Text · Comparison of two versions
Changes from plenary report to adopted text
A-9-2024-0052 → TA-9-2024-0298
- From
- A-9-2024-0052 Plenary report of 22 Feb 2024
- To
- TA-9-2024-0298 Adopted text of 23 Apr 2024
- Changes
- 145 changes to the text
- Paragraphs
- +148 added · −11 removed · 4 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
- Title (to)
- Payment services in the internal market and amending Regulation (EU) No 1093/2010
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 18 of 24: Paragraphs 1021–1080
Abnormal and unforeseeable circumstances
No liability shall arise under Chapter 4 or 5 in cases of abnormal and unforeseeable circumstances beyond the control of the party pleading for the application of those circumstances, the consequences of which would have been unavoidable despite all efforts to the contrary, or where a payment service provider is bound by other legal obligations covered by Union or national law.
Change 100
AddedCHAPTER 6
Data protection
Change 101
AddedArticle 80
4 unchanged paragraphs
Data protection
Payment systems and payment service providers shall be allowed to process special categories of personal data as referred to in Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 to the extent necessary for the provision of payment services and for compliance with obligations under this Regulation, in the public interest of the well-functioning of the internal market for payment services, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons, including the following:
(a) technical measures to ensure compliance with the principles of purpose limitation, data minimisation and storage limitation, as laid down in Regulation (EU) 2016/679, including technical limitations on the re-use of data and use of state-of-the-art security and privacy-preserving measures, including pseudonymisation, or encryption;
(b) organizational measures, including training on processing special categories of data, limiting access to special categories of data and recording such access.
Change 102
AddedCHAPTER 7
Operational and security risks and authentication
Change 103
AddedArticle 81
8 unchanged paragraphs
Management of operational and security risks
1. Payment service providers shall establish a framework with appropriate mitigation measures and control mechanisms to manage operational and security risks relating to the payment services they provide. As part of that framework, payment service providers shall establish and maintain effective incident management procedures, including for the detection and classification of major operational and security incidents.
The first subparagraph shall be without prejudice to the application of Chapter II of Regulation (EU) 2022/2554 of the European Parliament and of the Council to:
(a) payment service providers referred to in Article 2(1), points (a), (b) and (d) of this Regulation;
(b) account information service providers referred to in Article 36(1) of Directive (EU) (PSD3); and
(c) payment institutions exempted pursuant to Article 34(1) of Directive (EU) (PSD3).
Payment service providers shall provide to the competent authority designated under Directive (EU) XXX (PSD3) on an annual basis, or at shorter intervals as determined by the competent authority, an updated and comprehensive assessment of the operational and security risks relating to the payment services they provide and on the adequacy of the mitigation measures and control mechanisms implemented in response to those risks.
2. The EBA shall promote cooperation, including the sharing of information, in the area of operational and security risks associated with payment services among the competent authorities, between the competent authorities and the ECB and, where relevant, the European Union Agency for Network and Information Security.
Change 104
AddedArticle 82
8 unchanged paragraphs
Fraud reporting
1. Payment service providers shall provide, at least on an annual basis, statistical data on fraud relating to different means of payment to their competent authorities. Those competent authorities shall provide the EBA and the ECB with such data in an aggregated form.
Statistical data on fraud shall include the number and value of reimbursed fraudulent transactions. Where reimbursement has been refused, payment service providers shall provide the reason for the rejection, such as stipulating that the consumer has acted fraudulently or with gross negligence.
1a. The EBA and the ECB shall publish the statistical data in aggregated form at least on a yearly basis.
2. The EBA shall, in close cooperation with the ECB, develop draft regulatory technical standards on statistical data to be provided in accordance with paragraph 1 on the fraud reporting requirements referred to in paragraph 1.
The EBA shall submit the regulatory technical standards referred to in first subparagraph to the Commission by [ OP please insert the date= one year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.
3. The EBA shall develop draft implementing technical standards establishing the standard forms and templates for the submission of the payment fraud data by competent authorities to the EBA, as referred to in paragraph 1.
The EBA shall submit the implementing technical standards referred to in first subparagraph to the Commission by [ OP please insert the date= one year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Article 15 of Regulation (EU) No 1093/2010.
Change 105
AddedArticle 83
28 unchanged paragraphs
Transaction monitoring mechanisms and fraud data sharing
1. Payment service providers shall have transaction monitoring mechanisms in place that:
(a) support the risk-based application of strong customer authentication in accordance with Article 85;
(b) exempt the application of strong customer authentication based on the criteria under Article 85(11), subject to specified and limited conditions based on the level of risk involved, the types and details of the data assessed by the payment service provider, including through the transaction monitoring mechanisms as set out in paragraph 2 of this Article;
(c) ▐prevent, detect and, where possible, resolve potentially fraudulent payment transactions, including transactions involving payment initiation services.
2. Transaction monitoring mechanisms shall be based on the analysis of previous payment transactions and access to payment accounts online as well as on the fraud data shared and observed fraud patterns. Processing shall include the following data required for the purposes referred to in paragraph 1:
(a) information on the payment service user, including the environmental and behavioural characteristics which are typical of the payment service user in the circumstances of a normal use of the personalised security credentials;
(b) information on the payment account, including the payment transaction history;
(c) transaction information, including the transaction amount and unique identifier of the payee;
(d) session data, including the device internet protocol address-range from which the payment account has been accessed.
When the transaction monitoring mechanisms provide strong evidence for suspecting a fraudulent transaction, or when a police report is notified by the user to the payment service provider, payment service providers shall have the right to block the execution of the payment order, or block and recover the related funds. That evidence shall be understood as objectively justified reasons relating to the security of the payment transaction and the suspicion of unauthorised or fraudulent transactions.
Payees’ payment service providers shall provide the data required for the purposes referred to in paragraph 1 to the payment service providers involved in the transaction.
Payment service providers shall not store data referred to in this paragraph longer than necessary for the purposes set out in paragraph 1, and, in any event, no longer than 10 years after the termination of the customer relationship. Payment service providers shall ensure that the transaction monitoring mechanisms take into account, at a minimum, each of the following risk-based factors:
(a) lists of compromised or stolen authentication elements;
(b) the amount of each payment transaction;
(c) known fraud scenarios in the provision of payment services;
(d) signs of malware infection in any sessions of the authentication procedure;
(e) in case the access device or the software is provided by the payment service provider, a log of the use of the access device or the software provided to the payment service user and the abnormal use of the access device or the software.
Payment service providers may process the data listed in the first subparagraph of Article 83(2) for strong customer authentication as an element of ‘inherence’ pursuant to Article 3, point (35).
3. To ▐comply with paragraph 1, point (c), payment service providers shall exchange information, including the unique identifier, name, personal identification number, organisation number, modus operandi and other transaction information of a payee with other payment service providers who are subject to information sharing arrangements as referred to in paragraph 5, when the payment service provider has sufficient evidence to assume that there was a fraudulent payment transaction. Sufficient evidence for sharing unique information shall be assumed when at least two different payment services users, who are customers of the same payment service provider have informed that a unique identifier of a payee was used to make a fraudulent credit transfer. Payment service providers shall not keep information obtained following the information exchange referred to in this paragraph and paragraph 5 for longer than it is necessary for the purposes laid down in paragraph 1, point (c).
3a. To the extent necessary to comply with paragraph 1, point (c), payment service providers, law enforcement agents and public authorities may also exchange the information referred to in paragraph 3 with public authorities.
4. The information sharing arrangements shall define details for participation and shall set out the details on operational elements, including the use of dedicated IT platforms, if applicable. Before concluding such arrangements, payment service providers shall conduct jointly a data protection impact assessment as referred to in Article 35 of the Regulation (EU) 2016/679 and, where applicable, carry out prior consultation of the supervisory authority as referred to in Article 36 of that Regulation. The information sharing arrangements shall be concluded by ... [12 months from the date of entry into force of this Regulation].
4a. The EBA shall set up a dedicated IT platform to allow payment service providers to exchange information on fraudulent unique identifiers and other relevant information described in this Article with other payment service providers.
That platform shall be set up by ... [12 months from the date of entry into force of this Regulation].
5. Payment service providers shall notify competent authorities of their participation in the information sharing arrangements referred to in paragraph 4, upon validation of their membership by participants of the information sharing arrangement or, as applicable, of the cessation of their membership, once that cessation takes effect.
5a. Where the payment service provider fails to block a unique identifier which was reported to that payment service provider as fraudulent or involved in transactions demonstrably confirmed as fraudulent, the payment service user shall not bear any resulting financial losses.
5b. Where payment fraud originates in the publication of fraudulent content online, payment service providers shall, without undue delay, inform providers of hosting services following the procedure laid down in Article 16 of Regulation (EU) 2022/2065 (Digital Services Act).
6. The processing of personal data in accordance with paragraph 4 shall not lead to termination of the contractual relationship with the customer by the payment service provider or affect their future on-boarding by another payment service provider unless a thorough fraud investigation conducted by the relevant authorities has concluded that the customer participated in the fraudulent activity.
Change 106
AddedArticle 84
Payment fraud risks and trends
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=18
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 30 September 2026
Cite as
European Parliament (2024). “Changes between A-9-2024-0052 and TA-9-2024-0298”. Text, 23 April 2024. from A-9-2024-0052, to TA-9-2024-0298. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=18 (retrieved 30 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-23,
author = {{European Parliament}},
title = {{Changes between A-9-2024-0052 and TA-9-2024-0298}},
year = {2024},
date = {2024-04-23},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=18}},
url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=18},
urldate = {2026-09-30},
publisher = {EU Parl Watch Research},
note = {Text. from A-9-2024-0052, to TA-9-2024-0298. Data: European Parliament Open Data (CC BY 4.0)}
}