Skip to content

Text · Comparison of two versions

Changes from plenary report to adopted text

A-9-2024-0052 → TA-9-2024-0298

From
A-9-2024-0052 Plenary report of 22 Feb 2024
To
TA-9-2024-0298 Adopted text of 23 Apr 2024
Changes
145 changes to the text
Paragraphs
+148 added · −11 removed · 4 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
Title (to)
Payment services in the internal market and amending Regulation (EU) No 1093/2010

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 19 of 24: Paragraphs 1081–1140

6 unchanged paragraphs

1. Payment service providers shall alert their customers via all appropriate means and media when new forms of payment fraud emerge, taking into account the needs of their most vulnerable groups of customers. Payment service providers shall give their customers clear indications on how to identify fraudulent attempts and warn them as to the necessary actions and precautions to be taken to avoid falling victim of fraudulent actions targeting them. Payment service providers shall inform their customers of where they can report fraudulent actions and rapidly obtain fraud-related information.

1a. Member States shall allocate substantial means to investing in education on payment-related fraud. Such education may take the form of a media campaign or lessons at schools. Payment service providers and electronic communications service providers shall cooperate free of charge with the Member States in those educational activities. Member States shall inform the European Parliament and the Commission about the planned campaigns.

Payment service providers, in cooperation with electronic communications services providers, shall take adequate prevention and robust technical safeguards to prevent cases where fraudsters replicate and misuse the payment service provider’s name, mail address or telephone number for misleading payment service users into making fraudulent transactions.

Electronic communications service providers shall cooperate with payment service providers to ensure that appropriate organisational and technical measures are in place to safeguard the security and confidentiality of communications in accordance with Directive 2002/58/EC, including with regard to calling line identification and electronic mail address.

2. Payment service providers shall organize at least annually training programmes on payment fraud risks and trends for their employees active in designing and maintaining payment services and offering them to customers and shall ensure that their employees are adequately trained to carry out their tasks and responsibilities in accordance with the relevant security policies and procedures to mitigate and manage payment fraud risks.

3. By [ OP please insert the date= 18 months after the date of entry into force of this Regulation], the EBA shall issue guidelines in accordance with Article 16 of Regulation (EU) No 1093/2010 with regard to the programmes on payment fraud risks referred to in paragraphs 1 and 2 of this Article.

Change 107

AddedArticle 85

22 unchanged paragraphs

Strong customer authentication

1. A payment service provider shall apply strong customer authentication, on the basis of the risk assesment carried out under the transaction monitoring mechanism as set out in Article 83, where the payer:

(a) accesses its payment account online;

▐

(c) places a payment order for an electronic payment transaction;

(d) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses.

2. Payment transactions that are not initiated by the payer but by the payee only shall not be subject to strong customer authentication to the extent that those transactions are initiated without any interaction or involvement of the payer. Such exemptions shall also apply to refunds that are initiated by the original payee in favour of the payer.

3. Where the payer has given a mandate authorising the payee to place a payment order for a payment transaction or a series of payment transactions through a particular payment instrument that is issued to be used by the payer to place payment orders for the payment transactions, and where the mandate is based on an agreement between the payer and the payee for the provision of products or services, the payment transactions initiated thereafter by the payee on the basis of such a mandate may be qualified as payee initiated transactions, provided that those transactions do not need to be preceded by a specific action of the payer to trigger their initiation by the payee.

4. The payment transactions for which payment orders are placed by the payee that are based on the mandate given by the payer shall be subject to the general provisions that apply to payee-initiated transactions as referred to in Articles 61, 62 and 63.

5. Where the mandate of the payer to the payee to place payment orders for transactions referred to in paragraph 3 is provided through a remote channel with the involvement of the payment service provider, the setting up of such a mandate shall be subject to strong customer authentication.

6. For direct debits, where the mandate given by the payer to the payee to initiate one or several direct debit transactions is provided through a remote channel with the direct involvement of a payment service provider in the setting up of such a mandate, strong customer authentication shall be applied.

7. Payment transactions for which payment orders are placed by the payer with modalities other than the use of electronic platforms or devices, such as paper-based payment orders, mail orders or telephone-based mechanisms, shall not be subject to strong customer authentication, irrespective of whether or not the execution of the transaction is performed electronically, provided that security requirements and checks are carried out by the payment service provider of the payer allowing another form of authentication of the payment transaction than strong customer authentication.

8. For the remote placement of a payment order as referred to in paragraph 1, point (c), payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.

9. For the placement of a payment order as referred to in paragraph 1, point (c), through a payer’s device using proximity technology for the exchange of information with the payee’s infrastructure, the authentication of which requires the use of internet on the payer’s device, payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee or harmonised security measures of identical effect, which ensure the confidentiality, authenticity and integrity of the amount of the transaction and the payee throughout all of the phases of initiation.

10. For the purposes of paragraph 1, payment service providers shall have in place adequate security measures to protect the confidentiality and integrity of payment service users’ personalised security credentials.

11. Any exemptions from the application of strong customer authentication to be designed by the EBA under Article 89 shall be based on one or more of the following criteria:

(a) the level of risk involved in the service provided;

(b) the amount, the recurrence of the transaction, or both;

(c) the payment channel used for the execution of the transaction;

(ca) whether the parties to the transaction are consumers or corporate payers.

12. The two or more elements referred to in Article 3, point (35), on which strong customer authentication shall be based do not necessarily need to belong to different categories. The independence of the elements shall at all times be fully preserved and the authentication procedure shall at all times ensure a high level of security.

The inherence element of strong customer authentication may include environmental and behavioural characteristics such as those related to the location of the payment service user, the time when the transaction occurs or the device being used.

Change 108

AddedArticle 86

5 unchanged paragraphs

Strong customer authentication in respect of payment initiation and account information services

1. Article 85(8) and (9) shall also apply where payments are initiated through a payment initiation service provider. Article 85(10) shall also apply where payments are initiated through a payment initiation service provider and when the information is requested through an account information service provider.

2. Account servicing payment service providers shall allow payment initiation service providers and the account information service providers to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user in accordance with Article 85(1) and (10) and, where the payment initiation service provider is involved, in accordance with Article 85(1), (8), (9), (10) and (11).

3. Without prejudice to paragraph 2, where payment account information is accessed by an account information service provider, the account servicing payment service provider shall only apply strong customer authentication for the first access to payment account data by a given account information service provider, unless the account servicing payment service provider has reasonable grounds to suspect fraud, but not for the subsequent access to that payment account by that account information service provider.

▐

Change 109

AddedArticle 88

Accessibility requirements regarding strong customer authentication

1. Without prejudice to the accessibility requirements under Directive (EU) 2019/882, payment service providers shall ensure that all their customers, including persons with disabilities, older persons, with low digital skills and those who do not have access to digital channels or payment instruments, have at their disposal at least a means, adapted to their specific situation, which enables them to perform strong customer authentication.

2. Payment services providers shall not make the performance of strong customer authentication – which is to be provided free of charge - dependant on the exclusive use of a single means of authentication and shall not make the performance of strong customer authentication depend, explicitly or implicitly, on the possession of a smartphone or other smart device. Payment services providers shall develop more than one means for the application of strong customer authentication to cater for the various specific situation of all their customers specifically those with disabilities, few digital skills, older persons and those who do not have access to digital channels or payment instruments.

Change 110

AddedArticle 88a

Fair, reasonable and non-discriminatory access to mobile devices

Change 111

Changed1. Without prejudice to Article 6 paragraph (7) of Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/14508,2020/1828, original equipment manufacturers of mobile devices and electronic communications service providers within the meaning of Article 2(1) of Directive (EU) 2018/1972 shall allow providers of front end services effective interoperability with, and access for the purposes of interoperability to, the technical features necessary for storing and transferring data to process payment transactions, on fair, reasonable and non-discriminatory terms.

2. Original equipment manufacturers of mobile devices and electronic communications service providers referred to in paragraph 1 shall not be prevented from taking strictly necessary and proportionate measures to ensure that interoperability does not compromise the integrity of the hardware and software features concerned by the interoperability obligation provided that such measures are duly justified.

3. For the purpose of applying fair, reasonable and non-discriminatory terms pursuant to paragraph 1, original equipment manufacturers of mobile devices and electronic communications service providers referred to in that paragraph shall publish general conditions of effective interoperability and access.

Change 112

AddedArticle 89

15 unchanged paragraphs

Regulatory technical standards on authentication, communication and transaction monitoring mechanisms

1. The EBA shall develop draft regulatory technical standards which shall specify:

(a) the requirements of strong customer authentication as referred to in Article 85;

(b) the exemptions from the application of Article 85(1), (8) and (9), based on the criteria laid down in Article 85(11);

(c) the requirements with which security measures have to comply, in accordance with Article 85(10) in order to protect the confidentiality and the integrity of the payment service users’ personalised security credentials;

(d) the requirements applicable, in accordance with Article 87, to the outsourcing agreements between the payers’ payments service providers and technical service providers concerning the provision and verification of the elements of strong customer authentication by technical service providers; When doing so, the EBA shall take into account its existing guidelines on outsourcing arrangements.

(e) the requirements under Title III, Chapter 3 for common and secure open standards of communication for the purpose of identification, authentication, notification, and information, as well as for the implementation of security measures, between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers;

(f) supplementary provisions on secure open standards of communication using dedicated interfaces;

(g) the technical requirements for transaction monitoring mechanisms referred to in Article 83;

For the purposes of point (b), as regards the exemption from the application of strong customer authentication for payment transactions, based on transaction risk analysis the draft regulatory technical standards shall specify, inter alia:

(i) the conditions that have to be met for a remote electronic payment transaction to be considered as posing a low level of risk, taking into consideration the levels of fraud in each economic activity;

(ii) the methodologies and models to implement transaction risk analysis;

(iii) the criteria for the calculation of fraud rates, including on the allocation of fraud rates between payment service providers providing issuing and acquiring services, or within payment service providers providing issuing and acquiring services through a single legal entity;

(iv) detailed and proportionate reporting and audit requirements.

(ga) a standardised list of categories of information to be disclosed on the dashboard;

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
29 September 2026

Cite as

European Parliament (2024). “Changes between A-9-2024-0052 and TA-9-2024-0298”. Text, 23 April 2024. from A-9-2024-0052, to TA-9-2024-0298. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=19 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-04-23,
  author = {{European Parliament}},
  title = {{Changes between A-9-2024-0052 and TA-9-2024-0298}},
  year = {2024},
  date = {2024-04-23},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=19}},
  url = {https://news.eu-parl.st-solutions.dev/texts/A-9-2024-0052/compare/TA-9-2024-0298?all=1&part=19},
  urldate = {2026-09-29},
  publisher = {EU Parl Watch Research},
  note = {Text. from A-9-2024-0052, to TA-9-2024-0298. Data: European Parliament Open Data (CC BY 4.0)}
}