Consumers and service providers should take note of some of the enhanced risks upon an e-money institution’s insolvency.

By Hongbei Li

Technology is rapidly changing the way customers and businesses interact with financial systems. Fintech companies are a driving force behind the disruption of traditional banking and payment services, with regulatory innovation close behind.

In the 12 months to June 2021, electronic money institutions (EMIs) in the UK processed more than £500 billion of transactions, according to Financial Conduct Authority

The guidance is part of the rapidly evolving rules on anti-money laundering and aims to promote UAE as a jurisdiction compliant with best practices.

By Brian Meenagh, Ksenia Koroleva, and Matthew Rodwell

On August 1, 2022, the UAE Central Bank (CBUAE) issued the Guidance for Licensed Financial Institutions on the Risks Relating to Payments.[1]

The guidance was issued to implement the requirements of Federal Decree Law No. 20 of 2018 on Anti-Money Laundering and Combating the Financing

Latham lawyers explore the latest insurtech trends and regulatory developments impacting the sector in Europe and Asia.

Disruptive technology is revolutionizing insurance, enabling insurers to achieve growth by leveraging big data and creating innovative solutions to enhance customers’ digital experience. We are pleased to launch Insurtech Insights, a series of webcasts to discuss the most recent trends in the insurtech space and how to navigate regulatory developments.

The report, from UK Finance, The Payments Association, and Latham & Watkins, urges fresh thinking about regulating payments in the growing digital economy.

By Stuart Davis and Brett Carr

UK Finance, The Payments Association, and Latham & Watkins have published UK Payments Regulation Review: Making sense of where to go now, a new report examining regulation of the UK’s payments industry and its impact on the financial sector, consumers, and businesses.

Amidst the rapid digitalisation of the UK economy,

In a long-awaited paper, the FRB continues its exploratory approach and emphasizes the need for congressional support.

By Alan W. Avery, Pia Naib, and Deric Behar

On January 20, 2022, the Board of Governors of the Federal Reserve System (FRB) published its long-awaited discussion paper (the Paper) on the potential benefits and risks of issuing a US central bank digital currency (CBDC). The Paper, titled “Money and Payments: The U.S. Dollar in the Age of Digital Transformation,” is intended to initiate a discussion around the various factors the FRB is considering with respect to a potential US CBDC rather than “advance a specific policy outcome.”

The guidelines set out the MAS’ expectation that digital payment token service providers should not promote their services to the general public in Singapore.

By Simon Hawkins, Farhana Sharmeen, and Tan Gen Huong

On 17 January 2022, the Monetary Authority of Singapore (the MAS) issued new guidelines (the Guidelines) setting out restrictions on the promotion of services related to digital payment tokens (DPTs) in Singapore. The Guidelines apply to banks and financial institutions providing DPT services in Singapore, and entities providing DPT services in Singapore that have either been granted a licence under the Payment Services Act (PSA) or that are currently operating under transitional exemptions under the PSA (collectively, DPT service providers).

The French Data Protection Authority’s white paper discusses how companies can comply with data privacy and security obligations.

By Christian F. McDermott, Myria Saarinen, Calum Docherty, Charlotte Guerin, Jiou (Alex) Park, and Amy Smyth

The use of card, contactless, and innovative digital payment solutions has significantly increased in recent years, fueled by the immediate impacts of the ongoing COVID-19 pandemic and the longer-term growth of e-commerce and open banking. In this context, the legal and regulatory environment around payment data is no longer limited to traditional actors in the banking sector or the long-established ambit of banking secrecy rules. As such, stakeholders from fintech startups to established technology giants face an increasing patchwork of compliance obligations.

Online retailers storing credit card data for the sole purpose of facilitating further purchases will likely need to obtain consumer consent.

By Christian F. McDermott, Calum Docherty, and Victoria Wan

Online shopping has boomed in recent years. In 2020, the European statistics agency Eurostat estimated that 7 out of 10 internet users made online purchases within a 12-month period. The European Central Bank found that the total number of non-cash payments in the euro area increased by 8.1% in 2019 (the last year statistics are available) year-on-year with a total value of €162 trillion, which included 45 billion transactions processed by retail payment systems worth €35 trillion. This growth has likely surged during the COVID-19 pandemic, when many consumers turned to e-commerce.

The opportunities for retailers also present data protection risks. On 19 May 2021, the European Data Protection Board (EDPB) adopted Recommendations 02/2021 on the legal basis for the storage of credit card data for the sole purpose of facilitating further online transactions (the Recommendations) to address the vast data processing operations behind these transactions. The Recommendations focus on when and how online retailers can store a customer’s credit card data after a sale or transaction for the sole purpose of facilitating future purchases by that customer. The EDPB has expressly excluded from the scope of the Recommendations the storage of credit card data in relation to ongoing contracts, such as for subscription services, and the activities of payment institutions operating in online stores. The Recommendations only reference credit cards and not payment cards more generally (such as debit cards, prepaid cards, etc.). It is unclear whether the EDPB might have similar expectations of online retailers that store other payment card or direct debit data for the same purposes.

The Recommendations are not legally binding, but provide a brief exploration of the EDPB’s assessment of the legal bases available to the online retailer. The EDPB concludes that, in its view, the only appropriate legal basis for such processing is consent under Article 6(1)(a) of the General Data Protection Regulation 2016/679.

A report from the Taskforce on Innovation, Growth and Regulatory Reform provides recommendations for how the UK can “re-imagine” its approach to regulation post-Brexit.

By Rob Moulton, Stuart Davis, and Charlotte Collins

On 16 June 2021, the Taskforce on Innovation, Growth and Regulatory Reform (the Taskforce) published a report (the Report) providing recommendations for how the UK could “refresh” its approach to regulation post-Brexit. The UK government convened the Taskforce in February with the directive to “re-imagine, quickly and creatively, the UK’s approach to regulation”.

The Report, which covers a broad range of sectors, includes notable recommendations in relation to financial services regulation. While it does not suggest a “bonfire of regulations”, the Report does convey a desire to move away from the European style of technical and prescriptive rule-making. The focus is very much on creating a flexible and adaptive regulatory system in the UK to encourage innovation and growth. The Report also hints at some specific areas of onshored EU legislation that the government may target for change in the near term.

The paper identifies potential gaps in protections for consumers, with a focus on consumer-to-business payments via the Faster Payments System.

By Christian F. McDermott, Claudia Sousa, and Alain Traill

In November, Pay.UK, the retail payments authority, released a summary paper exploring the consumer protection landscape relating to disputed retail payments.

The paper, titled “Consumer Protections in Payments”, was released in the context of changes in the usage of Pay.UK’s systems following recent regulatory developments, including the EU’s revised Payment Services Directive (2015/2366, known as PSD2) and the Open Banking initiative in the UK. Focusing in particular on real-time consumer-to-business (C2B) payments using the Faster Payments System (FPS), the paper explores the protections currently in place and consumers’ understanding of those protections. Together with ongoing primary research, the paper will be used to inform further policy work by Pay.UK and, potentially, introduce new rules and standards.