# PSD3 Article 36 — Account information service providers

Textual state: amended_substantial. 86 words changed

- Current text: Council final compromise text (Council document 8222/26) — not yet law.
- Compared against: COM(2023) 366 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Natural or legal persons providing only the payment service referred to in Annex I, point (7), shall not be subject to authorisation but shall register with the competent authority of the home Member State before taking up activity.

## Paragraph 2

2. Such registration request shall be accompanied by the information and documentation referred to in Article 3(3), points (a), (b), (e) to (h), (j), (l), (n), (p) and (q). For the purposes of the documentation referred to in Article 3(3), points (e), (f) and (l), the natural or legal person registering shall provide a description of its audit arrangements and of the organisational arrangements it has set up with a view to taking all reasonable steps to protect the interests of its users and to ensure continuity and reliability in the performance of the payment service as referred to in Annex I, point (7).

## Paragraph 3

3. The security control and mitigation measures referred to in Article 3(3), point (j), shall indicate how the natural or legal person registering will ensure a high level of digital operational resilience in accordance with Chapter II of Regulation (EU) 2022/2554, in particular in relation to technical security and data protection, including for the software and ICT systems used by the natural or legal person registering or the undertakings to which it outsources the whole or part of its operations.

## Paragraph 4

4. Member States shall require persons as referred to in paragraph 1, as a condition of their registration, to hold a professional indemnity insurance covering the territories in which they offer services, or some other comparable guarantee, and that they ensure that: (a) they can cover their liability vis-à-vis the account servicing payment service provider or the payment service user resulting from non-authorised or fraudulent access to or non-authorised or fraudulent use of payment account information service; (b) they can cover the value of any excess, threshold or deductible from the insurance or comparable guarantee; (c) they monitor the coverage of the insurance or comparable guarantee on an ongoing basis. {+For the purpose of the first subparagraph, the professional indemnity insurance or the other comparable guarantee shall be in place at the moment when the applicant starts providing payment services.+}

## Paragraph 5

5. Sections 1 and 2 of Chapter I shall not apply to the persons providing the services referred to in paragraph 1 of this Article. Section 3 of Chapter I shall apply to the persons providing the services referred to in paragraph 1 of this Article, with the exception of Article 25(3). [-As an alternative to holding a professional indemnity insurance as required in paragraphs 3 and 4, the undertakings as referred to in paragraph 1 shall hold an initial capital of EUR 50 000, which can be replaced by a professional indemnity insurance after those undertakings have commenced their activity as a payment institution, without undue delay.-]

## Paragraph 6

6. The persons referred to in paragraph 1 of this Article shall be treated as payment institutions.
