While in 2014 ING thought that third party payment service providers create an immediate online banking security risk, now in 2019 ING opens up its retail payments accounts to external providers.
Not so long ago, in 2014, the District Court of Midden-Nederland ruled that AFAS Software B.V. acted unlawfully when it asked ING customers to enter their banking credentials on its website so that it could log on automatically to ING’s secure online banking interface. I posted an article where I explained the main reasons of the so called AFAS case: https://www.linkedin.com/pulse/psd-2-access-payment-accounts-afas-case-andrea-egertz/
At that time ING reasoned that its general terms and conditions and the Uniform Safety Standards of the Dutch Banking Association prohibit customers to disclose their personal internet banking credentials to third parties. Furthermore, AFAS created an immediate online banking security risk by asking ING customers to supply their internet banking credentials. Then the court ruled in favour of ING and said that in order to prevent fraud, internet banking credentials should never be provided to third parties…
Most surprisingly the Dutch court rejected the argument of AFAS that its services, including the offer for an automatic connection between its third party applications and online banking environments, will be regulated by PSD2.
Now ING makes a turnaround and in the spirit of open banking, and in line with the new European Payment Services Directive (PSD2) opens up its retail payments accounts to external providers. In France licenced third parties can - with the explicit request of customers - access their payments accounts to initiate payments, confirm the availability of funds, or get account information, for example for a money management app. (Source: Finextra).


