Periodic update · new data 2026-08-25 · run wpm-2026-08-21Legal & Litigation
Finanstilsynet's supervisory finding this cycle is that certain account-servicing payment service providers breach PSD2's information-parity requirement, set out in Article 36 of the Regulatory Technical Standards on strong customer authentication and common and secure communication (Commission Delegated Regulation (EU) 2018/389), by supplying richer transaction categorisation within their own proprietary banking applications than through the PSD2 dedicated interface used by third-party account information service providers (AISPs). The finding is Tier 1 sourced, drawn directly from Finanstilsynet's own published PSD2 clarifications, and carries High confidence.
Article 36's information-parity standard exists to ensure that account-servicing payment service providers do not degrade the quality, breadth or usability of account data made available through the dedicated interface relative to what the same institution's own customer-facing channels provide. Finanstilsynet's finding that this is happening in practice, with respect to transaction categorisation specifically, moves this concern from a theoretical vulnerability in the PSD2 framework to a documented instance of it.
From a legal-risk perspective, this finding sits at an early stage of the enforcement continuum: Finanstilsynet has made a supervisory finding, but no named provider, fine, formal order, or litigation outcome has been identified this cycle. The finding nonetheless establishes a clear evidentiary and legal basis on which Finanstilsynet, or an affected third-party provider, could pursue further action, whether through direct supervisory measures against identified providers or a market-wide guidance update, although no such claims have been identified in the sourcing available this cycle. The finding specifically concerns account-servicing providers, which in the Norwegian market are predominantly bank entities that hold and administer the underlying payment accounts, as distinct from the non-bank payment institutions and e-money institutions that typically sit on the API-consuming, third-party-provider side of this particular relationship. This bank-versus-non-bank framing matters for remediation: any corrective action properly falls to the account-holding banks operating the dedicated interfaces, not to the third-party providers disadvantaged by the parity gap.
Because Norway is a full PSD2-implementing EEA member, the finding also carries signal value for supervisory practice beyond Norway's own borders: a national regulator identifying and publishing an information-parity deficiency in dedicated-interface implementations is a template other EEA supervisory authorities monitoring compliance with the same technical standard may find directly relevant, even though this cycle's evidentiary basis speaks specifically to the Norwegian market and no cross-jurisdictional enforcement coordination has been identified this cycle.
Whether Norwegian law affords a private right of action to a disadvantaged third-party provider for an Article 36 parity breach, as distinct from Finanstilsynet's own supervisory powers, has not been established in the sourcing available this cycle; this is a live legal question rather than a settled one, and it would typically depend on the specific transposition mechanics of the underlying EU technical standard into Norwegian administrative and civil law, which fall outside this cycle's evidentiary base. Absent primary legal analysis on this point, the finding should be read as a supervisory-enforcement development in the first instance, with any private-litigation dimension remaining speculative until further sourcing is obtained.
Outlook
The clearest next-cycle marker is whether Finanstilsynet escalates this finding into named-provider supervisory action, publishes updated market-wide technical guidance on the specific data fields or categorisation standards account-servicing providers must expose through the PSD2 interface, or leaves the finding as a standalone clarification without further follow-up. Any of the first two outcomes would represent a material escalation in this module's severity read; the third would suggest the finding functions primarily as an interpretive signal rather than the opening move of a supervisory case. Given the Tier 1 sourcing and High confidence already attached to the underlying finding, this is one of the stronger candidates in this cycle's Norway coverage for generating a follow-on, named-entity development in a subsequent cycle.