---
instrument_id: psr
chunk_id: psr_t03_ch04
chunk_title: Authorisation of payment transactions
path: "Title III RIGHTS AND OBLIGATIONS IN RELATION TO THE PROVISION AND USE OF PAYMENT SERVICES > Chapter 4"
source_class: operative_text
document_type: proposal
normative_weight: non_binding
legal_status: council_compromise_text
jurisdiction: EU
effective_period:
  from: null
  to: null
articles_contained:
  - 49
  - 50
  - 51
  - 52
  - 53
  - 54
  - 55
  - 56
  - 57
  - 58
  - 59
  - 59a
  - 59b
  - 60
  - 61
  - 62
  - 63
topics:
  - payments
  - payment_services
  - authorisation
  - strong_customer_authentication
  - fraud_prevention
  - liability
  - refunds
  - outsourcing
recitals:
  - number: 76a
    text: "Where a payment service user denies having authorised an executed payment transaction or claims that the payment transaction was not correctly executed, the use of a payment instrument in the form agreed by the payment service provider and the payment service user should not in itself necessarily be considered sufficient to prove that the payment transaction was authorised by the payer. The authentication or the use of the strong customer authentication recorded by the payment service provider, including the payment initiation service provider, as appropriate, should not alone necessarily constitute sufficient evidence either that the payment transaction was authorised by the payer or that the payer acted fraudulently or failed with intent or gross negligence to fulfil one or more of the obligations under Article 52."
  - number: 81c
    text: "Regulation 2022/2065 on a Single Market For Digital Services and amending Directive 2000/31/EC (Digital Services Act) lays down fully harmonised rules on the provision of intermediary services in the internal market and on specific due diligence obligations tailored to certain specific categories of providers of intermediary services (‘mere conduit’, ‘caching’ and ‘hosting’ services). In particular, it imposes specific due diligence obligations on online platforms and online search engines, including those designated as very large online platforms or very large online search engines. Such due diligence obligations play an important role in preventing the proliferation of illegal content online, such as financial scams. For instance, hosting services providers are obliged to put in place user-friendly notice and action mechanisms to allow the reporting of illegal content, such as illegal offers of financial services or attempted fraud, to the hosting service. Providers of online platforms are also obliged to address notices from trusted flaggers as a priority. Where, based on the information provided by the payer to the payment service provider, or on other information available to the payment service provider, it can be considered that a fraudulent payment transaction originates in an item of information online, payment service providers should make use of the notification mechanisms referred to in Article 16 of Regulation (EU) 2022/2065 to notify providers of hosting services of the presence on their service of that specific item of information. Where Very Large Online Platforms and Very Large Online Search Engines comply with Article 16 of Regulation (EU) 2022/2065, in particular putting in place notice and action mechanisms that are easy to access and user-friendly, this shall be deemed compliant with the condition in Article 59a(3) to inform the recipients of their services of the procedure for reporting fraudulent actions. Payment service providers should also be able to apply for the trusted flagger status pursuant to Article 22 of Regulation (EU) 2022/2065."
  - number: 86c
    text: "To ensure consistency across the objectives of preventing payment service users’ from becoming victims of fraud, compliance with obligations following from Regulation (EU) 2024/1624 with regard to suspicious transactions, and mitigating the impact on payment service users deriving from delays in the execution of legitimate payment transactions or the refusal of such transactions. For that reason, where a payment service provider refuses to execute a payment transaction in accordance with this Regulation, such refusal should be without prejudice to other obligations arising for that payment service provider under Regulation (EU) 2024/1624 with respect to that payment transaction, such as the obligation to report that suspicion to the Financial Intelligence Unit in accordance with Article 69 of that Regulation. In the case of credit transfers, while the outcome of the service ensuring the verification of the payee applied in accordance with Regulation (EU) 2024/886 and Article 50 this Regulation might constitute a relevant element in the payment service provider's monitoring of payment transactions with a view to detecting fraud, that outcome should not in itself be the sole ground for the payment service provider's decision to refuse to execute the payment transaction, with a view to ensuring the right of the payer to proceed with authorising the payment transaction concerned in accordance with Article 5c of Regulation (EU) 260/2012 and Article 50 of this Regulation."
---

# Chapter 4 - Authorisation of payment transactions

## Article 49 - Authorisation

1. A payment transaction or a series of payment transactions shall be authorised only if the payer has given its consent for the execution of the payment transaction. A payment transaction may be authorised by the payer prior to or, if agreed between the payer and the account servicing payment service provider, after the execution of the payment transaction.

1a. A payment transaction shall not be deemed to be authorised where the transaction was initiated or modified by a third party who is acting without the consent of the payment service user, including by using the personalised security credentials of the payment service user fraudulently obtained.

2. Access to a payment account for the purpose of account information services or payment initiation services by payment service providers shall be authorised only if the payment service user has given its consent to the account information services provider or, respectively, to the payment initiation service provider, to access the payment account and the relevant data in that account.

3. In the absence of consent , a payment transaction or access to a payment account by an account information service provider or a payment initiation service provider shall be considered to be unauthorised.

4. Account servicing payment service providers shall not verify the consent given by the payment service user to the account information service provider or payment initiation service provider.

5. The consent referred to in paragraphs 1 and 2 shall be expressed in the form agreed between the payer and the relevant payment service provider. Consent to execute a payment transaction may also be expressed via the payee or the payment initiation service provider.

6. The procedure for giving consent shall be agreed between the payer and the relevant payment service provider.

7. The payment service user may withdraw consent to execute a payment transaction or to access a payment account for the purpose of payment initiation services at any time, but no later than at the moment of irrevocability in accordance with Article 66. The payment service user may withdraw consent to access a payment account for the purpose of account information services at any time. The payment service user may also withdraw consent to execute a series of payment transactions, in which case any future payment transaction in that series shall be considered to be unauthorised.

## Article 50 - Discrepancies between the name and unique identifier of a payee in case of credit transfers

In the case of credit transfers, payment service providers shall comply with provisions of Articles 5c(1) to (7) and 5b(2) of Regulation (EU) 260/2012, and those articles shall apply mutatis mutandis to all credit transfers, including those that fall outside the scope of Regulation (EU) 260/2012.

For the purpose of the first subparagraph, where the payment account of the payee is not identified by the payment account identifier specified in point (1)(a) of the Annex of Regulation (EU) 260/2012, references in Article 5c of that Regulation to the payment account identifier shall be construed as referring to the unique identifier used to unambiguously identify the payment account of the payee.

## Article 51 - Limits and blocking of the use of the payment instrument

1. The payment service provider shall offer to the payment service user in the framework contract the possibility of setting in that contract a limit of a maximum amount that can be transferred, which may differ according to each means of payment, including for credit transfers, and each payment instrument. A limit may be on a per-transaction basis or within a set timeframe, at the sole discretion of the payment service user. Payment service providers shall not unilaterally change the spending limits set in the framework contract with their payment service users. It shall be possible for the payment service user to modify the spending limits set in the framework contract. Payment service providers shall ensure that the payer is able to modify the spending limits set prior to the placing of a payment order.

1a. If the payment service user increases the spending limits remotely, payment service providers shall set a delay of four hours for that increase to come into effect. Payment service users shall have the right to adjust or opt out of the application of such delay period. Where a delay period is in place, any subsequent adjustment or opting out of its application shall be subject to the delay period in place.

Payment service providers shall immediately notify payment service users, in an agreed manner, when a change to a spending limit is requested, when the delay period referred to in the first subparagraph has ended or when the opt-out referred to in the first subparagraph is exercised.

1c. Where a payment service user’s payment order exceeds, or leads to exceeding of the maximum amount, the payer’s payment service provider shall not execute the payment order and shall inform the payment service user of the reasons thereof and how to modify the maximum amount.

2. The payment service provider may block the payment instrument for objectively justified reasons relating to the security of the payment instrument, the suspicion of unauthorised or fraudulent use of the payment instrument or, in the case of a payment instrument with a credit line, a significantly increased risk that the payer might be unable to meet its obligation to pay.

3. In such cases the payment service provider shall inform the payer of the blocking of the payment instrument and the specific reasons for it in an agreed manner, where possible before the payment instrument is blocked and at the latest immediately thereafter, unless providing such information is prohibited by other relevant Union or national law. The payer’s payment service provider shall without undue delay and within two business days at the latest, assess whether the reasons to block the payment instrument are still justified.

4. The payment service provider shall unblock the payment instrument or replace it with a new payment instrument once the reasons for blocking no longer exist.

4a. Where the payment service provider offers the payment service user the possibility to initiate or give consent to payment transactions by means of a mobile application, the payment service provider shall require strong customer authentication and the use of different communication channels to activate the mobile application.

4b. If the payment service user activates the mobile application remotely, the provider shall set a delay of four hours for that activation to take effect. The payment service user shall have the right to adjust or opt out of the application of such a delay period. Where a delay period is in place, any subsequent adjustment or opting out of its application shall be subject to the delay period in place.

4c. The payment service provider shall immediately notify the payment service user, in an agreed manner, and through different communication channels, of the activation of a mobile application. The notification shall include instructions in case the payment service users have not installed the mobile application themselves. The procedure for the notification referred to in this paragraph shall be agreed between the payment service user and the payment service provider.

4d. Where the payment service user notifies the payment service provider that they have not activated the mobile application linked to their payment account in accordance with the procedure referred to in paragraph 4c, the payment service provider shall without undue delay ensure that the mobile application does not make it possible to access the payment account of the payment service user, or initiate or give consent to payment transactions.

4e. Paragraphs 4a, 4b and 4c shall not apply to the initial establishment of the customer relationship between the payment service user and the payment service provider through the use of a mobile application nor to the activation by the payment service provider at its physical premises of a mobile application on a device of the payment service user.

4f. This Article applies to all credit transfers, including credit transfers in euro, notwithstanding Regulation (EU) 260/2012.

## Article 52 - Obligations of the payment service user in relation to payment instruments and personalised security credentials

The payment service user entitled to use a payment instrument shall:

(a) use the payment instrument in accordance with the terms governing the issue and use of the payment instrument, which shall be objective, non-discriminatory and proportionate;

(b) notify the payment service provider, or the entity specified by the payment service provider, without undue delay on becoming aware of the loss, theft, misappropriation or unauthorised use of the payment instrument or its relevant personalised security credentials.

For the purposes of point (a) the payment service user shall, as soon as in receipt of a payment instrument, take all reasonable steps to keep its personalised security credentials safe.

## Article 53 - Obligations of the payment service provider in relation to payment instruments

1. The payment service provider issuing a payment instrument shall:

   (a) ensure that the personalised security credentials are not accessible to parties other than the payment service user that is entitled to use the payment instrument, without prejudice to the obligations on the payment service user set out in Article 52;

   (b) refrain from sending an unsolicited payment instrument, except where a payment instrument already given to the payment service user is to be replaced;

   (c) ensure that appropriate means are available at all times and free of charge to enable the payment service user to make a notification pursuant to Article 52 point (b), or to request unblocking of the payment instrument pursuant to Article 51(4), and that human support is available free of charge for those purposes in an official language of the Member State where the payment service is provided at least during business hours;

   (d) provide the payment service user with the possibility to make a notification pursuant to Article 52 point (b) free of charge and only charge any possible replacement costs directly attributed to the payment instrument;

   (e) prevent all use of the payment instrument once a notification pursuant to Article 52 point (b) has been made;

(ea) ensure that sensitive payment data are transmitted to the payment service user through safe channels.

For the purposes of point (c), the payment service provider shall provide the payment service user upon its request with the means to prove, for 18 months after notification, that the payment service user made such a notification.

2. The payment service provider shall bear the risk of sending a payment instrument or any personalised security credentials relating to it to the payment service user.

## Article 54 - Notification and rectification of unauthorised, authorised or incorrectly executed payment transactions

1. The payment service provider shall only rectify any unauthorised, incorrectly executed payment transaction or authorised payment transaction where the payment service user notifies the payment service provider in accordance with Article 56, 59 or 83 without undue delay after becoming aware of any such transaction giving rise to a claim, including a claim under Article 75, and no later than 18 months after the debit date.

The time limits for notification laid down in the first subparagraph shall not apply where the payment service provider has failed to provide or make available the information on the payment transaction in accordance with Title II.

2. Where a payment initiation service provider is involved, the payment service user shall obtain rectification from the account servicing payment service provider pursuant to paragraph 1 of this Article, without prejudice to Article 56(4) and Article 75(1).

## Article 55 - Evidence on authorisation and execution of payment transactions

1. Where a payment service user denies having authorised an executed payment transaction or claims that the payment transaction was not correctly executed, the burden shall be on the payment service provider to prove that the payment transaction was authorised, accurately recorded, entered in the accounts and not affected by a technical breakdown or some other deficiency of the service provided by the payment service provider.

If the payment transaction is initiated through a payment initiation service provider, the burden shall be on the payment initiation service provider to prove that within its sphere of competence, the payment transaction was authorised, accurately recorded and not affected by a technical breakdown or other deficiency linked to the payment service of which it is in charge.

2. Where a payment service user denies having authorised an executed payment transaction, the fact that the payment transaction was authenticated, including where applicable, via strong customer authentication, accurately recorded, entered in the accounts and not affected by a technical breakdown or some other deficiency of the service provided shall in itself not necessarily be sufficient to prove either that the payment transaction was authorised by the payer or that the payer acted fraudulently or failed with intent or gross negligence to fulfil one or more of the obligations under Article 52. The payment service provider, including, where appropriate, the payment initiation service provider, shall provide supporting evidence to prove fraud or gross negligence on part of the payment service user.

2a. For the purposes of paragraphs 1 and 2, and before concluding that a payment service user has authorised the transaction, acted fraudulently or failed with intent or gross negligence to fulfil one or more of the obligations under Article 52, the payment service provider shall invite the payment service user to provide information regarding the events leading up to the payment transaction and include this information in its assessment. Where the payment service user does not provide such information, this shall not in itself lead the payment service provider to conclude that the payment service user has authorised the transaction, acted fraudulently or failed with intent or gross negligence to fulfil one or more of the obligations under Article 52. The payment service user shall not be expected to provide information beyond what such a payment service user can reasonably be expected to have.

## Article 56 - Payment service provider’s liability for unauthorised payment transactions

1. Without prejudice to Article 54, in the case of an unauthorised payment transaction, the payer’s payment service provider shall refund the payer the amount of the unauthorised payment transaction immediately, and in any event no later than by the end of the following business day, after noting or being notified of the unauthorised transaction, except where the payer’s payment service provider has objectively justified reasons for suspecting that the payer failed with intent or gross negligence to fulfil one or more of the obligations under Article 52, and communicates those grounds to the payer in writing, or for suspecting fraud committed by the payer.

2. Where the payer’s payment service provider had objectively justified reasons for suspecting that the payer acted fraudulently or failed with intent or gross negligence to fulfil one or more of the obligations under Article 52, the payer’s payment service provider shall, within 15 business days after noting or being notified of the transaction, do either of the following:

   (a) refund the payer the amount of the unauthorised payment transaction if the payer’s payment service provider has concluded, after further investigation, that the payer did not act fraudulently or fail with intent or gross negligence to fulfil one or more of the obligations under Article 52;

   (b) provide a justification to the payer for refusing the refund and indicate the bodies to which the payer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the payer does not accept the reasons provided, and, where the payment service provider concludes that the payer acted fraudulently, communicate the reasons for that conclusion to the relevant national authority.

For the purpose of the paragraph 2, point (b), Member States shall publish the name of the relevant national authority to whom the justification is to be provided.

3. Where applicable, the payer’s payment service provider shall restore the debited payment account to the state in which it would have been had the unauthorised payment transaction not taken place. The payer’s payment service provider shall also ensure that the credit value date for the payer’s payment account shall be no later than the date the amount had been debited.

4. Where the payment transaction is initiated through a payment initiation service provider, the account servicing payment service provider shall refund immediately, and in any event no later than by the end of the following business day, the amount of the unauthorised payment transaction and, where applicable, restore the debited payment account to the state in which it would have been had the unauthorised payment transaction not taken place.

5. If the payment initiation service provider is liable for the unauthorised payment transaction, the payment initiation service provider shall immediately compensate the account servicing payment service provider at its request for the losses incurred or sums paid as a result of the refund to the payer, including the amount of the unauthorised payment transaction. In accordance with Article 55(1), the burden shall be on the payment initiation service provider to prove that, within its sphere of competence, the payment transaction was authorised, accurately recorded and not affected by a technical breakdown or other deficiency linked to the payment service of which it is in charge.

6. Any further financial loss caused to the payer may be compensated in accordance with the law applicable to the contract concluded between the payer and the relevant payment service provider.

## Article 57 - Payment service provider’s liability for incorrect application of the matching verification service

Where payment service providers fail to comply with Article 50, and where that failure results in a defectively executed payment transaction, the payer’s payment service provider shall without delay refund the payer the amount transferred and, where applicable, restore the debited payment account to the state in which it would have been had the transaction not taken place.

Where that failure occurs because the payee’s payment service provider, or the payment initiation service provider, failed to comply with Article 50, the payee’s payment service provider or, where relevant, the payment initiation service provider, shall compensate the payer’s payment service provider for the financial damage caused to the payer’s payment service provider by that failure.

Any further financial loss caused to the payer may be compensated in accordance with the law applicable to the contract concluded between the payer and the relevant payment service provider.

## Article 58 - Liability of technical service providers and of operators of payment schemes for failure to support the application of strong customer authentication

Technical service providers and operators of payment schemes that either provide services to the payee, or to the payment service provider of the payee or of the payer, shall be liable for direct financial damage caused to the payee, to the payment service provider of the payee or of the payer for, and proportionate to, their failure, within the remit of their contractual relationship, and not exceeding the amount of the transaction in question to provide the services that are necessary to enable the application of strong customer authentication.

## Article 59 - Payment service provider’s liability for impersonation fraud

-1. Payment service providers shall have adequate prevention and robust technical safeguards in place to prevent cases where fraudsters replicate and misuse the payment service provider’s communication channels for misleading payment service users into making fraudulent transactions.

1. Where a payment services user who is a consumer was manipulated by a third party pretending to be the consumer’s payment service provider using communication channels attributed to the consumer's payment service provider and that manipulation gave rise to subsequent fraudulent authorised payment transactions, the payment service provider shall refund the consumer the full amount of the fraudulent authorised payment transaction under the condition that the consumer has, without undue delay after becoming aware of the fraud, notified its payment service provider and reported the fraud to the police.

2. Within 15 business days of being notified and provided with the police report by the consumer, the payment service provider shall do either of the following:

   (a) refund the consumer the amount of the fraudulent authorised payment transaction;

   (b) where the payment service provider has objectively justified reasons to suspect a fraud or a gross negligence by the consumer, provide a justification for refusing the refund and indicate to the consumer the bodies to which the consumer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the consumer does not accept the reasons provided and, where the payment service provider concludes that the payer acted fraudulently, communicate the reasons for that conclusion to the national authority referred to in paragraph 56(2), point (b).

3. Paragraph 1 shall not apply if the consumer has acted fraudulently or with gross negligence.

4. The burden shall be on the payment service provider of the consumer to prove that the consumer acted fraudulently or with gross negligence. Before concluding that the consumer acted fraudulently or with gross negligence, the payment service provider shall invite the consumer to provide information regarding the events leading up to the payment transaction and include this information in its assessment. Where the consumer does not provide such information, this shall not in itself lead the payment service provider to conclude that the consumer acted fraudulently or with gross negligence. The consumer shall not be expected to provide information beyond what such a consumer can reasonably be expected to have.

## Article 59a - Cross-sectoral cooperation for the purpose of fraud prevention and detection

-1. Where payment fraud originates in the publication of fraudulent content online, payment service providers shall, without undue delay, inform providers of hosting services following the procedure laid down in Article 16, or, where applicable, Article 22 of Regulation (EU) 2022/2065.

1. To the extent necessary for the purposes of preventing and detecting potentially fraudulent payment transactions, including transactions involving payment initiation services, data may be exchanged, when there are objectively justified grounds to suspect fraudulent behaviour by a user of their service:
   (a) between payment service providers and providers of hosting services, as defined in Article 3, point (g)(iii), of Regulation (EU) 2022/2065;
   (b) between payment service providers and providers of electronic communications services, as defined in Article 2(4), point (b), of Directive (EU)2018/1972.

2. For the purpose of the first paragraph, without prejudice to Directive (EU) 2022/2555, Directive 2002/58/EC or Article 91 of this Regulation, providers of electronic communications services as defined in Article 2(4), point (b), of Directive (EU) 2018/1972 and providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU)2022/2065 shall establish dedicated communication channels with payment service providers, or participate in a system for effective communication or in an information sharing mechanism, to allow for faster and more effective exchanges in compliance with Regulation (EU) 2016/679 and Directive 2002/58/EC.

3. Providers of electronic communications services as defined in Article 2(4), point (b), of Directive (EU) 2018/1972 and providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU)2022/2065 shall have in place all necessary educational measures, including alerts to their recipients of their services via all appropriate means and media when new forms of online scams emerge, taking into account the needs of their most vulnerable groups of recipients of their services.

For the purpose of the first subparagraph, providers of electronic communication services as defined in Article 2(4), point (b), of Directive (EU) 2018/1972 shall give the recipients of their services clear indications as to:

   (i) how to identify fraudulent attempts;

      (ii) actions and precautions to be taken to avoid falling victim to fraudulent actions targeting them; and

      (iii) the procedure for reporting fraudulent actions.

For the purpose of the first subparagraph, providers of very large online platforms and of very large online search engines within the meaning of Regulation (EU) 2022/2065 shall give the recipients of their services clear indications as to:

      (i) how to identify fraudulent attempts;

      (ii) actions and precautions to be taken to avoid falling victim to fraudulent actions targeting them; and

      (iii) the procedure for reporting fraudulent actions, for the purpose of compliance with Article 16 of Regulation (EU) 2022/2065.

4. The Commission and the European Board of Digital Services shall encourage and facilitate the drawing up of a voluntary code of conduct at Union level to foster prevention, enhance security and combat payment fraud and financial scams, under the conditions set out in Article 45 of Regulation 2022/2065.

5. Without prejudice to Directive (EU) 2022/2555, electronic communications services providers as defined under Article 2(4), point (b) of Directive (EU) 2018/1972 shall take appropriate organisational and technical measures to detect and prevent the use of their services for impersonation fraud, including by means of manipulation of calling line identification or electronic mail address, where that use aims to induce payment services users to make a payment or to take an action that would compromise the security of the payment account. Those measures shall comply with applicable Union law, including Directive 2002/58/EC and Regulation (EU) 2016/679.

## Article 59b - Advertising of regulated financial services on very large online platforms and very large online search engines

1. For the purposes of this Article, ‘regulated financial service’ means any service of a banking, credit, insurance, personal pension, payment or investment (including cryptoassets and crowdfunding) nature for which authorisation from or registration with a competent authority is required under Union law.

2. Providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU)2022/2065, shall request from each advertiser of a regulated financial service an authorisation number, registration number or other information that that advertiser is a regulated financial service provider that is authorised or registered to provide the advertised regulated financial service in a Member State or at the Union level or is acting on behalf of such a provider.

2a. Providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU) 2022/2065 shall, upon receiving the information referred to in paragraph 2, and prior to allowing the advertiser concerned to use their service for the purpose of advertising those regulated financial services, make best efforts, including by using the registers of authorised or registered providers of regulated financial services made available in accordance with Directive [PSD3] or other relevant Union law, to assess whether that information, for the accuracy of which advertisers are solely responsible for the purposes of this Regulation, is reliable and complete, provided that the assessment can be carried out in a proportionate manner by automated tools.

3. Providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU)2022/2065 who have not obtained the information referred to in paragraph 2 shall refuse to allow the advertiser of regulated financial services to use their service for the purpose of advertising those regulated financial services.

4. For the purposes of compliance with Article 39(2), points (a), (b) and (c) of Regulation 2022/2065, where the subject matter of an advertisement is a regulated financial service, providers of very large online platforms and of very large online search engines within the meaning of Article 33 of Regulation (EU)2022/2065 shall include in their advertisement repositories information that the subject matter of the advertisement is a regulated financial service and whether the advertiser is acting on behalf of the regulated financial service provider referred to in paragraph 1.

## Article 60 - Payer’s liability for unauthorised payment transactions

1. By way of derogation from Article 56, the payer may be obliged to bear the losses relating to any unauthorised payment transactions, up to a maximum of EUR 50, resulting from the loss, theft or misappropriation of a payment instrument or personalised security credentials.

The first subparagraph shall not apply where any of the following occurred:

   (a) the loss, theft or misappropriation of a payment instrument or personalised security credentials was not detectable to the payer prior to a payment, except where the payer has acted fraudulently; or

   (b) the loss was caused by acts or lack of action of an employee, agent or branch of a payment service provider or of an entity to which its activities were outsourced.

Where the payer has neither acted fraudulently nor intentionally failed to fulfil its obligations under Article 52, national competent authorities, dispute resolution bodies or payment service providers may reduce the liability referred to in this paragraph, taking into account, in particular, the nature of the personalised security credentials and the specific circumstances under which the payment instrument was lost, stolen or misappropriated.

1a. The payer shall bear all of the losses relating to any unauthorised payment transactions if those losses were incurred by the payer acting fraudulently or failing to fulfil one or more of the obligations set out in Article 52 with intent or gross negligence. In such cases, the maximum amount referred to in the first paragraph shall not apply.

2. Where the payer’s payment service provider fails to fulfil the obligation to require strong customer authentication set out in Article 85, the payer shall not bear any financial losses unless the payer has acted fraudulently. The payer shall not bear any financial losses also where either the payment service provider of the payer or of the payee applies an exemption from the application of strong customer authentication. Where the payee or the payment service provider of the payee fails to develop or amend the systems, hardware and software that are necessary to apply strong customer authentication, the payee or the payment service provider of the payee shall refund the financial damage caused to the payer’s payment service provider.

3. Where the payee’s payment services provider applies an exemption from the application of strong customer authentication, the payee’s payment services provider shall be liable towards the payer’s payment services provider for any financial loss incurred by the latter.

4. The payer shall not bear any financial consequences resulting from use of the lost, stolen or misappropriated payment instrument after notification in accordance with of Article 52, point (b), except where the payer has acted fraudulently.

If the payment service provider does not provide appropriate means for the notification at all times of a lost, stolen or misappropriated payment instrument, as required under of Article 53(1), point (c), the payer shall not be liable for the financial consequences resulting from use of that payment instrument, except where the payer has acted fraudulently.

5. The Commission may adopt a delegated act in accordance with Article 106 to amend this Regulation by updating the amount referred to in paragraph 1.

## Article 61 - Payment transactions where the transaction amount is not known in advance

1. Where a payment transaction is initiated by or through the payee, in particular in the context of a card-based payment or of a credit transfer, and the exact future amount is not known at the moment when the payer authorises the execution of the payment transaction, the payer’s payment service provider may only block funds on the payer’s payment account if the payer has given his or her consent to that precise amount of funds to be blocked.

2. The amount of the funds blocked by the payer’s payment service provider shall be in proportion with the amount of the payment transaction which can reasonably be expected by the payer.

3. The payee shall inform its payment service provider of the exact amount of the payment transaction immediately after delivery of the service or goods to the payer.

4. The payer’s payment service provider shall release the funds blocked on the payer’s payment account immediately after receipt of the information about the exact amount of the payment transaction.

## Article 62 - Refunds for payment transactions initiated by or through a payee

1. A payer shall be entitled to a refund from the payment service provider of an authorised payment transaction which was initiated by or through a payee and which has already been executed, where both of the following conditions are met:

   (a) the authorisation did not specify the exact amount of the payment transaction when the authorisation was made;

   (b) the amount of the payment transaction exceeded the amount the payer could reasonably have expected taking into account the previous spending pattern, the conditions in the framework contract and relevant circumstances of the case.

At the payment service provider’s request, the payer shall bear the burden of proving such conditions are met.

The refund shall consist of the full amount of the executed payment transaction. The credit value date for the payer’s payment account shall be no later than the date the amount was debited.

Without prejudice to paragraph 3 of this Article, in addition to the right referred to in the first subparagraph of this paragraph, for direct debits, the payer shall have an unconditional right to a refund within the time limits laid down in Article 63 of this Regulation.

2. For the purposes of paragraph 1, first subparagraph, point (b), the payer shall not invoke reasons related to possible currency exchange costs if the reference exchange rate agreed with its payment service provider in accordance with Article 13(1), point (e), and Article 20, point (c)(iii), was applied.

3. The payer and the payment service provider may agree in a framework contract that the payer has no right to a refund where:

   (a) the payer has authorised the execution of the payment transaction directly with the payment service provider;

   (b) where applicable, information on the future payment transaction was provided or made available in an agreed manner to the payer for at least 4 weeks before the due date by the payment service provider or by the payee.

4. For direct debits in currencies other than euro, payment service providers may offer more favourable refund rights in accordance with their direct debit schemes provided that they are more advantageous to the payer.

## Article 63 - Requests for refunds for payment transactions initiated by or through a payee

1. The payer may request the refund referred to in Article 62 of an authorised payment transaction initiated by or through a payee for a period of 8 weeks from the date on which the funds were debited.

2. Within 15 business days of receiving a request for a refund, the payment service provider shall do either of the following:

   (a) refund the full amount of the payment transaction;

   (b) provide a justification for refusing the refund and indicate the bodies to which the payer may refer the matter in accordance with Articles 90, 91, 93, 94 and 95 if the payer does not accept the reasons provided.

The payment service provider’s right under the first subparagraph of this paragraph to refuse the refund shall not apply in the case set out in of Article 62(1), fourth subparagraph.
