Lex Browse everything How it works For developers

What changed, Directive (EU) 2015/2366

2024-04-08 → 2025-01-17 · no interpretation, just the text delta

on 2024-04-08eu-eurlex:32015l2366:2024-04-08 (2024-04-08 → 2025-01-16)
on 2025-01-17eu-eurlex:32015l2366:2025-01-17 (2025-01-17 → open)

1,467 line(s) in the old middle, 1,487 in the new; 59 unchanged leading and 598 trailing lines trimmed.

+ (j) services provided by technical service providers, which support the provision of payment services, without them entering at any time into possession of the funds to be transferred, including processing and storage of data, trust and privacy protection services, data and entity authentication, in…
− (j) services provided by technical service providers, which support the provision of payment services, without them entering at any time into possession of the funds to be transferred, including processing and storage of data, trust and privacy protection services, data and entity authentication, in…
+ (e) a description of the applicant’s governance arrangements and internal control mechanisms, including administrative, risk management and accounting procedures as well as arrangements for the use of ICT services in accordance with Regulation (EU) 2022/2554 of the European Parliament and of the Cou…
− (e) a description of the applicant’s governance arrangements and internal control mechanisms, including administrative, risk management and accounting procedures, which demonstrates that those governance arrangements, control mechanisms and procedures are proportionate, appropriate, sound and adequa…
+ (f) a description of the procedure in place to monitor, handle and follow up a security incident and security related customer complaints, including an incident reporting mechanism which takes account of the notification obligations of the payment institution laid down in Chapter III of Regulation (…
− (f) a description of the procedure in place to monitor, handle and follow up a security incident and security related customer complaints, including an incidents reporting mechanism which takes account of the notification obligations of the payment institution laid down in Article 96;
+ (h) a description of business continuity arrangements including a clear identification of the critical operations, effective ICT business continuity policy and plans and ICT response and recovery plans and a procedure to regularly test and review the adequacy and efficiency of such plans in accordan…
− (h) a description of business continuity arrangements including a clear identification of the critical operations, effective contingency plans and a procedure to regularly test and review the adequacy and efficiency of such plans;
+ The security control and mitigation measures referred to in point (j) of the first subparagraph shall indicate how they ensure a high level of digital operational resilience in accordance with Chapter II of Regulation (EU) 2022/2554, in particular in relation to technical security and data protectio…
− The security control and mitigation measures referred to in point (j) of the first subparagraph shall indicate how they ensure a high level of technical security and data protection, including for the software and IT systems used by the applicant or the undertakings to which it outsources the whole …
+ Outsourcing of important operational functions, including ICT systems, shall not be undertaken in such way as to impair materially the quality of the payment institution’s internal control and the ability of the competent authorities to monitor and retrace the payment institution’s compliance with a…
− Outsourcing of important operational functions, including IT systems, shall not be undertaken in such way as to impair materially the quality of the payment institution’s internal control and the ability of the competent authorities to monitor and retrace the payment institution’s compliance with al…
+ The first subparagraph is without prejudice to the application of Chapter II of Regulation (EU) 2022/2554 to:
+ 
+ (a) payment service providers referred to in points (a), (b) and (d) of Article 1(1) of this Directive;
+ 
+ (b) account information service providers referred to in Article 33(1) of this Directive;
+ 
+ (c) payment institutions exempted pursuant to Article 32(1) of this Directive; and
+ 
+ (d) electronic money institutions benefitting from a waiver as referred to in Article 9(1) of Directive 2009/110/EC.
+ 
+ **7.** Members States shall ensure that paragraphs 1 to 5 of this Article do not apply to:
+ 
+ (a) payment service providers referred to in points (a), (b) and (d) of Article 1(1) of this Directive;
+ 
+ (b) account information service providers referred to in Article 33(1) of this Directive;
+ 
+ (c) payment institutions exempted pursuant to Article 32(1) of this Directive; and
+ 
+ (d) electronic money institutions benefitting from a waiver as referred to in Article 9(1) of Directive 2009/110/EC.
+ 
+ **5.** In accordance with Article 10 of Regulation (EU) No 1093/2010, EBA shall review and, if appropriate, update the regulatory technical standards on a regular basis in order, inter alia, to take account of innovation and technological developments, and of the provisions of Chapter II of Regulati…
− **5.** In accordance with Article 10 of Regulation (EU) No 1093/2010, EBA shall review and, if appropriate, update the regulatory technical standards on a regular basis in order, inter alia, to take account of innovation and technological developments.
tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-04T13:17:09Z · corpus 6974532
stamp signaturevalid (ECDSA-P256)