Online credit card fraud has been a persistent, troublesome issue for conferences and congresses for years. According to the European Banking Authority, a new security procedure is set to put an end to this. The new standards of the PSD2 directive come into effect on September 14, 2019, which includes the 3D Secure 2.0 process with two-factor authentication. But what exactly is this, and what else should conference organizers take care of by then if they want to continue offering credit card payments during online registration?
What do PSD2 and 3D Secure 2.0 mean?
Behind the rather cryptic abbreviation PSD2 lies the EU directive for payment services and payment service providers (Payment Services Directive 2).
Strictly speaking, its implementation has been underway since the beginning of January 2018—at least as far as the first stage is concerned. Since then, the so-called surcharging ban has been in effect, which prevents extra fees from being charged for payments made by card, bank transfer, or direct debit.
The second stage, which will change the payment process, follows on September 14, 2019. Previously, online payments either required only credit card details or additionally used the original 3D Secure process. The latter prompted the buyer to enter a code to ensure that the person was the legitimate holder of the credit card details being used.
Such verification also makes sense for conferences, for example, if a ticket buyer pays with a company credit card rather than their own. The name on the card and the name on the registration form do not match, which could indicate an attempted fraud. If the buyer is subsequently unable to authenticate themselves—for example, because they do not have access to the smartphone to which the TAN was sent—the process is aborted. However, if a cardholder's smartphone is stolen along with their card, this does not provide sufficient protection either.
The new 3D Secure 2.0 process therefore refines this approach a little further. To ensure that there is no fraud, the credit card issuer will in future require the buyer to provide two of the following features during the transaction (2-factor authentication):
- Knowledge: something the person knows (e.g., a one-time password or PIN)
- Possession: an item the person carries with them (e.g., a smartphone)
- Inherence: a personal characteristic of the person that is uniquely linked to them (biometric data such as a fingerprint or facial recognition)
In the future, two of these three features will be combined to complete a payment process. Simply asking for a static password will no longer be sufficient for authentication. Credit card holders are currently being asked by banks to register their cards for Mastercard Identity Check or Visa Secure and to decide whether they would like to use Face ID, a PIN, or fingerprint verification for online payments in the future.
The alternative: risk analysis
Two-factor authentication is not mandatory, depending on the payment service provider. Computop, for example, skips it entirely in 95% of transactions. Instead, a complex risk assessment runs in the background, where the ticket buyer's data is transmitted to the issuer (= the bank that issued the credit card). This can include the cost of the ticket, the IP address, the browser language, and other details such as the provided billing and shipping address. This is technically enabled by the payment service provider itself, which is connected to the website where conference attendees register, ensuring that the data is transmitted to the issuer. Once there, the issuer evaluates the data and either concludes that the actual credit card holder is on the other end or that someone is trying to obtain conference access illegally. To clarify this, in the latter case, the person is prompted to confirm their identity via two-factor authentication. If they cannot do so, the transaction is declined and the ticket is not sold. The more details the issuer receives about the buyer, the more precisely they can assess whether a potential case of fraud exists or if everything is legitimate.
What needs to be done to transmit my conference data?
To prepare your conference for the new 3D Secure 2.0 process, a few technical adjustments must be made. As a rule, the conference organizer does not need to do anything here, as this is handled by the issuer in cooperation with the payment service provider.
However, a few tasks regarding your conference will still remain for you. First, you need to find out whether your current payment service provider even supports the new process yet. If so, you should clarify which specific data they require for forwarding to the issuer. This is especially important for providers that use the risk analysis described above. The data to be transmitted must match the information requested in the registration form for the conference. If this is not the case, you must adjust your form accordingly. The deadline does not necessarily have to be September 14. The only important thing is that everything works by the time your conference registration period begins.
Depending on how your registration is connected to the payment interface, other specific features and tasks may arise. However, this can only be fully clarified with the payment service provider itself, as it always depends on their specifications.
And even if it seems like no one ever reads them, you must update both your terms and conditions and your privacy policy. It should be clear there what data is being transmitted to whom and to what extent. Furthermore, it is helpful to inform users about the process used on the conference website before registration starts to avoid abandoned ticket purchases, as not everyone may have set up 2-factor authentication for their credit card yet.
I work with conference management software. What do I need to look out for?
As an organizer, you will have the least amount of work if the provider of the conference management software sells the tickets for you in your name and on your behalf during participant registration. The provider uses their own payment contracts for this, which means you no longer have to worry about signing additional contracts.
Is 3D Secure 2.0 really more secure?
3D Secure 2.0 can identify fraud attempts more quickly and prevent subsequent chargebacks. Previously, if the legitimate credit card holder intervened to cancel a fraudulent transaction, the event organizer usually had to cover the costs of the chargeback. PSD2 intervenes proactively here and can stop suspicious purchases in time. With the previous 3D Secure 1.0 process, it could also happen that a ticket purchase was incorrectly declined. This should also be avoided in the future. Claiming that there will be no more credit card fraud at conferences starting in September would likely be a bit too optimistic, despite the new method. However, the payment process will definitely become more resilient to problems, which will ultimately benefit conference organizers.





