(1) The payment service provider issuing a payment instrument is obliged
1. to ensure, regardless of the obligations incumbent on the payment service user under section 675l (1), that the personalised security features of the payment instrument are accessible only to the person authorised to use them,
2. to refrain from unsolicited dispatch of payment instruments to the payment service user unless a payment instrument already delivered to the payment service user must be replaced,
3. to ensure that the payment service user is able by suitable means at any time to make a notification as provided for under section 675l (1) sentence 2 or to demand that the payment instrument be unblocked pursuant to section 675k (2) sentence 5,
4. to enable the payment service user to issue a notification pursuant to section 675l (1) sentence 2 free of charge, and
5. to prevent any use of the payment instrument as soon as a notification has been made in accordance with section 675l (1) sentence 2.
If the payment service user has reported the loss, theft, abusive use or other unauthorised use of a payment instrument, then, on demand, their payment service provider will provide them with the means, by no later than 18 months following said report, allowing them to prove that a report was filed.
(2) The risk of the dispatch of a payment instrument and of the dispatch of personalised security features of the payment instrument to the payment service user is incumbent on the payment service provider.
(3) Where a payment service provider issuing card-based payment instruments requests confirmation from the payer’s account servicing payment service provider that an amount required for the execution of a card-based payment transaction is available on the payment account, the payer may demand of the account servicing payment service provider that the latter forward to them the identification data of this payment service provider and the answer given.