# PSR Article 45 — Use of the customer interface by account information service providers and payment initiation service providers

Textual state: amended_substantial. 141 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Account information service providers and payment initiation service providers shall access payment account data exclusively via the dedicated interface referred to in Article 35, [-except -]{+other than +}in the circumstances covered by Article [-38(4) -]{+39 or exceptionally via another safe +}and [-(5) and Article 39. -]{+efficient interface.+}

## Paragraph 2

2. Where [-an account information service provider or -]{+only the interface referred to Article 39 is accessible to +}a payment initiation service provider [-accesses payment account data via -]{+or +}an [-interface that the -]account [-servicing payment -]{+information +}service [-provider makes available to its payment service users for directly accessing their payment account, in accordance with Article 38(4) and (5), or where that is -]{+provider, +}the [-only interface accessible in accordance with Article 39, the -]account information service provider or the payment initiation service provider shall at all times: (a) identify itself towards the account servicing payment service provider; {+(aa) provide information in accordance with Article 43(2), point (a), points (ii) to (v); +}(b) rely on the authentication procedures provided by the account servicing payment service provider to the payment service user; (c) take the necessary measures to ensure that they do not process data (including access and storage of data) for purposes other than for the provision of the service as requested by the payment service user; (d) {+in order to allow the competent authority to investigate compliance with this Section, +}log the data that are accessed through the interface operated by the account servicing payment service provider for its payment service users, and provide, upon request and without undue delay, the log files to the competent authority. [-Logs shall be deleted 3 years after their creation. Logs may be kept for longer than this retention period if they are required for monitoring procedures that are already underway. -]For the purpose of point [-(d) -]{+(d), +}logs shall be deleted 3 years after their creation. Logs may be kept for longer than this retention period [-if -]{+to the extent that +}they are required for monitoring procedures that are already underway.
