# PSR Article 43 — Data access management by payment service users

Textual state: amended_substantial. 487 words changed; 3 paragraphs added

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. The account servicing payment service provider shall provide the payment service user with a dashboard, integrated into its user interface, to monitor and manage the [-permissions -]{+consents that +}the payment service user has given for the purpose of account information services or payment initiation services covering multiple or recurrent payments.

## Paragraph 2

2. The dashboard shall: (a) provide the payment service [-user -]{+user, at any time and in a format that is easy to understand, +}with an overview of each ongoing [-permission -]{+consent +}given for the purposes of account information services or payment initiation services, including: (i) the name of the account information service provider or payment initiation service provider to which access has been granted; (ii) the customer account to which access has been granted; (iii) the purpose of the [-permission; -]{+consent; +}(iv) the period of validity of the [-permission; -]{+consent, including the date on which the payment service user has given that consent; +}(v) the categories of data being [-shared. -]{+shared; (va) the dates on which payment account data was accessed. +}(b) allow the payment service user to withdraw data access for {+all account information service or payment initiation service providers or for +}a given account information service or payment initiation service [-provider; -]{+provider at any time and free of charge; +}(c) {+within 48 hours from withdrawal of a consent, +}allow the payment service user to re-establish any data access withdrawn; (d) include a record of data access [-permissions -]{+consents +}that have been withdrawn or {+that +}have expired, for a duration of two [-years. -]{+years;+}

## New paragraph 2b

{+2b. Where, pursuant to paragraph 2, point (b), a payment service user decides to withdraw data access, the payment initiation service provider or account information service provider concerned shall: - cease accessing and using the data; and - delete without undue delay, but not before 48 hours from withdrawal of a consent, the data received as a result of the data access consent granted by the payment services user. By way of derogation from the second indent of this paragraph, the payment service provider may retain the data if the payment service user explicitly so chooses.+}

## Paragraph 3

3. The account servicing payment service provider shall ensure that the dashboard is easy to find in its user interface and that information displayed on the dashboard is clear, {+neutral, +}accurate and easily understandable for the payment service [-user. -]{+user and does not contain any deterring or discouraging language that might dissuade the payment service user from making use of the services of a payment initiation service provider or account information service provider. The account servicing payment service provider shall not: - prompt the payment service user to withdraw a consent given for the purposes of account information services or payment initiation services; - design, organise or operate its dashboard in a manner that deceives, manipulates, or directs the payment service user to grant consents that are not in the user's best interest, or in a manner that materially distorts or impairs the user's ability to make free and informed decisions.+}

## New paragraph 3b

{+3b. The account information service or payment initiation service provider to which consent has been granted shall provide the information referred to in paragraph 2, point (a), to the account servicing payment service provider without undue delay. The account servicing payment service provider shall only provide the information referred to in paragraph 2, point (a), to the extent that it was provided to it by the account information service or payment initiation service provider to which consent has been granted.+}

## Paragraph 4

4. The account servicing payment service provider and the account information service or payment initiation service provider to which [-permission -]{+consent +}has been granted shall cooperate to make information available to the payment service user via the dashboard [-in real-time. For the purposes of paragraph 2 points (a), (b), (c) and (e): (a) -]{+without undue delay. +}The account servicing payment service provider shall [-inform -]{+make information available to +}the account information service or payment initiation service provider [-in real time -]{+without undue delay +}of {+any +}changes made [-to a permission concerning that provider made -]by [-a -]{+the +}payment service user via the [-dashboard; (b) -]{+dashboard to a consent, including the withdrawal of a permission. +}An account information service or payment initiation service provider shall inform the account servicing payment service provider [-in real time -]{+without undue delay +}of a new [-permission -]{+consent +}granted by a payment service user regarding a payment account provided by that account servicing payment service provider, [-including: (i) -]{+including all +}the [-purpose of the permission granted by the payment service user; (ii) the period of validity of the permission; (iii) the categories of data concerned. -]{+information listed in paragraph 2, point (a), points (i) to (v).+}

## New paragraph 4a

{+4a. The account servicing payment service provider shall bear no liability for the actions referred to in paragraph 2, points (b) and (c), undertaken by the payment service user.+}
