# PSR Article 53 — Obligations of the payment service provider in relation to payment instruments

Textual state: amended_substantial. 58 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. The payment service provider issuing a payment instrument shall: (a) [-make sure -]{+ensure +}that the personalised security credentials are not accessible to parties other than the payment service user that is entitled to use the payment instrument, without prejudice to the obligations on the payment service user set out in Article 52; (b) refrain from sending an unsolicited payment instrument, except where a payment instrument already given to the payment service user is to be replaced; (c) ensure that appropriate means are available at all times {+and free of charge +}to enable the payment service user to make a notification pursuant to Article 52 point (b), or to request unblocking of the payment instrument pursuant to Article [-51(4); -]{+51(4), and that human support is available free of charge for those purposes in an official language of the Member State where the payment service is provided at least during business hours; +}(d) provide the payment service user with the possibility to make a notification pursuant to Article 52 point (b) free of charge and only charge any possible replacement costs directly attributed to the payment instrument; (e) prevent all use of the payment instrument once a notification pursuant to Article 52 point (b) has been [-made. (f) -]{+made; (ea) ensure that sensitive payment data are transmitted to the payment service user through safe channels. +}For the purposes of point (c), the payment service provider shall provide the payment service user upon its request with the means to prove, for 18 months after notification, that the payment service user made such a notification.

## Paragraph 2

2. The payment service provider shall bear the risk of sending a payment instrument or any personalised security credentials relating to it to the payment service user.
