Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2024-0052 → TA-9-2024-0298
- From
- A-9-2024-0052 Plenary report of 22 Feb 2024
- To
- TA-9-2024-0298 Adopted text of 23 Apr 2024
- Changes
- 145 changes to the text
- Paragraphs
- +148 added · −11 removed · 4 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
- Title (to)
- Payment services in the internal market and amending Regulation (EU) No 1093/2010
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 13 of 24: Paragraphs 721–780
14 unchanged paragraphs
(a) preventing the use by payment initiation services providers or account information services providers of the personalised security credentials issued by account servicing payment service providers to their payment services users;
(b) requiring the payment service users to manually input their unique identifier into the domain of the account servicing payment service provider to be able to use account information or payment initiation services;
(c) requiring additional checks of the permission given by the payment service users to a payment initiation service provider or an account information services provider;
(d) requiring additional registrations by payment initiation and account information services providers to be able to access the payment services user’s payment account or the dedicated interface;
(e) requiring, unless indispensable to facilitate the exchange of information between account servicing payment service providers and payment initiation and account information services providers related, in particular, to the updating of the dashboard referred to in Article 43, that payment initiation and account information services providers pre-register their contact details with the account servicing payment service provider;
(f) restricting the possibility of a payment service user to initiate payments via a payment initiation service provider only to those payees that are on the payer’s beneficiaries list;
(g) restricting payment initiations to or from domestic unique identifiers only;
(h) requiring that strong customer authentication is applied more times in comparison with the strong customer authentication as required by the account servicing payment service provider when the payment service user is directly accessing their payment account or initiating a payment with the account servicing payment services provider;
(i) providing a dedicated interface that does not support all the authentication procedures made available by the account servicing payment service provider to its payment service user;
(j) imposing an account information or payment initiation journey, in a ‘redirection’ or ‘decoupled’ approach for the authentication of the payment service user as well as imposing additional steps or required actions in the user journey compared to the equivalent authentication procedure offered to payment service users when directly accessing their payment accounts or initiating a payment with the account servicing payment service provider;
(k) imposing that the user be automatically redirected, at the stage of authentication, to the account servicing payment service provider’s web page address when this is the sole method of carrying out the authentication of the payment services user that is supported by an account servicing payment service provider;
(l) requiring two strong customer authentications in a payment initiation service-only journey where the payment initiation service provider transmits to the account servicing payment service provider all the information necessary to initiate the payment, namely one strong customer authentication for the yes/no confirmation and a second strong customer authentication for payment initiation.
1a. Measures and instruments used by account servicing payment service providers in response to suspected fraud or to comply with Regulation (EU) 2016/679 shall not constitute prohibited obstacles.
2. For the activities of payment initiation services and account information services the name and the account number or any other unique identifier of the account owner shall not constitute sensitive payment data.
Change 59
AddedSection 4
Rights and obligations of account information service providers and payment initiation service providers
Change 60
AddedArticle 45
21 unchanged paragraphs
Use of the customer interface by account information service providers and payment initiation service providers
1. Account information service providers and payment initiation service providers shall access payment account data exclusively via the dedicated interface referred to in Article 35, except in the circumstances covered by Article 38(4) and (5) and Article 39.
2. Where an account information service provider or a payment initiation service provider accesses payment account data via an interface that the account servicing payment service provider makes available to its payment service users for directly accessing their payment account, in accordance with Article 38(4) and (5), or where that is the only interface accessible in accordance with Article 39, the account information service provider or the payment initiation service provider shall at all times:
(a) identify itself towards the account servicing payment service provider;
(b) rely on the authentication procedures provided by the account servicing payment service provider to the payment service user;
(c) take the necessary measures to ensure that they do not process data (including access and storage of data) for purposes other than for the provision of the service as requested by the payment service user;
(d) log the data that are accessed through the interface operated by the account servicing payment service provider for its payment service users, and provide, upon request and without undue delay, the log files to the competent authority. Logs shall be deleted 3 years after their creation. Logs may be kept for longer than this retention period if they are required for monitoring procedures that are already underway, but only for as long as is strictly necessary to perform such procedures.
▐Article 46
Specific obligations of payment initiation service providers
1. Payment initiation service providers shall:
(a) provide account servicing payment service providers with the same information as the information requested from the payment service user when initiating the payment transaction directly;
(b) provide services only where based on the payment service user’s permission, in accordance with Article 49;
(c) not hold at any time the payer’s funds in connection with the provision of the payment initiation service;
(d) ensure that the personalised security credentials of the payment services user are not, with the exception of the payer and the issuer of the personalised security credentials, accessible to other parties, including the payment initiation service provider itself, and that they are transmitted by the payment initiation service provider through safe and efficient channels;
(e) ensure that any other information about the payment services user obtained when providing payment initiation services, is only provided to the payee and only with the payment services user’s permission;
(f) every time a payment is initiated, identify itself towards the account servicing payment service provider and communicate with the account servicing payment service provider, the payer and the payee in a secure way.
2. Payment initiation service providers shall not:
(a) store, access and use sensitive payment data of the payment service user;
(b) request from the payment service user any data other than those necessary to provide the payment initiation service;
(c) process any personal or non-personal data (including use, access or storage of data) for purposes other than for the provision of the payment initiation service as permitted by the payment services user;
(d) modify the amount, the payee or any other feature of the transaction.
Change 61
AddedArticle 47
11 unchanged paragraphs
Specific obligations of and other provisions concerning account information service providers
1. The account information service provider shall:
(a) provide services only where based on the payment service user’s permission, in accordance with Article 49;
(b) ensure that the personalised security credentials of the payment service user are not accessible to other parties, including the account information service provider itself, with the exception of the user and the issuer of the personalised security credentials, and that when those credentials are transmitted by the account information service provider, transmission is done through safe and efficient channels;
(c) for each communication session, identify itself towards the account servicing payment service provider of the payment service user and securely communicate with the account servicing payment service provider and the payment service user;
(d) access only information from designated payment accounts and associated payment transactions;
(e) have in place suitable and effective mechanisms that prevent access to information other than from designated payment accounts and associated payment transactions, in accordance with the payment service user's permission.
2. The account information service provider shall not:
(a) request sensitive payment data linked to the payment accounts;
(b) use, access or store any data for purposes other than for performing the account information service permitted by the payment service user, in accordance with Regulation (EU) 2016/679.
3. The following Articles shall not apply to account information service providers: Articles 4 to 8, Articles 10, 11 and 12, Articles 14 to 19, Articles 21 to 29, Articles 50 and 51, Articles 53 to 79, and Articles 83 and 84.
Change 62
AddedSection 5
Implementation
Change 63
AddedArticle 48
7 unchanged paragraphs
Role of competent authorities
1. Competent authorities shall ensure that account servicing payment service providers comply at all times with their obligations in relation to the dedicated interface referred to in Article 35(1) and that any identified prohibited obstacle listed in Article 44 is immediately removed by the relevant account servicing payment service provider. Where such non-compliance of the dedicated interfaces with this Regulation or obstacles are identified, including on the basis of information transmitted by payment initiation services and account information services providers, the competent authorities shall take without undue delay the necessary and adequate enforcement measures and impose any appropriate and proportionate sanction or, where appropriate and duly justified, grant access rights in accordance with Article 38(4).
2. Competent authorities shall take without delay every necessary enforcement action where necessary to preserve the access rights of payment initiation services and account information services providers. Enforcement actions may include appropriate sanctions.
3. Competent authorities shall ensure that payment initiation service and account information service providers comply with their obligations in relation to the use of data access interfaces at all times.
4. Competent authorities shall have the necessary resources, notably in terms of dedicated staff, in order to comply at all times with their tasks.
5. Competent authorities shall cooperate with supervisory authorities under Regulation (EU) 2016/679 where processing of personal data is concerned.
6. Competent authorities shall, on their initiative, hold regular joint meetings with account servicing payment service providers, payment initiation service and account information service providers and shall deploy their best efforts to ensure that possible issues arising from the use of and access to data exchange interfaces between account servicing payment service providers, payment initiation service and account information service providers are rapidly et durably solved.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=13
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 29 September 2026
Cite as
European Parliament (2024). “Changes between A-9-2024-0052 and TA-9-2024-0298”. Text, 23 April 2024. from A-9-2024-0052, to TA-9-2024-0298. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=13 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-23,
author = {{European Parliament}},
title = {{Changes between A-9-2024-0052 and TA-9-2024-0298}},
year = {2024},
date = {2024-04-23},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=13}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=13},
urldate = {2026-09-29},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2024-0052, to TA-9-2024-0298. Data: European Parliament Open Data (CC BY 4.0)}
}