# PSR Article 44 — Prohibited obstacles to data access

Textual state: amended_substantial. 129 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Account servicing payment service providers shall ensure that their dedicated interface does not create obstacles to the provision of payment initiation and account information services. Prohibited obstacles shall [-include -]{+include, but not be limited to, +}the following: (a) preventing the use by payment initiation services providers or account information services providers of the {+personalised security +}credentials issued by account servicing payment service providers to their payment services users; (b) requiring the payment service users to manually input their unique identifier into the domain of the account servicing payment service provider to be able to use account information or payment initiation services; (c) requiring [-additional -]checks of the permission given by the payment service users to a payment initiation service provider or an account information services provider; (d) requiring additional registrations by payment initiation and account information services providers to be able to access the payment services user’s payment account or the dedicated interface; (e) requiring, unless [-indispensable -]{+necessary +}to facilitate the exchange of information between account servicing payment service providers and payment initiation and account information services providers related, in particular, to the updating of the dashboard referred to in Article 43, that payment initiation and account information services providers pre-register their contact details with the account servicing payment service provider; (f) restricting the possibility of a payment service user to initiate payments via a payment initiation service provider only to those payees that are on the payer’s beneficiaries [-list; -]{+list, unless the payment service user is unable to perform those payments in the customer interface; +}(g) restricting payment initiations to or from domestic unique identifiers only; (h) requiring that strong customer authentication is applied more times in comparison with the strong customer authentication as required by the account servicing payment service provider when the payment service user is directly accessing their payment account or initiating a payment with the account servicing payment services provider; (i) providing a dedicated interface that does not support all the authentication procedures made available by the account servicing payment service provider to its payment service user; (j) imposing an account information or payment initiation journey, in a ‘redirection’ or ‘decoupled’ approach, where the authentication of the payment service user with the account servicing payment service provider adds additional steps or required actions in the user journey compared to the equivalent authentication procedure offered to payment service users when directly accessing their payment accounts or initiating a payment with the account servicing payment service provider; (k) imposing that the user be automatically redirected, at the stage of authentication, to the account servicing payment service provider’s web page [-address -]{+address, +}when [-this is -]the [-sole method of carrying out -]{+dedicated interface does not support all +}the authentication [-of the payment services user that is supported -]{+procedures made available +}by [-an -]{+the +}account servicing payment service [-provider; -]{+provider to its payment service users; +}(l) requiring two strong customer authentications in a payment initiation service-only journey where the payment initiation service provider transmits to the account servicing payment service provider all the information necessary to initiate the payment, namely one strong customer authentication for the yes/no confirmation and a second strong customer authentication for payment initiation.

## New paragraph 1a

{+1a. Measures taken by account servicing payment service providers which are necessary to address suspected fraud under this Regulation or to comply with Regulation (EU) 2016/679 shall not be deemed to constitute obstacles to data access unless those measures are prohibited obstacles referred to in points (a) to (l) of paragraph 1.+}

## Paragraph 2 (removed)

[-2. For the activities of payment initiation services and account information services the name and the account number of the account owner shall not constitute sensitive payment data.-]
