# PSR Article 59a — Cross-sectoral cooperation for the purpose of fraud prevention and detection

Textual state: inserted. New in the compromise text.

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## New paragraph -1

{+-1. Where payment fraud originates in the publication of fraudulent content online, payment service providers shall, without undue delay, inform providers of hosting services following the procedure laid down in Article 16, or, where applicable, Article 22 of Regulation (EU) 2022/2065.+}

## New paragraph 1

{+1. To the extent necessary for the purposes of preventing and detecting potentially fraudulent payment transactions, including transactions involving payment initiation services, data may be exchanged, when there are objectively justified grounds to suspect fraudulent behaviour by a user of their service: (a) between payment service providers and providers of hosting services, as defined in Article 3, point (g)(iii), of Regulation (EU) 2022/2065; (b) between payment service providers and providers of electronic communications services, as defined in Article 2(4), point (b), of Directive (EU)2018/1972.+}

## New paragraph 2

{+2. For the purpose of the first paragraph, without prejudice to Directive (EU) 2022/2555, Directive 2002/58/EC or Article 91 of this Regulation, providers of electronic communications services as defined in Article 2(4), point (b), of Directive (EU) 2018/1972 and providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU)2022/2065 shall establish dedicated communication channels with payment service providers, or participate in a system for effective communication or in an information sharing mechanism, to allow for faster and more effective exchanges in compliance with Regulation (EU) 2016/679 and Directive 2002/58/EC.+}

## New paragraph 3

{+3. Providers of electronic communications services as defined in Article 2(4), point (b), of Directive (EU) 2018/1972 and providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU)2022/2065 shall have in place all necessary educational measures, including alerts to their recipients of their services via all appropriate means and media when new forms of online scams emerge, taking into account the needs of their most vulnerable groups of recipients of their services. For the purpose of the first subparagraph, providers of electronic communication services as defined in Article 2(4), point (b), of Directive (EU) 2018/1972 shall give the recipients of their services clear indications as to: (i) how to identify fraudulent attempts; (ii) actions and precautions to be taken to avoid falling victim to fraudulent actions targeting them; and (iii) the procedure for reporting fraudulent actions. For the purpose of the first subparagraph, providers of very large online platforms and of very large online search engines within the meaning of Regulation (EU) 2022/2065 shall give the recipients of their services clear indications as to: (i) how to identify fraudulent attempts; (ii) actions and precautions to be taken to avoid falling victim to fraudulent actions targeting them; and (iii) the procedure for reporting fraudulent actions, for the purpose of compliance with Article 16 of Regulation (EU) 2022/2065.+}

## New paragraph 4

{+4. The Commission and the European Board of Digital Services shall encourage and facilitate the drawing up of a voluntary code of conduct at Union level to foster prevention, enhance security and combat payment fraud and financial scams, under the conditions set out in Article 45 of Regulation 2022/2065.+}

## New paragraph 5

{+5. Without prejudice to Directive (EU) 2022/2555, electronic communications services providers as defined under Article 2(4), point (b) of Directive (EU) 2018/1972 shall take appropriate organisational and technical measures to detect and prevent the use of their services for impersonation fraud, including by means of manipulation of calling line identification or electronic mail address, where that use aims to induce payment services users to make a payment or to take an action that would compromise the security of the payment account. Those measures shall comply with applicable Union law, including Directive 2002/58/EC and Regulation (EU) 2016/679.+}
