How does 3DS 2.0 meet SCA?
SCA requires companies use 3DS 2.0 whenever a customer in the EEA uses a credit/debit card to complete an online purchase (see a full list of exemptions later in this section). 3DS 2.0 sends over 80 data points to the customer’s issuing bank — including points like device fingerprint, previous transaction history, and shipping address — to create an accurate risk profile of the customer. With this risk profile, the issuing bank then determines how to send the customer down one of two paths: a “frictionless flow” and a “challenge flow.”
If the issuing bank identifies a low-risk profile, then the customer is sent down the “frictionless flow” in which their purchase experience is completely uninterrupted.
On the other hand, if the issuing bank identifies a high-risk profile, then the customer is sent down the “challenge flow” which will prompt the customer to authenticate themselves along with two of the three independent factors mentioned earlier in this post.
In short, 3DS 2.0 works with SCA to better authenticate legitimate purchases and better deny fraudulent purchases, benefitting your gaming company as well as your community of paying gamers.
Exemptions
SCA applies to all “customer-initiated” CNP transactions when both the customer and issuing bank are located in the EEA. However, there are some exemptions to SCA which we’ll highlight below.
Subscriptions
SCA applies to the initial transaction of a subscription or recurring-payment service because it is “customer-initiated.” Every transaction after the first is defined as “merchant-initiated,” which means those transactions are exempt from 3DS 2.0. SCA will apply to the subscription once again only if the subscription amount changes.
Low-value transactions
Transactions less than €30 will be exempt unless one of the following thresholds is reached.
Low-risk transactions
Low-risk transactions will also be exempt based on the average fraud levels of the card issuer and acquirer processing the transaction in question.
How Xsolla helps your gaming company comply with PSD2
Gaming companies that partner with Xsolla comply with the SCA technical requirements of PSD2 on September 14, 2019, without any additional work. All the resource-intensive changes for 3DS 2.0 integration have already been made by our team to ensure your business continues to operate smoothly and predictably in this part of the world.
And while 3DS 2.0 certainly helps to improve payments security, it’s worth remembering that Xsolla partners also receive fraud protection with the most trusted anti-fraud system in the video game industry.
If you’re a video game developer or publisher who wants to learn more about how Xsolla can help you comply with payment regulations worldwide while lowering fraud, go ahead and schedule a time to talk with one of our experts or email business@xsolla.com.
Sources:
Ready to maximize revenue opportunities? Reach out to our experts and learn how to start earning more and spending less.