
The directive (EU) 2023/2225 transposed by the ordinance of September 3 comes into effect on November 20, 2026. It redefines the functional scope of the banking customer space well beyond simple balance display. Online management interfaces must now integrate pre-contractual information flows, creditworthiness verification mechanisms, and regulatory alerts that did not exist in previous versions.
Integrated creditworthiness verification in the customer space: what the transposition changes
The obligation for creditworthiness verification now applies to any new authorized overdraft, including for small amounts and short durations. Before November 2026, only overdrafts exceeding 200 euros or lasting more than a month triggered a formal analysis. The new framework removes this threshold.
In practice, the customer space must offer an overdraft request process that collects the financial data of the account holder before any validation. Banks retain a margin for setting on a case-by-case basis, within the limits of the applicable usury rate, but no universal overdraft ceiling is established by the reform.
We observe that several institutions have chosen to integrate this verification directly into the online subscription tunnel, with pre-filling from already held transactional data. Others maintain a referral to an advisor, creating a break in the digital journey. To access the Propatrimonia customer space, the chosen logic favors a mixed support between digital interface and wealth advice.
A technical point often overlooked: overdrafts already granted before the entry into force are not subject to the new initial verification. Only renewals or increases in limits trigger the process. The customer space must therefore manage two simultaneous regimes during a transitional period.

Functional limits of banking customer spaces in the face of instant payment
The deployment of SCT Inst instant transfers at the European level imposes real-time display constraints on customer spaces. The displayed balance must reflect movements to the second, whereas most historical architectures operated with daily delays.
The gap between accounting balance and available balance remains a blind spot in many interfaces. A debited instant transfer does not always immediately appear in the available balance, which skews the reading of the remaining authorized overdraft. Customers managing their cash flow from the mobile app find themselves with partial information.
Instant transfer limits, now aligned with those of classic transfers by European regulation, must be adjustable from the online space. We recommend checking that the interface indeed allows modifying these limits without going to a branch, as some banks have not yet deployed this feature in their application.
Regulatory alerts and overdraft monitoring in the online interface
An overdraft cannot last beyond three months. This principle predated the reform, but the new framework strengthens the obligation to inform the customer. The online space must now integrate proactive notifications when the overdraft approaches this time limit.
In practice, banks must provide via the customer space:
- A detailed pre-contractual information before any overdraft grant, explicitly mentioning the total cost, including for amounts below 200 euros
- A periodic summary of overdraft fees, accessible in the documents section of the online space
- Automatic alerts when the overdraft exceeds a configurable threshold or approaches the limit of three consecutive months
- Direct access to the account agreement mentioning the applicable overdraft conditions
The overdraft is legally equated to a consumer credit, which imposes an equivalent level of information. Customer spaces that were content with a simple quarterly fee statement will need to enhance their display.
Cybersecurity and authentication: constraints on banking data in 2026
Strong authentication remains the foundation for accessing the customer space. Biometrics (fingerprint, facial recognition) have become widespread on mobile applications, but web sessions often remain limited to an SMS code and a password, creating a security asymmetry between channels.
The CNIL continues to monitor the use of data collected by banking applications. The control particularly focuses on the proportionality of the data requested during the creditworthiness verification integrated into online journeys. An application that accesses account statements held in other institutions via open banking must justify the necessity of each piece of data collected.

Recent case law on banking fraud tends towards a rebalancing of responsibilities between the bank and the customer. Customer spaces are gradually integrating features for temporarily blocking cards, setting payment limits, and disabling contactless payments, but these security options remain scattered in the menus instead of being grouped in a dedicated dashboard.
What the banking customer space still does not manage in 2026
Despite the advanced digitization of services, certain operations resist dematerialization. Closing an account, disputing a fraudulent transaction beyond a certain amount, or modifying the power of attorney regime still require a visit to a branch or a mail exchange in the majority of institutions.
Multi-bank management from a single space is progressing through account aggregation, but the displayed data often remains read-only. Initiating a transfer from an account held in another institution via the main customer space remains technically possible thanks to the DSP2, but few banks have implemented it smoothly.
The real ceiling of the customer space in 2026 is not technology: it is the willingness of institutions to open their processes to operations that currently generate foot traffic in branches. As long as closing or renegotiating an overdraft remains a lever for physical retention, the online space will remain a consultation tool rather than a complete management tool.