, April version of the draft.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

“Withdraw from contract here” – what next for the new button in online shops, on trading platforms and in mobile apps?

From 19 June, national legislation was to require businesses in the European Union entering into distance contracts with consumers via an online interface to provide consumers with the option to withdraw from the contract via a dedicated function/button. However, due to Poland’s delay in transposing Directive 2023/2673, which requires the use of such a button, this obligation has been postponed in our country. We look at what remote contract withdrawal entails and which transactions the new feature will apply to.

Municipal master plans – new deadline, same old challenges

On 11 June 2026, the President signed into law a bill extending the deadline for municipalities to adopt their master plans (plany ogólne). The key deadline for adopting master plans was moved from 30 June to 31 August 2026. We examine the reasons behind this change and consider what the absence of a master plan might mean for potential investors and their future projects.

Record fines and the upcoming 21st sanctions package – what should businesses expect?

The past year has brought a series of enforcement actions that clearly signal a tightening approach by the Polish customs and revenue authorities towards breaches of the sanctions regime. Importantly, businesses should already be preparing for further changes, as the European Union has announced its 21st sanctions package and updated the list of designated persons and entities. We examine the key developments and offer guidance on how to minimise the risk of non-compliance.

Contact us:

Szymon Bolimowski

Szymon Bolimowski

Advocate / Senior Associate / Disputes of Financial Institutions

+48 888 461 965

s.bolimowski@kochanski.pl