Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2024-0046 → TA-9-2024-0297

From
A-9-2024-0046 Plenary report of 21 Feb 2024
To
TA-9-2024-0297 Adopted text of 23 Apr 2024
Changes
73 changes to the text
Paragraphs
+68 added · −10 removed · 10 changed
More facts (2)
Title (from)
on the proposal for a directive of the European Parliament and of the Council on payment services and electronic money services in the Internal Market amending Directive 98/26/EC and repealing Directives 2015/2366/EU and 2009/110/EC
Title (to)
Payment services and electronic money services in the internal market

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 4 of 12: Paragraphs 181–240

9 unchanged paragraphs

Applications for authorisation

1. Member States shall require undertakings other than the undertakings referred to in Article 2(1), points (a), (b), (d), and (e), of Regulation XXX [PSR], and other than natural or legal persons benefiting from an exemption pursuant to Articles 34, 36, 37 and 38 of this Directive, that intend to provide any of the payment services referred to in Annex I, or electronic money services, to obtain authorisation from the competent authorities of the home Member Sate for the provision of those services.

2. The authorisation referred to in paragraph 1 shall only be required for those payment services that the applicant payment institutions actually intend to provide.

3. Member States shall ensure that undertakings that apply for an authorisation as referred to in paragraph 1 provide the competent authorities of the home Member State with an application for authorisation, together with the following:

(a) a programme of operations setting out in particular the type of payment services envisaged;

(b) a business plan, which may include a forecast budget calculation ▌which demonstrates that the applicant is able to employ the appropriate and proportionate systems, resources and procedures to operate soundly;

(c) evidence that the applicant holds initial capital as provided for in Article 5;

(d) for the undertakings applying to provide services as referred to in Annex I, points (1) to (5), and electronic money services, a description of the measures taken for safeguarding payment service users’ funds in accordance with Article 9;

(e) a description of the applicant’s governance arrangements and internal control mechanisms, including administrative, risk management and accounting procedures, and a description of the applicant’s arrangements for the use of ICT services as referred to in Articles 6 and 7 of Regulation (EU) 2022/2554, which demonstrates that those governance arrangements, internal control mechanisms and arrangements for the use of ICT services are proportionate, appropriate, sound and adequate;

Change 15

Changed(f) a description of the procedure in place to monitor, handle and follow up a security incident and security related customer complaints, including an incident reporting mechanism which takes account of the notification obligations of the payment institution laid down in Chapter III of Regulation (EU) 2022/ 2554;2022/2554;

40 unchanged paragraphs

(g) a description of the process in place to file, monitor, track and restrict access to sensitive payment data;

(h) a description of business continuity arrangements including a clear identification of the critical operations, a description of the ICT business continuity plans and ICT response and recovery plans, and a description of the procedure to regularly test and review the adequacy and efficiency of such ICT business continuity and ICT response and recovery plans, as required by Article 11(6) of Regulation (EU) 2022/2554;

(i) a description of the principles and definitions applied for the collection of statistical data on performance, transactions and fraud;

(j) a security policy document, including:

(i) a detailed risk assessment in relation to the applicant’s payment and electronic money services;

(ii) a description of security control and mitigation measures to adequately protect payment service users against the risks identified, including fraud and the illegal use of sensitive and personal data;

(iii) for applicant institutions wishing to enter information sharing arrangements with other payment service providers for the exchange of payment fraud related data as referred to in Article 83(3) of Regulation XXX [PSR], the conclusions of the data protection impact assessment referred to in Article 83(4) of Regulation XXX [PSR] and pursuant to Article 35 of Regulation (EU) 2016/679 and, where applicable, the outcome of the prior consultation of the competent supervisory authority pursuant to Article 36 of that Regulation;

(k) for applicant institutions that are subject to the obligations in relation to money laundering and terrorist financing under Directive (EU) 2015/849 of the European Parliament and of the Council and Regulation (EU) 2015/847 of the European Parliament and of the Council, a description of the internal control mechanisms which the applicant has established to comply with that Directive and Regulation;

(l) a description of the applicant’s structural organisation, including, where applicable, a description of:

▌

▌

(iii) a description of outsourcing arrangements;

(iv) the applicant’s participation in a national or international payment system;

(m) the identity of the persons that hold in the applicant, directly or indirectly, qualifying holdings within the meaning of Article 4(1), point (36), of Regulation (EU) No 575/2013, the size of their holdings and evidence of their suitability to ensure the sound and prudent management of the applicant;

(n) the identity of directors and other persons responsible for the management of the applicant payment institution and, where relevant:

(i) the identity of the persons responsible for the management of the payment services activities of the payment institution;

(ii) evidence that the persons responsible for the management of the payment services activities of the payment institution are of good repute and possess appropriate knowledge and experience to perform payment services as determined by the home Member State of the applicant;

(o) where applicable, the identity of the statutory auditors and audit firms as defined in Article 2, points 2 and 3, of Directive 2006/43/EC of the European Parliament and of the Council;

(p) the applicant’s legal status and articles of association;

(q) the address of the applicant’s registered office;

(r) an overview of EU jurisdictions where the applicant is submitting or is planning to submit an application for authorisation to operate as a payment institution.

(s) a winding-up plan in case of failure, which is adapted to the envisaged size and business model of the applicant.

For the purposes of the first subparagraph, points (d), (e), (f) and (l), Member States shall ensure that the applicant provides a description of its audit arrangements and of the organisational arrangements it has set up to protect the interests of its users and to ensure continuity and reliability in the performance of payment or electronic money services.

The security control and mitigation measures referred to in the first subparagraph, point (j), shall indicate how the applicant will ensure a high level of digital operational resilience as required by Chapter II of Regulation (EU) 2022/2554, in particular in relation to technical security and data protection, including for the software and ICT systems used by the applicant or the undertakings to which it outsources its operations.

4. Member States shall require undertakings that apply for authorisation to provide payment services as referred to in Annex I, point (6), as a condition of their authorisation, to hold a professional indemnity insurance, covering the territories in which they offer services, or some other comparable guarantee against liability which may, only for the initial authorisation period, include a minimum initial capital of EUR 50 000 to ensure that:

(a) they can cover their liabilities as specified in Articles 56, 57, 59, 76, and 78 of Regulation XXX [PSR];

(b) they cover the value of any excess, threshold or deductible from the insurance cover or comparable guarantee;

(c) they monitor the coverage of the insurance or comparable guarantee on an ongoing basis.

5. The EBA shall develop draft regulatory technical standards specifying:

(a) the information to be provided to the competent authorities in the application for the authorisation of payment institutions, including the requirements laid down in paragraph 3, points (a), (b), (c), (e) and (g) to (k) and (r);

(b) a common assessment methodology for granting authorisation as a payment institution, or registration as an account information service provider or ATM deployer, under this Directive;

(c) what is a comparable guarantee, as referred in paragraph 4, first subparagraph, which should be interchangeable with a professional indemnity insurance;

(d) the criteria on how to stipulate the minimum monetary amount of the professional indemnity insurance or other comparable guarantee as referred in paragraph 4.

6. When developing those draft regulatory technical standards referred to in paragraph 5, the EBA shall take account of the following:

(a) the risk profile of the undertaking;

(b) whether the undertaking provides other payment services as referred to in Annex I or is engaged in other businesses;

(c) the size of the activity of the undertaking;

(d) the specific characteristics of comparable guarantees, as referred in paragraph 4, and the criteria for their implementation.

The EBA shall submit those draft regulatory technical standards referred to in paragraph 5 to the Commission by [OP please insert the date = 1 year after the date of entry into force of this Directive].

Power is delegated to the Commission to adopt the regulatory technical standards in accordance with Article 10 to 14 of Regulation (EU) No 1093/2010.

Change 16

AddedArticle 4

6 unchanged paragraphs

Control of the shareholding

1. Any natural or legal person who has taken a decision to acquire or to further increase, directly or indirectly, a qualifying holding within the meaning of Article 4(1), point (36), of Regulation (EU) No 575/2013 in a payment institution, as a result of which the proportion of the capital or of the voting rights held would reach or exceed 20 %, 30 % or 50 %, or so that the payment institution would become its subsidiary, shall inform the competent authorities of that payment institution in writing of their intention in advance. The same applies to any natural or legal person who has taken a decision to dispose, directly or indirectly, of a qualifying holding, or to reduce its qualifying holding so that the proportion of the capital or of the voting rights held would fall below 20 %, 30 % or 50 %, or so that the payment institution would cease to be its subsidiary.

2. The proposed acquirer of a qualifying holding in the payment institution shall inform the competent authority about the size of the intended holding and relevant necessary information as referred to in Article 23(4) of Directive 2013/36/EU.

3. Member States shall require that where the influence exercised by a proposed acquirer, as referred to in paragraph 1, is likely to operate to the detriment of the prudent and sound management of the payment institution, the competent authorities shall express their opposition or take other appropriate measures to bring that situation to an end. Such measures may include injunctions, penalties against directors or the persons responsible for the management of the payment institution in question, or the suspension of the exercise of the voting rights attached to the shares held by the shareholders or members of this payment institution.

Similar measures shall apply to natural or legal persons who fail to comply with the obligation to provide prior information, as laid down in paragraph 2.

4. Where a holding as referred to in paragraph 1 is acquired despite the opposition of the competent authorities, Member States shall, regardless of any other penalty to be adopted, provide for the exercise of the corresponding voting rights to be suspended, the nullity of votes cast or the possibility of annulling those votes.

Change 17

AddedArticle 5

Initial capital

Member States shall require payment institutions to hold, at the time of authorisation, initial capital, comprised of one or more of the items referred to in Article 26, points (1)(a) to (e), of Regulation (EU) No 575/2013 as follows:

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2024-0046 and TA-9-2024-0297”. Text, 23 April 2024. from A-9-2024-0046, to TA-9-2024-0297. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0046/compare/TA-9-2024-0297?all=1&part=4 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-23,
  author = {{European Parliament}},
  title = {{Changes between A-9-2024-0046 and TA-9-2024-0297}},
  year = {2024},
  date = {2024-04-23},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0046/compare/TA-9-2024-0297?all=1&part=4}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0046/compare/TA-9-2024-0297?all=1&part=4},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2024-0046, to TA-9-2024-0297. Data: European Parliament Open Data (CC BY 4.0)}
}