All articles

What PSD3's fee-transparency rules will require from your payment providers

PSD3 and its companion regulation will force providers to disclose every charge before a payment is initiated. That is a cleaner promise, not a verified charge. The rules mandate disclosure. They do not check a single transaction against it.

What PSD3's fee-transparency rules will require from your payment providers

Short answer

PSD3 and its companion regulation will force your payment providers to disclose every charge before a payment is initiated, including currency conversion and cash withdrawal fees. That is a real gain for transparency. It is also where most readers stop, and where the risk hides. A disclosed fee schedule is a promise about what you will be charged. It is not a check that the amount actually taken matched it. The rules mandate disclosure. They do not verify a single transaction. That gap is yours to close.

Here is where the rules stand and what they change.

QuestionPSD2 (current law)PSD3 and PSR (agreed, not yet in force)
Legal form of the conduct rulesA directive, transposed differently in each member stateThe conduct rules move into the PSR, a regulation that applies directly in every member state
What the directive still coversPSD2 covered both licensing and conductPSD3 covers authorisation, prudential supervision, and licensing
What the regulation coversNo regulation existed under PSD2The PSR covers conduct, strong customer authentication, transparency, open banking, and fraud liability
National variationMember states could vary the rules when transposingFull harmonisation, with discretion limited to supervision and authorisation
Fee disclosureExisted, but hidden fees persistedAll charges disclosed before initiation, currency conversion shown as a percentage mark-up, ATM fees disclosed
StatusIn forceprovisional agreement November 2025, texts published April 2026, expected to apply 2027 to 2028

What PSD3 and the PSR actually are

The European Commission published the reform on 28 June 2023 as two linked proposals. On the Parliament's own record, "On 28 June 2023, the Commission published two proposals: a proposal (PSD3) for an amendment to the current Payment Services Directive (PSD2), and a related proposal for the Payment Services Regulation (PSR)."

The two-part shape matters more than it looks. PSD3 is a directive, which means each member state writes it into national law. The PSR is a regulation, which applies directly across the whole EU with no national rewriting. The Commission split the old single directive on purpose. As one legal analysis puts it, "PSD3 (a directive requiring national transposition) will govern authorisations, prudential supervision, and licensing," while "The PSR (a regulation with direct effect at the Member State level) will govern conduct of business rules, including SCA, transparency, open banking standards, and fraud liability."

For fee transparency, that split has a practical consequence. The rules about what your providers must tell you, and when, sit in the PSR. They are the same in Dublin, Frankfurt, and Madrid, and they take effect without waiting on any national parliament. This is the part of the package that reaches into how you are charged.

Disclosure is not verification

Now the part almost no one writes about.

The transparency rules are disclosure rules. They govern what a provider must tell you before you pay. The Parliament's own summary of the deal states that "Customers should be properly informed about all charges prior to the initiation of a payment." The named examples are exactly the fees that go unexamined, including "currency conversion charges or any fixed fees for cash withdrawal at automatic telling machines."

That is a schedule. It is what the provider says it will charge. It is a promise, published in advance, in a clearer format than PSD2 ever required. It is genuinely better for you.

It is also silent on the one question that decides whether the promise was kept. Did the amount actually charged, on this transaction, match the schedule the provider disclosed? Nothing in the rules answers that. No provision requires any party to compare the fee taken against the fee disclosed, transaction by transaction, and flag the ones that drift. Disclosure creates the reference. It does not check anything against it.

The gap is not hypothetical. A rate can be disclosed correctly and applied wrongly. A currency mark-up quoted at one percentage can post at another. A cash withdrawal fee published as fixed can arrive with an extra line. A schedule that is accurate on the website tells you nothing about the ten thousand charges that settled last month. The disclosure and the charge are two different things, produced by two different systems, and the rules only govern the first one.

So the reform gives you a cleaner promise and leaves the auditing of it entirely to you. That is the work that does not disappear when PSD3 arrives. It grows, because now there is a documented schedule to hold every charge against, and no one checking whether they match.

The specific fees the rules put on the table

The reform names the charges that have been hardest to see. Currency conversion is the headline. Under the agreed texts, a provider has to show currency conversion costs before you commit, and show them in a way you can compare, expressed as a percentage mark-up over a reference rate such as the latest available European Central Bank euro rate. A percentage over a public benchmark is a number you can independently reconstruct, which is the point.

Cash withdrawal charges are named directly, so an ATM fee has to be disclosed regardless of who operates the machine. The reform also widens the ban on surcharging. One analysis notes the "ban on surcharging is extended explicitly to credit transfers and direct debits in all EU currencies," closing a gap where extra charges could be added on payment types the old rules left ambiguous.

Read together, these provisions do one consistent thing. They turn vague or buried charges into stated numbers, tied to public references, disclosed before the money moves. They make every fee something you could check. They do not check it for you.

Why the EU decided PSD2 was not enough

The reform exists because the last one left fees hidden. The Parliament put the point in the headline of its own announcement of the deal: "Payment services deal: More protection from online fraud and hidden fees." Hidden fees are named as a problem the previous regime failed to solve, which is why the new one tightens disclosure and moves it into a directly applicable regulation.

The shift from directive to regulation is itself a statement. Conduct rules that member states could interpret and soften during transposition now apply uniformly. One legal summary describes the aim as "greater harmonisation, consistent enforcement and legal certainty for market participants operating on a cross-border basis." For a company operating across several EU markets, the transparency your providers owe you stops depending on which country's version of the law they answer to.

Where the rules stand, precisely

This is the part to state carefully, because it is easy to get wrong in both directions.

PSD3 and the PSR are agreed but not yet in force. Parliament and Council reached a provisional political agreement on 27 November 2025, then published the final compromise texts on 23 April 2026. The Parliament's own record confirms the milestone: "On 27 November 2025, after negotiations, the Parliament and the Council reached a provisional political agreement on PSR and PSD3."

The package is not law yet. On the Parliament's own words, "The deal needs to be formally adopted by Parliament and Council before it can come into force." After that comes publication in the Official Journal, then a phased application. The regulation is set to apply months after entry into force, and member states get time to transpose the directive, which puts practical application across 2027 and 2028 depending on the provision.

So the honest reading is this. The direction is settled and the texts are public. The dates are not fully fixed, and the rules do not bind your providers today. The transparency they promise is coming, on a timeline measured in years, not weeks. The verification gap they leave is already here.

What this means for your finance team

Two things follow, and they point the same way.

First, a disclosed schedule is only useful if something holds charges against it. When your providers publish clearer fee terms, that document becomes the reference for an audit that the rules do not perform. The better the disclosure, the more valuable the check, because now there is a precise, provider-stated number to catch a deviation against.

Second, the work is per transaction, not per policy. Reading your provider's new fee page once tells you what they promised. It does not tell you what they charged on the thousands of payments that settled since. Only a transaction-level comparison does that, and only that comparison turns a disclosure rule into money kept.

That is the job Bluefyn is built for. Bluefyn verifies that providers charge exactly what they agreed to charge. It reconstructs the contract, or the disclosed schedule, into an expected charge for every transaction, compares it to what was actually taken, and flags the gaps. It analyzes transaction and provider data. It never moves, holds, or custodies funds. When PSD3 hands you a cleaner promise, reconstructing the expected charge for every transaction is what confirms the promise was kept.

PSD3 will make the fees easier to read. It will not make them correct. Regulation can require a number to be shown. It cannot require the number to be right on your account. That last step, the one the rules leave out, is the fee audit itself.

Frequently asked questions

What is the current status of PSD3?

PSD3 and the PSR are agreed but not yet in force. Parliament and Council reached a provisional political agreement in November 2025, and the Council published the final compromise texts in April 2026. The package still needs formal adoption and publication in the Official Journal, after which it applies on a phased timeline expected to run across 2027 and 2028. It does not bind payment providers today.

What is the difference between PSD2 and PSD3?

PSD2 is a single directive that each member state wrote into its own law, which let the rules vary by country. The reform splits that into two instruments. PSD3 is a directive covering authorisation, supervision, and licensing. The PSR is a regulation that applies directly across the EU and carries the conduct rules, including transparency, strong customer authentication, open banking, and fraud liability. The fee-transparency requirements live in the PSR.

What do PSD3 and the PSR require about fees?

Providers must inform customers about all charges before a payment is initiated. Named examples include currency conversion charges and cash withdrawal fees at ATMs. Currency conversion has to be shown as a percentage mark-up over a reference rate, such as the latest available European Central Bank euro rate, so it can be compared. The rules also extend the ban on surcharging to more payment types. All of these are disclosure requirements.

Does PSD3's fee-transparency rule mean disclosed fees are automatically correct?

No, and this is the key point. The rules require a provider to disclose its charges. They do not require anyone to check that the amount actually charged on each transaction matched what was disclosed. Disclosure produces a schedule, which is a promise. Confirming that every real charge matched that schedule is a separate task the rules do not perform. That verification is left to you.

Do the new rules apply outside the EU?

The rules bind payment services provided within the EU. If your providers operate in the EU, the transparency and conduct rules in the PSR reach the services they offer there, without national variation. A company outside the EU that uses EU-based providers, or serves EU customers through them, will see the disclosure improve on those flows. The verification gap is the same everywhere the rules apply.

PSD3PSRFee verificationPayment regulationEU payments
BF
Bluefyn Team
Bluefyn

Operators and engineers building the economic control plane for fintech infrastructure.

Run one benchmark. One contract.

Send one provider contract and a month of statements, in whatever format they exist. We reconstruct the pricing, verify the transactions, and show you the discrepancies on your own numbers.

Request access

Start with one contract. No integration required to see the first findings.

Bluefyn never moves, holds, or custodies funds.