Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ECON-PR-755995 → A-9-2024-0052
- From
- ECON-PR-755995 report parliamentary committee draft of 13 Nov 2023
- To
- A-9-2024-0052 Plenary report of 22 Feb 2024
- Changes
- Not comparable
- Paragraphs
- +1 233 added · −106 removed · 1 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 14 of 24: Paragraphs 737–796
Added2. The dashboard shall:
Added(a) provide the payment service user, to the extent that the information is in the possession of the account servicing payment service provider, with an overview of each ongoing permission given for the purposes of account information services or payment initiation services, including:
Added(i) the name of the account information service provider or payment initiation service provider to which access has been granted;
Added(ii) the customer account to which access has been granted;
Added(iii) the purpose of the permission;
Added(iv) the period of validity of the permission;
Added(v) the categories of data being shared;
Added(va) the dates on which the data was accessed.
Added(b) allow the payment service user to withdraw data access for all account information services or payment initiation service providers or for a given account information service or payment initiation service provider;
Added▐
Added(ca) allow payment services users to opt out from data sharing with third parties in a general way for all present and future data access permission requests;
Added(d) include a record of data access permissions that have been withdrawn or have expired, for a duration of two years;
Added(da) be consistent with the FIDA dashboards and allow data holders to manage data permissions stemming from both that Regulation and this Regulation through a single dashboard upon the request of the user.
Added2a. The EBA shall develop guidelines to specify the categories of data referred to in paragraph 2, point (a), so that the data are easily understandable for consumers.
Added2b. Where, pursuant to paragraph 2, point (b), a payment services user decides to withdraw data access, the account information service provider or payment initiation service provider concerned shall:
Added(a) no longer use the data;
Added(b) withdraw the data; and
Added(c) without undue delay erase all data received as a result of the data access permission granted by the payment services user.
Added3. The account servicing payment service provider shall ensure that the dashboard is easy to find in its user interface and that information displayed on the dashboard is clear, accurate and easily understandable for the payment service user.
Added4. The account servicing payment service provider and the account information service or payment initiation service provider to which permission has been granted shall cooperate to make information available to the payment service user via the dashboard in real-time. For the purposes of paragraph 2▐:
Added(a) The account servicing payment service provider shall inform the account information service or payment initiation service provider in real time of changes made to a permission concerning that provider made by a payment service user via the dashboard;
Added(b) An account information service or payment initiation service provider shall inform the account servicing payment service provider in real time of a new permission granted by a payment service user regarding a payment account provided by that account servicing payment service provider, including:
Added(i) the purpose of the permission granted by the payment service user, in a clear and comprehensible manner for the user;
Added(ii) the period of validity of the permission;
Added(iii) the categories of data concerned.
AddedProhibited obstacles to data access
Added1. Account servicing payment service providers shall ensure that their dedicated interface does not create obstacles to the provision of payment initiation and account information services and enables a straightforward and seamless consumer experience.
AddedProhibited obstacles shall include, but are not limited to, the following:
Added(a) preventing the use by payment initiation services providers or account information services providers of the personalised security credentials issued by account servicing payment service providers to their payment services users;
Added(b) requiring the payment service users to manually input their unique identifier into the domain of the account servicing payment service provider to be able to use account information or payment initiation services;
Added(c) requiring additional checks of the permission given by the payment service users to a payment initiation service provider or an account information services provider;
Added(d) requiring additional registrations by payment initiation and account information services providers to be able to access the payment services user’s payment account or the dedicated interface;
Added(e) requiring, unless indispensable to facilitate the exchange of information between account servicing payment service providers and payment initiation and account information services providers related, in particular, to the updating of the dashboard referred to in Article 43, that payment initiation and account information services providers pre-register their contact details with the account servicing payment service provider;
Added(f) restricting the possibility of a payment service user to initiate payments via a payment initiation service provider only to those payees that are on the payer’s beneficiaries list;
Added(g) restricting payment initiations to or from domestic unique identifiers only;
Added(h) requiring that strong customer authentication is applied more times in comparison with the strong customer authentication as required by the account servicing payment service provider when the payment service user is directly accessing their payment account or initiating a payment with the account servicing payment services provider;
Added(i) providing a dedicated interface that does not support all the authentication procedures made available by the account servicing payment service provider to its payment service user;
Added(j) imposing an account information or payment initiation journey, in a ‘redirection’ or ‘decoupled’ approach for the authentication of the payment service user as well as imposing additional steps or required actions in the user journey compared to the equivalent authentication procedure offered to payment service users when directly accessing their payment accounts or initiating a payment with the account servicing payment service provider;
Added(k) imposing that the user be automatically redirected, at the stage of authentication, to the account servicing payment service provider’s web page address when this is the sole method of carrying out the authentication of the payment services user that is supported by an account servicing payment service provider;
Added(l) requiring two strong customer authentications in a payment initiation service-only journey where the payment initiation service provider transmits to the account servicing payment service provider all the information necessary to initiate the payment, namely one strong customer authentication for the yes/no confirmation and a second strong customer authentication for payment initiation.
Added1a. Measures and instruments used by account servicing payment service providers in response to suspected fraud or to comply with Regulation (EU) 2016/679 shall not constitute prohibited obstacles.
Added2. For the activities of payment initiation services and account information services the name and the account number or any other unique identifier of the account owner shall not constitute sensitive payment data.
AddedRights and obligations of account information service providers and payment initiation service providers
AddedUse of the customer interface by account information service providers and payment initiation service providers
Added1. Account information service providers and payment initiation service providers shall access payment account data exclusively via the dedicated interface referred to in Article 35, except in the circumstances covered by Article 38(4) and (5) and Article 39.
Added2. Where an account information service provider or a payment initiation service provider accesses payment account data via an interface that the account servicing payment service provider makes available to its payment service users for directly accessing their payment account, in accordance with Article 38(4) and (5), or where that is the only interface accessible in accordance with Article 39, the account information service provider or the payment initiation service provider shall at all times:
Added(a) identify itself towards the account servicing payment service provider;
Added(b) rely on the authentication procedures provided by the account servicing payment service provider to the payment service user;
Added(c) take the necessary measures to ensure that they do not process data (including access and storage of data) for purposes other than for the provision of the service as requested by the payment service user;
Added(d) log the data that are accessed through the interface operated by the account servicing payment service provider for its payment service users, and provide, upon request and without undue delay, the log files to the competent authority. Logs shall be deleted 3 years after their creation. Logs may be kept for longer than this retention period if they are required for monitoring procedures that are already underway, but only for as long as is strictly necessary to perform such procedures.
Added▐Article 46
AddedSpecific obligations of payment initiation service providers
Added1. Payment initiation service providers shall:
Added(a) provide account servicing payment service providers with the same information as the information requested from the payment service user when initiating the payment transaction directly;
Added(b) provide services only where based on the payment service user’s permission, in accordance with Article 49;
Added(c) not hold at any time the payer’s funds in connection with the provision of the payment initiation service;
Added(d) ensure that the personalised security credentials of the payment services user are not, with the exception of the payer and the issuer of the personalised security credentials, accessible to other parties, including the payment initiation service provider itself, and that they are transmitted by the payment initiation service provider through safe and efficient channels;
Added(e) ensure that any other information about the payment services user obtained when providing payment initiation services, is only provided to the payee and only with the payment services user’s permission;
Added(f) every time a payment is initiated, identify itself towards the account servicing payment service provider and communicate with the account servicing payment service provider, the payer and the payee in a secure way.
Added2. Payment initiation service providers shall not:
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=14
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 28 September 2026
Cite as
European Parliament (2024). “Changes between ECON-PR-755995 and A-9-2024-0052”. Text, 22 February 2024. from ECON-PR-755995, to A-9-2024-0052. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=14 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-22,
author = {{European Parliament}},
title = {{Changes between ECON-PR-755995 and A-9-2024-0052}},
year = {2024},
date = {2024-02-22},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=14}},
url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=14},
urldate = {2026-09-28},
publisher = {EU Parl Watch Research},
note = {Text. from ECON-PR-755995, to A-9-2024-0052. Data: European Parliament Open Data (CC BY 4.0)}
}