# PSR Article 47 — Specific obligations of and other provisions concerning account information service providers

Textual state: amended_substantial. 19 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. The account information service provider shall: (a) provide services only where based on the payment service user’s [-permission, -]{+consent , +}in accordance with Article 49; (b) ensure that the personalised security credentials of the payment service user are not accessible to other [-parties, -]{+parties +}with the exception of the user and the issuer of the personalised security credentials, and that when those credentials are transmitted by the account information service provider, transmission is done through safe and efficient channels; (c) for each communication session, identify itself towards the account servicing payment service provider of the payment service user and securely communicate with the account servicing payment service provider and the payment service user; (d) access only information from designated payment accounts and associated payment transactions; (e) have in place suitable and effective mechanisms that prevent access to information other than from designated payment accounts and associated payment transactions, in accordance with the payment service user's [-permission. -]{+consent.+}

## Paragraph 2

2. The account information service provider shall not: (a) [-request -]{+access +}sensitive payment data linked to the payment accounts; (b) [-use, access or store -]{+process +}any data for purposes other than for performing the account information service permitted by the payment service [-user, in accordance with Regulation (EU) 2016/679. -]{+user.+}

## Paragraph 3

3. The following Articles shall not apply to account information service providers: Articles 4 to 8, Articles 10, 11 and 12, Articles 14 to 19, Articles 21 to 29, Articles 50 and 51, Articles 53 to 79, and Articles 83 and 84.
