Open Banking is a model for sharing financial data that allows a customer to grant third-party payment service providers access to their account information or the ability to initiate payments through dedicated interfaces (APIs), solely based on the user's consent.
The following parties are involved in the interaction:
Payment Service User (PSU) – the account holder;
Account Servicing Payment Service Provider (ASPSP) – Piraeus Bank ICB JSC;
Third-Party Payment Service Provider (TPP) – an external service provider;
Technology Operator (UPC) – responsible for technical API connectivity and interaction.
Open Banking provides customers with greater control and convenience when using financial services.
Key Benefits
Customers may use a third-party financial service (TPP) that requests access to their accounts held with Piraeus Bank ICB JSC or initiates a payment.
Interaction Process
1. The customer initiates an action in the application of a third-party service provider (TPP).
2. The customer provides consent and is automatically redirected to the Winbank application for confirmation.
3. In Winbank, the customer:
- reviews the consent parameters or transaction details;
- confirms or rejects the request using Strong Customer Authentication (SCA).
4. Once confirmed:
- the consent becomes active;
- the TPP receives access or the ability to perform operations within the granted permissions.
In the Winbank mobile application, customers can:
View all granted consents (active and inactive);
Review consent details and parameters;
Manage and revoke consents at any time (individually or all at once).
The Open Banking platform of Piraeus Bank ICB JSC complies with international standards and regulatory requirements, including:
Berlin Group NextGenPSD2 as the primary standard for API implementation and interaction with TPPs;
Requirements of the National Bank of Ukraine regarding account access, consent management, and onboarding of third-party payment service providers;
Information security requirements, ensuring data protection, access control, and secure authentication.
For matters related to Open Banking operations, customers may contact the Bank through:
If unauthorized, incorrect, or improper payment transactions initiated through a Third-Party Payment Service Provider (TPP) within the Open Banking framework are identified, Piraeus Bank ICB JSC will investigate such transactions in accordance with its internal procedures and the requirements of Ukrainian legislation.
Where the customer is not at fault, the Bank will refund the funds related to such transactions.
For investigation purposes, the Bank may cooperate with the relevant TPP, including requesting necessary information and supporting documents. If the TPP is found responsible, the Bank reserves the right to seek reimbursement of incurred losses from the respective provider.
Technical integration with the services of Piraeus Bank ICB JSC within the Open Banking framework is performed through the Bank's Open APIs implemented via the technology operator Ukrainian Processing Center (UPC).
UPC Technology Operator Provides:
Connecting a Third-Party Payment Service Provider to the Open Banking API platform includes:
Registration of the TPP with the National Bank of Ukraine;
Access to the Sandbox environment;
Integration testing;
Access to the Production environment.
Access to the Production environment is granted upon successful completion of testing.
Detailed information regarding the implementation specifics of the Open Banking API platform at Piraeus Bank ICB JSC is available in the technical documentation provided by the UPC technology operator:
Regulatory APIs
https://docs.api.upc.ua/ua/api-servisi/regulyatorni-api
Piraeus Bank ICB JSC Integration Specification
https://docs.api.upc.ua/ua/api-servisi/regulyatorni-api/specifika-aspsp
The documentation includes all information required for proper integration with the Bank's dedicated interfaces, including:
Format and types of PSU identifiers;
Supported authentication approaches (including decoupled authentication);
Other technical implementation specifics of the Bank's APIs that may differ from the standard UPC specification.
When integrating, TPPs must consider both the general UPC requirements and specifications as well as the implementation specifics of Piraeus Bank ICB JSC.
Account Information Service (AIS)
Provides access to user account information, including:
Account balances;
Transaction history;
Account details.
Payment Initiation Service (PIS)
Allows payment initiation from a user's account, including:
Customer payment authorization;
Retrieval of payment status information.
Technologies Used
The APIs are based on the following technologies:
REST API;
Data exchange format: JSON;
Security protocols: OAuth 2.0, OpenID Connect;
Secure connection: TLS 1.2 or higher.
Terms of Cooperation and Liability
Terms of Cooperation
Access to the Open Banking API platform is provided under equal conditions for all Third-Party Payment Service Providers.
We ensure:
Technical Support
For all questions related to Open Banking dedicated interfaces, the developer portal, or testing procedures, please contact the UPC support team:
ob@upc.ua
For matters requiring direct interaction with Piraeus Bank ICB JSC, TPPs may contact:
Retail@piraeusbank.ua
(Please include in the email subject line: "Open Banking – [subject of inquiry]")
These contacts may also be used for resolving disputes related to access to Open Banking interfaces.
Maintenance Windows and Service Availability
Information regarding planned maintenance activities that may affect the availability of Open Banking services is published on the Bank's official website in advance.
Liability
The Bank provides access to customer's accounts within the Open Banking framework and is responsible for organizing such access in accordance with the requirements of Ukrainian legislation.
Download the Winbank application from Piraeus Bank and open your card Online
Download the Winbank application from Piraeus Bank and open your deposit Online