# PSR Article 60 — Payer’s liability for unauthorised payment transactions

Textual state: amended_substantial. 178 words changed; 2 paragraphs added

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. By way of derogation from Article 56, the payer may be obliged to bear the losses relating to any unauthorised payment transactions, up to a maximum of EUR 50, resulting from the [-use of a lost -]{+loss, theft +}or [-stolen payment instrument or from the -]misappropriation of a payment [-instrument. -]{+instrument or personalised security credentials. +}The first subparagraph shall not apply where any of the following occurred: (a) the loss, theft or misappropriation of a payment instrument {+or personalised security credentials +}was not detectable to the payer prior to a payment, except where the payer has acted fraudulently; or (b) the loss was caused by acts or lack of action of an employee, agent or branch of a payment service provider or of an entity to which its activities were outsourced. [-The payer shall bear all of the losses relating to any unauthorised payment transactions if those losses were incurred by the payer acting fraudulently or failing to fulfil one or more of the obligations set out in Article 52 with intent or gross negligence. In such cases, the maximum amount referred to in the first subparagraph shall not apply. -]Where the payer has neither acted fraudulently nor intentionally failed to fulfil its obligations under Article 52, national competent [-authorities -]{+authorities, dispute resolution bodies +}or payment service providers may reduce the liability referred to in this paragraph, taking into account, in particular, the nature of the personalised security credentials and the specific circumstances under which the payment instrument was lost, stolen or misappropriated.

## New paragraph 1a

{+1a. The payer shall bear all of the losses relating to any unauthorised payment transactions if those losses were incurred by the payer acting fraudulently or failing to fulfil one or more of the obligations set out in Article 52 with intent or gross negligence. In such cases, the maximum amount referred to in the first paragraph shall not apply.+}

## Paragraph 2

2. Where the payer’s payment service provider fails to fulfil the obligation to require strong customer authentication set out in Article 85, the payer shall not bear any financial losses unless the payer has acted fraudulently. The [-same -]{+payer +}shall [-apply -]{+not bear any financial losses also +}where either the payment service provider of the payer or of the payee applies an exemption from the application of strong customer authentication. Where the payee or the payment service provider of the payee fails to develop or amend the systems, hardware and software that are necessary to apply strong customer authentication, the payee or the payment service provider of the payee shall refund the financial damage caused to the payer’s payment service provider.

## Paragraph 3

3. Where the payee’s payment services provider applies an exemption from the application of strong customer authentication, the payee’s payment services provider shall be liable towards the payer’s payment services provider for any financial loss incurred by the latter.

## Paragraph 4

4. The payer shall not bear any financial consequences resulting from use of the lost, stolen or misappropriated payment instrument after notification in accordance with of Article 52, point (b), except where the payer has acted fraudulently. If the payment service provider does not provide appropriate means for the notification at all times of a lost, stolen or misappropriated payment instrument, as required under of Article 53(1), point (c), the payer shall not be liable for the financial consequences resulting from use of that payment instrument, except where the payer has acted fraudulently.

## New paragraph 5

{+5. The Commission may adopt a delegated act in accordance with Article 106 to amend this Regulation by updating the amount referred to in paragraph 1.+}
