---
instrument_id: psr
chunk_id: psr_t03_ch03
chunk_title: Account information services and payment initiation services
path: "Title III RIGHTS AND OBLIGATIONS IN RELATION TO THE PROVISION AND USE OF PAYMENT SERVICES > Chapter 3"
source_class: operative_text
document_type: proposal
normative_weight: non_binding
legal_status: council_compromise_text
jurisdiction: EU
effective_period:
  from: null
  to: null
articles_contained:
  - 33
  - 34
  - 35
  - 36
  - 37
  - 38
  - 39
  - 40
  - 41
  - 42
  - 43
  - 44
  - 45
  - 46
  - 47
  - 48
topics:
  - payments
  - payment_services
  - payment_initiation
  - open_banking
  - account_information
  - authorisation
  - data_protection
  - operational_resilience
  - competent_authorities
  - liability
  - fraud_prevention
  - strong_customer_authentication
recitals:
  - number: 81
    text: "Where the relevant conditions, including the requirements of Regulation (EU) 2016/679, for the exchange, on a voluntary basis, of information necessary to prevent and detect fraud are fulfilled, providers of interpersonal communication services and providers of very large online platforms and very large online search engines within the meaning of Article 33 of Regulation (EU) 2022/2065 should have in place dedicated communication channels, or enter into information sharing arrangements or systems for effective communication with payment service providers, such as the information sharing arrangements established under Article 29 of Directive (EU) 2022/2555. Such mechanisms should contain robust safeguards in relation to confidentiality, data protection and use of information, in compliance with Regulation (EU) 2016/679."
  - number: 81h
    text: "Whereas providers of very large online platforms and of very large online search engines within the meaning of Regulation (EU) 2022/2065 have transparency and due diligence obligations with regard to online advertising under that Regulation, this Regulation further specifies how those obligations should apply in the specific case of advertising of regulated financial services. In particular, in order to comply with their obligation to make reasonable efforts to ensure that the information contained in their repositories established pursuant to Article 39 of Regulation (EU) 2022/2065 is accurate and complete, providers of very large online platforms and very large online search engines could use the registers of authorised or registered providers of regulated financial services made available in accordance with relevant Union law, including Directive [PSD3], including the public registers maintained by European Supervisory Authorities."
  - number: 81i
    text: "Providers of very large online platforms and very large online search engines within the meaning of Regulation (EU) 2022/2065 are required, under that Regulation, to diligently identify, analyse and assess any systemic risks stemming from the design or functioning of their service, including the dissemination of illegal content through their services, such as malicious or fraudulent online content within the meaning of this Regulation. Where applicable, further to that assessment, providers of very large online platforms and very large online search engines should put in place reasonable, proportionate and effective mitigation measures in accordance with Article 35 of Regulation (EU) 2022/2065 to address those risks, under the direct supervision of the Commission. Where, pursuant to Articles 35 of Regulation (EU) 2022/2065, providers of very large online platforms and very large online search engines should put in place mitigation measures related to the risk of fraudulent advertising of regulated financial services which they have identified pursuant to Article 34 of that Regulation, measures put in place in compliance with the obligations set out in this Regulation could be considered to be one of the possible means of ensuring compliance of such providers with Article 35(1), point (e), of Regulation 2022/2065. However, compliance with the obligations set out in this Regulation should not necessarily be construed as sufficient in itself to ensure compliance of such providers with Article 35(1), point (e), of Regulation 2022/2065, and should therefore be without prejudice to further mitigation measures which such providers may be required to put in place."
  - number: 103a
    text: "Information sharing should be subject to robust state-of-the-art safeguards relating to confidentiality, data protection and use of information, such as pseudonymisation and encryption, access and user control, and should be in accordance with Regulation (EU) 2016/679. Before concluding an information sharing arrangement, payment service providers should carry out a data protection impact assessment, in accordance with Article 35 of that Regulation. Where the data protection impact assessment indicates that, in the absence of safeguards, security measures and mechanisms to mitigate the risk, the processing would result in a high risk to the rights and freedoms of natural persons, payment service providers should consult the relevant data protection authority in accordance with Article 36 of that Regulation. A new impact assessment should not be required when a payment service provider joins an existing information sharing arrangement for which a data protection impact assessment has already been carried out. The information sharing arrangement should lay down technical and organisational measures to protect personal data. It should also lay down the roles and responsibilities of all involved payment service providers in accordance with data protection rules, including in the case of joint controllership."
  - number: 103b
    text: "Payment service providers are able to exchange data related to payment transactions where there is a suspicion of fraud with other participants of information sharing partnerships established in accordance with Article 75 of Regulation (EU) 2024/1624, including competent authorities such as Financial Intelligence Units (FIUs), supervisory authorities and any public authority that has the function of investigating or prosecuting money laundering, its predicate offences or terrorist financing, or that has the function of tracing, seizing or freezing and confiscating criminal assets, in accordance with fundamental rights and judicial procedural safeguards. Payment service providers are also able to share with other payment service providers and other participants, including public authorities, data related to threats to the security of their ICT systems, including where ‘spoofing’, phishing and malware are used to commit fraud against payment service users, in the context of information sharing arrangements on cyber threat information and intelligence established under Article 45 of Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. As such partnerships or arrangements already provide adequate frameworks for the involvement of public authorities, including law enforcement authorities, in the voluntary sharing of data related with fraud, subject to adequate safeguards, it is not considered necessary to create an additional regime for such exchange under this Regulation."
  - number: 103c
    text: "Where a payment service provider participates in information sharing partnerships or arrangements established in accordance with Article 75 of Regulation (EU) 2024/1624 and Article 45 of Regulation (EU) 2022/2554, and where those information sharing partnerships or arrangements enable the payment service provider to exchange the data necessary for the purposes of detecting and preventing fraud in accordance with this Regulation, the sharing of data within the framework of those information sharing partnerships should be considered sufficient to ensure compliance by the payment service provider with its obligations under this Regulation to share payment fraud data in the framework of information sharing arrangements. Where payment service providers participate in those information sharing partnerships or arrangements for the purpose of complying with obligations under this Regulation, they should be allowed to process personal data exchanged in the context of such partnerships or arrangements for the purpose of complying with the transaction monitoring obligations set out in this Regulation."
  - number: 122a
    text: "In accordance with Directive 2013/11/EU, the right to an effective remedy and the right to a fair trial are fundamental rights laid down in Article 47 of the Charter of Fundamental Rights of the European Union. Therefore, ADR procedures should not be designed to replace court procedures and should not deprive consumers or traders of their rights to seek redress before the courts. This Regulation should not prevent parties from exercising their right of access to the judicial system. In cases where a dispute could not be resolved through a given ADR procedure whose outcome is not binding, the parties should subsequently not be prevented from initiating judicial proceedings in relation to that dispute. Member States should be free to choose the appropriate means to achieve this objective. They should have the possibility to provide, inter alia, that limitation or prescription periods do not expire during an ADR procedure."
  - number: 147
    text: "The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council23 and delivered an opinion on [XX XX 2023]24,"
---

# Chapter 3 - Account information services and payment initiation services

## Article 33 - Rights of payment service users

1. Payment service providers shall not prevent payment service users from making use of a payment initiation service provider to obtain payment initiation services as referred to in point (6) of Annex I to Directive XXX [PSD3]. That obligation shall apply to all the payment accounts held by the payment service user that are accessible online.

2. Payment service providers shall not prevent payment service users from making use of account information services as referred to in point (7) of Annex I to Directive XXX [PSD3]. That obligation shall apply to all the payment accounts held by the payment service user that are accessible online.

## Article 34 - Contractual relations

1. The provision of account information services and payment initiation services shall not be conditioned by any party on the existence of a contractual relationship to that end between providers of such services and an account servicing payment service provider.

2. Where a multilateral contractual arrangement is in place and where the same payment account data as regulated under this Regulation is also available in the framework of that multilateral contractual arrangement, access by account information and payment initiation service providers to payment account data regulated under this Regulation shall always be possible without the need to be part of such multilateral contractual arrangement.

## Article 35 - Provision of dedicated access interfaces

1. Account servicing payment service providers that offer to a payer a payment account that is accessible online shall have in place at least one dedicated interface for the purpose of data exchange with account information and payment initiation service providers.

2. Account servicing payment service providers shall put in place their dedicated interface within three months of obtaining their authorisation. The account servicing payment service provider shall provide the relevant technical documentation of the dedicated interface without undue delay, upon request by authorised payment initiation service providers, account information service providers or by undertakings that have applied to their competent authorities for the relevant authorisation so that these service providers can use the dedicated interface as soon as possible. Account servicing payment service providers shall always permit access to the dedicated interface in order to allow business continuity for payment initiation service providers and account information service providers.

3. Account servicing payment service providers shall ensure that their dedicated interfaces referred to in paragraph 1 use standards of communication which are issued by European or international standardisation organisations including the European Committee for Standardization (CEN) or the International Organization for Standardization (ISO) or other relevant, widely recognised standards offering equivalent security. Account servicing payment service providers shall also ensure that the technical specifications of any of the dedicated interfaces referred to in paragraph 1 are documented specifying a set of routines, protocols and tools needed by payment initiation service providers and account information service providers for allowing their software and applications to interoperate with the systems of the account servicing payment service provider. Account servicing payment service providers shall make the documentation on technical specifications of their dedicated interfaces referred to in paragraph 1 available, free of charge and without undue delay, upon request by authorised payment initiation service providers, account information service providers or by payment service providers that have applied to their competent authorities for the relevant authorisation and shall make a summary of that documentation publicly available on their website.

4. Account servicing payment service providers shall ensure that, except for emergency situations which prevent them from doing so, any change to the technical specifications of their dedicated interface referred to in paragraph 1 is made available, as a minimum through publication on their website, to authorised payment initiation service providers, account information service providers, or relevant applicant payment institutions as defined in Article 2(39b) of [PSD3], in advance, as soon as possible and not less than 2 months before the change is implemented. Account servicing payment service providers shall document emergency situations where changes were implemented without such advance information and make the documentation available to competent authorities on request.

5. Account servicing payment service providers shall publish on their website quarterly statistics on the availability, unplanned unavailability and performance of their dedicated interface, and, for comparison purposes, of the interfaces that the account servicing payment service provider makes available to its payment service users for directly accessing their payment account online. The performance of the dedicated interfaces shall be measured by the number of successful account information requests over the total number of account information requests, and by the number and transaction volume of the successful payment initiation requests over the total number and transaction volume of the total number of payment initiation requests.

6. Account servicing payment service providers shall make available a testing facility, including support, for connection to the dedicated interfaces and functional testing to enable authorised payment initiation service providers and account information service providers, or relevant applicant payment institutions as defined in Article 2(39b) of [PSD3], to test their software and applications used for offering a payment service to users. No sensitive payment data or any other personal data shall be shared through the testing facility.

7. In case of an unexpected event or error occurring during the process of identification, authentication, or the exchange of the data elements via the dedicated interface, the account servicing payment service provider shall provide for notification messages to the payment initiation service provider or the account information service provider which explains the reason for the unexpected event or error.

## Article 36 - Requirements regarding dedicated data access interfaces

1. Account servicing payment service providers shall ensure that the dedicated interface referred to in Article 35(1) meets the following security and performance requirements:

   (a) the dedicated interface shall establish and maintain communication sessions between the account servicing payment service provider, the account information service provider, the payment initiation service provider and any payment service user concerned throughout the authentication of the payment service user;

   (b) the dedicated interface shall ensure the integrity and confidentiality of the personalised security credentials and of authentication codes transmitted by or through the payment initiation service provider or the account information service provider;

   (c) the response time of the dedicated interface to account information service providers’ and payment initiation service providers’ access requests shall not be longer than the response time of the interface that the account servicing payment service provider makes available to its payment service users for directly accessing their payment account online.

2. Account servicing payment service providers shall ensure that the dedicated interface referred to in Article 35(1) allows both account information service providers and payment initiation service providers to:

   (a) identify themselves towards the account servicing payment service provider;

   (b) instruct the account servicing payment service provider to start the authentication based on the consent of the payment service user given to the account information service provider or the payment initiation service providers in accordance with Article 49(2);

   (c) make use, in a non-discriminatory manner, of any authentication exemptions applied by the account servicing payment service provider;

3. Account servicing payment service providers shall allow account information service providers to communicate securely, via the dedicated interface, in order to request and receive information on one or more designated payment accounts and associated payment transactions. That information shall include the unique identifier of the account, the associated name of the account holder, the currencies, the account balance, and payment transactions initiated through a payment instrument which have not yet been charged to the payment account, if those transactions are already visible in the customer interface.

4. Account servicing payment service providers shall ensure that the dedicated interface allows payment initiation service providers, at a minimum, to:

   (a) place and revoke a standing payment order;

   (b) initiate a single payment;

   (c) initiate and revoke a future dated payment;

   (d) initiate payments to multiple beneficiaries;

   (e) initiate payments, regardless of whether the payee is on the payer’s beneficiaries list, unless the payment service user is unable to perform those payments in the customer interface;

   (f) communicate securely to place a payment order from the payer's payment account and receive all information on the initiation of the payment transaction and all information accessible to the account servicing payment service provider regarding the execution of the payment transaction;

   (g) verify the name of the account holder before the payment is initiated and regardless of whether the name of the account holder is available via the direct interface;

(ha) in cases where the account servicing payment service provider offers multiple authentication procedures, choose which authentication procedure is to be presented to the payer;

(hc) prior to initiation of the payment, see the unique identifier of the account, the associated names of the account holder and the currencies, where available to the payment service user.

5. Account servicing payment service providers shall ensure that the dedicated interface provides to payment initiation service providers:

   (a) the immediate confirmation, upon request, in a simple ‘yes’ or ‘no’ format, of whether the amount necessary for the execution of a payment transaction is available on the payment account of the payer;

   (b) the confirmation from the account servicing payment service provider as soon as possible, that the payment has been or will be executed on the basis of the information available to the account servicing payment service provider, taking into account any pre-existing payment orders that might affect the full execution of the payment order being placed.

The information referred to in point (b) shall not be shared with the payment initiation service provider but may be used by the account servicing payment service provider in order to provide confirmation of the execution of the operation.

5a. For the purposes of the activities of payment initiation service providers and account information service providers, the name of the account owner and the unique identifier of the account shall not constitute sensitive payment data.

## Article 37 - Data access parity between dedicated access interface and customer interface

1. Without prejudice to Article 36, account servicing payment service providers shall ensure that their dedicated interface referred to in Article 35(1) offers at all times at least the same level of availability and performance, including technical and IT support, as the interfaces that account servicing payment service providers make available to the payment service user for directly accessing its payment account online.

2. Account servicing payment service providers shall provide account information services providers with at least the same information from designated payment accounts and associated payment transactions that is made available to the payment service user when directly requesting access to the account information, provided that this information does not include sensitive payment data.

3. Account servicing payment service providers shall provide payment initiation service providers with at least the same information on the initiation and execution of the payment transaction as is provided or made available to the payment service user when the transaction is initiated directly by the payment service user. That information shall be provided immediately after receipt of the payment order. Any update to that information, including to the payment status, shall be made available to the payment initiation service provider via the dedicated interface and on an ongoing basis until the payment is executed or rejected.

## Article 38 - Availability and performance requirements for the dedicated interface

1. Account servicing payment service providers shall take all measures in their power to limit planned unavailability of the dedicated interface to the extent strictly necessary and to prevent unplanned unavailability and underperformance of the dedicated interface. Unavailability shall be presumed to have arisen when five consecutive requests for access to information for the provision of payment initiation services or account information services receive server error responses or no response from the account servicing payment service provider’s dedicated interface within 30 seconds.

2. In case of planned unavailability of the dedicated interface, account servicing payment service providers shall, except for emergency changes, inform payment service providers making use of the dedicated interface at least one month in advance of the planned unavailability and its duration. Planned unavailability shall normally occur between 00:00 and 06:00.

2a. In case of unplanned unavailability of the dedicated interface, account servicing payment service providers shall timely inform payment initiation service providers and account information service providers making use of the dedicated interface of measures taken to restore the interface and of the time estimated necessary for the problem to be resolved. Account servicing payment service providers shall ensure an optimal recovery time of the dedicated interface.

2b. The account servicing payment service providers shall ensure that the dedicated interface provides availability and performance that are equal at least to those of the interface that the account servicing payment service provider uses for authentication and communication with its users.

5. The EBA shall develop draft regulatory technical standards which shall specify:

   (a) the requirements related to the quarterly statistics on the availability and performance of the interfaces referred to in Article 35(5) and the publication thereof;

   (b) the standards establishing an optimal recovery time in case of dedicated interface unplanned unavailability pursuant to paragraph 3, based on the severity of the incident.

For the purposes of point (b) of the first subparagraph, the severity shall take into account, among others, the number of customers impacted and types of functionality affected of account information and payment initiation service providers.

The EBA shall submit the draft regulatory technical standards referred to in this paragraph to the Commission by [ OP please insert the date = nine months after the date of entry into force of this Regulation]. Power is delegated to the Commission to adopt these regulatory technical standards in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

## Article 39 - Derogation from having a dedicated interface for data access

1. By way of derogation from Article 35(1), on request of an account servicing payment service provider, the competent authority may exempt the requesting account servicing payment service provider from the obligation to have in place a dedicated interface and allow the account servicing payment service provider to either offer, as interface for secure data exchange, the interfaces that the account servicing payment service provider uses for authentication and communication with its payment services users provided this interface offers equivalent functionality to support access by payment initiation service providers and account information service providers and uses widely accepted and interoperable standards or, where justified, not to offer any interface at all for secure data exchange. Where appropriate, Member States may exempt national central banks not acting in their capacity as monetary authority or other public authorities referred to in Article 2, paragraph 1, letter (d) of this Regulation, from the obligation to have in place a dedicated interface.

2. The EBA shall develop draft regulatory technical standards which shall specify the criteria on the basis of which, in accordance with paragraph 1, it is justified for an account servicing payment service provider not to offer any interface at all for secure data exchange. When specifying those criteria, the EBA shall, inter alia, consider the size, annual turnover and payments volume of the account servicing payment service provider.

The EBA shall submit the draft regulatory technical standards referred to in the first subparagraph to the Commission by [ OP please insert the date= one year after the date of entry into force of this Regulation]. Power is delegated to the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1093/2010.

## Article 40 - Obligations on account servicing payment service providers regarding payment initiation services

The account servicing payment service provider shall perform the following actions to ensure the payer’s right to use the payment initiation service:

(a) communicate securely with payment initiation service providers;

(b) immediately after receipt of the payment order, and on an ongoing basis, on request from a payment initiation service provider, make available all information on the initiation of the payment transaction and all information accessible to the account servicing payment service provider regarding the execution of the payment transaction to the payment initiation service provider;

(c) treat payment orders transmitted through the services of a payment initiation service provider as if those payment orders were payment orders transmitted directly by the payer or the payee, in particular in terms of timing, priority or charges.

For the purposes of point (b), where some or all of the information referred to in that point is unavailable immediately after receipt of the payment order, the account servicing payment service provider shall ensure that any information, including any payment status update, about the execution of the payment order is made available to the payment initiation service provider immediately after that information becomes available to the account servicing payment service provider.

## Article 41 - Obligations of account servicing payment service providers regarding account information services

1. The account servicing payment service provider shall perform the following actions to ensure the payment service user’s right to use the account information service:

   (a) communicate securely with the account information service provider;

   (b) treat data requests transmitted through the services of an account information service provider as if the data were requested by the payment service user via the interface that the account servicing payment service provider makes available to its payment service users for directly accessing their payment account.

2. Account servicing payment service providers shall allow account information service providers to access information from designated payment accounts and associated payment transactions held by account servicing payment service providers for the purposes of performing the account information service whether or not the payment service user is actively requesting such information.

2a. Where the account information service provider intends to access information based on paragraph 2 at times when the payment service user is not actively requesting such information, it shall ensure that the payment service user is duly aware of that intention before making use of that functionality.

## Article 42 - Restriction of access to payment accounts by account information service providers and payment initiation service providers

1. An account servicing payment service provider may deny an account information service provider or a payment initiation service provider access to a payment account for objectively justified and duly evidenced reasons. Those reasons shall relate to unauthorised, as per Article 49(3), or fraudulent access to the payment account by that account information service provider or that payment initiation service provider, including the unauthorised or fraudulent initiation of a payment transaction. In such cases, the account servicing payment service provider shall inform the payment services user that access to the payment account is denied and provide the reasons therefor. That information shall, where possible, be provided to the payment services user before access is denied and at the latest immediately thereafter, unless providing such information would compromise objectively justified security reasons or is prohibited by other relevant Union or national law.

2. In the cases referred to in paragraph 1, the account servicing payment service provider shall immediately report the incident relating to the account information service provider or the payment initiation service provider to the competent authority. The information shall include the relevant details of the case and the reasons for taking action. The competent authority shall assess the case and shall, if necessary, take appropriate measures.

## Article 43 - Data access management by payment service users

1. The account servicing payment service provider shall provide the payment service user with a dashboard, integrated into its user interface, to monitor and manage the consents that the payment service user has given for the purpose of account information services or payment initiation services covering multiple or recurrent payments.

2. The dashboard shall:

   (a) provide the payment service user, at any time and in a format that is easy to understand, with an overview of each ongoing consent given for the purposes of account information services or payment initiation services, including:

      (i) the name of the account information service provider or payment initiation service provider to which access has been granted;

      (ii) the customer account to which access has been granted;

      (iii) the purpose of the consent;

      (iv) the period of validity of the consent, including the date on which the payment service user has given that consent;

      (v) the categories of data being shared;

(va) the dates on which payment account data was accessed.

   (b) allow the payment service user to withdraw data access for all account information service or payment initiation service providers or for a given account information service or payment initiation service provider at any time and free of charge;

   (c) within 48 hours from withdrawal of a consent, allow the payment service user to re- establish any data access withdrawn;

   (d) include a record of data access consents that have been withdrawn or that have expired, for a duration of two years;

2b. Where, pursuant to paragraph 2, point (b), a payment service user decides to withdraw data access, the payment initiation service provider or account information service provider concerned shall: - cease accessing and using the data; and - delete without undue delay, but not before 48 hours from withdrawal of a consent, the data received as a result of the data access consent granted by the payment services user. By way of derogation from the second indent of this paragraph, the payment service provider may retain the data if the payment service user explicitly so chooses.

3. The account servicing payment service provider shall ensure that the dashboard is easy to find in its user interface and that information displayed on the dashboard is clear, neutral, accurate and easily understandable for the payment service user and does not contain any deterring or discouraging language that might dissuade the payment service user from making use of the services of a payment initiation service provider or account information service provider.

The account servicing payment service provider shall not: - prompt the payment service user to withdraw a consent given for the purposes of account information services or payment initiation services; - design, organise or operate its dashboard in a manner that deceives, manipulates, or directs the payment service user to grant consents that are not in the user's best interest, or in a manner that materially distorts or impairs the user's ability to make free and informed decisions.

3b. The account information service or payment initiation service provider to which consent has been granted shall provide the information referred to in paragraph 2, point (a), to the account servicing payment service provider without undue delay. The account servicing payment service provider shall only provide the information referred to in paragraph 2, point (a), to the extent that it was provided to it by the account information service or payment initiation service provider to which consent has been granted.

4. The account servicing payment service provider and the account information service or payment initiation service provider to which consent has been granted shall cooperate to make information available to the payment service user via the dashboard without undue delay.

The account servicing payment service provider shall make information available to the account information service or payment initiation service provider without undue delay of any changes made by the payment service user via the dashboard to a consent, including the withdrawal of a permission.

An account information service or payment initiation service provider shall inform the account servicing payment service provider without undue delay of a new consent granted by a payment service user regarding a payment account provided by that account servicing payment service provider, including all the information listed in paragraph 2, point (a), points (i) to (v).

4a. The account servicing payment service provider shall bear no liability for the actions referred to in paragraph 2, points (b) and (c), undertaken by the payment service user.

## Article 44 - Prohibited obstacles to data access

1. Account servicing payment service providers shall ensure that their dedicated interface does not create obstacles to the provision of payment initiation and account information services.

Prohibited obstacles shall include, but not be limited to, the following:

   (a) preventing the use by payment initiation services providers or account information services providers of the personalised security credentials issued by account servicing payment service providers to their payment services users;

   (b) requiring the payment service users to manually input their unique identifier into the domain of the account servicing payment service provider to be able to use account information or payment initiation services;

   (c) requiring checks of the permission given by the payment service users to a payment initiation service provider or an account information services provider;

   (d) requiring additional registrations by payment initiation and account information services providers to be able to access the payment services user’s payment account or the dedicated interface;

   (e) requiring, unless necessary to facilitate the exchange of information between account servicing payment service providers and payment initiation and account information services providers related, in particular, to the updating of the dashboard referred to in Article 43, that payment initiation and account information services providers pre-register their contact details with the account servicing payment service provider;

   (f) restricting the possibility of a payment service user to initiate payments via a payment initiation service provider only to those payees that are on the payer’s beneficiaries list, unless the payment service user is unable to perform those payments in the customer interface;

   (g) restricting payment initiations to or from domestic unique identifiers only;

   (h) requiring that strong customer authentication is applied more times in comparison with the strong customer authentication as required by the account servicing payment service provider when the payment service user is directly accessing their payment account or initiating a payment with the account servicing payment services provider;

      (i) providing a dedicated interface that does not support all the authentication procedures made available by the account servicing payment service provider to its payment service user;

   (j) imposing an account information or payment initiation journey, in a ‘redirection’ or ‘decoupled’ approach, where the authentication of the payment service user with the account servicing payment service provider adds additional steps or required actions in the user journey compared to the equivalent authentication procedure offered to payment service users when directly accessing their payment accounts or initiating a payment with the account servicing payment service provider;

   (k) imposing that the user be automatically redirected, at the stage of authentication, to the account servicing payment service provider’s web page address, when the dedicated interface does not support all the authentication procedures made available by the account servicing payment service provider to its payment service users;

   (l) requiring two strong customer authentications in a payment initiation service-only journey where the payment initiation service provider transmits to the account servicing payment service provider all the information necessary to initiate the payment, namely one strong customer authentication for the yes/no confirmation and a second strong customer authentication for payment initiation.

1a. Measures taken by account servicing payment service providers which are necessary to address suspected fraud under this Regulation or to comply with Regulation (EU) 2016/679 shall not be deemed to constitute obstacles to data access unless those measures are prohibited obstacles referred to in points (a) to (l) of paragraph 1.

## Article 45 - Use of the customer interface by account information service providers and payment initiation service providers

1. Account information service providers and payment initiation service providers shall access payment account data exclusively via the dedicated interface referred to in Article 35, other than in the circumstances covered by Article 39 or exceptionally via another safe and efficient interface.

2. Where only the interface referred to Article 39 is accessible to a payment initiation service provider or an account information service provider, the account information service provider or the payment initiation service provider shall at all times:

   (a) identify itself towards the account servicing payment service provider;

(aa) provide information in accordance with Article 43(2), point (a), points (ii) to (v);

   (b) rely on the authentication procedures provided by the account servicing payment service provider to the payment service user;

   (c) take the necessary measures to ensure that they do not process data (including access and storage of data) for purposes other than for the provision of the service as requested by the payment service user;

   (d) in order to allow the competent authority to investigate compliance with this Section, log the data that are accessed through the interface operated by the account servicing payment service provider for its payment service users, and provide, upon request and without undue delay, the log files to the competent authority.

For the purpose of point (d), logs shall be deleted 3 years after their creation. Logs may be kept for longer than this retention period to the extent that they are required for monitoring procedures that are already underway.

## Article 46 - Specific obligations of payment initiation service providers

1. Payment initiation service providers shall:

   (a) provide account servicing payment service providers with the same information as the information requested from the payment service user when initiating the payment transaction directly;

   (b) provide services only where based on the payment service user’s consent , in accordance with Article 49;

   (c) not hold at any time the payer’s funds in connection with the provision of the payment initiation service;

   (d) ensure that the personalised security credentials of the payment services user are not, with the exception of the payer and the issuer of the personalised security credentials, accessible to other parties and that they are transmitted by the payment initiation service provider through safe and efficient channels;

   (e) ensure that any other information about the payment services user obtained when providing payment initiation services, is only provided to the payee and only with the payment services user’s consent;

   (f) every time a payment is initiated, identify itself towards the account servicing payment service provider and communicate with the account servicing payment service provider, the payer and the payee in a secure way;

(fa) be able to refuse to initiate a payment transaction for objectively justified reasons.

2. Payment initiation service providers shall not:

   (a) without prejudice to Article 45(2), point (d), store sensitive payment data of the payment service user;

   (b) request from the payment service user any data other than those necessary to provide the payment initiation service;

   (c) process any personal or non-personal data (including use, access or storage of data) for purposes other than for the provision of the payment initiation service as permitted by the payment services user;

   (d) modify the amount, the payee or any other feature of the transaction.

## Article 47 - Specific obligations of and other provisions concerning account information service providers

1. The account information service provider shall:

   (a) provide services only where based on the payment service user’s consent , in accordance with Article 49;

   (b) ensure that the personalised security credentials of the payment service user are not accessible to other parties with the exception of the user and the issuer of the personalised security credentials, and that when those credentials are transmitted by the account information service provider, transmission is done through safe and efficient channels;

   (c) for each communication session, identify itself towards the account servicing payment service provider of the payment service user and securely communicate with the account servicing payment service provider and the payment service user;

   (d) access only information from designated payment accounts and associated payment transactions;

   (e) have in place suitable and effective mechanisms that prevent access to information other than from designated payment accounts and associated payment transactions, in accordance with the payment service user's consent.

2. The account information service provider shall not:

   (a) access sensitive payment data linked to the payment accounts;

   (b) process any data for purposes other than for performing the account information service permitted by the payment service user.

3. The following Articles shall not apply to account information service providers: Articles 4 to 8, Articles 10, 11 and 12, Articles 14 to 19, Articles 21 to 29, Articles 50 and 51, Articles 53 to 79, and Articles 83 and 84.

## Article 48 - Role of competent authorities

1. Competent authorities shall ensure that account servicing payment service providers comply at all times with their obligations in relation to the dedicated interface referred to in Articles 35(1) and 38 and that any identified prohibited obstacle listed in Article 44 is immediately removed by the relevant account servicing payment service provider. Where such non-compliance of the dedicated interfaces with this Regulation or obstacles are identified, including on the basis of information transmitted by payment initiation services and account information services providers, the competent authorities shall take without undue delay the necessary and adequate enforcement measures and impose any appropriate sanction.

2. Competent authorities shall take without delay every necessary enforcement action where necessary to preserve the access rights of payment initiation services and account information services providers. Enforcement actions may include appropriate sanctions.

3. Competent authorities shall ensure that payment initiation service and account information service providers comply with their obligations in relation to the use of data access interfaces at all times.

4. Competent authorities shall have the necessary resources, notably in terms of dedicated staff, in order to comply at all times with their tasks.

5. Competent authorities shall cooperate with supervisory authorities under Regulation (EU) 2016/679 where processing of personal data is concerned.

6. Competent authorities shall, on their initiative, hold joint meetings with account servicing payment service providers, payment initiation service and account information service providers for the purposes of paragraph 6a.

6a. Competent authorities shall deploy their best efforts to ensure that possible issues arising from the use of and access to data exchange interfaces between account servicing payment service providers, payment initiation service and account information service providers are rapidly and durably solved.

7. Account servicing payment service providers shall provide competent authorities with data on access by account information service providers and payment initiation service providers to payment accounts which they service. Competent authorities may also, where appropriate, require account information service providers and payment initiation service providers to provide any relevant data on their operations. In accordance with its powers pursuant to Article 29, point (b), Article 31 and Article 35(2) of Regulation (EU) No 1093/2010, the EBA shall coordinate that monitoring activity by competent authorities, avoiding data reporting duplication. The EBA shall report every two years to the Commission on the size and operation of the markets for account information services and payment initiation services in the Union. Those periodical reports may, where appropriate, contain recommendations.

8. The EBA shall develop draft regulatory technical standards specifying the data to be provided to competent authorities pursuant to paragraph 7 as well as the methodology and periodicity to be applied for such data provision.

The EBA shall submit those draft regulatory technical standards to the Commission by [ OP please insert the date= 18 months after the date of entry into force of this Regulation].

Power is delegated to the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Article 10 to 14 of Regulation (EU) No 1093/2010.
