Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-755995 → A-9-2024-0052

From
ECON-PR-755995 report parliamentary committee draft of 13 Nov 2023
To
A-9-2024-0052 Plenary report of 22 Feb 2024
Changes
Not comparable
Paragraphs
+1 233 added · −106 removed · 1 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 16 of 24: Paragraphs 857–916

Added(a) make sure that the personalised security credentials are not accessible to parties other than the payment service user that is entitled to use the payment instrument, without prejudice to the obligations on the payment service user set out in Article 52;

Added(b) refrain from sending an unsolicited payment instrument, except where a payment instrument already given to the payment service user is to be replaced;

Added(c) ensure that appropriate means, including a free of charge communication channel allowing for human support in the official language of the host Member State, are available at all times to enable the payment service user to make a notification pursuant to Article 52 point (b), or to request unblocking of the payment instrument pursuant to Article 51(4);

Added(d) provide the payment service user with the possibility to make a notification pursuant to Article 52 point (b) free of charge and only charge any possible replacement costs directly attributed to the payment instrument;

Added(e) prevent all use of the payment instrument once a notification pursuant to Article 52 point (b) has been made;

Added(ea) use safe communication channels and, in principle, refrain from sending links and documents via e-mail;

Added(f) For the purposes of point (c), the payment service provider shall provide the payment service user upon its request with the means to prove, for 18 months after notification, that the payment service user made such a notification.

Added2. The payment service provider shall bear the risk of sending a payment instrument or any personalised security credentials relating to it to the payment service user.

Added2a. Where the payer’s payment service provider does not comply with the obligations set out in this Article, the payer shall not bear any resulting financial losses unless the payer acted fraudulently.

AddedNotification and rectification of unauthorised, authorised or incorrectly executed payment transactions

Added1. The payment service provider shall only rectify any unauthorised, incorrectly executed payment transaction or authorised payment transaction where the payment service user notifies the payment service provider in accordance with Articles 57 and 59 without undue delay after becoming aware of any such transaction giving rise to a claim, including a claim under Article 75, and no later than 18 months after the debit date.

AddedThe time limits for notification laid down in the first subparagraph shall not apply where the payment service provider has failed to provide or make available the information on the payment transaction in accordance with Title II.

Added2. Where a payment initiation service provider is involved, the payment service user shall obtain rectification from the account servicing payment service provider pursuant to paragraph 1 of this Article, without prejudice to Article 56(4) and Article 75(1).

AddedEvidence on authorisation and execution of payment transactions

Added1. Where a payment service user denies having authorised an executed payment transaction or claims that the payment transaction was not correctly executed, the burden shall be on the payment service provider to prove that the payment transaction was authorised, accurately recorded, entered in the accounts and not affected by a technical breakdown or some other deficiency of the service provided by the payment service provider.

AddedIf the payment transaction is initiated through a payment initiation service provider, the burden shall be on the payment initiation service provider to prove that within its sphere of competence, the payment transaction was authorised, accurately recorded and not affected by a technical breakdown or other deficiency linked to the payment service of which it is in charge.

Added2. Where a payment service user denies having authorised an executed payment transaction, the use of a payment instrument recorded by the payment service provider, including the payment initiation service provider as appropriate, shall in itself not be sufficient to prove either that the payment transaction was authorised by the payer or that the payer acted fraudulently or failed with intent or gross negligence to fulfil one or more of the obligations under Article 52. The payment service provider, including, where appropriate, the payment initiation service provider, shall provide supporting evidence to prove fraud or gross negligence on part of the payment service user.

AddedPayment service provider’s liability for unauthorised payment transactions

Added1. Without prejudice to Article 54, in the case of an unauthorised payment transaction, the payer’s payment service provider shall refund the payer the amount of the unauthorised payment transaction immediately, and in any event no later than by the end of the following business day, after noting or being notified of the unauthorised transaction, except where the payer’s payment service provider has reasonable grounds for suspecting fraud committed by the payer and communicates those grounds to the relevant national authority in writing.

Added2. Where the payer’s payment service provider had reasonable grounds for suspecting fraud committed by the payer, the payer’s payment service provider shall, within 14 business days after noting or being notified of the transaction, do either of the following:

Added(a) refund the payer the amount of the unauthorised payment transaction if the payer’s payment service provider has concluded, after further investigation, that no fraud has been committed by the payer;

Added(b) provide a justification to the relevant national authority and to the payer for refusing the refund and indicate the bodies to which the payer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the payer does not accept the reasons provided.

Added3. Where applicable, the payer’s payment service provider shall restore the debited payment account to the state in which it would have been had the unauthorised payment transaction not taken place. The payer’s payment service provider shall also ensure that the credit value date for the payer’s payment account shall be no later than the date the amount had been debited.

Added4. Where the payment transaction is initiated through a payment initiation service provider, the account servicing payment service provider shall refund immediately, and in any event no later than by the end of the following business day, the amount of the unauthorised payment transaction and, where applicable, restore the debited payment account to the state in which it would have been had the unauthorised payment transaction not taken place.

Added5. If the payment initiation service provider is liable for the unauthorised payment transaction, the payment initiation service provider shall immediately compensate the account servicing payment service provider at its request for the losses incurred or sums paid as a result of the refund to the payer, including the amount of the unauthorised payment transaction. In accordance with Article 55(1), the burden shall be on the payment initiation service provider to prove that, within its sphere of competence, the payment transaction was authorised, accurately recorded and not affected by a technical breakdown or other deficiency linked to the payment service of which it is in charge.

Added6. The payer may be entitled to further financial compensation from the payment service provider in accordance with the law applicable to the contract concluded between the payer and the payment service provider or the contract concluded between the payer and the payment initiation service provider, where applicable.

AddedPayment service provider’s liability for incorrect application of the matching verification service

Added1. The payer shall not bear any financial losses for any authorised credit transfer where the payment service provider of the payer failed, in breach of Article 50(1), to notify the payer of a detected discrepancy between the unique identifier and the name of the payee provided by the payer.

Added2. Within 14 business days after noting or being notified of a credit transfer transaction executed in the circumstances referred to in paragraph 1, the payment service provider shall do either of the following:

Added(a) refund the payer the full amount of the authorised credit transfer;

Added(b) provide an accurate and substantiated justification to the payer in writing for refusing the refund, provide proof to the relevant competent authority that there was no infringement of Article 50(1) and indicate the bodies to which the payer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the payer does not accept the reasons provided.

Added3. Where the payment service provider of the payee is responsible for the breach of Article 50(1) committed by the payment service provider of the payer, the payment service provider of the payee shall refund the financial damage incurred by the payment service provider of the payer.

Added4. The burden shall be on the payment service provider of the payer or, in the case referred to in paragraph 3, of the payee to prove that there was no breach of Article 50(1).

Added5. Paragraphs 1 to 4 shall not apply if the payer has acted fraudulently or if the payer opted out from receiving the verification service in accordance with Article 50(4).

Added6. This Article shall not apply to instant credit transfers denominated in euro falling within the scope of by Regulation XXX (IPR).

AddedLiability of technical service providers and of operators of payment schemes for failure to support the application of strong customer authentication

AddedTechnical service providers and operators of payment schemes that either provide services to the payee, or to the payment service provider of the payee or of the payer, shall be liable for direct financial damage caused to the payee, to the payment service provider of the payee or of the payer for, and proportionate to, their failure, within the remit of their contractual relationship, and not exceeding the amount of the transaction in question to provide the services that are necessary to enable the application of strong customer authentication.

AddedImpersonation fraud

Added1. Where a payment services user who is a consumer was manipulated by a third party pretending to be an employee of the consumer’s payment service provider or any other relevant entity of a public or private nature using the name or e-mail address or telephone number of that entity unlawfully and that manipulation gave rise to subsequent fraudulent authorised payment transactions, the payment service provider shall refund the consumer the full amount of the fraudulent authorised payment transaction under the condition that the consumer has, without any delay, reported the fraud to the police and notified its payment service provider.

Added2. Within 10 business days after ▐being notified of the fraudulent authorised payment transaction by the consumer and being presented with the police report, the payment service provider shall do either of the following:

Added(a) refund the consumer the amount of the fraudulent authorised payment transaction;

Added(b) where the payment service provider has reasonable grounds to suspect a fraud or a gross negligence by the consumer, provide to the relevant national authority a substantiated justification for refusing the refund and indicate to the consumer the bodies to which the consumer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the consumer does not accept the reasons provided.

Added3. Paragraph 1 shall not apply if the consumer has acted fraudulently or with gross negligence or refuses to comply with the payment service provider’s investigation, or to provide relevant information regarding the circumstances of the impersonation.

Added4. The burden shall be on the payment service provider of the consumer to prove that the consumer acted fraudulently or with gross negligence.

Added5. Where informed by a payment service provider of the occurrence of the type of fraud as referred to in paragraph 1, electronic communications services providers shall cooperate closely with payment service providers and act swiftly to ensure that appropriate organizational and technical measures are in place to safeguard the security and confidentiality of communications in accordance with Directive 2002/58/EC, including with regard to calling line identification and electronic mail address. If the electronic communications service providers do not remove the fraudulent or illegal content, after being informed of its occurence, they shall refund the payment service provider the full amount of the fraudulent authorised payment transaction under the condition that the consumer has, without any delay, reported the fraud to the police and notified its payment service provider.

Added5a. Electronic communications service providers shall have in place all necessary educational measures, including alerts to their customers via all appropriate means and media when new forms of online scams emerge, taking into account the needs of their most vulnerable groups of customers.

AddedElectronic communications service providers shall give their customers clear indications as to how to identify fraudulent attempts and warn them as to the necessary actions and precautions to be taken to avoid falling victim to fraudulent actions targeting them. Electronic communications service providers shall inform their customers of the procedure for reporting fraudulent actions and how to rapidly obtain fraud-related information.

Added5b. All providers involved in the fraud chain shall act swiftly to ensure that the appropriate organisational and technical measures are in place to safeguard the security of payments users when making transactions. Payment service providers, electronic communications service providers and digital platform service providers shall have in place fraud prevention and mitigation techniques to fight fraud in all its configurations, including non-authorised and authorised push payment fraud.

Added5c. By ... [12 months from the date of entry in force of this Regulation], the EBA shall issue technical guidelines in accordance with Article 16 of Regulation (EU) No 1093/2010 regarding the concept of gross negligence in the context of this Regulation and respecting the national legal frameworks on that matter.

AddedPayer’s liability for unauthorised payment transactions

Added1. By way of derogation from Article 56, the payer may be obliged to bear the losses relating to any unauthorised payment transactions, up to a maximum of EUR 50, resulting from the use of a lost or stolen payment instrument or from the misappropriation of a payment instrument.

AddedThe first subparagraph shall not apply where any of the following occurred:

Added(a) the loss, theft or misappropriation of a payment instrument or security credentials was not detectable to the payer prior to a payment, except where the payer has acted fraudulently; or

Added(b) the loss was caused by acts or lack of action of an employee, agent or branch of a payment service provider or of an entity to which its activities were outsourced.

AddedThe payer shall bear all of the losses relating to any unauthorised payment transactions if those losses were incurred by the payer acting fraudulently or failing to fulfil one or more of the obligations set out in Article 52 with intent or gross negligence. In such cases, the maximum amount referred to in the first subparagraph shall not apply.

AddedWhere the payer has neither acted fraudulently nor intentionally failed to fulfil its obligations under Article 52, national competent authorities or payment service providers may reduce the liability referred to in this paragraph, taking into account, in particular, the nature of the personalised security credentials and the specific circumstances under which the payment instrument was lost, stolen or misappropriated.

Added2. Where the payer’s payment service provider fails to fulfil the obligation to require strong customer authentication set out in Article 85, the payer shall not bear any financial losses unless the payer has acted fraudulently. The same shall apply where either the payment service provider of the payer or of the payee applies an exemption from the application of strong customer authentication. Where the payee or the payment service provider of the payee fails to develop or amend the systems, hardware and software that are necessary to apply strong customer authentication, the payee or the payment service provider of the payee shall refund the financial damage caused to the payer’s payment service provider.

Added3. Where the payee’s payment services provider applies an exemption from the application of strong customer authentication, the payee’s payment services provider shall be liable towards the payer’s payment services provider for any financial loss incurred by the latter.

Added4. The payer shall not bear any financial consequences resulting from use of the lost, stolen or misappropriated payment instrument after notification in accordance with of Article 52, point (b), except where the payer has acted fraudulently.

AddedIf the payment service provider does not provide appropriate means for the notification at all times of a lost, stolen or misappropriated payment instrument, as required under of Article 53(1), point (c), the payer shall not be liable for the financial consequences resulting from use of that payment instrument, except where the payer has acted fraudulently.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2024). “Changes between ECON-PR-755995 and A-9-2024-0052”. Text, 22 February 2024. from ECON-PR-755995, to A-9-2024-0052. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=16 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-22,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-755995 and A-9-2024-0052}},
  year = {2024},
  date = {2024-02-22},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=16}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=16},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-755995, to A-9-2024-0052. Data: European Parliament Open Data (CC BY 4.0)}
}