---
instrument_id: psr
chunk_id: psr_t02_ch01
chunk_title: General rules
path: "Title II TRANSPARENCY OF CONDITIONS AND INFORMATION REQUIREMENTS FOR PAYMENT SERVICES > Chapter 1"
source_class: operative_text
document_type: proposal
normative_weight: non_binding
legal_status: council_compromise_text
jurisdiction: EU
effective_period:
  from: null
  to: null
articles_contained:
  - 4
  - 5
  - 6
  - 7
  - 8
  - 9
  - 10
topics:
  - payments
  - payment_services
  - general_provisions
  - information_requirements
  - trading_venues
  - liability
recitals:
  - number: 31a
    text: "Payment service providers and technical service providers that provide services to payment service providers should be able to secure interoperability with, and to have access for the purposes of interoperability to hardware and software features provided or controlled by original equipment manufacturers of mobile devices or electronic communications service providers, that are necessary to process and execute payment transactions online or offline in a competitive way. Those technical features include hardware and software that is necessary to manage the transaction flow between the payment method and the acceptance device, such as near filed communication technology (NFC) on mobile devices and the payment terminal kernel, or to ensure that mobile payment applications run in a secure environment that protects cryptographic keys and algorithms, the customer PIN code or biometric data, such as the so-called secure elements of mobile devices (e.g.: Universal Integrated Circuit Card (UICC), embedded SE (eSE), and microSD etc). Original equipment manufacturers of mobile devices and electronic communications service providers should be obliged to enable interoperability with, and provide access to all hardware and software features that are necessary to process and execute online and offline transactions on fair, reasonable and non-discriminatory terms. That obligation should be without prejudice to Article 6(7) of Regulation (EU) 2022/1925 of the European Parliament and of the Council1, which obliges gatekeepers to provide, free of charge, effective interoperability with, and access for the purposes of interoperability to, the operating system, hardware or software features of mobile devices and which is applicable to existing and new digital means of payments."
  - number: 55
    text: "Account servicing payment service providers should allow access by account information and payment initiation service providers to payment account data if the payment account can be accessed by the payment service user online and if the payment service user has granted consent for such access. Directive (EU) 2015/2366 was based on the principle of access to payment account data without a need for a contractual relationship between the account servicing payment service provider and the account information and payment initiation service providers, which had the effect that charging for access to data was in practice not possible. Access to data under open banking has been taking place on such a non-contractual basis, and without charging, since the application of Directive (EU) 2015/2366. If regulated data access services were to be subjected to a charge, where there was no charge hitherto, the impact on the continued provision of those services, and therefore on competition and innovation in payment markets, could be very significant. That principle should therefore be maintained. Maintaining that approach is in line with Chapters III and IV of Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)15, in particular Article 9(3) of that proposal on compensation, to which this Regulation is without prejudice."
  - number: 68
    text: "To be fully successful, ‘open banking’ requires a robust and effective enforcement of the rules that regulate that activity. As there exists no single authority at the level of the Union to enforce ‘open banking’ rights and duties, national competent authorities are the first level enforcers of open banking. It is essential that national competent authorities deploy their best efforts to ensure the respect of the Union ‘open banking’ regulated framework. National competent authorities should have the appropriate resources to perform their enforcement tasks effectively and efficiently. National competent authorities should facilitate a smooth and regular dialogue between the various actors of the ‘open banking’ ecosystem. In particular, it must be ensured that account servicing payment service providers comply at all times with their obligations in relation to the dedicated interface. Account servicing payment service providers and account information and payment initiation service providers which do not comply with their obligations should be subject to appropriate sanctions. Regular monitoring of the ‘open banking’ market in the Union by national competent authorities, coordinated by the EBA, should facilitate enforcement, and collection of data on the ‘open banking’ market should remedy a data gap which currently exists, hampering any effective measurement of the actual take-up of ‘open banking’ in the Union. Account servicing payment service providers and account information and payment initiation service providers should have access to dispute settlement bodies, pursuant to Article 10 of Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data (Data Act)."
  - number: 80b
    text: "Payment fraud including the initiation or modification of payment orders without the payer’s consent, the theft of sensitive payment data, including personal security credentials, or the manipulation of the payer, including by means of impersonation, frequently involves fraudulent activity of users of services such as interpersonal communication services or hosting services, which allow the storage and, where applicable, dissemination to the public of online content. Depending on the technical characteristics of the service provided, providers of those services have access to different data, and as such, to different types of indications of potentially fraudulent activity. As such, those providers have the capacity to contribute to the collective fight against fraud, including via ‘spoofing’, by exchanging relevant information with payment service providers, with the aim of preventing and detecting fraudulent uses of interpersonal communication or hosting services. By way of example, relevant information may include the payment account details of traders obtained by providers of online platforms allowing consumers to conclude distance contracts with traders in accordance with Article 30 of Regulation (EU) 2022/2065 related to items of information identified as illegal content by those providers, or information on payment instruments reported as stolen by payment service users to payment service providers. The processing of personal data strictly necessary for the purpose of fraud prevention constitutes a legitimate interest of the interpersonal communication service providers, providers of hosting services, payment service providers and their customers. Providers of interpersonal communication services and of hosting services should be able to exchange personal data with payment service providers to identify fraudulent actors and fraudulent behaviours, where all conditions of Article 6(1)(f) of Regulation (EU) 2016/679 are fulfilled. Furthermore, providers of interpersonal communication services and hosting services should also assist the fight against fraud by exchanging with payment service providers information regarding fraud scenarios, trends and threats identified in relation to the use of their services. In doing so, they may help improve the effectiveness of transaction monitoring mechanisms and the educational campaigns and training on fraud prevention implemented in accordance with this Regulation."
  - number: 96c
    text: "With regard to providers of intermediary services, Regulation (EU) 2022/2065 sets up a fully harmonised framework for the conditional exemption from liability of those providers, under certain conditions and as interpreted by the Court of Justice of the European Union. In order to benefit from the exemption from liability for hosting services under Regulation (EU) 2022/2065, providers of hosting services including online platforms, should remove illegal content or disable access to it, expeditiously, upon obtaining actual knowledge or, in the case of claims for damages, upon becoming aware of the content, in particular in cases in which the provider of hosting services has been made aware of facts or circumstances on the basis of which a diligent economic operator should have identified the illegality in question. In particular with regard to providers of hosting services as defined in Article 3(g)(iii) of the Digital Services Act, where those conditions for exemption from liability under Article 6(1) of Regulation (EU) 2022/2065 are not met, and hosting service providers become liable for content stored in their services, and where that content gave rise to one or a series of unauthorized payment transactions or fraudulent authorized payment transactions within the meaning of this Regulation, payment service providers should be able to obtain compensation from hosting services providers for the amount refunded to their customers for those transactions under this Regulation."
  - number: 98
    text: "As acknowledged in the Communication from the Commission on a Retail Payments Strategy for the EU, the good functioning of EU payments markets, including the security of payments and the protection of payment service users against fraud, is of substantial public interest. For that reason, when it is necessary in the context of this Regulation for the provision of payment services and for compliance with this Regulation, payment service providers and operators of payment systems and payment schemes should be able to process special categories of personal data as defined in Article 9(1) of Regulation (EU) 2016/679, and Article 10(1) of Regulation (EU) 2018/1725, in accordance with Articles 9(2), point (g), and 10(2), point (g) of those Regulations respectively. Where special categories of personal data are processed, payment service providers and payment system operators should implement appropriate technical and organisational measures to safeguard the fundamental rights and freedoms of natural persons. Those measures should include technical limitations on the re-use of data and the use of state-of-the-art security and privacy-preserving measures, including pseudonymisation, or encryption to ensure compliance with the principles of purpose limitation, data minimisation and storage limitation, as laid down in Regulation (EU) 2016/679. The payment service providers and payment systems should also implement specific organisation measures, including training on processing such data, limiting access to special categories of data and recording such access."
  - number: 140
    text: "The EBA should, in line with Article 9(5) of Regulation (EU) No 1093/2010, be granted product intervention powers to be able to temporarily prohibit or restrict in the Union certain type or a specific feature of a payment service or an electronic money service which is identified as potentially causing harm to consumers, threatening the orderly functioning and integrity of financial markets. Regulation (EU) No 1093/2010 should therefore be amended accordingly."
  - number: 142
    text: "Since the objective of this Regulation, namely further integration of an internal market in payment services, cannot be sufficiently achieved by the Member States because it requires harmonisation of various different rules in Union and national law, but can rather, by reason of its scale and effects, be better achieved at Union level, the Union may adopt measures in accordance with the principle of subsidiarity as set out in Article 5 of the Treaty on European Union. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective."
---

# Chapter 1 - General rules

## Article 4 - Scope

1. This Title applies to single payment transactions, framework contracts and payment transactions covered by those contracts. The parties to such single payment transactions, framework contracts and payment transactions covered by them may agree that this Title shall not apply in whole or in part where the payment service user is not a consumer.

2. Member States may apply this Title to microenterprises in the same way as to consumers.

3. Member States shall notify to the Commission the provisions of its law which it adopts pursuant to paragraph 2, by the date of application of this Regulation and, without delay, any subsequent amendment affecting them.

## Article 5 - Currency and currency conversion

1. Payment transactions shall be made in the currency agreed between the parties.

2. Where a currency conversion service is offered prior to the initiation of the payment transaction and where that currency conversion service is offered at an ATM, at the point of sale or by the payee, the party offering the currency conversion service to the payer shall disclose to the payer all charges and the exchange rate to be used for converting the payment transaction.

For the purposes of the first subparagraph, and of Articles 7, 13(1), point (f) and 20(c), point (v), of this Regulation, the aggregated mid-market exchange rate used shall accurately reflect the market, with a maximum delay of 10 minutes or, for currencies where this is not possible, it shall reflect the last traded price from a reputable trading venue. It shall be provided by a trusted administrator who complies with the IOSCO Principles for Financial Benchmarks.

3. The payer shall be given the possibility to agree to the currency conversion service on that basis.

## Article 6 - Information on additional charges or reductions

1. Where, for the use of a given payment instrument, the payee requests a charge or offers a reduction, the payee shall inform the payer thereof prior to the initiation of the payment transaction, in a clear, neutral and comprehensible manner.

2. Where, for the use of a given payment instrument, the payment service provider or another party involved in the transaction requests a charge, it shall inform the payment service user thereof in a clear, neutral and comprehensible manner prior to the initiation of the payment transaction.

3. The payer shall only be obliged to pay for the charges referred to in paragraphs 1 and 2 if their full amount was made known prior to the initiation of the payment transaction.

## Article 7 - Information requirements applicable to cash withdrawal services

Natural or legal persons providing cash withdrawal services, including those referred to in Article 38 of Directive (EU) [PSD3], shall display at the ATM to their customers information on any charges for the withdrawal payable by the customer, including, if applicable, conversion charges in accordance with Article 5(4). The information shall be displayed in a clear, neutral and comprehensible manner prior to the initiation of the payment transaction. The information on any charges shall also be made available to the customer upon request of the customer on a durable medium when the transaction is completed.

## Article 8 - Charges for information

1. Payment service providers shall not charge payment service users for providing information under this Title.

2. Payment service providers and payment service users may agree on charges for additional or more frequent information, or transmission by means of communication other than those specified in the framework contract, provided at the payment service user’s request.

3. Charges for information referred to in paragraph 2 shall be reasonable and in line with the payment service provider’s actual costs.

## Article 9 - Burden of proof on information requirements

The burden of proof shall lie with the payment service providers to prove that they have complied with the information requirements set out in this Title.

## Article 10 - Derogation from information requirements for low-value payment instruments and electronic money

1. In cases of payment instruments which, according to the relevant framework contract, concern only individual payment transactions that do not exceed EUR 50 or that either have a spending limit that does not exceed EUR 300 or store funds that do not exceed EUR 300 at any time:

   (a) by way of derogation from Articles 19, 20 and 24, the payment service provider shall provide the payer only with information on the main characteristics of the payment service, including the way in which the payment instrument can be used, liability, charges levied and other material information needed for the payer to take an informed decision as well as an indication of where any other information and conditions specified in Article 20 are made available in an easily accessible manner;

   (b) it may be agreed by the parties to the framework contract that, by way of derogation from Article 22, the payment service provider is not required to propose changes to the conditions of the framework contract in the same way as provided for in Article 19(1);

   (c) it may be agreed by the parties to the framework contract that, by way of derogation from Articles 25 and 26, after the execution of a payment transaction:

      (i) the payment service provider provides or makes available only a reference enabling the payment service user to identify the payment transaction, the amount of the payment transaction, any charges or, in the case of several payment transactions of the same kind made to the same payee, information on the total amount and charges for those payment transactions;

      (ii) the payment service provider is not required to provide or make available information referred to in point (i) if the payment instrument is used anonymously or if the payment service provider is not otherwise technically in a position to provide it. The payment service provider shall provide the payer with a possibility to verify the amount of funds stored.

2. By way of derogation from paragraph 1, the spending and storing limits for prepaid payment instruments shall not exceed EUR 500.
