Secure protocol 3DS for safe online purchases

I'm a buyerI'm a seller

I'm a buyer

What is this extra level of security I’m being asked to complete?

3D-Secure is the secure protocol designed to ensure enhanced security and strong authentication for you when you use your debit or credit cards for online purchases. It is called, depending on the card type, “MasterCard SecureCode”, “Verified by Visa” and, in the case of American Express cards, “Safekey”. In the future when you transact, you may be asked to provide a special security code to the card issuing bank in order for the bank to authorise the online transaction when prompted in the PayPal payments page. Card issuing banks have different methods of generating and delivering these codes and so if you don’t know your 3D-Secure passcode or password, and you are not being given the option to enrol online in the bank’s pop up screen, then you will need to contact your bank. Please note that this is not your PayPal account password.

Why is PayPal enabling this new set of extra security?

It means even greater security for all users of PayPal, both buyers and sellers. 3D-secure enablement provides a form of stronger authentication and makes your transactions even safer than before. We use 3D-Secure card authentication in addition to the other things we do to help the security and simplicity of your payments.

So how does it work?

3D-Secure authentication is the interaction between your card issuing bank and you, where you may be requested to enter a special security code to verify you are the legitimate owner of the banking card you are either registering with PayPal or using to make a transaction. If the security code is correct, you will be able to add your credit or debit card to the PayPal account for future transactions, some of which might also prompt you to re-enter your 3D-Secure passcode or password, though this should be the exception rather than the norm. If the security code is incorrect and 3D-Secure authentication fails, you will not be able to use the card to fund a transaction until you successfully complete the 3D-Secure password challenge from your bank.

Why are you requesting this additional level of security now? Is my account safe?

We are introducing this additional security check where it is necessary to help keep your transactions safe and secure. We will not necessarily ask for this additional code every time but you should be sure to remember the 3D-Secure code you setup with your bank should you be asked for it.

When will I need to enter this code? Do I now need to do it every time?

Our aim is to balance convenience and security, so we are adding this additional level of security in certain cases in order to keep your account safe. We will not ask for it every time and most of the time you should be able to pay with PayPal by just entering your email address and your PayPal password.

Where can I get this additional code? Isn’t it the same as my PayPal password?

No, the 3D-secure code is given to you by your card issuing bank and is not the same as your PayPal password. The bank that issued the card that you’ve added to your PayPal wallet can give you the details on how to register to get your 3D-Secure code. You may also find that your bank has made it even easier for you in case you never received this 3D-Secure code for the card. For example, on the 3D-Secure verification screen which is controlled by the bank, you may see helpful options such as ‘forgot your code?’ or a similar type of message. If not then you’ll need to contact your bank. You can also pay with your bank account directly in many countries or alternatively your existing PayPal balance should you have funds already on your PayPal account, without needing the 3D-Secure code. Banks’ processes are all different, so you will need to contact your bank should the above options not prove successful.

Am I going to have to do this extra step every time I pay with PayPal?

No. We will only ask for this additional code from your bank where it is necessary. In most cases, you will be able to continue to pay with PayPal with just a few easy steps. This additional step has been deployed for the safety and security of all users of PayPal in addition to the continuing efforts we provide to keep your money safer.

How many attempts are permitted before I’m locked out?

You will have 3 to 5 attempts to achieve a successful authentication of the card. If the code you enter repeatedly fails, you will be asked to use another financial instrument to make the payment, such as from your bank account, or your PayPal balance. Alternatively, if you are given the option in the 3D-Secure process to enrol your card or, if you’ve forgotten your password, you can click on those links to do so. Otherwise, you will need to contact your bank.

What happens if I haven’t received my 3DS password or it is declined by the bank/is incorrect?

If you’re not given the option of enrolling or being reminded of your password in the pop up on the PayPal payment page, you’ll need to contact your bank.

Do other payment service providers require this 3D-Secure?

Yes, all Payment Service Providers (PSPs) in the EU are expected to support and enforce 3D-Secure by August 1 2015.

Can I opt-out from having to enter my 3D Secure Code?

Not if you want to make a payment using a credit or debit card. You can add your bank account details to your PayPal account, or pay from your PayPal balance instead. But again, we will only prompt you for this code in limited cases when paying with a credit or debit card. In most cases, you will be able to continue to use PayPal just as you did before with just your PayPal email address on file and your PayPal password.

If you couldn’t find the answer to your questions here please contact us

I'm a seller

What is 3D-Secure?

3D-Secure is the secure protocol designed to ensure enhanced security and strong authentication for consumers when they use their debit or credit cards for online purchases. It is called, depending on the card type, “MasterCard SecureCode”, “Verified by Visa” and in the case of American Express cards, “Safekey”. It is deployed at the point of transaction, and typically involves the customer being asked by their card issuing bank to enter a passcode or password to prove that they are the legitimate card holder. Card Issuing banks have different methods of generating and delivering these codes, so consumers need to contact their card issuing bank to find out how to register for 3D-Secure and when challenged enter their passcode/password for their card, and not the passcode/password for their PayPal account.

Why is PayPal enabling 3D-Secure on my PayPal payment page?

The European Banking Authority requires Payment Service Providers and their merchants to deploy strong authentication by the card issuing bank when the legitimate cardholder first registers their card with a Wallet, and also for higher risk transactions – which in effect means deploying 3D-Secure. For PayPal, 3D-secure enablement means stronger authentication of users and more successfully processed transactions for you. 3D-Secure card authentication is in addition to the multiple efforts that we take to further support the security and simplicity of your payments.

How does 3D-Secure work?

3D-Secure authentication is the secure and direct interaction between the card issuing bank and consumer, in which PayPal is unable to ‘view’ the cardholders banking details. PayPal generates a secure session between the card issuing bank and the cardholder to verify that the consumer is the owner of the card that they are trying to add to their wallet. For Sellers that have deployed the PayPal branded checkout, there is nothing more to do - we deploy 3D-Secure when it is necessary to comply with the regulations. Once the consumer’s payment card is added to the wallet, there will be very few instances when the level of risk in the transaction is sufficiently high for us to require this higher level of verification. Exceptions will be when we believe that the risk in the transaction can be mitigated using 3D-Secure, and rather than declining the payment, we will process such transactions through the 3D-Secure systems to request that the card issuing bank authenticate the consumer is the real cardholder. One of the benefits of using PayPal’s checkout is that we can mostly differentiate good from bad transactions, and invoke the use of 3D-Secure when it is necessary, and minimise consumer disruption from over-use of the system. We are confident that this process should increase your business with more ‘good’ approved transactions.

How does 3D-secure affect my business?

You should experience an increase in sales conversion for transactions that were previously considered to be high risk and declined. However, Sellers shouldn’t expect to experience an increase in chargebacks because the use of 3D-Secure involves the liability for unauthorised transactions that were selected for a 3D-Secure challenge to be absorbed by the card issuing bank. It is possible that there will also be customers who have forgotten the passcode/password for their card, and they may abandon the checkout. Importantly, 3D-Secure will frustrate fraudsters. Overall our experience to date has been that sellers experience increased sales conversion and offer a better PayPal payment experience in which buyers and sellers can confidently transact.

Do I need to do anything?

No, you don’t. If you get any question from your shopper that they have difficulty to pay because they can’t remember the passcode/password for their card, please refer them to the ‘forgot password link’ within the 3D-Secure screen, or to their card issuing bank to re-set it, otherwise ask them to contact PayPal and we will take care of the process. You don’t have to do anything. The 3D-Secure process is just one of many security checks we have in place to protect you and your customers.

What are the benefits for me now when someone pays with PayPal compared with before?

For customers checking out through PayPal, you will benefit from the use of 3D-Secure without having to implement it separately into your website, and determine your own policy rules for when to require it, and when not to. Our findings are that you will find that customers take comfort in the additional security requirements, as the 3D-Secure card security becomes the norm around Europe and around the globe. Overall, you can take comfort, as before, that PayPal will take care of everything and ensure a convenient, simple and secure payment environment. If anything goes wrong, we’ll take care of it for you through our extensive buyer and seller protection policies. The 3D-Secure security doesn’t change any of these things.

Can I ask you for my website to opt-out from 3D Secure with PayPal transactions?

No, the use of card issuer authentication is mandated across Europe for certain circumstances, such as when a customer registers a card with a Wallet (e.g. PayPal), and for risky transactions. But we are focussing closely on ensuring that PayPal’s deployment of 3D-Secure technology doesn’t negatively affect your sales – firstly, we have a wealth of experience and capabilities to identify good from bad transactions and minimise the unnecessary use of 3D-Secure. Secondly, the new 3D-Secure standard will soon be regarded as the European standard, and customers will get used to this increased level of security whenever they shop online using any card based payment methods.

Can I help my customer to complete their transaction should they have trouble with the new 3DS security in the PayPal wallet?

You can try, but please note that 3D-Secure passcode/password is discrete to the customer and their card issuing bank. If they cannot remember the passcode/password for their card, they should follow the ‘forgot password’ link in the 3D-Secure session, or contact their card issuing bank to re-set their passcode/password. In all other cases we suggest that you refer them to our customer service department and we will work with the customer to try and find alternative payment solutions or methods of authentication to help them complete the transaction.

Will the introduction of this new 3DS security impact my seller protection program?

No. Your rights are unchanged. The new security will, according to our expectations, only help in increasing your sales turnover, approval rates and customer satisfaction.

If you couldn’t find the answer to your questions here please contact us