# PSR Article 59 — Payment service provider’s liability for impersonation fraud

Textual state: amended_substantial. 257 words changed; 1 paragraph removed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## New paragraph -1

{+-1. Payment service providers shall have adequate prevention and robust technical safeguards in place to prevent cases where fraudsters replicate and misuse the payment service provider’s communication channels for misleading payment service users into making fraudulent transactions.+}

## Paragraph 1

1. Where a payment services user who is a consumer was manipulated by a third party pretending to be [-an employee of -]the consumer’s payment service provider using {+communication channels attributed to +}the [-name or e-mail address or telephone number of that -]{+consumer's +}payment service provider [-unlawfully -]and that manipulation gave rise to subsequent fraudulent authorised payment transactions, the payment service provider shall refund the consumer the full amount of the fraudulent authorised payment transaction under the condition that the consumer has, without [-any delay, reported -]{+undue delay after becoming aware of +}the [-fraud to the police and -]{+fraud, +}notified its payment service [-provider. -]{+provider and reported the fraud to the police.+}

## Paragraph 2

2. Within [-10 -]{+15 +}business days [-after noting or -]{+of +}being notified [-of -]{+and provided with +}the [-fraudulent authorised payment transaction, -]{+police report by +}the {+consumer, the +}payment service provider shall do either of the following: (a) refund the consumer the amount of the fraudulent authorised payment transaction; (b) where the payment service provider has [-reasonable grounds -]{+objectively justified reasons +}to suspect a fraud or a gross negligence by the consumer, provide a justification for refusing the refund and indicate to the consumer the bodies to which the consumer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the consumer does not accept the reasons [-provided. -]{+provided and, where the payment service provider concludes that the payer acted fraudulently, communicate the reasons for that conclusion to the national authority referred to in paragraph 56(2), point (b).+}

## Paragraph 3

3. Paragraph 1 shall not apply if the consumer has acted fraudulently or with gross negligence.

## Paragraph 4

4. The burden shall be on the payment service provider of the consumer to prove that the consumer acted fraudulently or with gross negligence. {+Before concluding that the consumer acted fraudulently or with gross negligence, the payment service provider shall invite the consumer to provide information regarding the events leading up to the payment transaction and include this information in its assessment. Where the consumer does not provide such information, this shall not in itself lead the payment service provider to conclude that the consumer acted fraudulently or with gross negligence. The consumer shall not be expected to provide information beyond what such a consumer can reasonably be expected to have.+}

## Paragraph 5 (removed)

[-5. Where informed by a payment service provider of the occurrence of the type of fraud as referred to in paragraph 1, electronic communications services providers shall cooperate closely with payment service providers and act swiftly to ensure that appropriate organizational and technical measures are in place to safeguard the security and confidentiality of communications in accordance with Directive 2002/58/EC, including with regard to calling line identification and electronic mail address.-]
