# PSR Article 83a — Fraud information sharing

Textual state: inserted. New in the compromise text.

- Current text: Council final compromise text (Council document 8221/26) — not yet law.
- Compared against: COM(2023) 367 final — superseded.
- Classification is mechanical; method: https://paymentslaw.eu/method/
- Editorial review state: not_assessed. Markers are curated and selective, not a complete assessment.

Word-level diff, proposal → compromise: `{+text+}` was inserted, `[-text-]` was deleted.

## New paragraph 1

{+1. Payment service providers shall participate in information sharing arrangements with other payment service providers as referred to in paragraph 3 and shall exchange data to the extent necessary to comply with their obligations in Article 83(1), point (c), where the payment service provider has objectively justified reasons to suspect fraudulent behaviour by a payment service user. The categories of data to be shared shall be limited to the data listed in Article 83(2), points (a) to (ea), and 83(2a), points (a), (b) and (c), to the payment service provider’s objectively justified reasons that gave rise to the suspicion of fraudulent behaviour on basis of that data, and to notifications made by the payment service provider to a provider of hosting services in accordance with Article 16 of Regulation EU/2022/2065. Information on the environmental and behavioural characteristics which are typical of the payer in the circumstances of a normal use of the personalised security credentials shall be excluded from information sharing under this Article.+}

## New paragraph 2

{+2. Payment service providers shall implement appropriate technical and organisational measures, including measures to allow pseudonymisation, to ensure a level of security and confidentiality proportionate to the nature and extent of the information exchanged.+}

## New paragraph 3

{+3. Payment service providers shall not keep data obtained following the information exchange referred to in paragraph 1 for longer than it is necessary for the purposes laid down in Article 83(1), point (c), and in any case no longer than 5 years after the suspected fraudulent transaction has taken place.+}

## New paragraph 4

{+4. The information sharing arrangements shall specify the details of participation and the details of operational elements, including the use of dedicated IT platforms. Before concluding such arrangements, payment service providers shall jointly carry out a data protection impact assessment in accordance with Article 35 of Regulation (EU) 2016/679 and, where applicable, prior consultation of the supervisory authority in accordance with Article 36 of that Regulation.+}

## New paragraph 5

{+5. Payment service providers shall not draw conclusions or take decisions that have an impact on a business relationship with the payment service user, such as terminating the contractual relationship with the user or affecting their future onboarding, solely on the basis of information received from other payment service providers who are subject to an information sharing arrangement without having assessed that information.+}
