Skip to content

Text · Comparison of two versions

Changes from report parliamentary committee draft to plenary report

ECON-PR-778136 → A-10-2026-0185

From
ECON-PR-778136 report parliamentary committee draft of 3 Nov 2025
To
A-10-2026-0185 Plenary report of 26 Jun 2026
Changes
Not comparable
Paragraphs
+669 added · −303 removed · 7 changed
More facts (3)
Title (from)
on the proposal for a regulation of the European Parliament and of the Council on the establishment of the digital euro
Title (to)
on the proposal for a regulation of the European Parliament and of the Council on the establishment of the digital euro

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 15 of 18: Paragraphs 813–872

Added(e) the obligations of payment service providers under Directive (EU) 2015/2366 related to the execution of transactions and the prevention and detection of fraud, combatting money laundering and terrorist financing under Directive (EU) 2015/849, taxation compliance under Council Directive 2006/112/EC, Directive (EU) 2011/16/EU and relevant national law, the management of operational and security risks under Regulation (EU) 2022/2554 and obligations under Directive (EU) 2014/92/EU, in so far as they concern the digital euro.

AddedFor the provision of offline digital euro, the processing of personal data by payment service providers is limited to funding and defunding in accordance with Article 37 paragraphs 3, 4 and 5. The principle of privacy preservation shall be maintained at all times and no further processing of personal data shall be allowed.

Added2. For the purposes referred to in paragraph 1 (a) to (c), of this Article, Annex III lays down the types of personal data that may be processed.

Added3. The Commission is empowered to adopt delegated acts in accordance with Article 38 to update the types of personal data listed in Annex III.

AddedPayment service providers shall be considered to be the controllers of personal data as regards the purposes referred to in paragraph 1 of this Article. Where a digital euro payment account held by one payment service provider is linked with a non-digital euro payment account held by another payment service provider in accordance with Article 13(4), these payment service providers shall be joint controllers.

Added4. Payment service providers shall implement appropriate and up-to-date technical and organisational measures including state-of-the-art security and comprehensive privacy-preserving measures to ensure that any data communicated to the European Central Bank and the national central banks or to providers of support services do not ▌ identify individual digital euro users or link them to specific transactions and to ensure that data about digital euro users is never unlawfully transferred to third country authorities or entities. Those measures shall be subject to regular review and updating to ensure that privacy preservation remains at the most advanced and comprehensive level.

Added4 a. The European Data Protection Board, in consultation with the European Central Bank, shall issue guidelines on the implementation of appropriate technical and organisation measures, including of anonymisation techniques, to ensure compliance with this Article and with Regulation 2016/679. Compliance of such processing with Regulation (EU) 2016/679 shall be demonstrated.

Added4 b. The purposes of processing of personal data shall be limited to legal obligations under this Regulation and there shall be no further processing of personal data for other purposes nor any data sharing with third parties.

Added4 c. This Article is without prejudice to additional digital euro payment services developed and provided by payment service providers in addition to basic digital euro payment services, for which Article 6(1), point (a) or (b), of Regulation (EU) 2016/679 apply, considering that those services are subject to Directive (EU) 2015/2366.

Added4 d. For the purpose of authentication and identification and in line with the principles of data minimisation and privacy by design and by default as laid down in 2016/679/EU, payment service providers shall offer, upon their clients’ request, authentication and identification by nonbiometric methods.

AddedArticle 35 Processing of personal data by the European Central Bank and the national central banks

Added1. The European Central Bank and the national central banks shall comply with Article 6(1), point (e), GDPR and with Article 5(1), point (a), of Regulation (EU) 2018/1725 ▌ where they process personal data that is strictly necessary for the following purposes:

Added(a) provision of access for payment service providers to the digital euro settlement infrastructure and support the exchange of messages between payment service providers;

Added(aa) provision of access for digital euro users to the European Central Bank digital euro user interface;

Added(b) settlement of online digital euro payment transactions;

Added(c) safeguarding the security, resilience and integrity of the digital euro settlement infrastructure of the digital euro accounts and of local storage devices;

Added(d) supporting verification by payment service providers of whether a prospective user already has digital euro payment accounts with other payment service providers in order to prevent the circumvention of limits in accordance with Article 16;

Added(e) in exceptional circumstances as defined in Article 31(2), authorising payment service providers in switching digital euro payment accounts held with a payment services provider to another payment service providers designated by the digital euro user.

Added1 a. The digital euro settlement infrastructure shall be designed in such a way that neither the European Central Bank nor the national central banks are able to identify a specific digital euro user.

Added2. For the purposes referred to in paragraph 1, Annex IV lays down the types of personal data, that may be processed.

Added3. The Commission is empowered to adopt delegated acts in accordance with Article 38 to update and clarify the types of personal data listed in Annex IV, while maintaining a complete and closed list of personal data to be processed for the stated purpose.

Added4. Personal data processed for tasks referred to in paragraph 1 shall be supported by appropriate technical and organisational measures including state-of-the-art security and comprehensive privacy-preserving measures. This shall include the clear segregation of personal data to ensure that the European Central Bank and the national central banks cannot ▌ identify individual digital euro users or link them to specific transactions. Privacy protection shall be of paramount importance at all times. Those measures shall be subject to regular review and updating to ensure that privacy preservation remains at the most advanced and comprehensive level. When implementing those technical and organisational measures, the European Central Bank and the national central banks shall implement principles of data protection by design and by default, as defined in Regulation (EU) 2016/679.

Added5. The European Central Bank shall be considered the controller of personal data ▌ as regards to the purposes referred to in paragraphs 1 and 8 of this Article. When the European Central Bank carries out a task referred to in paragraphs 1 and 8 jointly with the national central banks, they shall be joint controllers for that task.

Added6. This Article is without prejudice to the processing of personal data involved in the performance of the other tasks and powers, including for the supervision of credit institutions and the oversight of payment systems, of the European Central Bank and the national central banks.

Added7. Where the European Central Bank decides not to confer tasks referred to in Articles 27 and 32 upon providers of support services, the European Central Bank may process the types of personal data referred to in Annex V subject to the requirements referred to in paragraph 4 of this Article.

Added8. For purpose of supporting the task of payment service providers to enforce the ▌ limits in accordance with Article 16 and ensuring the emergency switching upon the request of the user in accordance with Article 31(2), the ECB may alone or jointly with national central banks establish a single access point of digital euro user identifiers and the related digital euro holding limits as referred to in point (4) of Annex IV.The European Central Bank shall implement appropriate technical and organisational measures including state-of-the-art security and comprehensive privacy-preserving measures to ensure that the identity of individual digital euro users cannot be inferred from the information accessed via the single access point by entities other than payment service providers whose customer or potential customer is the digital euro user. When establishing the single access point, the Eurosystem shall ensure that the processing of personal data is minimised to what is strictly necessary and that data protection by design and by default as defined in Regulation 2016/679 is embedded in its technical and operational features in accordance with Article 24a. Those measures shall be subject to regular review and updating to ensure that privacy preservation remains at the most advanced and comprehensive level.

Added1. Where the European Central Bank decides to confer tasks referred to in Article 27 and 32 upon providers of support services, providers of support services shall provide payment-related services across payment service providers. In such a situation, providers of support services shall solely process personal data where they perform a task in the public interest pursuant to Article 6(1), point (e), of Regulation (EU) 2016/679, which are limited to, the following purposes:

Added(a) supporting the prevention and detection of fraud across payment service providers in accordance with Article 32;

Added(b) supporting the exchange of messages for the resolution of disputes in accordance with Article 27.

Added2. For the purposes referred to in paragraph 1, Annex V lays down the types of personal data, that may be processed. For the purposes referred to in point (b) of paragraph 1, the Commission shall be empowered to define the types of personal data that are permitted to be processed by the providers of support services by means of a delegated acts in accordance with paragraph 3.

Added2 a. For the purposes referred to paragraph 1 processing shall be limited to the data required for the prevention and detection of fraud across payment service providers, the Commission is empowered to adopt delegated acts in accordance with Article 38 in order to define the types of personal data.

Added3. The Commission is empowered to adopt delegated acts in accordance with Article 38 to update and clarify the types of personal data listed in Annex V, while maintaining a complete and closed list of personal data to be processed for the stated purpose.

Added4. The processing of personal data for the purposes referred to in paragraph 1 shall only take place when appropriate technical and organisational measures including state-of-the-art security and comprehensive privacy-preserving measures are implemented to ensure that the providers of support services cannot ▌identify individual digital euro users or link them to specific transactions. These measures shall be subject to regular review and updating to ensure that privacy preservation remains at the most advanced and comprehensive level.

Added4 a. Providers of support services designated under this Article shall be subject to the Directive (EU) 2022/2556 and Regulation (EU) 2022/2554.

Added5. The providers of support services shall be considered to be the controllers of personal data as regards the purposes referred to in paragraph 1 of this Article. This paragraph is without prejudice to the European Central Bank and the national central banks appointing the operators of any payment-related services across payment service providers and auditing of the service performance level without processing any personal data.

AddedArticle 37 Anti-money laundering rules applying to offline digital euro payment transactions

Added1. Payment services providers shall apply paragraphs 2 to 6 to offline digital euro payment transactions.

Added2. Transaction data relating to offline digital euro transactions shall not be retained by payment service providers, providers of support services or by the European Central Bank and the national central banks, and shall not be stored on the local storage device unless upon request of the digital euro user.

Added3. Payment service providers shall obtain or retain data of funding and defunding for storing digital euros on payment instruments in accordance with Article 40 of Directive (EU) 2015/849 and national provisions transposing that Article. Payment service providers shall, upon request, make those data available to the Financial Intelligence Unit and other competent authorities as referred in Article 2(44) of Regulation 2024/1624.

Added4. For the purposes of paragraph 3, the funding and defunding data means the following:

Added(a) the amount funded or defunded;

Added(b) the identifier of the local storage device for offline digital euro payment;

Added(c) the date and hour of the funding and defunding transaction;

Added(d) the digital euro payment accounts numbers used for funding and defunding.

Added5. The Commission is empowered to adopt delegated acts setting additional individual or accumulated offline digital euro payment transaction limits and holding limits due to AML/CFT considerations in addition to those referred to in Article 16 derived from financial stability considerations. ▌

AddedThe applicable holding limit shall be the lower of:

Added(a) the limit established pursuant to Article 16, or

Added(b) any AML/CFT-related limit adopted by the Commission in accordance with the first subparagraph of this paragraph.

Added5 a. No later than … [six months from the date of entry into force of this Regulation], AMLA shall issue a recommendation to the European Commission to specify:

Added(a) the recommended maximum amount per offline transaction;

Added(b) the recommended maximum holdings permitted offline;

Added6. Transaction and holding limits shall take into account the need to prevent money laundering and terrorist financing while not unduly restricting the use of the offline digital euro as a means of payment. The Commission, when drawing up the delegated acts referred to in paragraph 5, shall take into account the AMLA recommendation and in particular the following:

Added(a) an assessment of the money laundering and terrorist financing threats, vulnerabilities and risks of the offline digital euro payment functionality when funding and defunding their payment instrument and its risk profile when used for transactions;

Added(b) relevant recommendations and reports drawn up by international organisations and standard setters with competence in the field of preventing money laundering and combating terrorist financing;

Added(c) the objective of ensuring the usability and acceptance of the digital euro as a legal tender instrument;

Added(ca) the objective of introducing a payment instrument offering a similar level of privacy to banknotes and coins.

AddedFor the purposes of point (a), the Commission may request AMLA to adopt an opinion assessing the level of money laundering and terrorist financing threats associated with the offline digital euro and its vulnerabilities. The Commission may consult the European Data Protection Board.

Added1. The power to adopt delegated acts is conferred on the Commission subject to the conditions laid down in this Article.

Added2. The power to adopt delegated acts referred to in Articles 14, 16a, 35, 36 and 37 shall be conferred on the Commission for▌ period of five years from [date of entry into force of this Regulation]. The Commission shall draw up a report in respect of the delegation of power no later than nine months before the end of the five-year period. The delegation of power shall be tacitly extended for periods of an identical duration, unless the European Parliament or the Council opposes such extension not later than three months before the end of each period.

Added3. The power to adopt the delegated acts referred to in Articles 14, 16a, 34, 35, 36 and 37 may be revoked at any time by the European Parliament or by the Council. A decision to revoke shall put an end to the delegation of the power specified in that decision. It shall take effect the day following the publication of the decision in the Official Journal of the European Union or at a later date specified therein. It shall not affect the validity of any delegated acts already in force.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2026). “Changes between ECON-PR-778136 and A-10-2026-0185”. Text, 26 June 2026. from ECON-PR-778136, to A-10-2026-0185, reference 2023/0212(COD). EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/ECON-PR-778136/compare/A-10-2026-0185?all=1&part=15 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2026-06-26,
  author = {{European Parliament}},
  title = {{Changes between ECON-PR-778136 and A-10-2026-0185}},
  year = {2026},
  date = {2026-06-26},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/ECON-PR-778136/compare/A-10-2026-0185?all=1&part=15}},
  url = {https://news.eu-parl.st-solutions.dev/texts/ECON-PR-778136/compare/A-10-2026-0185?all=1&part=15},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from ECON-PR-778136, to A-10-2026-0185, reference 2023/0212(COD). Data: European Parliament Open Data (CC BY 4.0)}
}