Connecting 1,800+ banks via PSD2: how Open Banking works

94% of European banks are PSD2-compliant. But what does that mean for your business? A clear explanation of Open Banking without the jargon.

PSD2 Open Banking netwerk met 1800+ banken

In 2018 the European Union changed the rules for banking. With the introduction of PSD2, the revised directive for payment services, banks were required to share their data through secure APIs. Not with everyone, but with certified third parties that you as a customer explicitly authorise.

That sounds technical. But the effect is very practical: your bank transactions can now flow automatically and securely into your bookkeeping, without downloading files or importing them manually. That is Open Banking.

What exactly is PSD2?

PSD2 stands for Payment Services Directive 2. It is a European regulation that came into force in January 2018. The core: if you choose to, banks must give access to your transaction data to registered third parties.

Those third parties are called AISPs: Account Information Service Providers. They may view your transactions, but cannot make payments or move money. Read only, no writing.

94% of European banks are now PSD2-compliant. Worldwide, Open Banking APIs process more than 137 billion calls per year (2025). This is no longer an experiment. It is the standard.

How does a PSD2 bank connector work?

The process is surprisingly simple. Three steps:

Step 1: Give permission. Through your own banking app or online banking you authorise a specific party to view your transactions. This is called "consent". You see exactly which accounts and which data you share.

Step 2: Secure connection. The AISP sets up an encrypted connection through the bank API. No passwords are shared. Authentication runs through Strong Customer Authentication (SCA), think of your banking app, fingerprint or text message code.

Step 3: Automatic synchronisation. Transactions come in through the API. Depending on your bank and provider this happens several times a day. The data goes straight to your bookkeeping.

That is it. No downloading files, no manual uploading, no MT940.

Why is this safer than the old way?

Before PSD2 there were services that used "screen scraping". They literally logged in to your online banking with your credentials and read the page. Effective, but risky: a third party had your password.

PSD2 puts a definitive end to that. The differences are fundamental:

Feature Screen scraping PSD2 Open Banking
Sharing credentials Yes, fully No, never
Authentication Through third party Through your own bank (SCA)
Permission Implicit Explicit per account
Regulation None EU legislation + supervision
Revocable Difficult Directly through your bank
Read access Everything Only what you share

Screen scraping is now banned in the EU for payment services. PSD2 replaces it with a system that takes privacy and security as its starting point.

Strong Customer Authentication: the gatekeeper

SCA may well be the most important part of PSD2. For every new authorisation, and every 90 days for renewal, you must identify yourself with at least two of these three factors:

  • Something you know: PIN code, password
  • Something you have: phone, bank card
  • Something you are: fingerprint, facial recognition

This is the same security your bank uses for online banking. No compromises.

1,800+ banks in one network

One of the most powerful aspects of Open Banking is scale. Because PSD2 is a European standard, it applies to banks in all EU member states. Plus the UK, which has its own Open Banking standard that is compatible.

For the Netherlands this means that ABN AMRO, ING, Rabobank and all other licensed banks offer a PSD2 API. But it goes further. Through specialised aggregators, parties that maintain the connection with hundreds of banks, you can also connect Belgian, German, Spanish, French, British and other European banks.

Through our platform we offer access to more than 1,800 banks. That is relevant if you operate internationally, have foreign customers, or simply hold an account with a bank outside the Netherlands.

Encryption and data minimisation

All data that flows through PSD2 APIs is encrypted, both in transit (TLS 1.2+) and at rest. But a principle of data minimisation also applies: an AISP may only request the data that is needed for the service.

In concrete terms this concerns transaction data: date, amount, counter account, description. No savings account balances, no investment portfolio, no personal data beyond what is strictly necessary.

At iWebDevelopment we go a step further: we do not store any financial data. Transactions are passed on to your bookkeeping and not kept on our servers. Our infrastructure is ISO 27001 certified and independently pen-tested.

And PSD3? What is coming?

The European Union is working on PSD3, the successor to PSD2. In November 2025 the European Parliament and the Council reached a political agreement on the new regulatory framework. PSD3 is expected to come into force in the second half of 2027 or early 2028.

What changes? The most important improvements:

Data parity. Through their APIs banks must offer the same quality and speed as through their own channels. No more stripped-down APIs.

FIDA — Financial Data Access. An extension of Open Banking to other financial products: insurance, pensions, mortgages. The scope becomes wider.

Stricter enforcement. National supervisors get more powers to tackle banks that neglect their APIs.

Fraud prevention. New measures against spoofing and social engineering, including mandatory Verification of Payee (already required from October 2025 under the Instant Payment Regulation).

Our experience is that every PSD update strengthens the position of AISPs. PSD2 made Open Banking possible. PSD3 makes it more reliable and broader.

What does this mean for you?

If you still import MT940 files manually, PSD2 is the logical replacement. It is safer (no sharing passwords), faster (automatic, several times a day) and future-proof (EU regulated, PSD3 on the way).

The switch does not take weeks. With us you are up and running within a day. You give permission through your bank, choose which accounts you want to connect, and the transactions flow automatically to Exact Online, Twinfield or AFAS.

No files. No manual work. Full control over who may see what.

Want to try it yourself? View our bank connector →