Skip to main content

AI Summary of Article 67 Rules on access to and use of payment account information in the case of account information services

This document outlines the rights and responsibilities applicable to account information services, emphasising the protection of payment service users' data. Member States are required to ensure that users can access account information services, provided the account is online accessible.

Account information service providers must obtain explicit consent, safeguard users' security credentials, and communicate securely with account servicing providers. Additionally, they are restricted from using sensitive payment data for purposes beyond the requested service. The framework promotes non-discriminatory practices in data requests and does not necessitate a contractual relationship between service providers.

Version status: Entered into force | Document consolidation status: Updated to reflect all known changes
Version date: 12 January 2016 - onwards
Version 2 of 2

Article 67 Rules on access to and use of payment account information in the case of account information services

1. Member States shall ensure that a payment service user has the right to make use of services enabling access to account information as referred to in point (8) of Annex I. That right shall not apply where the payment account is not accessible online.

2. The account information service provider shall:

(a) provide services only where based on the payment service user's explicit consent;

(b) ensure that the personalised security credentials of the payment service user are not, with the exception of the user and the issuer of the personalised security credentials, accessible to other parties and that when they are transmitted by the account information service provider, this is done through safe and efficient channels;

(c) for each communication session, identify itself towards the account servicing payment service provider(s) of the payment service user and securely communicate with the account servicing payment service provider(s) and the payment service user, in accordance with point (d) of Article 98(1);