(1) The payment initiation service provider may not change the amount, the payee or any other feature of the payment transaction. It may not at any time hold funds of the payer in connection with the provision of the payment initiation service.
(2) A payment initiation service provider is required to identify itself to the payer's account servicing payment service provider each time it initiates a payment. It must ensure that the payment service user's personalised security credentials are not accessible to any party other than the user and the party that issued the personalised security credentials.
(3) The payment initiation service provider must communicate with the account servicing payment service provider, the payer and the payee in a secure manner. Insofar as it is necessary to transmit the payer's personalised security credentials, this may take place only through safe and efficient channels.
(4) The payment initiation service provider may request from the payer only the data required to provide the payment initiation service, and may not store sensitive payment data of the payer. It may store, use or access data only for the purposes of the payment initiation service explicitly requested by the payer. It may disclose to the payee any other information it obtains about the payer in providing payment initiation services only with the payer's explicit consent.
(5) As soon as the payment order has been initiated, the payment initiation service provider must make the payment transaction's reference particulars accessible to the payer's account servicing payment service provider.
(6) Further details are governed by the delegated act under Article 98 of Directive (EU) 2015/2366.
Home› Payment Services› ZAG-EN
Part 10 · Common Provisions for All Payment Service Providers › Chapter 2 · Access of Payment Initiation Service Providers and Account Information Service Providers to Payment Accounts › Section 49
Duties of the Payment Initiation Service Provider
←→ also move between sections