PSD2 Compliance?

Just had an email from PayPal telling me that my checkout needs to be updated to confirm with PSD2 - whatever that is. Here’s some of the email below:

“As a business accepting card payments, your online checkout will need upgrading to comply with a new European Union directive requiring Strong Customer Authentication (SCA). The directive applies from 14 September 2019, but card issuers are working towards SCA by April so that their systems are fully operational by the deadline.”

“What you need to do?
Because you’re using a PayPal Pro direct solution to accept card payments on your website, you’ll need to update your online checkout to meet card issuers’ PSD2 obligations. We recommend you integrate, test and launch your new authentication processes as soon as possible. Missing the deadline could lead to declined payments.”


Anyone shed any light on this? Thanks.

Comments
  • brettbrett FoxyCart Team
    Hi @Pecan. The short version of this is:
    * PSD2 is a big thing in the EU that'll eventually (potentially) lead to many changes in how different businesses and services can interact with banks on customers' behalf.
    * SCA in the context of PSD2, for all intents and purposes, means 3D Secure v2. Basically, there's new 3D Secure coming, which is great, because the old 3D Secure functionality … let's say it's not really as nice and clean as we'd all hope.

    We'll be focusing on implementing 3D Secure v2 in 2019, as details and documentation becomes available. So you won't have to worry about anything.

    If you're not sure what 3D Secure is, it's the "Verified by Visa" or "MasterCard SecureCode" functionality you may have seen in the past. The promise is nice: It'll shift chargeback liability from the merchant to the bank. We're hoping that v2 works better than v1 has tended to work. :)
  • PecanPecan Member
    Hey Brett,

    Thanks for the explanation. I hated those 3D secure processes - you don't see them around so much now (unless that's just me..) Anyway that's great.
  • brettbrett FoxyCart Team
    I keep this image on my desktop as a reminder of my last experience with 3D Secure. I'm hoping v2 is significantly improved, as the chargeback liability shift for merchants really is great, but the rest of it isn't :)

    image
  • watouwatou Member
    Hello,
    Realex / Global Payments has sent notice to their (redirect) customers regarding 3D Secure 2 / SCA, and sent a link to their draft documentation for changes (API users: https://developer.globalpay.com/#!/api/3d-secure-two). There are lots of fields marked "European merchants: mandatory for SCA." Can I tell my client that you have this well in hand for the relevant deadline?

    Many thanks!
  • fc_adamfc_adam FoxyCart Team
    @watou,

    Thanks for posting to ask! We'll be working through the new 3D Secure v2 requirements as they are finalised for each gateway this year, including for Global Payments. Feel free to reach out if you have any questions at any time though, we're happy to help.
  • Global Payments have sent another email to out to all clients today stating that "As you're integrated with our Remote API, changes are needed to work with the new 3DS2 protocol... We've set a deadline of July 2019 for you to make the API changes".

    Is this something that we need to worry about, and if/when foxycart is ready for this what changes do we need to make in our foxy cart admin settings (or anywhere else) to avoid any issues?
    eg. In the Payment settings at the moment my clients have 3D Secure disabled - does this have to be enabled and if so which of the four 'enabled' options should be chosen?
    Thanks
  • PhilippePhilippe Member
    Stripe also sent today a notice to their customers.... is your integration with them SCA ready yet, please ?
  • fc_adamfc_adam FoxyCart Team
    @neilcreagh, @Philippe,

    Thanks for posting to ask - and I'm really sorry for the delay in replying!

    We're working through our many different gateway integrations to add the necessary support for 3DS 2.0 to meet the upcoming SCA/PSD2 deadline. We don't have an public list yet of those gateways we're working or - but we'll be ensuring that all are updated before the deadline.

    If you'd like to forward the emails you received from the gateway - that can help us ensure we're across any specific requirements that gateways may be sending to their users too.

    In terms of changes that may need to be made - if any are required for specific gateways, we'll be reaching out to stores that use those to let them know as the integrations are updated.
  • Just got another email in from Global Payments about this. I've forwarded the email to help@foxycart.com is that right?

    Any update for us, with Foxycart continue to work with Global Payments in the meantime?
  • fc_adamfc_adam FoxyCart Team
    @neilcreagh,

    Thanks for checking in. Forwarding to that email is spot on, thanks.

    Your existing integration will continue to work moving forward, and should continue to work after the necessary PSD2 changes are completed without any changes needed on your side. If there is anything though, we'll be sure to reach out as soon as we're aware of those.
Sign In or Register to comment.