Commission Delegated Regulation (EU) 2022/2360 of 3 August 2022 amending the regulatory te…
as it stood on 2022-08-03, permalink: /eu-eurlex/32022r2360/2022-08-03
Article 1
Delegated Regulation (EU) 2018/389 is amended as follows:
| (1) | Article 10 is replaced by the following:‘Article 10Access to the payment account information directly with the account servicing payment service provider1. Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where a payment service user is accessing its payment account online directly, provided that access is limited to one of the following items online without disclosure of sensitive payment data:(a)the balance of one or more designated payment accounts;(b)the payment transactions executed in the last 90 days through one or more designated payment accounts.2. By way of derogation from paragraph 1, payment service providers shall not be exempted from the application of strong customer authentication where one of the following conditions is met:(a)the payment service user is accessing online the information specified in paragraph 1 for the first time;(b)more than 180 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1 and strong customer authentication was applied.’; |
|---|---|
| (a) | the balance of one or more designated payment accounts; |
| (b) | the payment transactions executed in the last 90 days through one or more designated payment accounts. |
| (a) | the payment service user is accessing online the information specified in paragraph 1 for the first time; |
| (b) | more than 180 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1 and strong customer authentication was applied.’ |
| (2) | the following Article 10a is inserted:‘Article 10aAccess to the payment account information through an account information service provider1. Payment service providers shall not apply strong customer authentication where a payment service user is accessing its payment account online through an account information service provider, provided that access is limited to one of the following items online without disclosure of sensitive payment data:(a)the balance of one or more designated payment accounts;(b)the payment transactions executed in the last 90 days through one or more designated payment accounts.2. By way of derogation from paragraph 1, payment service providers shall apply strong customer authentication where one of the following conditions is met:(a)the payment service user is accessing online the information specified in paragraph 1 for the first time through the account information service provider;(b)more than 180 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1 through the account information service provider and strong customer authentication was applied.3. By way of derogation from paragraph 1, payment service providers shall be allowed to apply strong customer authentication where a payment service user is accessing its payment account online through an account information service provider and the payment service provider has objectively justified and duly evidenced reasons relating to unauthorised or fraudulent access to the payment account. In such a case, the payment service provider shall document and duly justify to its competent national authority, upon request, the reasons for applying strong customer authentication.4. Account servicing payment service providers that offer a dedicated interface as referred to in Article 31 shall not be required to implement the exemption laid down in paragraph 1 of this Article for the purpose of the contingency mechanism referred to in Article 33(4), where they do not apply the exemption laid down in Article 10 in the direct interface used for authentication and communication with their payment service users.’; |
|---|---|
| (a) | the balance of one or more designated payment accounts; |
| (b) | the payment transactions executed in the last 90 days through one or more designated payment accounts. |
| (a) | the payment service user is accessing online the information specified in paragraph 1 for the first time through the account information service provider; |
| (b) | more than 180 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1 through the account information service provider and strong customer authentication was applied. |
| (3) | in Article 30, the following paragraph 4a is inserted:‘4a. By way of derogation from paragraph 4, account servicing payment service providers shall make available to the payment service providers referred to in this Article the changes made to the technical specifications of their interfaces in order to comply with Article 10a not less than 2 months before such changes are implemented.’. |
|---|
Article 2
Payment service providers that applied the exemption in Article 10 of Delegated Regulation (EU) 2018/389 before 25 July 2023 shall be allowed to continue to apply that exemption for access requests received through an account information service provider up to the expiry of the period covered by that exemption.
By way of derogation from paragraph 1, whenever a new strong customer authentication is applied for access request through an account information service provider before the expiry of the period covered by the exemption referred to in paragraph 1, Article 10a as introduced by this Regulation applies.
Article 3
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
It shall apply from 25 July 2023.
Provenance and validity dates, identifier, hash
| as of | 2022-08-03 → this version applied |
| valid | 2022-08-03 → open publisher-asserted |
| type | REG_DEL Commission Delegated Regulation (EU) 2022/2360 of 3 August 2022 amending the regulatory technical standards laid down in Delegated Regulation (EU) 2018/389 as regards the 90-day exemption for account access (Text with EEA relevance) |
| language | en |
| published | 2022-08-03 |
| lex_id | eu-eurlex:32022r2360:2022-08-03 |
| record sha256 | 508ddc2b00b2df6b1cbad98919f352ab9c404da6db536cd23a8771dbe6bd27f2 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2022-08-03) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |