# PSR Article 36 — Requirements regarding dedicated data access interfaces

Textual state: amended_substantial. 252 words changed; 1 paragraph added

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Account servicing payment service providers shall ensure that the dedicated interface referred to in Article 35(1) meets the following security and performance requirements: (a) the dedicated interface shall establish and maintain communication sessions between the account servicing payment service provider, the account information service provider, the payment initiation service provider and any payment service user concerned throughout the authentication of the payment service user; (b) the dedicated interface shall ensure the integrity and confidentiality of the personalised security credentials and of authentication codes transmitted by or through the payment initiation service provider or the account information service provider; (c) the response time of the dedicated interface to account information service providers’ and payment initiation service providers’ access requests shall not be longer than the response time of the interface that the account servicing payment service provider makes available to its payment service users for directly accessing their payment account online.

## Paragraph 2

2. Account servicing payment service providers shall ensure that the dedicated interface referred to in Article 35(1) allows both account information service providers and payment initiation service providers to: (a) identify themselves towards the account servicing payment service provider; (b) instruct the account servicing payment service provider to start the authentication based on the [-permission -]{+consent +}of the payment service user given to the account information service provider or the payment initiation service providers in accordance with Article 49(2); (c) make use, in a non-discriminatory manner, of any authentication exemptions applied by the account servicing payment service provider; [-(d) see, prior to initiation of the payment in the case of payment initiation service providers, the unique identifier of the account, the associated names of the account holder and the currencies as available to the payment service user.-]

## Paragraph 3

3. Account servicing payment service providers shall allow account information service providers to communicate securely, via the dedicated interface, {+in order +}to request and receive information on one or more designated payment accounts and associated payment transactions. {+That information shall include the unique identifier of the account, the associated name of the account holder, the currencies, the account balance, and payment transactions initiated through a payment instrument which have not yet been charged to the payment account, if those transactions are already visible in the customer interface.+}

## Paragraph 4

4. Account servicing payment service providers shall ensure that the dedicated interface allows payment initiation service providers, at a minimum, to: (a) place and revoke a standing payment [-order or a direct debit; -]{+order; +}(b) initiate a single payment; (c) initiate and revoke a future dated payment; (d) initiate payments to multiple beneficiaries; (e) initiate payments, regardless of whether the payee is on the payer’s beneficiaries [-list; -]{+list, unless the payment service user is unable to perform those payments in the customer interface; +}(f) communicate securely to place a payment order from the payer's payment account and receive all information on the initiation of the payment transaction and all information accessible to the account servicing payment service provider regarding the execution of the payment transaction; (g) verify the name of the account holder before the payment is initiated and regardless of whether the name of the account holder is available via the direct interface; [-(h) initiate a payment with one single strong customer authentication, provided -]{+(ha) in cases where +}the [-payment initiation service provider has provided the -]account servicing payment service provider [-with all -]{+offers multiple authentication procedures, choose which authentication procedure is to be presented to the payer; (hc) prior to initiation +}of the [-following: (i) -]{+payment, see +}the [-payer’s -]unique [-identifier, (ii) -]{+identifier of +}the [-payee’s legal and commercial name and ‘unique identifier’, (iii) a transaction reference, (iv) -]{+account, +}the [-payment amount and the currency -]{+associated names +}of the [-payment, based on which -]{+account holder and +}the [-single strong customer authentication is triggered. -]{+currencies, where available to the payment service user.+}

## Paragraph 5

5. Account servicing payment service providers shall ensure that the dedicated interface provides to payment initiation service providers: (a) the immediate confirmation, upon request, in a simple ‘yes’ or ‘no’ format, of whether the amount necessary for the execution of a payment transaction is available on the payment account of the payer; (b) the confirmation from the account servicing payment service provider {+as soon as possible, +}that the payment {+has been or +}will be executed on the basis of the information available to the account servicing payment service provider, taking into account any pre-existing payment orders that might affect the full execution of the payment order being placed. The information referred to in point (b) shall not be shared with the payment initiation service provider but may be used by the account servicing payment service provider in order to provide confirmation of the execution of the operation.

## New paragraph 5a

{+5a. For the purposes of the activities of payment initiation service providers and account information service providers, the name of the account owner and the unique identifier of the account shall not constitute sensitive payment data.+}
