Lex Browse everything How it works For developers

What changed, Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366

2017-11-27 → 2023-07-25 · no interpretation, just the text delta

on 2017-11-27eu-eurlex:32018r0389:2017-11-27 (2017-11-27 → 2023-07-24) · official source ↗
on 2023-07-25eu-eurlex:32018r0389:2023-07-25 (2023-07-25 → 2023-09-11) · official source ↗

Open the structured article comparison → matched by provision anchor, with changed, added, removed and unchanged articles separated

648 line(s) in the old middle, 357 in the new; 1 unchanged leading and 1 trailing lines trimmed.

+ ## CHAPTER I — GENERAL PROVISIONS
− ### art_1
+ ### Article 1 — Subject matter
− Article 1
+ (a) apply the procedure of strong customer authentication in accordance with Article 97 of Directive (EU) 2015/2366;
− | (a) | apply the procedure of strong customer authentication in accordance with Article 97 of Directive (EU) 2015/2366; |
− | --- | --- |
+ (b) exempt the application of the security requirements of strong customer authentication, subject to specified and limited conditions based on the level of risk, the amount and the recurrence of the payment transaction and of the payment channel used for its execution;
− | (b) | exempt the application of the security requirements of strong customer authentication, subject to specified and limited conditions based on the level of risk, the amount and the recurrence of the payment transaction and of the payment channel used for its execution; |
− | --- | --- |
+ (c) protect the confidentiality and the integrity of the payment service user's personalised security credentials;
− | (c) | protect the confidentiality and the integrity of the payment service user's personalised security credentials; |
− | --- | --- |
+ (d) establish common and secure open standards for the communication between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers in relation to the provision and use of payment se…
− | (d) | establish common and secure open standards for the communication between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers in relation to the provision and use of paymen…
− | --- | --- |
+ ### Article 2 — General authentication requirements
− ### art_2
+ **1.** Payment service providers shall have transaction monitoring mechanisms in place that enable them to detect unauthorised or fraudulent payment transactions for the purpose of the implementation of the security measures referred to in points (a) and (b) of Article 1.
− Article 2

− 1. Payment service providers shall have transaction monitoring mechanisms in place that enable them to detect unauthorised or fraudulent payment transactions for the purpose of the implementation of the security measures referred to in points (a) and (b) of Article 1.
+ **2.** Payment service providers shall ensure that the transaction monitoring mechanisms take into account, at a minimum, each of the following risk-based factors:(a) lists of compromised or stolen authentication elements;(b) the amount of each payment transaction;(c) known fraud scenarios in the pr…
− 2. Payment service providers shall ensure that the transaction monitoring mechanisms take into account, at a minimum, each of the following risk-based factors:
+ ### Article 3 — Review of the security measures
− | (a) | lists of compromised or stolen authentication elements; |
− | --- | --- |
+ **1.** The implementation of the security measures referred to in Article 1 shall be documented, periodically tested, evaluated and audited in accordance with the applicable legal framework of the payment service provider by auditors with expertise in IT security and payments and operationally indep…
− | (b) | the amount of each payment transaction; |
− | --- | --- |
+ **2.** The period between the audits referred to in paragraph 1 shall be determined taking into account the relevant accounting and statutory audit framework applicable to the payment service provider.
− | (c) | known fraud scenarios in the provision of payment services; |
− | --- | --- |

− | (d) | signs of malware infection in any sessions of the authentication procedure; |
− | --- | --- |

− | (e) | in case the access device or the software is provided by the payment service provider, a log of the use of the access device or the software provided to the payment service user and the abnormal use of the access device or the software. |
− | --- | --- |

− ### art_3

− Article 3

− 1. The implementation of the security measures referred to in Article 1 shall be documented, periodically tested, evaluated and audited in accordance with the applicable legal framework of the payment service provider by auditors with expertise in IT security and payments and operationally independe…

− 2. The period between the audits referred to in paragraph 1 shall be determined taking into account the relevant accounting and statutory audit framework applicable to the payment service provider.
+ **3.** This audit shall present an evaluation and report on the compliance of the payment service provider's security measures with the requirements set out in this Regulation.
− 3. This audit shall present an evaluation and report on the compliance of the payment service provider's security measures with the requirements set out in this Regulation.
+ ## CHAPTER II — SECURITY MEASURES FOR THE APPLICATION OF STRONG CUSTOMER AUTHENTICATION
− ### art_4
+ ### Article 4 — Authentication code
− Article 4
+ **1.** Where payment service providers apply strong customer authentication in accordance with Article 97(1) of Directive (EU) 2015/2366, the authentication shall be based on two or more elements which are categorised as knowledge, possession and inherence and shall result in the generation of an au…
− 1. Where payment service providers apply strong customer authentication in accordance with Article 97(1) of Directive (EU) 2015/2366, the authentication shall be based on two or more elements which are categorised as knowledge, possession and inherence and shall result in the generation of an authen…
+ **2.** For the purpose of paragraph 1, payment service providers shall adopt security measures ensuring that each of the following requirements is met:(a) no information on any of the elements referred to in paragraph 1 can be derived from the disclosure of the authentication code;(b) it is not poss…
− 2. For the purpose of paragraph 1, payment service providers shall adopt security measures ensuring that each of the following requirements is met:
+ **3.** Payment service providers shall ensure that the authentication by means of generating an authentication code includes each of the following measures:(a) where the authentication for remote access, remote electronic payments and any other actions through a remote channel which may imply a risk…
− | (a) | no information on any of the elements referred to in paragraph 1 can be derived from the disclosure of the authentication code; |
− | --- | --- |

− | (b) | it is not possible to generate a new authentication code based on the knowledge of any other authentication code previously generated; |
− | --- | --- |
+ **4.** Where the block referred to in paragraph 3(b) is temporary, the duration of that block and the number of retries shall be established based on the characteristics of the service provided to the payer and all the relevant risks involved, taking into account, at a minimum, the factors referred …
− | (c) | the authentication code cannot be forged. |
− | --- | --- |

− 3. Payment service providers shall ensure that the authentication by means of generating an authentication code includes each of the following measures:

− | (a) | where the authentication for remote access, remote electronic payments and any other actions through a remote channel which may imply a risk of payment fraud or other abuses has failed to generate an authentication code for the purposes of paragraph 1, it shall not be possible to identify wh…
− | --- | --- |

− | (b) | the number of failed authentication attempts that can take place consecutively, after which the actions referred to in Article 97(1) of Directive (EU) 2015/2366 shall be temporarily or permanently blocked, shall not exceed five within a given period of time; |
− | --- | --- |
− | (c) | the communication sessions are protected against the capture of authentication data transmitted during the authentication and against manipulation by unauthorised parties in accordance with the requirements in Chapter V; |
− | --- | --- |

− | (d) | the maximum time without activity by the payer after being authenticated for accessing its payment account online shall not exceed 5 minutes. |
− | --- | --- |

− 4. Where the block referred to in paragraph 3(b) is temporary, the duration of that block and the number of retries shall be established based on the characteristics of the service provided to the payer and all the relevant risks involved, taking into account, at a minimum, the factors referred to i…

+ ### Article 5 — Dynamic linking
− ### art_5
+ **1.** Where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366, in addition to the requirements of Article 4 of this Regulation, they shall also adopt security measures that meet each of the following requirements:(a) the paye…
− Article 5
+ **2.** For the purpose of paragraph 1, payment service providers shall adopt security measures which ensure the confidentiality, authenticity and integrity of each of the following:(a) the amount of the transaction and the payee throughout all of the phases of the authentication;(b) the information …
− 1. Where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366, in addition to the requirements of Article 4 of this Regulation, they shall also adopt security measures that meet each of the following requirements:
+ **3.** For the purpose of paragraph 1(b) and where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366 the following requirements for the authentication code shall apply:(a) in relation to a card-based payment transaction for wh…
− | (a) | the payer is made aware of the amount of the payment transaction and of the payee; |
− | --- | --- |
+ ### Article 6 — Requirements of the elements categorised as knowledge
− | (b) | the authentication code generated is specific to the amount of the payment transaction and the payee agreed to by the payer when initiating the transaction; |
− | --- | --- |
+ **1.** Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as knowledge are uncovered by, or disclosed to, unauthorised parties.
− | (c) | the authentication code accepted by the payment service provider corresponds to the original specific amount of the payment transaction and to the identity of the payee agreed to by the payer; |
− | --- | --- |
+ **2.** The use by the payer of those elements shall be subject to mitigation measures in order to prevent their disclosure to unauthorised parties.
− | (d) | any change to the amount or the payee results in the invalidation of the authentication code generated. |
− | --- | --- |
+ ### Article 7 — Requirements of the elements categorised as possession
− 2. For the purpose of paragraph 1, payment service providers shall adopt security measures which ensure the confidentiality, authenticity and integrity of each of the following:
+ **1.** Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as possession are used by unauthorised parties.
− | (a) | the amount of the transaction and the payee throughout all of the phases of the authentication; |
− | --- | --- |
+ **2.** The use by the payer of those elements shall be subject to measures designed to prevent replication of the elements.
− | (b) | the information displayed to the payer throughout all of the phases of the authentication including the generation, transmission and use of the authentication code. |
− | --- | --- |
+ ### Article 8 — Requirements of devices and software linked to elements categorised as inherence
− 3. For the purpose of paragraph 1(b) and where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366 the following requirements for the authentication code shall apply:
+ **1.** Payment service providers shall adopt measures to mitigate the risk that the authentication elements categorised as inherence and read by access devices and software provided to the payer are uncovered by unauthorised parties. At a minimum, the payment service providers shall ensure that thos…
− | (a) | in relation to a card-based payment transaction for which the payer has given consent to the exact amount of the funds to be blocked pursuant to Article 75(1) of that Directive, the authentication code shall be specific to the amount that the payer has given consent to be blocked and agreed …
− | --- | --- |
+ **2.** The use by the payer of those elements shall be subject to measures ensuring that those devices and the software guarantee resistance against unauthorised use of the elements through access to the devices and the software.
− | (b) | in relation to payment transactions for which the payer has given consent to execute a batch of remote electronic payment transactions to one or several payees, the authentication code shall be specific to the total amount of the batch of payment transactions and to the specified payees. |
− | --- | --- |
+ ### Article 9 — Independence of the elements
− ### art_6
+ **1.** Payment service providers shall ensure that the use of the elements of strong customer authentication referred to in Articles 6, 7 and 8 is subject to measures which ensure that, in terms of technology, algorithms and parameters, the breach of one of the elements does not compromise the relia…
− Article 6
+ **2.** Payment service providers shall adopt security measures, where any of the elements of strong customer authentication or the authentication code itself is used through a multi-purpose device, to mitigate the risk which would result from that multi-purpose device being compromised.
− 1. Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as knowledge are uncovered by, or disclosed to, unauthorised parties.
+ **3.** For the purposes of paragraph 2, the mitigating measures shall include each of the following:(a) the use of separated secure execution environments through the software installed inside the multi-purpose device;(b) mechanisms to ensure that the software or device has not been altered by the p…
− 2. The use by the payer of those elements shall be subject to mitigation measures in order to prevent their disclosure to unauthorised parties.
+ ## CHAPTER III — EXEMPTIONS FROM STRONG CUSTOMER AUTHENTICATION
− ### art_7
+ ### Article 10 — Access to the payment account information directly with the account servicing payment service provider
− Article 7
+ **1.** Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where a payment service user is accessing its payment account online directly, provided that access is limited to one of the following it…
− 1. Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as possession are used by unauthorised parties.
+ **2.** By way of derogation from paragraph 1, payment service providers shall not be exempted from the application of strong customer authentication where one of the following conditions is met:(a) the payment service user is accessing online the information specified in paragraph 1 for the first ti…
− 2. The use by the payer of those elements shall be subject to measures designed to prevent replication of the elements.
+ ### Article 10a — Access to the payment account information through an account information service provider
− ### art_8
+ **1.** Payment service providers shall not apply strong customer authentication where a payment service user is accessing its payment account online through an account information service provider, provided that access is limited to one of the following items online without disclosure of sensitive p…
− Article 8
+ **2.** By way of derogation from paragraph 1, payment service providers shall apply strong customer authentication where one of the following conditions is met:(a) the payment service user is accessing online the information specified in paragraph 1 for the first time through the account information…
− 1. Payment service providers shall adopt measures to mitigate the risk that the authentication elements categorised as inherence and read by access devices and software provided to the payer are uncovered by unauthorised parties. At a minimum, the payment service providers shall ensure that those ac…
+ **3.** By way of derogation from paragraph 1, payment service providers shall be allowed to apply strong customer authentication where a payment service user is accessing its payment account online through an account information service provider and the payment service provider has objectively justi…
− 2. The use by the payer of those elements shall be subject to measures ensuring that those devices and the software guarantee resistance against unauthorised use of the elements through access to the devices and the software.
+ **4.** Account servicing payment service providers that offer a dedicated interface as referred to in Article 31 shall not be required to implement the exemption laid down in paragraph 1 of this Article for the purpose of the contingency mechanism referred to in Article 33(4), where they do not appl…
− ### art_9
+ ### Article 11 — Contactless payments at point of sale
− Article 9

− 1. Payment service providers shall ensure that the use of the elements of strong customer authentication referred to in Articles 6, 7 and 8 is subject to measures which ensure that, in terms of technology, algorithms and parameters, the breach of one of the elements does not compromise the reliabili…

− 2. Payment service providers shall adopt security measures, where any of the elements of strong customer authentication or the authentication code itself is used through a multi-purpose device, to mitigate the risk which would result from that multi-purpose device being compromised.

− 3. For the purposes of paragraph 2, the mitigating measures shall include each of the following:
− | (a) | the use of separated secure execution environments through the software installed inside the multi-purpose device; |
− | --- | --- |

− | (b) | mechanisms to ensure that the software or device has not been altered by the payer or by a third party; |
− | --- | --- |

− | (c) | where alterations have taken place, mechanisms to mitigate the consequences thereof. |
− | --- | --- |

− ### art_10

− Article 10

− 1. Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2 and to paragraph 2 of this Article and, where a payment service user is limited to accessing either or both of the following items online with…

− | (a) | the balance of one or more designated payment accounts; |
− | --- | --- |

− | (b) | the payment transactions executed in the last 90 days through one or more designated payment accounts. |
− | --- | --- |

− 2. For the purpose of paragraph 1, payment service providers shall not be exempted from the application of strong customer authentication where either of the following condition is met:

− | (a) | the payment service user is accessing online the information specified in paragraph 1 for the first time; |
− | --- | --- |

− | (b) | more than 90 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1(b) and strong customer authentication was applied. |
− | --- | --- |

− ### art_11

− Article 11

+ (a) the individual amount of the contactless electronic payment transaction does not exceed EUR 50; and
− | (a) | the individual amount of the contactless electronic payment transaction does not exceed EUR 50; and |
− | --- | --- |
+ (b) the cumulative amount of previous contactless electronic payment transactions initiated by means of a payment instrument with a contactless functionality from the date of the last application of strong customer authentication does not exceed EUR 150; or
− | (b) | the cumulative amount of previous contactless electronic payment transactions initiated by means of a payment instrument with a contactless functionality from the date of the last application of strong customer authentication does not exceed EUR 150; or |
− | --- | --- |
+ (c) the number of consecutive contactless electronic payment transactions initiated via the payment instrument offering a contactless functionality since the last application of strong customer authentication does not exceed five.
− | (c) | the number of consecutive contactless electronic payment transactions initiated via the payment instrument offering a contactless functionality since the last application of strong customer authentication does not exceed five. |
− | --- | --- |
+ ### Article 12 — Unattended terminals for transport fares and parking fees
− ### art_12

− Article 12
+ ### Article 13 — Trusted beneficiaries
− ### art_13
+ **1.** Payment service providers shall apply strong customer authentication where a payer creates or amends a list of trusted beneficiaries through the payer's account servicing payment service provider.
− Article 13
+ **2.** Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the general authentication requirements, where the payer initiates a payment transaction and the payee is included in a list of trusted beneficiaries previously created by the pa…
− 1. Payment service providers shall apply strong customer authentication where a payer creates or amends a list of trusted beneficiaries through the payer's account servicing payment service provider.
+ ### Article 14 — Recurring transactions
− 2. Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the general authentication requirements, where the payer initiates a payment transaction and the payee is included in a list of trusted beneficiaries previously created by the payer.
+ **1.** Payment service providers shall apply strong customer authentication when a payer creates, amends, or initiates for the first time, a series of recurring transactions with the same amount and with the same payee.
− ### art_14

− Article 14
+ **2.** Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the general authentication requirements, for the initiation of all subsequent payment transactions included in the series of payment transactions referred to in paragraph 1.
− 1. Payment service providers shall apply strong customer authentication when a payer creates, amends, or initiates for the first time, a series of recurring transactions with the same amount and with the same payee.
+ ### Article 15 — Credit transfers between accounts held by the same natural or legal person
− 2. Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the general authentication requirements, for the initiation of all subsequent payment transactions included in the series of payment transactions referred to in paragraph 1.
− ### art_15

− Article 15

+ ### Article 16 — Low-value transactions
− ### art_16

− Article 16
+ (a) the amount of the remote electronic payment transaction does not exceed EUR 30; and
− | (a) | the amount of the remote electronic payment transaction does not exceed EUR 30; and |
− | --- | --- |
+ (b) the cumulative amount of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed EUR 100; or
− | (b) | the cumulative amount of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed EUR 100; or |
− | --- | --- |
+ (c) the number of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed five consecutive individual remote electronic payment transactions.
− | (c) | the number of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed five consecutive individual remote electronic payment transactions. |
− | --- | --- |
+ ### Article 17 — Secure corporate payment processes and protocols
− ### art_17

− Article 17
+ ### Article 18 — Transaction risk analysis
− ### art_18
+ **1.** Payment service providers shall be allowed not to apply strong customer authentication where the payer initiates a remote electronic payment transaction identified by the payment service provider as posing a low level of risk according to the transaction monitoring mechanisms referred to in A…
− Article 18
+ **2.** An electronic payment transaction referred to in paragraph 1 shall be considered as posing a low level of risk where all the following conditions are met:(a) the fraud rate for that type of transaction, reported by the payment service provider and calculated in accordance with Article 19, is …
− 1. Payment service providers shall be allowed not to apply strong customer authentication where the payer initiates a remote electronic payment transaction identified by the payment service provider as posing a low level of risk according to the transaction monitoring mechanisms referred to in Artic…

− 2. An electronic payment transaction referred to in paragraph 1 shall be considered as posing a low level of risk where all the following conditions are met:
+ **3.** Payment service providers that intend to exempt electronic remote payment transactions from strong customer authentication on the ground that they pose a low risk shall take into account at a minimum, the following risk-based factors:(a) the previous spending patterns of the individual paymen…
− | (a) | the fraud rate for that type of transaction, reported by the payment service provider and calculated in accordance with Article 19, is equivalent to or below the reference fraud rates specified in the table set out in the Annex for ‘remote electronic card-based payments’ and ‘remote electron…
− | --- | --- |

− | (b) | the amount of the transaction does not exceed the relevant exemption threshold value (‘ETV’) specified in the table set out in the Annex; |
− | --- | --- |

− | (c) | payment service providers as a result of performing a real time risk analysis have not identified any of the following:(i)abnormal spending or behavioural pattern of the payer;(ii)unusual information about the payer's device/software access;(iii)malware infection in any session of the authen…
− | --- | --- |
− | (i) | abnormal spending or behavioural pattern of the payer; |
− | (ii) | unusual information about the payer's device/software access; |
− | (iii) | malware infection in any session of the authentication procedure; |
− | (iv) | known fraud scenario in the provision of payment services; |
− | (v) | abnormal location of the payer; |
− | (vi) | high-risk location of the payee. |

− 3. Payment service providers that intend to exempt electronic remote payment transactions from strong customer authentication on the ground that they pose a low risk shall take into account at a minimum, the following risk-based factors:

− | (a) | the previous spending patterns of the individual payment service user; |
− | --- | --- |
− | (b) | the payment transaction history of each of the payment service provider's payment service users; |
− | --- | --- |

− | (c) | the location of the payer and of the payee at the time of the payment transaction in cases where the access device or the software is provided by the payment service provider; |
− | --- | --- |

− | (d) | the identification of abnormal payment patterns of the payment service user in relation to the user's payment transaction history. |
− | --- | --- |

+ ### Article 19 — Calculation of fraud rates
− ### art_19
+ **1.** For each type of transaction referred to in the table set out in the Annex, the payment service provider shall ensure that the overall fraud rates covering both payment transactions authenticated through strong customer authentication and those executed under any of the exemptions referred to…
− Article 19

− 1. For each type of transaction referred to in the table set out in the Annex, the payment service provider shall ensure that the overall fraud rates covering both payment transactions authenticated through strong customer authentication and those executed under any of the exemptions referred to in …
+ **2.** The calculation of the fraud rates and resulting figures shall be assessed by the audit review referred to in Article 3(2), which shall ensure that they are complete and accurate.
− 2. The calculation of the fraud rates and resulting figures shall be assessed by the audit review referred to in Article 3(2), which shall ensure that they are complete and accurate.
+ **3.** The methodology and any model, used by the payment service provider to calculate the fraud rates, as well as the fraud rates themselves, shall be adequately documented and made fully available to competent authorities and to EBA, with prior notification to the relevant competent authority(ies…
− 3. The methodology and any model, used by the payment service provider to calculate the fraud rates, as well as the fraud rates themselves, shall be adequately documented and made fully available to competent authorities and to EBA, with prior notification to the relevant competent authority(ies), u…
+ ### Article 20 — Cessation of exemptions based on transaction risk analysis
− ### art_20
+ **1.** Payment service providers that make use of the exemption referred to in Article 18 shall immediately report to the competent authorities where one of their monitored fraud rates, for any type of payment transactions indicated in the table set out in the Annex, exceeds the applicable reference…
− Article 20
+ **2.** Payment service providers shall immediately cease to make use of the exemption referred to in Article 18 for any type of payment transactions indicated in the table set out in the Annex in the specific exemption threshold range where their monitored fraud rate exceeds for two consecutive quar…
− 1. Payment service providers that make use of the exemption referred to in Article 18 shall immediately report to the competent authorities where one of their monitored fraud rates, for any type of payment transactions indicated in the table set out in the Annex, exceeds the applicable reference fra…
+ **3.** Following the cessation of the exemption referred to in Article 18 in accordance with paragraph 2 of this Article, payment service providers shall not use that exemption again, until their calculated fraud rate equals to, or is below, the reference fraud rates applicable for that type of paym…
− 2. Payment service providers shall immediately cease to make use of the exemption referred to in Article 18 for any type of payment transactions indicated in the table set out in the Annex in the specific exemption threshold range where their monitored fraud rate exceeds for two consecutive quarters…
+ **4.** Where payment service providers intend to make use again of the exemption referred to in Article 18, they shall notify the competent authorities in a reasonable timeframe and shall before making use again of the exemption, provide evidence of the restoration of compliance of their monitored f…
− 3. Following the cessation of the exemption referred to in Article 18 in accordance with paragraph 2 of this Article, payment service providers shall not use that exemption again, until their calculated fraud rate equals to, or is below, the reference fraud rates applicable for that type of payment …
+ ### Article 21 — Monitoring
− 4. Where payment service providers intend to make use again of the exemption referred to in Article 18, they shall notify the competent authorities in a reasonable timeframe and shall before making use again of the exemption, provide evidence of the restoration of compliance of their monitored fraud…
+ **1.** In order to make use of the exemptions set out in Articles 10 to 18, payment service providers shall record and monitor the following data for each type of payment transactions, with a breakdown for both remote and non-remote payment transactions, at least on a quarterly basis:(a) the total v…
− ### art_21
+ **2.** Payment service providers shall make the results of the monitoring in accordance with paragraph 1 available to competent authorities and to EBA, with prior notification to the relevant competent authority(ies), upon their request.
− Article 21
+ ## CHAPTER IV — CONFIDENTIALITY AND INTEGRITY OF THE PAYMENT SERVICE USERS' PERSONALISED SECURITY CREDENTIALS
− 1. In order to make use of the exemptions set out in Articles 10 to 18, payment service providers shall record and monitor the following data for each type of payment transactions, with a breakdown for both remote and non-remote payment transactions, at least on a quarterly basis:
+ ### Article 22 — General requirements
− | (a) | the total value of unauthorised or fraudulent payment transactions in accordance with Article 64(2) of Directive (EU) 2015/2366, the total value of all payment transactions and the resulting fraud rate, including a breakdown of payment transactions initiated through strong customer authentic…
− | --- | --- |
+ **1.** Payment service providers shall ensure the confidentiality and integrity of the personalised security credentials of the payment service user, including authentication codes, during all phases of the authentication.
− | (b) | the average transaction value, including a breakdown of payment transactions initiated through strong customer authentication and under each of the exemptions; |
− | --- | --- |
+ **2.** For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:(a) personalised security credentials are masked when displayed and are not readable in their full extent when input by the payment service user during the authentication;(b) …
− | (c) | the number of payment transactions where each of the exemptions was applied and their percentage in respect of the total number of payment transactions. |
− | --- | --- |
+ **3.** Payment service providers shall fully document the process related to the management of cryptographic material used to encrypt or otherwise render unreadable the personalised security credentials.
− 2. Payment service providers shall make the results of the monitoring in accordance with paragraph 1 available to competent authorities and to EBA, with prior notification to the relevant competent authority(ies), upon their request.
+ **4.** Payment service providers shall ensure that the processing and routing of personalised security credentials and of the authentication codes generated in accordance with Chapter II take place in secure environments in accordance with strong and widely recognised industry standards.
− ### art_22
+ ### Article 23 — Creation and transmission of credentials
− Article 22

− 1. Payment service providers shall ensure the confidentiality and integrity of the personalised security credentials of the payment service user, including authentication codes, during all phases of the authentication.

− 2. For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:
− | (a) | personalised security credentials are masked when displayed and are not readable in their full extent when input by the payment service user during the authentication; |
− | --- | --- |

− | (b) | personalised security credentials in data format, as well as cryptographic materials related to the encryption of the personalised security credentials are not stored in plain text; |
− | --- | --- |

− | (c) | secret cryptographic material is protected from unauthorised disclosure. |
− | --- | --- |

− 3. Payment service providers shall fully document the process related to the management of cryptographic material used to encrypt or otherwise render unreadable the personalised security credentials.

− 4. Payment service providers shall ensure that the processing and routing of personalised security credentials and of the authentication codes generated in accordance with Chapter II take place in secure environments in accordance with strong and widely recognised industry standards.

− ### art_23

− Article 23

+ ### Article 24 — Association with the payment service user
− ### art_24

− Article 24
+ **1.** Payment service providers shall ensure that only the payment service user is associated, in a secure manner, with the personalised security credentials, the authentication devices and the software.
− 1. Payment service providers shall ensure that only the payment service user is associated, in a secure manner, with the personalised security credentials, the authentication devices and the software.
+ **2.** For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:(a) the association of the payment service user's identity with personalised security credentials, authentication devices and software is carried out in secure environments un…
− 2. For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:
+ ### Article 25 — Delivery of credentials, authentication devices and software
− | (a) | the association of the payment service user's identity with personalised security credentials, authentication devices and software is carried out in secure environments under the payment service provider's responsibility comprising at least the payment service provider's premises, the intern…
− | --- | --- |
+ **1.** Payment service providers shall ensure that the delivery of personalised security credentials, authentication devices and software to the payment service user is carried out in a secure manner designed to address the risks related to their unauthorised use due to their loss, theft or copying.
− | (b) | the association by means of a remote channel of the payment service user's identity with the personalised security credentials and with authentication devices or software is performed using strong customer authentication. |
− | --- | --- |
+ **2.** For the purpose of paragraph 1, payment service providers shall at least apply each of the following measures:(a) effective and secure delivery mechanisms ensuring that the personalised security credentials, authentication devices and software are delivered to the legitimate payment service u…
− ### art_25
+ ### Article 26 — Renewal of personalised security credentials
− Article 25

− 1. Payment service providers shall ensure that the delivery of personalised security credentials, authentication devices and software to the payment service user is carried out in a secure manner designed to address the risks related to their unauthorised use due to their loss, theft or copying.

− 2. For the purpose of paragraph 1, payment service providers shall at least apply each of the following measures:
− | (a) | effective and secure delivery mechanisms ensuring that the personalised security credentials, authentication devices and software are delivered to the legitimate payment service user; |
− | --- | --- |

− | (b) | mechanisms that allow the payment service provider to verify the authenticity of the authentication software delivered to the payment services user by means of the internet; |
− | --- | --- |

− | (c) | arrangements ensuring that, where the delivery of personalised security credentials is executed outside the premises of the payment service provider or through a remote channel:(i)no unauthorised party can obtain more than one feature of the personalised security credentials, the authenticat…
− | --- | --- |
− | (i) | no unauthorised party can obtain more than one feature of the personalised security credentials, the authentication devices or software when delivered through the same channel; |
− | (ii) | the delivered personalised security credentials, authentication devices or software require activation before usage; |

− | (d) | arrangements ensuring that, in cases where the personalised security credentials, the authentication devices or software have to be activated before their first use, the activation shall take place in a secure environment in accordance with the association procedures referred to in Article 2…
− | --- | --- |

− ### art_26

− Article 26

+ ### Article 27 — Destruction, deactivation and revocation
− ### art_27

− Article 27
+ (a) the secure destruction, deactivation or revocation of the personalised security credentials, authentication devices and software;
− | (a) | the secure destruction, deactivation or revocation of the personalised security credentials, authentication devices and software; |
− | --- | --- |
+ (b) where the payment service provider distributes reusable authentication devices and software, the secure re-use of a device or software is established, documented and implemented before making it available to another payment services user;
− | (b) | where the payment service provider distributes reusable authentication devices and software, the secure re-use of a device or software is established, documented and implemented before making it available to another payment services user; |
− | --- | --- |
+ (c) the deactivation or revocation of information related to personalised security credentials stored in the payment service provider's systems and databases and, where relevant, in public repositories.
− | (c) | the deactivation or revocation of information related to personalised security credentials stored in the payment service provider's systems and databases and, where relevant, in public repositories. |
− | --- | --- |
+ ## CHAPTER V — COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION / Section 1 — General requirements for communication
− ### art_28
+ ### Article 28 — Requirements for identification
− Article 28
+ **1.** Payment service providers shall ensure secure identification when communicating between the payer's device and the payee's acceptance devices for electronic payments, including but not limited to payment terminals.
− 1. Payment service providers shall ensure secure identification when communicating between the payer's device and the payee's acceptance devices for electronic payments, including but not limited to payment terminals.
+ **2.** Payment service providers shall ensure that the risks of misdirection of communication to unauthorised parties in mobile applications and other payment services users' interfaces offering electronic payment services are effectively mitigated.
− 2. Payment service providers shall ensure that the risks of misdirection of communication to unauthorised parties in mobile applications and other payment services users' interfaces offering electronic payment services are effectively mitigated.
+ ### Article 29 — Traceability
− ### art_29
+ **1.** Payment service providers shall have processes in place which ensure that all payment transactions and other interactions with the payment services user, with other payment service providers and with other entities, including merchants, in the context of the provision of the payment service a…
− Article 29
+ **2.** For the purpose of paragraph 1, payment service providers shall ensure that any communication session established with the payment services user, other payment service providers and other entities, including merchants, relies on each of the following:(a) a unique identifier of the session;(b)…
− 1. Payment service providers shall have processes in place which ensure that all payment transactions and other interactions with the payment services user, with other payment service providers and with other entities, including merchants, in the context of the provision of the payment service are t…
+ ## CHAPTER V — COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION / Section 2 — Specific requirements for the common and secure open standards of communication
− 2. For the purpose of paragraph 1, payment service providers shall ensure that any communication session established with the payment services user, other payment service providers and other entities, including merchants, relies on each of the following:
+ ### Article 30 — General obligations for access interfaces
− | (a) | a unique identifier of the session; |
− | --- | --- |
+ **1.** Account servicing payment service providers that offer to a payer a payment account that is accessible online shall have in place at least one interface which meets each of the following requirements:(a) account information service providers, payment initiation service providers and payment s…
− | (b) | security mechanisms for the detailed logging of the transaction, including transaction number, timestamps and all relevant transaction data; |
− | --- | --- |
+ **2.** For the purposes of authentication of the payment service user, the interface referred to in paragraph 1 shall allow account information service providers and payment initiation service providers to rely on all the authentication procedures provided by the account servicing payment service pr…
− | (c) | timestamps which shall be based on a unified time-reference system and which shall be synchronised according to an official time signal. |
− | --- | --- |
− ### art_30

− Article 30

− 1. Account servicing payment service providers that offer to a payer a payment account that is accessible online shall have in place at least one interface which meets each of the following requirements:

− | (a) | account information service providers, payment initiation service providers and payment service providers issuing card-based payment instruments are able to identify themselves towards the account servicing payment service provider; |
− | --- | --- |

− | (b) | account information service providers are able to communicate securely to request and receive information on one or more designated payment accounts and associated payment transactions; |
− | --- | --- |

− | (c) | payment initiation service providers are able to communicate securely to initiate a payment order from the payer's payment account and receive all information on the initiation of the payment transaction and all information accessible to the account servicing payment service providers regard…
− | --- | --- |

− 2. For the purposes of authentication of the payment service user, the interface referred to in paragraph 1 shall allow account information service providers and payment initiation service providers to rely on all the authentication procedures provided by the account servicing payment service provid…

+ (a) a payment initiation service provider or an account information service provider shall be able to instruct the account servicing payment service provider to start the authentication based on the consent of the payment service user;
− | (a) | a payment initiation service provider or an account information service provider shall be able to instruct the account servicing payment service provider to start the authentication based on the consent of the payment service user; |
− | --- | --- |
+ (b) communication sessions between the account servicing payment service provider, the account information service provider, the payment initiation service provider and any payment service user concerned shall be established and maintained throughout the authentication;
− | (b) | communication sessions between the account servicing payment service provider, the account information service provider, the payment initiation service provider and any payment service user concerned shall be established and maintained throughout the authentication; |
− | --- | --- |
+ (c) the integrity and confidentiality of the personalised security credentials and of authentication codes transmitted by or through the payment initiation service provider or the account information service provider shall be ensured.
− | (c) | the integrity and confidentiality of the personalised security credentials and of authentication codes transmitted by or through the payment initiation service provider or the account information service provider shall be ensured. |
− | --- | --- |
+ **3.** Account servicing payment service providers shall ensure that their interfaces follow standards of communication which are issued by international or European standardisation organisations.
− 3. Account servicing payment service providers shall ensure that their interfaces follow standards of communication which are issued by international or European standardisation organisations.
+ **4.** In addition to paragraph 3, account servicing payment service providers shall ensure that, except for emergency situations, any change to the technical specification of their interface is made available to authorised payment initiation service providers, account information service providers …
− 4. In addition to paragraph 3, account servicing payment service providers shall ensure that, except for emergency situations, any change to the technical specification of their interface is made available to authorised payment initiation service providers, account information service providers and …
+ 
+ **4a.** By way of derogation from paragraph 4, account servicing payment service providers shall make available to the payment service providers referred to in this Article the changes made to the technical specifications of their interfaces in order to comply with Article 10a not less than 2 months…
+ **5.** Account servicing payment service providers shall make available a testing facility, including support, for connection and functional testing to enable authorised payment initiation service providers, payment service providers issuing card-based payment instruments and account information ser…
− 5. Account servicing payment service providers shall make available a testing facility, including support, for connection and functional testing to enable authorised payment initiation service providers, payment service providers issuing card-based payment instruments and account information service…
+ **6.** Competent authorities shall ensure that account servicing payment service providers comply at all times with the obligations included in these standards in relation to the interface(s) that they put in place. In the event that an account servicing payment services provider fails to comply wit…
− 6. Competent authorities shall ensure that account servicing payment service providers comply at all times with the obligations included in these standards in relation to the interface(s) that they put in place. In the event that an account servicing payment services provider fails to comply with th…

− ### art_31
+ ### Article 31 — Access interface options
− Article 31
+ ### Article 32 — Obligations for a dedicated interface
− ### art_32
+ **1.** Subject to compliance with Article 30 and 31, account servicing payment service providers that have put in place a dedicated interface shall ensure that the dedicated interface offers at all times the same level of availability and performance, including support, as the interfaces made availa…
− Article 32
+ **2.** Account servicing payment service providers that have put in place a dedicated interface shall define transparent key performance indicators and service level targets, at least as stringent as those set for the interface used by their payment service users both in terms of availability and of…
− 1. Subject to compliance with Article 30 and 31, account servicing payment service providers that have put in place a dedicated interface shall ensure that the dedicated interface offers at all times the same level of availability and performance, including support, as the interfaces made available …
+ **3.** Account servicing payment service providers that have put in place a dedicated interface shall ensure that this interface does not create obstacles to the provision of payment initiation and account information services. Such obstacles, may include, among others, preventing the use by payment…
− 2. Account servicing payment service providers that have put in place a dedicated interface shall define transparent key performance indicators and service level targets, at least as stringent as those set for the interface used by their payment service users both in terms of availability and of dat…
+ **4.** For the purpose of paragraphs 1 and 2, account servicing payment service providers shall monitor the availability and performance of the dedicated interface. Account servicing payment service providers shall publish on their website quarterly statistics on the availability and performance of …
− 3. Account servicing payment service providers that have put in place a dedicated interface shall ensure that this interface does not create obstacles to the provision of payment initiation and account information services. Such obstacles, may include, among others, preventing the use by payment ser…
+ ### Article 33 — Contingency measures for a dedicated interface
− 4. For the purpose of paragraphs 1 and 2, account servicing payment service providers shall monitor the availability and performance of the dedicated interface. Account servicing payment service providers shall publish on their website quarterly statistics on the availability and performance of the …
+ **1.** Account servicing payment service providers shall include, in the design of the dedicated interface, a strategy and plans for contingency measures for the event that the interface does not perform in compliance with Article 32, that there is unplanned unavailability of the interface and that …
− ### art_33
+ **2.** Contingency measures shall include communication plans to inform payment service providers making use of the dedicated interface of measures to restore the system and a description of the immediately available alternative options payment service providers may have during this time.
− Article 33
+ **3.** Both the account servicing payment service provider and the payment service providers referred to in Article 30(1) shall report problems with dedicated interfaces as described in paragraph 1 to their respective competent national authorities without delay.
− 1. Account servicing payment service providers shall include, in the design of the dedicated interface, a strategy and plans for contingency measures for the event that the interface does not perform in compliance with Article 32, that there is unplanned unavailability of the interface and that ther…
+ **4.** As part of a contingency mechanism, payment service providers referred to in Article 30(1) shall be allowed to make use of the interfaces made available to the payment service users for the authentication and communication with their account servicing payment service provider, until the dedic…
− 2. Contingency measures shall include communication plans to inform payment service providers making use of the dedicated interface of measures to restore the system and a description of the immediately available alternative options payment service providers may have during this time.
+ **5.** For this purpose, account servicing payment service providers shall ensure that the payment service providers referred to in Article 30(1) can be identified and can rely on the authentication procedures provided by the account servicing payment service provider to the payment service user. Wh…
− 3. Both the account servicing payment service provider and the payment service providers referred to in Article 30(1) shall report problems with dedicated interfaces as described in paragraph 1 to their respective competent national authorities without delay.
+ **6.** Competent authorities, after consulting EBA to ensure a consistent application of the following conditions, shall exempt the account servicing payment service providers that have opted for a dedicated interface from the obligation to set up the contingency mechanism described under paragraph …
− 4. As part of a contingency mechanism, payment service providers referred to in Article 30(1) shall be allowed to make use of the interfaces made available to the payment service users for the authentication and communication with their account servicing payment service provider, until the dedicated…
+ **7.** Competent authorities shall revoke the exemption referred to in paragraph 6 where the conditions (a) and (d) are not met by the account servicing payment service providers for more than 2 consecutive calendar weeks. Competent authorities shall inform EBA of this revocation and shall ensure th…
− 5. For this purpose, account servicing payment service providers shall ensure that the payment service providers referred to in Article 30(1) can be identified and can rely on the authentication procedures provided by the account servicing payment service provider to the payment service user. Where …
+ ### Article 34 — Certificates
− | (a) | take the necessary measures to ensure that they do not access, store or process data for purposes other than for the provision of the service as requested by the payment service user; |
− | --- | --- |
+ **1.** For the purpose of identification, as referred to in Article 30(1)(a), payment service providers shall rely on qualified certificates for electronic seals as referred to in Article 3(30) of Regulation (EU) No 910/2014 or for website authentication as referred to in Article 3(39) of that Regul…
− | (b) | continue to comply with the obligations following from Article 66(3) and Article 67(2) of Directive (EU) 2015/2366 respectively; |
− | --- | --- |
+ **2.** For the purpose of this Regulation, the registration number as referred to in the official records in accordance with Annex III (c) or Annex IV (c) to Regulation (EU) No 910/2014 shall be the authorisation number of the payment service provider issuing card-based payment instruments, the acco…
− | (c) | log the data that are accessed through the interface operated by the account servicing payment service provider for its payment service users, and provide, upon request and without undue delay, the log files to their competent national authority; |
− | --- | --- |
+ **3.** For the purposes of this Regulation, qualified certificates for electronic seals or for website authentication referred to in paragraph 1 shall include, in a language customary in the sphere of international finance, additional specific attributes in relation to each of the following:(a) the …
− | (d) | duly justify to their competent national authority, upon request and without undue delay, the use of the interface made available to the payment service users for directly accessing its payment account online; |
− | --- | --- |
+ **4.** The attributes referred to in paragraph 3 shall not affect the interoperability and recognition of qualified certificates for electronic seals or website authentication.
− | (e) | inform the account servicing payment service provider accordingly. |
− | --- | --- |
+ ### Article 35 — Security of communication session
− 6. Competent authorities, after consulting EBA to ensure a consistent application of the following conditions, shall exempt the account servicing payment service providers that have opted for a dedicated interface from the obligation to set up the contingency mechanism described under paragraph 4 wh…
+ **1.** Account servicing payment service providers, payment service providers issuing card-based payment instruments, account information service providers and payment initiation service providers shall ensure that, when exchanging data by means of the internet, secure encryption is applied between …
− | (a) | it complies with all the obligations for dedicated interfaces as set out in Article 32; |
− | --- | --- |
+ **2.** Payment service providers issuing card-based payment instruments, account information service providers and payment initiation service providers shall keep the access sessions offered by account servicing payment service providers as short as possible and they shall actively terminate any suc…
− | (b) | it has been designed and tested in accordance with Article 30(5) to the satisfaction of the payment service providers referred to therein; |
… diff truncated at 500 changed lines …
tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)