Bring your own PSD2 license
When using Ockto's PSD2 services, most commonly Ockto will be the operating PSD2 provider that enables secure data sharing between your organisation and your end user. Ockto is licensed by the DNB to provide Account Information Services (Read more). In some cases, however, your organisation may already have an own PSD2 license. In such cases, it could be beneficial to operate your own license, for example due to:
-
Brand recognition - Using your own license will allow you to offer PSD2 without the name 'Ockto' being visible to the end user.
-
Company policy - Your organisation's policies may impose that no third-party PSD2 license should be used
Our platform supports a setup where you bring your own PSD2 license, and merely leverage the technical capabilities provided by Ockto. Whenever an own PSD2 license is used to offer PSD2 services, there are a number of requirements and responsibilities that deviate from a setup with Ockto's license.
|
Ockto's PSD2 license |
Your organisation's license |
|
|---|---|---|
|
Role of Ockto |
Ockto is a Third Party Provider (TPP) under the PSD2 regulation. This means that Ockto is retrieving the data on behalf of the user. |
Ockto is a Technical Service Provider (TSP) to your organisation. In other words, Ockto is a standard sub-processor contracted by you. |
|
Data sharing |
After Ockto has retrieved the PSD2 data, the user agrees to a GDPR data sharing action between Ockto and your organisation. The user also accepts the privacy and service conditions of Ockto |
The user shares the data directly with your organisation via PSD2. Only the service conditions of your organisation apply. |
|
Customer journey |
Ockto is shown in the frontend as the party delivering the PSD2 services. The terms of service and privacy statement of Ockto apply and have to be accepted. During the consent flow of the banks, the user will see that they are sharing their data with 'Ockto B.V.'. |
The name Ockto is not shown anywhere to the user. During the consent flow at the banks, uses will see they will be sharing their data with your organisation. Usually, the legal entity's name is shown to which the PSD2 license is registered. |
|
PSD2 compliance |
Ockto is reponsible for complying with the Customer Due Diligence (CDD), Transaction Monitoring (TM) and fraud reporting requirements set under the PSD2 regulation. |
Your organisation is reponsible for complying with the CDD, TM and fraud reporting requirements set under the PSD2 regulation. Ockto can provide advice and expertise. |