---
instrument_id: psr
chunk_id: psr_t03_ch06
chunk_title: Data protection
path: "Title III RIGHTS AND OBLIGATIONS IN RELATION TO THE PROVISION AND USE OF PAYMENT SERVICES > Chapter 6"
source_class: operative_text
document_type: proposal
normative_weight: non_binding
legal_status: council_compromise_text
jurisdiction: EU
effective_period:
  from: null
  to: null
articles_contained:
  - 80
topics:
  - payments
  - payment_services
  - consumer_protection
  - data_protection
---

# Chapter 6 - Data protection

## Article 80 - Data protection

Payment systems, payment schemes, processing entities and payment service providers shall be allowed to process special categories of personal data as referred to in Article 9(1) of Regulation (EU) 2016/679 and Article 10(1) of Regulation (EU) 2018/1725 to the extent necessary for the provision of payment services and for compliance with obligations under this Regulation, in the public interest of the well-functioning of the internal market for payment services, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons, including the following:

(a) technical measures to ensure compliance with the principles of purpose limitation, data minimisation and storage limitation, as laid down in Regulation (EU) 2016/679, including technical limitations on the re-use of data and use of state-of-the-art security and privacy- preserving measures, including pseudonymisation, or encryption;

(b) organisational measures, including training on processing special categories of data, limiting access to special categories of data and recording such access.
