# PSR Article 83 — Transaction monitoring mechanisms

Textual state: amended_substantial. 634 words changed

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## Paragraph 1

1. Payment service providers shall have transaction monitoring mechanisms in place [-that: -]{+to: +}(a) support the application of strong customer authentication in accordance with Article 85; (b) exempt the application of strong customer authentication based on the criteria under Article 85(11), subject to specified and limited conditions based on the level of risk involved, the types and details of the data assessed by the payment service provider; (c) [-enable payment service providers to -]prevent and detect potentially fraudulent payment transactions, including transactions involving payment initiation services.

## New paragraph 1a

{+1a. The payment service provider of the payer shall carry out the transaction monitoring referred to in paragraph 1 prior to the execution of a payment transaction. The payment service provider of the payee shall also carry out transaction monitoring before the funds are made available to the payee in accordance with Article 69(2). Where a payment service provider does not carry out such monitoring with respect to a transaction and the payer incurs financial damage, that payment service provider shall bear liability. Where the payer's payment service provider does not provide evidence to the payer that such monitoring for a transaction has been carried out by both providers, it shall refund the payer the amount of the transaction. The payer shall not bear any financial consequences from that transaction, except where the payer has acted fraudulently. The burden to prove that there was no breach of this Article shall be on the payment service provider concerned.+}

## New paragraph 1b

{+1b. Transaction monitoring mechanisms shall be based on the analysis of previous payment transactions and access to payment accounts online.+}

## Paragraph 2

2. [-Transaction monitoring mechanisms shall be based on -]{+Processing by +}the [-analysis of previous -]payment [-transactions and access to payment accounts online. Processing -]{+service provider of the payer +}shall be limited to the following [-data required for -]{+data, insofar as necessary to achieve +}the purposes referred to in paragraph 1: (a) information on the [-payment service user, -]{+payer, +}including the environmental and behavioural characteristics which are typical of the [-payment service user -]{+payer +}in the circumstances of a normal use of the personalised security credentials; (b) information on the payment account, including the payment transaction history; (c) transaction information, including the transaction [-amount -]{+amount, payment instrument, currency, date +}and {+time of execution, as well as +}unique identifier of the payee; (d) session data, including the device internet protocol address-range from which the payment account has been [-accessed. Payment service providers shall not store data referred to in this paragraph longer than necessary for -]{+accessed, from which +}the [-purposes set out in paragraph 1, and not after the termination of the customer relationship. Payment service providers shall ensure that the -]transaction [-monitoring mechanisms take into account, at a minimum, each of the following risk-based factors: (a) lists of compromised or stolen authentication elements; (b) the amount of each payment transaction; (c) known fraud scenarios in the provision of payment services; (d) signs of malware infection in any sessions of the authentication procedure; -]{+was initiated; +}(e) [-in case the access -]device [-or the software is provided by the payment service provider, a log of the use of the access -]{+data, including +}device [-or -]{+identifiers from which +}the [-software provided to -]{+transaction was initiated; (ea) information on +}the [-payment service user and -]{+payee, including +}the [-abnormal use -]{+unique identifier +}of the [-access device or -]{+payee; (eb) information received through +}the [-software. -]{+information sharing arrangements.+}

## New paragraph 2a

{+2a. Processing by the payment service provider of the payee shall be limited to the following data, insofar as necessary to achieve the purpose referred to in paragraph 1, as applicable: (a) information on the payee; (aa) information received through the information sharing arrangements; (b) information on the payment account of the payee, including the payment transaction history; (c) transaction information, including the transaction amount, payment instrument, currency, date and time of execution, as well as the name of the payer.+}

## New paragraph 2b

{+2b. Payment service providers shall not store data referred to in paragraphs 2 and 2a longer than necessary for the purposes set out in paragraph 1, and, in any event, no longer than 5 years after the termination of the customer relationship. Payment service providers shall ensure that the transaction monitoring mechanisms take into account, at a minimum, each of the following risk-based factors: (a) lists of compromised or stolen authentication elements; (b) the amount of each payment transaction; (c) known fraud scenarios in the provision of payment services; (d) signs of malware infection in any sessions of the authentication procedure; (e) in case the access device or the software is provided by the payment service provider, a log of the use of the access device or the software provided to the payment service user and the abnormal use of the access device or the software.+}

## Paragraph 3 (removed)

[-3. To the extent necessary to comply with paragraph 1, point (c), payment service providers may exchange the unique identifier of a payee with other payment service providers who are subject to information sharing arrangements as referred to in paragraph 5, when the payment service provider has sufficient evidence to assume that there was a fraudulent payment transaction. Sufficient evidence for sharing unique identifiers shall be assumed when at least two different payment services users who are customers of the same payment service provider have informed that a unique identifier of a payee was used to make a fraudulent credit transfer. Payment service providers shall not keep unique identifiers obtained following the information exchange referred to in this paragraph and paragraph 5 for longer than it is necessary for the purposes laid down in paragraph 1, point (c).-]

## Paragraph 4 (removed)

[-4. The information sharing arrangements shall define details for participation and shall set out the details on operational elements, including the use of dedicated IT platforms. Before concluding such arrangements, payment service providers shall conduct jointly a data protection impact assessment as referred to in Article 35 of the Regulation (EU) 2016/679 and, where applicable, carry out prior consultation of the supervisory authority as referred to in Article 36 of that Regulation.-]

## Paragraph 5 (removed)

[-5. Payment service providers shall notify competent authorities of their participation in the information sharing arrangements referred to in paragraph 5, upon validation of their membership by participants of the information sharing arrangement or, as applicable, of the cessation of their membership, once that cessation takes effect.-]

## Paragraph 6 (removed)

[-6. The processing of personal data in accordance with paragraph 4 shall not lead to termination of the contractual relationship with the customer by the payment service provider or affect their future on-boarding by another payment service provider.-]
