Text · Comparison of two versions
Changes from report parliamentary committee draft to plenary report
ECON-PR-755995 → A-9-2024-0052
- From
- ECON-PR-755995 report parliamentary committee draft of 13 Nov 2023
- To
- A-9-2024-0052 Plenary report of 22 Feb 2024
- Changes
- Not comparable
- Paragraphs
- +1 233 added · −106 removed · 1 changed
More facts (2)
- Title (from)
- on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
- Title (to)
- on the proposal for a regulation of the European Parliament and of the Council on payment services in the internal market and amending Regulation (EU) No 1093/2010
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 3 of 24: Paragraphs 121–180
RemovedArticle 43 – paragraph 2 a (new): 2a. The EBA shall develop draft regulatory technical standards to specify the categories of data referred to in paragraph 2, point (a)(v), so that the data are easily understandable for consumers. / The EBA shall submit the draft regulatory technical standards referred to in the first subparagraph to the Commission by ... [one year from the date of entry into force of this Regulation]. / Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.
Added(37) To make well-informed choices and to be able to choose their payment service provider easily within the Union, payment service users should receive comparable and clear information about payment services. To ensure that necessary, sufficient and comprehensible information is given to payment service users with regard to the payment service contract and payment transactions, it is necessary to specify and to harmonise the obligations on payment service providers as regards the provision of information to payment service users.
RemovedArticle 43 – paragraph 2 b (new): 2b. Where, pursuant to paragraph 2, point (b), a payment services user decides to withdraw data access, the account information service provider or payment initiation service provider concerned shall: / (a) no longer use the data; / (b) withdraw the data; and / (c) erase all data received as a result of the data access permission granted by the payment services user.
Added(38) When providing the required information to payment service users, payment service providers should take into account the needs of payment service users and practical aspects and cost-efficiency depending on the respective payment service contract. Payment service providers should either actively communicate at the appropriate time without any prompting by the payment service user, or they should make the information available to payment service users request. In the second situation, payment service users should take active steps to obtain the information, including requesting that information explicitly from payment service providers, logging into a bank account mailbox or inserting a bank card into a printer for account statements. For those purposes, the payment service providers should ensure that access to the information is possible, and that the information is available to payment service users.
RemovedArticle 44 – paragraph 1 – subparagraph 2 – point j: deleted
Added(39) As consumers and undertakings are not in the same position of vulnerability, they do not need the same level of protection. While it is important to guarantee consumer rights by provisions from which it is not possible to derogate by contract, it is reasonable to let undertakings and organisations agree otherwise when they are not dealing with consumers. Such agreements could govern whether or not strong customer authentication (SCA) is applied. Micro-enterprises, as defined in Commission Recommendation 2003/361/EC, may be treated in the same way as consumers. Certain rules should always apply, irrespective of the status of the user.
RemovedArticle 44 – paragraph 1 – subparagraph 2 – point k: deleted
Added(40) To maintain a high level of consumer protection, consumers should have the right to receive information on services’ conditions and prices free of charge before being bound by any payment service contract. To enable consumers to compare the services and conditions offered by payment service providers and, in the case of a dispute, to verify their contractual rights and obligations, consumers should be able to request that information and the framework contract on paper, free of charge and at any time during the contractual relationship.
RemovedArticle 46 – paragraph 1 – point d: (d) ensure that the personalised security credentials of the payment services user are not, with the exception of the payer and the issuer of the personalised security credentials, accessible to other parties, including the payment initiation service provider itself, and that they are transmitted by the payment initiation service provider through safe and efficient channels;
Added(41) To increase the level of transparency, payment service providers should provide basic information on executed payment transactions at no additional charge to the consumer. In the case of a single payment transaction, the payment service provider should not charge separately for that information. Similarly, payment service providers should provide free of charge and on a monthly basis subsequent information on payment transactions under a framework contract. However, considering the importance of transparency in pricing and differing customer needs, the parties to the contract should be able to agree on charges for more frequent or additional information.
RemovedArticle 46 – paragraph 2 – point a: (a) store, use and access sensitive payment data of the payment service user;
Added(42) Low-value payment instruments should be a cheap and easy-to-use alternative in the case of low-priced goods and services and should not be overburdened by excessive requirements. The relevant information requirements and rules on their execution should therefore be limited to essential information, also considering the technical capabilities that can justifiably be expected from instruments dedicated to low-value payments. Despite the lighter regime, payment service users should have adequate protection, having regard to the limited risks posed by those payment instruments, in particular as concerns prepaid payment instruments.
RemovedArticle 47 – paragraph 1 – point b: (b) ensure that the personalised security credentials of the payment service user are not accessible to other parties, including the account information service provider itself, with the exception of the user and the issuer of the personalised security credentials, and that when those credentials are transmitted by the account information service provider, transmission is done through safe and efficient channels;
Added(43) In single payment transactions, the essential information should always be given at the payment service providers’ own initiative. As payers are usually present when giving the payment order, it should not be necessary that information be always provided on paper or on another durable medium. Payment service providers should be able to give information orally or make it otherwise easily accessible, including by keeping the conditions on a notice board on the premises. Information should also be given on where to find other, more detailed, information, including on the website. However, where the consumer so requests, the essential information should also be given by payment service providers on paper or on another durable medium.
RemovedArticle 49 – paragraph 4: 4. Account servicing payment service providers shall verify the permission given by the payment service user to the account information service provider or payment initiation service provider.
Added(44) The information required should be proportionate to the needs of users. The information requirements for a single payment transaction should be different from the information requirements for a framework contract which provides for a series of payment transactions.
RemovedArticle 49 – paragraph 5: 5. The permission referred to in paragraphs 1 and 2 shall be expressed in the form agreed between the payer and the relevant payment service provider. Permission to execute a payment transaction may also be expressed via the payee or the payment initiation service provider. The registered use of a valid payment instrument by the payer and the use of the payer's personalised security credentials shall be considered to be the expression of the permission to execute a payment transaction. If the required authentication has been carried out with respect to a payment transaction, and the transaction was accurately recorded, entered in the accounts, and not affected by a technical breakdown or some other deficiency of the payment service provided by the payment service provider, the payer's permission to execute the payment transaction shall be presumed to have been expressed until evidence demonstrating the lack of expression is collected and properly evaluated. The payment service provider shall provide to the payment service user all relevant information in cases where the granting of the permission is being questioned by the payment service user and the payment service user is gathering information to prove the lack of expression of permission to execute the transaction.
Added(45) To be able to make an informed choice payment service users should be able to compare Automatic Teller Machine (ATM) charges with those of other providers. To increase the transparency of ATM charges for the payment service user payment service providers should provide payment service users with information on all applicable charges at the initiation of a transaction for Union ATM withdrawals in different situations, depending on the ATM from which the payment service users withdraw cash. Specifically, ATMs operated by credit institutions should display in monetary form any fixed fees that a user will be expected to pay upon withdrawal of cash from that credit institution’s ATM. That fixed fee should be displayed at or before the point at which the user inserts or taps their card against the ATM to initiate the process of withdrawal of cash. More transparency also means better information from the payment service provider as regards the currency exchange, if applicable.
RemovedArticle 50 – paragraph 1 a (new): 1a. The EBA, taking into account the definition of a unique identifier as well as current practices on the market, shall develop draft regulatory technical standards setting out an exhaustive list of the methods that can be used as a unique identifier with reference to paragraph 1. / The EBA shall submit the draft regulatory technical standards referred to in the first subparagraph to the Commission by ... [12 months from the date of entry into force of this Regulation]. / Power is delegated to the Commission to supplement this Regulation by adopting the regulatory technical standards referred to in the first subparagraph of this paragraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010. / Under this Regulation, the 'unique identifier' check shall be carried out for euro and non-euro transfers in the Union.
Added(46) Framework contracts and the payment transactions covered by those contracts are more common and economically significant than single payment transactions. If there is a payment account or a specific payment instrument, a framework contract is required. Therefore, the requirements for prior information on framework contracts should be comprehensive and information should always be provided on paper or on another durable medium. However, payment service providers and payment service users should be able to agree in the framework contract on the manner in which subsequent information on executed payment transactions is to be given.
RemovedArticle 51 – paragraph 1: 1. Where a specific payment instrument is used for the purposes of giving permission, the payer’s payment service provider shall offer to the payment service user the possibility of setting spending limits for payment transactions executed through that payment instrument. Payment service providers shall not unilaterally increase the spending limits agreed with their payment service users. By default, the spending limit set shall be at a low level and shall be specified in the contract between the payment service provider and the payer.
Added(47) Contractual provisions should not discriminate against consumers who are legally resident in the Union on the grounds of their nationality or place of residence. Where a framework contract provides for the right to block a payment instrument for objectively justified reasons, the payment service provider should not be able to invoke that right merely because the payment service user has changed his or her place of residence within the Union.
RemovedArticle 52 – paragraph 1 – point b: (b) notify the payment service provider, or the entity specified by the payment service provider, without undue delay on becoming aware of the loss, theft, misappropriation or unauthorised use of the payment instrument or its relevant personalised security credentials.
Added(48) To ensure a high level of consumer protection, Member States should, in the interest of the consumer, be able to maintain or introduce restrictions or prohibitions on unilateral changes in the conditions of a framework contract, for instance if there is no justified reason for such a change.
RemovedArticle 53 – paragraph 1 – point c: (c) ensure that appropriate means, including a free of charge telephone line allowing for personal human support in the language of the host Member State, are available at all times to enable the payment service user to: / (i) make a notification pursuant to Article 52 point (b), or to request unblocking of the payment instrument pursuant to Article 51(4); / (ii) notify a fraudulent transaction; / (iii) receive feedback when the payment service user suspects a fraud;
Added(49) To facilitate payment service users’ mobility, users should be able to terminate a framework contract without incurring charges. However, for contracts terminated by the payment service users less than 6 months after their entry into force, payment service providers should be allowed to apply charges in line with the costs incurred due to the termination of the framework contract by the user. Where, under a framework contract, payment services are offered jointly with technical services supporting the provision of payment services, such as the rental of terminals used for payment services, payment service users should not be locked in with their payment service provider via more onerous terms set in the contractual clauses governing the technical services. To preserve competition, such contractual terms should be subject to the framework contract requirements on termination fees. For consumers, the period of notice agreed should be no longer than 1 month, and for payment service providers no shorter than 2 months. Those rules should be without prejudice to the payment service provider’s obligation to terminate the payment service contract in exceptional circumstances under other relevant Union or national law, such as that on money laundering or financing of terrorism, any action targeting the freezing of funds, or any specific measure linked to the prevention and investigation of crimes.
RemovedArticle 53 – paragraph 1 – point e a (new): (ea) use safe communication channels and refrain from sending links and documents via e-mail;
Added(50) To achieve comparability, the estimated currency conversion charges for credit transfers and remittances carried out within the Union and from the Union to a third country should be expressed in the same way, namely as a percentage mark-up over a foreign exchange benchmark rate which complies with Regulation (EU) 2016/1011 of the European Parliament and of the Council, and the resultant currency conversion charge shown as a monetary amount in the currency used by the customer to initiate the currency conversion. The accuracy and integrity of such benchmarks, which is ensured by the regime for benchmark administrators introduced by that Regulation, protects the interests of customers of payment service providers and parties providing currency conversion services. A payment service provider should use the same benchmark consistently and for exchanges made in both directions. When reference is made to ‘charges’ in this Regulation, it should also cover, where applicable, ‘currency conversion’ charges.
RemovedArticle 53 – paragraph 2 a (new): 2a. Where the payer's payment service provider does not comply with the obligations set out in this Article, the payer shall not bear any resulting financial losses unless the payer acted fraudulently. / The burden of proof shall lie on the payment service provider to prove that it complied with this Article.
Added(51) Experience has shown that the sharing of charges between a payer and a payee is the most efficient system since it facilitates the straight-through processing of payments. Provision should therefore be made for charges to be levied directly on the payer and the payee by their respective payment service providers. The amount of any charges levied may also be zero as the rules should not affect the practice whereby a payment service provider does not charge consumers for crediting their accounts. Similarly, depending on the contract terms, a payment service provider may charge only the payee for the use of the payment service, in which case no charges are imposed on the payer. It is possible that the payment systems impose charges by way of a subscription fee. The provisions on the amount transferred or any charges levied have no direct impact on pricing between payment service providers or any intermediaries.
RemovedArticle 55 – paragraph 2 a (new): 2a. This Article shall be without prejudice to Article 49.
Added(52) A surcharge is a charge by merchants to consumers that is added on top of the requested price for goods and services when a certain payment method is used by the consumer. One of the reasons for surcharging is to direct consumers to cheaper or more efficient payment instruments, hence fostering competition between alternative payment methods. Under the regime introduced by Directive (EU) 2015/2366, payees were prevented from requesting charges for the use of payment instruments for which interchange fees are regulated under Chapter II of Regulation (EU) 2015/751, i.e. for consumer debit and credit cards issued under four-party card schemes, and for those payment services to which Regulation (EU) No 260/2012 of the European Parliament and of the Council applies, i.e. credit transfer and direct debit transactions denominated in euro within the Union. Member States were allowed under Directive (EU) 2015/2366 to further prohibit or limit the right of the payee to request charges, taking into account the need to encourage competition and promote the use of efficient payment instruments. It is necessary to harmonise that approach in order to foster a level playing field in the Union, and therefore to enact a complete ban on surcharging across the Union.
RemovedArticle 56 – paragraph 2 – point b: (b) provide a justification to the payer for refusing the refund, provide proof that the payer acted fraudulently and indicate the bodies to which the payer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the payer does not accept the reasons provided.
Added(53) ▐In its review of Directive (EU) 2015/2366, the Commission identified a lack of harmonisation that allows surcharging for payment instruments and different interpretations concerning the payment instruments covered by the surcharging ban. It is therefore necessary to explicitly extend the surcharging ban to all credit transfers and direct debits and not just to those covered by Regulation (EU) No 260/2012, as was the case under Directive (EU) 2015/2366.
RemovedArticle 57 – paragraph 2 – point b: (b) provide an accurate justification for refusing the refund, provide proof to the relevant competent authority that there was no infringement of Article 50(1) and indicate the bodies to which the payer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the payer does not accept the reasons provided.
Added(54) Account information services and payment initiation services, often collectively known as ‘open banking services’, are payment services involving access to the data of a payment service user by payment service providers which do not hold the account holder’s funds nor service a payment account. Account information services allow the aggregation of a user’s data, at the request of the payment service user, with different account servicing payment service providers in one single place. Payment initiation services allow the initiation of a payment from the user’s account, such as a credit transfer or a direct debit, in a convenient way for the user and the payee without the use of an instrument such as a payment card.
RemovedArticle 58 – paragraph 1: Technical service providers, e-wallet providers and operators of payment schemes that either provide services to the payee, or to the payment service provider of the payee or of the payer, shall be liable for any financial damage caused to the payee, to the payment service provider of the payee or of the payer for their failure, within the remit of their contractual relationship, to provide the services that are necessary to enable the application of strong customer authentication.
Added(55) Account servicing payment service providers should allow access by account information and payment initiation service providers to payment account data if the payment account can be accessed by the payment service user online and if the payment service user has granted permission for such access. Directive (EU) 2015/2366 was based on the principle of access to payment account data without a need for a contractual relationship between the account servicing payment service provider and the account information and payment initiation service providers, which had the effect that charging for access to data was in practice not possible. Access to data under open banking has been taking place on such a non-contractual basis, and without charging, since the application of Directive (EU) 2015/2366. If regulated data access services were to be subjected to a charge, where there was no charge hitherto, the impact on the continued provision of those services, and therefore on competition and innovation in payment markets, could be very significant. That principle should therefore be maintained. Maintaining that approach is in line with Chapters III and IV of the proposal of a Regulation on harmonised rules on fair access to and use of data (Data Act), in particular Article 9(3) of that proposal on compensation, to which this Regulation is without prejudice. The Commission’s proposal for a Regulation on Financial Data Access (FIDA) provides for a possible compensation for data access which will be covered by FIDA. Such regime would thus be different from the one governed by the present Regulation. This difference of treatment is justified by the fact that, unlike for payment account data access, which is regulated by Union law since the entry into force of Directive (EU) 2015/2366, access to other financial data has not yet been subject to Union regulation. There is therefore no risk of disruption as, unlike access to payment account data, this market is emerging and will be regulated for the first time with FIDA.
RemovedArticle 59 – paragraph 1 a (new): 1a. In order to avoid fraud within their purview, electronic communications service providers and payment service providers shall ensure that all required technological safeguards, particularly those pertaining to the security of the communication between payment service providers and payment service users, are in place. Those technological safeguards shall be provided free of charge. / Electronic communications providers shall have in place at least the following technical safeguards in order to prevent fraudulent activities: / (a) verifying the legitimacy of all calls and messages that are routed through telecommunication networks; / (b) preventing the use of a specific telephone number in violation of its attribution, authorisation, or allocation; / (c) preventing the creation of fraudulent websites and preventing internet search engines from displaying those websites in their list of results; / (d) storing proof of IT and identity verification measures, in particular in the event of sim swap, to justify their due diligence. / If electronic communications service providers fail to establish the technical safeguards set out in the first subparagraph, they shall be financially liable towards the payer’s payment service provider for the amount that the payment service provider has refunded to the payment service user.
Added(56) Account servicing payment service providers and account information and payment initiation service providers may establish a contractual relationship, including in the context of a multilateral contractual arrangement (e.g. a scheme), with possible compensation, for access to payment account data and provision of open banking services other than those required by this Regulation. An example of such value-added services offered via so-called ‘premium’ Application Programming Interfaces (APIs) is the possibility to schedule future variable recurring payments. Any compensation for such services would have to be in line with Chapters III and IV of the proposed Data Act after its date of application, in particular as regards its articles 9(1) and 9(2) on compensation. Access by account information and payment initiation service providers to payment account data regulated under this Regulation without a requirement of a contractual relationship, and thus without charging, should always be possible even in cases where a multilateral contractual arrangement (e.g. a scheme) is in place and where the same data is also available as part of the said multilateral contractual arrangement.
RemovedArticle 59 – paragraph 5: 5. Where informed by a payment service provider of the occurrence of any type of fraud , electronic communications services providers shall immediately cooperate closely with payment service providers and act swiftly to ensure that the essential organizational and technical measures referred to in paragraph 1a of this Article are in place to safeguard the security and confidentiality of communications in accordance with Directive 2002/58/EC, including with regard to calling line identification and electronic mail address.
Added(57) To guarantee a high level of security in data access and exchange, access to payment accounts and the data therein should, barring specific circumstances, be provided to account information and payment initiation service providers via an interface designed and dedicated for ‘open banking’ purposes, such as an API. To that end, the account servicing payment service provider should set up a secure communication with account information and payment initiation service providers. To avoid any uncertainty as to who is accessing the payment service user’s data, the dedicated interface should enable account information and payment initiation service providers to identify themselves to the account servicing payment service provider, and to rely on all the authentication procedures provided by the account servicing payment service provider to the payment service user. Account information service providers and payment initiation service providers should as a general rule use the interface dedicated for their access and therefore should not use the customer interface of an account servicing payment service provider for the purpose of data access, except in cases of failure or unavailability of the dedicated interface in the conditions laid down in this Regulation. In such circumstances their business continuity would be endangered by their incapacity to access the data for which they have been granted a permission. It is indispensable that account information and payment initiation service providers be at all times able to access the data indispensable for them to service their clients.
RemovedArticle 59 – paragraph 5 a (new): 5a. Electronic communications service providers shall have in place all necessary educational measures, including alerts to their customers via all appropriate means and media when new forms of online scams emerge, taking into account the needs of their most vulnerable groups of customers. / Electronic communications service providers shall give their customers clear indications as to how to identify fraudulent attempts and warn them as to the necessary actions and precautions to be taken to avoid falling victim to fraudulent actions targeting them. Electronic communications service providers shall inform their customers of the procedure for reporting fraudulent actions and how to rapidly obtain fraud-related information.
Added(57a) Account servicing payment service providers should not be required to offer an alternative interface where the dedicated interface is unavailable other than the interface that the account servicing payment service provider uses for authentication and communication with its users to access payment account data.
RemovedArticle 60 – paragraph 1 – subparagraph 2 – point a: (a) the loss, theft or misappropriation of security credentials or a payment instrument was not detectable to the payer prior to a payment, except where the payer has acted fraudulently; or
Added(58) To facilitate the smooth use of the dedicated interface, its technical specifications should be adequately documented and a summary be made publicly available by the account servicing payment service provider. To enable the open banking service providers to adequately prepare their future access and to solve any possible technical problems, the account servicing payment service provider should enable account information and payment initiation service providers to test an interface prior to the date on which the interface will be activated. Only authorised account information and payment initiation service providers should access payment account data via that interface, although applicants for authorisation as account information and payment initiation service providers should be able to consult the technical specifications. To ensure the interoperability of different technological communication solutions, the interface should use standards of communication which are developed by international or European standardisation organisations including the European Committee for Standardization (CEN) or the International Organization for Standardization (ISO).
RemovedArticle 60 – paragraph 1 a (new): 1a. Where the payer’s payment service provider has reasonable grounds to suspect fraud or gross negligence by the consumer, within 10 business days after noting or being notified of the fraudulent authorised payment transaction, the payment service provider shall do one of the following: / (a) refund the consumer the amount of the fraudulent authorised payment transaction; / (b) provide proof that the consumer has acted fraudulently or with gross negligence to the relevant national authority and provide to the payer a substantiated justification for refusing the refund and indicate to the consumer the bodies to which the consumer can refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the consumer does not accept the reasons provided.
Added(59) For account information and payment initiation service providers to ensure at all times their business continuity and to be able to provide high quality services to their clients, the dedicated interface that they are expected to use must meet high level requirements in terms of performance and functionalities. It should at a minimum ensure ‘data parity’ with the customer interface provided to its users by the account servicing payment service provider, therefore including the payment account data which is also available to the payment service users in the interface provided to them by the account servicing payment service provider. With regard to payment initiation services, the dedicated interface should allow not only the initiation of single payments but of standing orders and direct debits. More detailed requirements for dedicated interfaces should be laid down in Regulatory Technical Standards developed by the EBA.
RemovedArticle 63 a (new): Article 63a / Education on fraud / Member States shall allocate substantial means to invest in education on payment-related fraud. Such education may take the form of a media campaign or lessons at schools. Payment service providers and electronic communications service providers shall cooperate free of charge with the Member States in those educational activities. Member States shall inform the Parliament, the Commission and the EBA about the planned campaigns.
Added(60) Given the dramatic impact that a prolonged unavailability of a dedicated interface would have on account information and payment initiation service providers’ business continuity, account servicing payment service providers should remedy such unavailability without delay. Account servicing payment service providers should inform account information and payment initiation service providers of any such unavailability of their dedicated interface and of the measures taken to remedy them without delay. In case of unavailability of a dedicated interface, and where no effective alternative solution is offered by the account servicing payment service provider, account information and payment initiation service providers should be able to preserve their business continuity. They should be allowed to request their national competent authority to make use of the interface provided to its users by the account servicing payment service provider until the dedicated interface is again available. The competent authority should, upon receiving the request, take its decision without delay. Pending the decision from the authority the requesting account information and payment initiation service providers should be allowed to temporarily use the interface provided to its users by the account servicing payment service provider. The relevant competent authority should set a deadline to the account servicing payment service provider to restore the full functioning of the dedicated interface, with the possibility of sanctions in case of failure to do so by the deadline. All account information and payment initiation service providers, not just those which introduced the request, should be allowed to access the data they need to ensure their business continuity.
RemovedArticle 80 – paragraph 1 – introductory part: Payment systems and payment service providers shall be allowed to process special categories of personal data as referred to in Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 when necessary for the prevention, investigation and detection of payment fraud. / Payment service providers shall only access, retain and process personal data necessary for the provision of their payment services, with the explicit consent of the payment service user.
Added(61) Such temporary direct access should have no negative effect on consumers. Account information and payment initiation service providers should therefore always duly identify themselves and respect all their obligations, such as the limits of the permission which was granted to them, and should in particular access only the data that they need to meet their contractual obligations and provide the regulated service. Access to payments account data without proper identification (so-called ‘screen-scraping’) should, in any circumstances, never be performed.
RemovedArticle 80 – paragraph 1 – point a: deleted
Added(62) Given the fact that setting up a dedicated interface could, for certain account servicing payment service providers, be deemed disproportionately burdensome, a national competent authority should be able to exempt an account servicing payment service provider, on its request, from the obligation to have in place a dedicated data access interface, and to either offer payment data access only via its ‘customer interface’ or not to offer any open banking data access interface at all. Data access via the customer interface (with no dedicated interface) may be appropriate in the case of a very small account servicing payment service provider for which a dedicated interface would be a significant financial and resource burden. Being exempted from the obligation to maintain any ‘open banking’ data access interface may be justified where the account servicing payment service provider has a specific business model, for example where open banking services would present no relevance to its customers. Detailed criteria for granting such different types of exemption decisions should be laid down in regulatory technical standards developed by the EBA.
RemovedArticle 80 – paragraph 1 – point b: deleted
Added(63) To fully reap the potential of open banking in the Union, it is essential to prevent any discriminatory treatment of account information and payment initiation service providers by account servicing payment service providers. Where the payment service user has decided to make use of the services of an account information service provider or a payment initiation service provider, the account servicing payment service provider should treat that order in the same way as it would treat such a request if made by the payment service user directly in its ‘customer interface’, unless the account servicing payment provider has objective reasons to treat the request to access the account differently, including serious suspicions of fraud.
RemovedArticle 81 – paragraph 1 – subparagraph 1: Payment service providers and e-wallet providers shall establish a framework with appropriate mitigation measures and control mechanisms to manage operational and security risks relating to the payment services they provide. As part of that framework, payment service providers shall establish and maintain effective incident management procedures, including for the detection and classification of major operational and security incidents.
Added(64) For the provision of payment initiation services, the account servicing payment service provider should provide the payment initiation service provider with all information accessible to it regarding the execution of the payment transaction immediately after the payment order has been received. Sometimes more information becomes available to the account servicing payment service provider after it has received the payment order, but before it has executed the payment transaction. Where relevant for the payment order and the execution of the payment transaction, the account servicing payment service provider should provide that information to the payment initiation service provider. The payment initiation service provider should benefit only from the information necessary to assess the risks of non-execution of the initiated transaction. That information is indispensable to enable the payment initiation service provider to offer to a payee on behalf of whom it initiates the transaction a service whose quality can compete with other means of electronic payments available to the payee, including payment cards.
RemovedArticle 81 – paragraph 1 – subparagraph 2 – point a: (a) payment service providers and e-wallet providers referred to in Article 2(1), points (a), (b) and (d) of this Regulation;
Added(65) To increase trust in open banking, it is essential that payment service users who use account information and payment initiation services be in full control of their data and have access to clear information on the data access permissions that those payment service users have granted to payment service providers, including the purpose of permission and the categories of payment account data concerned, including identity data of the account, transaction and account balance. Account servicing payment service providers should therefore make available to payment service users who use such services a ‘dashboard’, for monitoring and withdrawing ▐data access granted to ‘open banking’ services providers. Permissions for initiation of one-off payments should not feature on that dashboard. A dashboard may not allow a payment service user to establish new data access permissions with an account information or payment initiation service provider to which no previous data access has been given. Account servicing payment service providers should inform account information and payment initiation service providers promptly of any withdrawal of data access. Account information and payment initiation service providers should inform account servicing payment service providers promptly of new and re-established data access permissions granted by payment service users, including the duration of validity of the permission and its purpose (in particular whether the consolidation of data is for the benefit of the user or for transmission to a third party). An account servicing payment service provider should not encourage, in any manner, a payment service user to withdraw the permissions given to account information and payment initiation service providers. The dashboard should warn the payment service user in a standard way of the risk of possible contractual consequences of withdrawal of data access to an open banking service provider, since the dashboard does not manage the contractual relationship between the user and an ‘open banking’ provider, but it is for the payment service user to verify that risk. A permissions dashboard should empower customers to manage their permissions in an informed and impartial manner and give customers a strong measure of control over how their personal and non-personal data is used. A permissions dashboard should take into account, where appropriate, the accessibility requirements under Directive (EU) 2019/882 of the European Parliament and of the Council.
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=3
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 26 September 2026
Cite as
European Parliament (2024). “Changes between ECON-PR-755995 and A-9-2024-0052”. Text, 22 February 2024. from ECON-PR-755995, to A-9-2024-0052. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=3 (retrieved 26 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2024-02-22,
author = {{European Parliament}},
title = {{Changes between ECON-PR-755995 and A-9-2024-0052}},
year = {2024},
date = {2024-02-22},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=3}},
url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-755995/compare/A-9-2024-0052?all=1&part=3},
urldate = {2026-09-26},
publisher = {EU Parl Watch Research},
note = {Text. from ECON-PR-755995, to A-9-2024-0052. Data: European Parliament Open Data (CC BY 4.0)}
}