# PSD3 Article 38 — Services enabling cash withdrawals offered by ATM deployers not servicing payment accounts

Textual state: amended_substantial. 132 words changed; 1 paragraph added

- Current text: Council final compromise text (Council document 8222/26) — not yet law.
- Compared against: COM(2023) 366 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. [-Natural or legal persons providing cash withdrawal services as referred to Annex I, point 1, and who do not service payment accounts and do not provide other payment services referred to in Annex I, -]{+ATM deployers +}shall not be subject to authorisation but shall [-register -]{+register, before taking up activity, +}with [-a -]{+the +}competent authority of the [-home -]Member State [-before taking up activity. -]{+where the cash withdrawal services are intended to be provided.+}

## Paragraph 2

2. The registration referred to in paragraph 1 shall be accompanied by the information and documentation referred to in Article 3(3), points (a), (b), (e) to (h), [-(j), -]{+(j) to +}(l), (n), (p) and (q). For the purposes of the documentation referred to in Article 3(3), points [-(e) -]{+(e), +}(f) and (l), the [-natural or legal -]person registering shall provide a description of its audit arrangements and of the organisational arrangements it has set up to taking all reasonable steps to protect the interests of its users and to ensure continuity and reliability in the performance of the payment service as referred to in point (1) of Annex I. The security control and mitigation measures referred to in Article 3(3), point (j), shall indicate how the [-natural or legal -]person registering will ensure a high level of digital operational resilience in accordance with Chapter II of Regulation (EU) 2022/2554, in particular in relation to technical security and data protection, including for the software and ICT systems used by the [-natural or legal -]person registering or the undertakings to which it outsources the whole or part of its operations.

## New paragraph 2a

{+2a. The competent authority referred to in paragraph 1 may refuse a registration, and may revoke a registration, if the competent authority establishes that the ATM deployer does not comply with, or has ceased to comply with, any of the requirements set out in paragraph 2. The competent authority shall provide a justification for the refusal or revocation.+}

## Paragraph 3

3. Sections 1 and 2 of Chapter 1 shall not apply to the persons providing the services referred to in paragraph 1 of this Article. Section 3 of Chapter 1 shall apply to the persons providing the services referred to in paragraph 1 of this Article, with the exception of [-Article 25(3). -]{+Articles 25(3) and 30.+}

## Paragraph 4

4. The persons providing the services referred to in paragraph 1 of this Article shall be treated as payment institutions.
