AC

Open Banking Compliance: PSD2 Reflection in Türkiye

TL;DR

Açık Bankacılık: Hesap Bilgisi Hizmeti (AIS) + Ödeme Başlatma Hizmeti (PIS). Türkiye'de BDDK çerçevesinde TPP rolü.

15 Şubat 2026 Financial Law 2 dk okuma 6 görüntülenme Son güncelleme: 9 Mayıs 2026

Open Banking is the ability of a 3rd party fintech to access account information and initiate payments with the approval of the bank customer. It operates with the infrastructure of BKM and TRSPI in Türkiye; TPP (Third Party Provider) license is required.

3 main roles

  • AISP (Account Information Service Provider): Reading account information; personal finance apps.
  • PISP (Payment Initiation Service Provider): Payment initiation; e-commerce.
  • CBPII (Card-Based Payment Instrument Issuer): Card product issuance.

TPP license + certification

  • BRSA payment institution license (PI or EMI).
  • BKM/TRSPI certification (eToken/eIDAS compatible).
  • API access with the bank (sandbox + production).
  • User consent management infrastructure.
  • Technical requirements

    • OAuth 2.0 + OpenID Connect.
    • FAPI (Financial-grade API) profile.
    • mTLS + JWS signature.
    • PSD2 SCA (Strong Customer Authentication): MFA + dynamic linking.

    Is sharing the Bank API mandatory?

    There is no compulsory sharing at the EU PSD2 level in Türkiye yet. BKM's services such as "Paribu Open Banking" are optional; bank's participation decision.

    Data retention period?

    "Purpose bound" within the framework of KVKK. Maximum 90 days rolling for AIS (unless user consent is renewed).

    Is PSD2 compliance necessary for Türkiye?

    If you are selling to the EU market, yes. BRSA + TRSPI is sufficient for the Turkish domestic market.

    How is user consent management?

    Open, revocable, granular (account-based) consent. Compatible with KVKK m.5 + m.11. Show what data was accessed and the duration in the confirmation panel in the UI.

    Who is responsible if the bank API malfunctions?

    It is decided in the SLA agreement. If annual downtime is > 1%, customer compensation liability may arise on the fintech side; Multi-bank integration is recommended as a backup.

    Relevant legislation

    • Law No. 6493 — Payment & electronic money; licensing, operating permit.
    • BRSA Regulations — Payment institution / EML permission, capital, reporting.
    • 5549 SKMASAK; KYC, STR, regular activity.
    • KVKK + GDPR — Data security, cross-border transfer.
    • PCI-DSS — Card storage; PCI level 1-4 compliance.
    Legal notice: This article is for general information purposes; A meeting with a lawyer is required for a concrete case. Durations, rates and practice are shaped by jurisprudence; Check the current legislation before applying.

    Kaynaklar ve referanslar

    Kaynaklar

    Açık Bankacılık (Open Banking) Uyumu: Türkiye'de PSD2 Yansıması içeriği hazırlanırken resmi mevzuat ve yüksek yargı kaynakları esas alınmıştır.

    Telif bildirimi This content and all related Q&A texts are protected under Turkish Copyright Law No. 5846. Unauthorized copying, reproduction, publication, adaptation, bulk extraction, or commercial use is prohibited; legal and criminal remedies are reserved in case of infringement.

    Hukuki destek arıyorsanız

    Bu konuda profesyonel hukuki destek için Aycan Ceylan Avukatlık Bürosu olarak yanınızdayız.

    Görüşme Planla