Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-755995 → A-9-2024-0052

From
ECON-PR-755995 report parliamentary committee draft of 13 Nov 2023
To
A-9-2024-0052 Plenary report of 22 Feb 2024
Changes
Not comparable
Paragraphs
+1 233 added · −106 removed · 1 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 19 of 24: Paragraphs 1037–1096

AddedPayment service providers shall provide to the competent authority designated under Directive (EU) XXX (PSD3) on an annual basis, or at shorter intervals as determined by the competent authority, an updated and comprehensive assessment of the operational and security risks relating to the payment services they provide and on the adequacy of the mitigation measures and control mechanisms implemented in response to those risks.

Added2. The EBA shall promote cooperation, including the sharing of information, in the area of operational and security risks associated with payment services among the competent authorities, between the competent authorities and the ECB and, where relevant, the European Union Agency for Network and Information Security.

AddedFraud reporting

Added1. Payment service providers shall provide, at least on an annual basis, statistical data on fraud relating to different means of payment to their competent authorities. Those competent authorities shall provide the EBA and the ECB with such data in an aggregated form.

AddedStatistical data on fraud shall include the number and value of reimbursed fraudulent transactions. Where reimbursement has been refused, payment service providers shall provide the reason for the rejection, such as stipulating that the consumer has acted fraudulently or with gross negligence.

Added1a. The EBA and the ECB shall publish the statistical data in aggregated form at least on a yearly basis.

Added2. The EBA shall, in close cooperation with the ECB, develop draft regulatory technical standards on statistical data to be provided in accordance with paragraph 1 on the fraud reporting requirements referred to in paragraph 1.

AddedThe EBA shall submit the regulatory technical standards referred to in first subparagraph to the Commission by [ OP please insert the date= one year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

Added3. The EBA shall develop draft implementing technical standards establishing the standard forms and templates for the submission of the payment fraud data by competent authorities to the EBA, as referred to in paragraph 1.

AddedThe EBA shall submit the implementing technical standards referred to in first subparagraph to the Commission by [ OP please insert the date= one year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Article 15 of Regulation (EU) No 1093/2010.

AddedTransaction monitoring mechanisms and fraud data sharing

Added1. Payment service providers shall have transaction monitoring mechanisms in place that:

Added(a) support the risk-based application of strong customer authentication in accordance with Article 85;

Added(b) exempt the application of strong customer authentication based on the criteria under Article 85(11), subject to specified and limited conditions based on the level of risk involved, the types and details of the data assessed by the payment service provider, including through the transaction monitoring mechanisms as set out in paragraph 2 of this Article;

Added(c) ▐prevent, detect and, where possible, resolve potentially fraudulent payment transactions, including transactions involving payment initiation services.

Added2. Transaction monitoring mechanisms shall be based on the analysis of previous payment transactions and access to payment accounts online as well as on the fraud data shared and observed fraud patterns. Processing shall include the following data required for the purposes referred to in paragraph 1:

Added(a) information on the payment service user, including the environmental and behavioural characteristics which are typical of the payment service user in the circumstances of a normal use of the personalised security credentials;

Added(b) information on the payment account, including the payment transaction history;

Added(c) transaction information, including the transaction amount and unique identifier of the payee;

Added(d) session data, including the device internet protocol address-range from which the payment account has been accessed.

AddedWhen the transaction monitoring mechanisms provide strong evidence for suspecting a fraudulent transaction, or when a police report is notified by the user to the payment service provider, payment service providers shall have the right to block the execution of the payment order, or block and recover the related funds. That evidence shall be understood as objectively justified reasons relating to the security of the payment transaction and the suspicion of unauthorised or fraudulent transactions.

AddedPayees’ payment service providers shall provide the data required for the purposes referred to in paragraph 1 to the payment service providers involved in the transaction.

AddedPayment service providers shall not store data referred to in this paragraph longer than necessary for the purposes set out in paragraph 1, and, in any event, no longer than 10 years after the termination of the customer relationship. Payment service providers shall ensure that the transaction monitoring mechanisms take into account, at a minimum, each of the following risk-based factors:

Added(a) lists of compromised or stolen authentication elements;

Added(b) the amount of each payment transaction;

Added(c) known fraud scenarios in the provision of payment services;

Added(d) signs of malware infection in any sessions of the authentication procedure;

Added(e) in case the access device or the software is provided by the payment service provider, a log of the use of the access device or the software provided to the payment service user and the abnormal use of the access device or the software.

AddedPayment service providers may process the data listed in the first subparagraph of Article 83(2) for strong customer authentication as an element of ‘inherence’ pursuant to Article 3, point (35).

Added3. To ▐comply with paragraph 1, point (c), payment service providers shall exchange information, including the unique identifier, name, personal identification number, organisation number, modus operandi and other transaction information of a payee with other payment service providers who are subject to information sharing arrangements as referred to in paragraph 5, when the payment service provider has sufficient evidence to assume that there was a fraudulent payment transaction. Sufficient evidence for sharing unique information shall be assumed when at least two different payment services users, who are customers of the same payment service provider have informed that a unique identifier of a payee was used to make a fraudulent credit transfer. Payment service providers shall not keep information obtained following the information exchange referred to in this paragraph and paragraph 5 for longer than it is necessary for the purposes laid down in paragraph 1, point (c).

Added3a. To the extent necessary to comply with paragraph 1, point (c), payment service providers, law enforcement agents and public authorities may also exchange the information referred to in paragraph 3 with public authorities.

Added4. The information sharing arrangements shall define details for participation and shall set out the details on operational elements, including the use of dedicated IT platforms, if applicable. Before concluding such arrangements, payment service providers shall conduct jointly a data protection impact assessment as referred to in Article 35 of the Regulation (EU) 2016/679 and, where applicable, carry out prior consultation of the supervisory authority as referred to in Article 36 of that Regulation. The information sharing arrangements shall be concluded by ... [12 months from the date of entry into force of this Regulation].

Added4a. The EBA shall set up a dedicated IT platform to allow payment service providers to exchange information on fraudulent unique identifiers and other relevant information described in this Article with other payment service providers.

AddedThat platform shall be set up by ... [12 months from the date of entry into force of this Regulation].

Added5. Payment service providers shall notify competent authorities of their participation in the information sharing arrangements referred to in paragraph 4, upon validation of their membership by participants of the information sharing arrangement or, as applicable, of the cessation of their membership, once that cessation takes effect.

Added5a. Where the payment service provider fails to block a unique identifier which was reported to that payment service provider as fraudulent or involved in transactions demonstrably confirmed as fraudulent, the payment service user shall not bear any resulting financial losses.

Added5b. Where payment fraud originates in the publication of fraudulent content online, payment service providers shall, without undue delay, inform providers of hosting services following the procedure laid down in Article 16 of Regulation (EU) 2022/2065 (Digital Services Act).

Added6. The processing of personal data in accordance with paragraph 4 shall not lead to termination of the contractual relationship with the customer by the payment service provider or affect their future on-boarding by another payment service provider unless a thorough fraud investigation conducted by the relevant authorities has concluded that the customer participated in the fraudulent activity.

AddedPayment fraud risks and trends

Added1. Payment service providers shall alert their customers via all appropriate means and media when new forms of payment fraud emerge, taking into account the needs of their most vulnerable groups of customers. Payment service providers shall give their customers clear indications on how to identify fraudulent attempts and warn them as to the necessary actions and precautions to be taken to avoid falling victim of fraudulent actions targeting them. Payment service providers shall inform their customers of where they can report fraudulent actions and rapidly obtain fraud-related information.

Added1a. Member States shall allocate substantial means to investing in education on payment-related fraud. Such education may take the form of a media campaign or lessons at schools. Payment service providers and electronic communications service providers shall cooperate free of charge with the Member States in those educational activities. Member States shall inform the European Parliament and the Commission about the planned campaigns.

AddedPayment service providers, in cooperation with electronic communications services providers, shall take adequate prevention and robust technical safeguards to prevent cases where fraudsters replicate and misuse the payment service provider’s name, mail address or telephone number for misleading payment service users into making fraudulent transactions.

AddedElectronic communications service providers shall cooperate with payment service providers to ensure that appropriate organisational and technical measures are in place to safeguard the security and confidentiality of communications in accordance with Directive 2002/58/EC, including with regard to calling line identification and electronic mail address.

Added2. Payment service providers shall organize at least annually training programmes on payment fraud risks and trends for their employees active in designing and maintaining payment services and offering them to customers and shall ensure that their employees are adequately trained to carry out their tasks and responsibilities in accordance with the relevant security policies and procedures to mitigate and manage payment fraud risks.

Added3. By [ OP please insert the date= 18 months after the date of entry into force of this Regulation], the EBA shall issue guidelines in accordance with Article 16 of Regulation (EU) No 1093/2010 with regard to the programmes on payment fraud risks referred to in paragraphs 1 and 2 of this Article.

AddedStrong customer authentication

Added1. A payment service provider shall apply strong customer authentication, on the basis of the risk assesment carried out under the transaction monitoring mechanism as set out in Article 83, where the payer:

Added(a) accesses its payment account online;

Added▐

Added(c) places a payment order for an electronic payment transaction;

Added(d) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses.

Added2. Payment transactions that are not initiated by the payer but by the payee only shall not be subject to strong customer authentication to the extent that those transactions are initiated without any interaction or involvement of the payer. Such exemptions shall also apply to refunds that are initiated by the original payee in favour of the payer.

Added3. Where the payer has given a mandate authorising the payee to place a payment order for a payment transaction or a series of payment transactions through a particular payment instrument that is issued to be used by the payer to place payment orders for the payment transactions, and where the mandate is based on an agreement between the payer and the payee for the provision of products or services, the payment transactions initiated thereafter by the payee on the basis of such a mandate may be qualified as payee initiated transactions, provided that those transactions do not need to be preceded by a specific action of the payer to trigger their initiation by the payee.

Added4. The payment transactions for which payment orders are placed by the payee that are based on the mandate given by the payer shall be subject to the general provisions that apply to payee-initiated transactions as referred to in Articles 61, 62 and 63.

Added5. Where the mandate of the payer to the payee to place payment orders for transactions referred to in paragraph 3 is provided through a remote channel with the involvement of the payment service provider, the setting up of such a mandate shall be subject to strong customer authentication.

Added6. For direct debits, where the mandate given by the payer to the payee to initiate one or several direct debit transactions is provided through a remote channel with the direct involvement of a payment service provider in the setting up of such a mandate, strong customer authentication shall be applied.

Added7. Payment transactions for which payment orders are placed by the payer with modalities other than the use of electronic platforms or devices, such as paper-based payment orders, mail orders or telephone-based mechanisms, shall not be subject to strong customer authentication, irrespective of whether or not the execution of the transaction is performed electronically, provided that security requirements and checks are carried out by the payment service provider of the payer allowing another form of authentication of the payment transaction than strong customer authentication.

Added8. For the remote placement of a payment order as referred to in paragraph 1, point (c), payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee.

Added9. For the placement of a payment order as referred to in paragraph 1, point (c), through a payer’s device using proximity technology for the exchange of information with the payee’s infrastructure, the authentication of which requires the use of internet on the payer’s device, payment service providers shall apply strong customer authentication that includes elements which dynamically link the transaction to a specific amount and a specific payee or harmonised security measures of identical effect, which ensure the confidentiality, authenticity and integrity of the amount of the transaction and the payee throughout all of the phases of initiation.

Added10. For the purposes of paragraph 1, payment service providers shall have in place adequate security measures to protect the confidentiality and integrity of payment service users’ personalised security credentials.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
28 September 2026

Cite as

European Parliament (2024). “Changes between ECON-PR-755995 and A-9-2024-0052”. Text, 22 February 2024. from ECON-PR-755995, to A-9-2024-0052. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=19 (retrieved 28 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-22,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-755995 and A-9-2024-0052}},
  year = {2024},
  date = {2024-02-22},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=19}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=19},
  urldate = {2026-09-28},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-755995, to A-9-2024-0052. Data: European Parliament Open Data (CC BY 4.0)}
}