Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-755995 → A-9-2024-0052

From
ECON-PR-755995 report parliamentary committee draft of 13 Nov 2023
To
A-9-2024-0052 Plenary report of 22 Feb 2024
Changes
Not comparable
Paragraphs
+1 233 added · −106 removed · 1 changed
More facts (2)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 20 of 24: Paragraphs 1097–1156

Added11. Any exemptions from the application of strong customer authentication to be designed by the EBA under Article 89 shall be based on one or more of the following criteria:

Added(a) the level of risk involved in the service provided;

Added(b) the amount, the recurrence of the transaction, or both;

Added(c) the payment channel used for the execution of the transaction;

Added(ca) whether the parties to the transaction are consumers or corporate payers.

Added12. The two or more elements referred to in Article 3, point (35), on which strong customer authentication shall be based do not necessarily need to belong to different categories. The independence of the elements shall at all times be fully preserved and the authentication procedure shall at all times ensure a high level of security.

AddedThe inherence element of strong customer authentication may include environmental and behavioural characteristics such as those related to the location of the payment service user, the time when the transaction occurs or the device being used.

AddedStrong customer authentication in respect of payment initiation and account information services

Added1. Article 85(8) and (9) shall also apply where payments are initiated through a payment initiation service provider. Article 85(10) shall also apply where payments are initiated through a payment initiation service provider and when the information is requested through an account information service provider.

Added2. Account servicing payment service providers shall allow payment initiation service providers and the account information service providers to rely on the authentication procedures provided by the account servicing payment service provider to the payment service user in accordance with Article 85(1) and (10) and, where the payment initiation service provider is involved, in accordance with Article 85(1), (8), (9), (10) and (11).

Added3. Without prejudice to paragraph 2, where payment account information is accessed by an account information service provider, the account servicing payment service provider shall only apply strong customer authentication for the first access to payment account data by a given account information service provider, unless the account servicing payment service provider has reasonable grounds to suspect fraud, but not for the subsequent access to that payment account by that account information service provider.

Added▐

AddedAccessibility requirements regarding strong customer authentication

Added1. Without prejudice to the accessibility requirements under Directive (EU) 2019/882, payment service providers shall ensure that all their customers, including persons with disabilities, older persons, with low digital skills and those who do not have access to digital channels or payment instruments, have at their disposal at least a means, adapted to their specific situation, which enables them to perform strong customer authentication.

Added2. Payment services providers shall not make the performance of strong customer authentication – which is to be provided free of charge - dependant on the exclusive use of a single means of authentication and shall not make the performance of strong customer authentication depend, explicitly or implicitly, on the possession of a smartphone or other smart device. Payment services providers shall develop more than one means for the application of strong customer authentication to cater for the various specific situation of all their customers specifically those with disabilities, few digital skills, older persons and those who do not have access to digital channels or payment instruments.

AddedFair, reasonable and non-discriminatory access to mobile devices

Added1. Without prejudice to Article 6 paragraph (7) of Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/14508, original equipment manufacturers of mobile devices and electronic communications service providers within the meaning of Article 2(1) of Directive (EU) 2018/1972 shall allow providers of front end services effective interoperability with, and access for the purposes of interoperability to, the technical features necessary for storing and transferring data to process payment transactions, on fair, reasonable and non-discriminatory terms.

Added2. Original equipment manufacturers of mobile devices and electronic communications service providers referred to in paragraph 1 shall not be prevented from taking strictly necessary and proportionate measures to ensure that interoperability does not compromise the integrity of the hardware and software features concerned by the interoperability obligation provided that such measures are duly justified.

Added3. For the purpose of applying fair, reasonable and non-discriminatory terms pursuant to paragraph 1, original equipment manufacturers of mobile devices and electronic communications service providers referred to in that paragraph shall publish general conditions of effective interoperability and access.

AddedRegulatory technical standards on authentication, communication and transaction monitoring mechanisms

Added1. The EBA shall develop draft regulatory technical standards which shall specify:

Added(a) the requirements of strong customer authentication as referred to in Article 85;

Added(b) the exemptions from the application of Article 85(1), (8) and (9), based on the criteria laid down in Article 85(11);

Added(c) the requirements with which security measures have to comply, in accordance with Article 85(10) in order to protect the confidentiality and the integrity of the payment service users’ personalised security credentials;

Added(d) the requirements applicable, in accordance with Article 87, to the outsourcing agreements between the payers’ payments service providers and technical service providers concerning the provision and verification of the elements of strong customer authentication by technical service providers; When doing so, the EBA shall take into account its existing guidelines on outsourcing arrangements.

Added(e) the requirements under Title III, Chapter 3 for common and secure open standards of communication for the purpose of identification, authentication, notification, and information, as well as for the implementation of security measures, between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers;

Added(f) supplementary provisions on secure open standards of communication using dedicated interfaces;

Added(g) the technical requirements for transaction monitoring mechanisms referred to in Article 83;

AddedFor the purposes of point (b), as regards the exemption from the application of strong customer authentication for payment transactions, based on transaction risk analysis the draft regulatory technical standards shall specify, inter alia:

Added(i) the conditions that have to be met for a remote electronic payment transaction to be considered as posing a low level of risk, taking into consideration the levels of fraud in each economic activity;

Added(ii) the methodologies and models to implement transaction risk analysis;

Added(iii) the criteria for the calculation of fraud rates, including on the allocation of fraud rates between payment service providers providing issuing and acquiring services, or within payment service providers providing issuing and acquiring services through a single legal entity;

Added(iv) detailed and proportionate reporting and audit requirements.

Added(ga) a standardised list of categories of information to be disclosed on the dashboard;

Added(gb) an exhaustive list of the methods that can be used as a unique identifier;

Added(gc) the criteria for the exclusion for payment transactions from the payer to the payee through a commercial agent referred to in Article 2(2), point (b).

Added2. When developing the draft regulatory technical standards referred to in paragraph 1, the EBA shall take into account:

Added(a) the need to ensure an appropriate level of security for payment service users and payment service providers, through the adoption of effective and risk-based requirements;

Added(b) the need to ensure the safety of payment service users’ funds and personal data;

Added(c) the need to secure and maintain fair competition among all payment service providers;

Added(d) the need to ensure technology and business-model neutrality;

Added(e) the need to allow for the development of user-friendly, accessible and innovative means of payment;

Added(ea) the need to balance fraud risk versus the consumer experience with regards to low value transactions;

Added(eb) the different situation and specific needs of consumer and corporate payers.

AddedThe EBA, before submitting its draft regulatory technical standards to the Commission, shall hold an open consultation with public and private stakeholders in order to ensure that the most up to date advances in technology and payment processing, as well as the specificities of business to business and business to government transactions, are taken into account in the draft regulatory technical standards.

AddedThe EBA shall submit the draft regulatory technical standards referred to in paragraph 1 to the Commission by [ OP please insert the date= 1 year after the date of entry into force of this Regulation]. Power is delegated on the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

Added3. In accordance with Article 10 of Regulation (EU) No 1093/2010, the EBA shall review and, if appropriate, update the regulatory technical standards on a regular basis in order, inter alia, to take account of innovation and technological developments, and the provisions of Chapter II of Regulation (EU) 2022/2554, and the European Digital Identity Wallets implemented under Regulation (EU) No 910/2014.

AddedEnforcement procedures, competent authorities and penalties

AddedComplaint procedures

AddedComplaints

Added1. Member States shall set up procedures which allow payment service users and other interested parties including consumer associations, to submit complaints to the competent authorities designated to ensure enforcement of this Regulation, with regard to payment service providers' alleged infringements of the provisions of this Regulation.

Added2. Where appropriate and without prejudice to the right to bring proceedings before a court in accordance with national procedural law, the reply from the competent authorities to the complaints referred to in paragraph 1 shall inform the complainant of the existence of the alternative dispute resolution (ADR) procedures set up in accordance with Article 95.

AddedCompetent authorities and investigatory powers

Added1. Competent authorities shall exercise their powers to investigate potential infringements of this Regulation, and impose administrative sanctions and administrative measures laid down in their national legal frameworks in accordance with this Regulation, in any of the following ways:

Added(a) directly;

Added(b) in collaboration with other authorities;

Added(c) by delegating powers to other authorities or bodies, while retaining the responsibility for overseeing the delegated authority or body;

Added(d) by applying to the competent judicial authorities.

AddedWhere competent authorities delegate the exercise of their powers to other authorities or bodies in accordance with point (c) the delegation of power shall specify the delegated tasks, the conditions under which they are to be carried out, and the conditions under which the delegation of power may be revoked. The authorities or bodies to which the powers are delegated shall be organised in such a manner as to ensure that conflicts of interest are avoided. Competent authorities shall oversee the activity of the authorities or bodies to which the powers are delegated.

Added2. Member States shall designate competent authorities to ensure and monitor effective compliance with this Regulation. Those competent authorities shall take all appropriate measures to ensure such compliance.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2024). “Changes between ECON-PR-755995 and A-9-2024-0052”. Text, 22 February 2024. from ECON-PR-755995, to A-9-2024-0052. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=20 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-22,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-755995 and A-9-2024-0052}},
  year = {2024},
  date = {2024-02-22},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=20}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=20},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-755995, to A-9-2024-0052. Data: European Parliament Open Data (CC BY 4.0)}
}