Regulation 120 Authentication
(1) A payment service provider shall apply strong customer authentication where a payer -
(a) accesses its payment account online,
(b) initiates an electronic payment transaction, or
(c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses.
(2) Where a payer initiates an electronic remote payment transaction, a payment service provider shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.
(3) Where paragraph (1) applies, a payment service provider shall have in place adequate security measures to protect the confidentiality and integrity of the personalised security credentials of the payment service user concerned.
(4) Paragraphs (2) and (3) also apply where a payment is initiated through a payment initiation service provider.
(5) Paragraphs (1) and (3) also apply where information is requested through an account information service provider.