[eu]cite

Home› Payment Services› ZAG-EN

Part 10 · Common Provisions for All Payment Service Providers  ›  Chapter 2 · Access of Payment Initiation Service Providers and Account Information Service Providers to Payment Accounts › Section 51

Duties of the Account Information Service Provider

(1) The account information service provider may provide its services only with the payment service user's explicit consent. It may access only information from payment accounts designated by the payment service user, and payment transactions connected with those accounts. It may not request sensitive payment data connected with the payment accounts. It may store, use or access data only for the purposes of the account information service explicitly requested by the payment service user.
(2) An account information service provider is required to identify itself to the payment service user's account servicing payment service provider each time it communicates with it. It must ensure that the payment service user's personalised security credentials are not accessible to any party other than the user and the party that issued the personalised security credentials.
(3) The account information service provider must communicate with the account servicing payment service provider and the payment service user in a secure manner. Insofar as the transmission of personalised security credentials is necessary, this may take place only through safe and efficient channels.
(4) Further details are governed by the delegated act under Article 98 of Directive (EU) 2015/2366.

←→ also move between sections