BJBRookie
Card number, name, expiry date and CVV combined are all very fraud sensitive card data that were only necessary before the introduction of proper SCA. With 3DS v1.x or 3DS v2.x there is no need for merchants or PSP's to ask those data from card holders who use a 3DS-app from their card issuer. That is one of the major objectives of SCA for online card payments: to do away with fraud sensitive data at the merchant or PSP and to redirect the card holder securely to the authentication environment of the card issuer. That way, the card holder only needs to submit sensitive authentication data to the card issuer and nobody else. Very similar to how this is already implemented for iDEAL since 2005.
Most existing merchants and PSP's still ask for all those card data, as they have done so for many years and use the option to postpone the full implementation of SCA until January 1st, 2021. But bunq launched this functionality in 2020, several months after the PSD2 SCA-regulations were originally introduced. One would expect bunq not to implement old, outdated stuff and launch new functionality with modern future-proof and secure stuff from day one. What bunq does now, as a PSP, will be in violation of PSD2 SCA on January 1st, 2021.