Article 66 › 3
The payment initiation service provider shall: (a) not hold at any time the payer’s funds in connection with the provision of the payment initiation service; (b) ensure that the personalised security credentials of the payment service user are not, with the exception of the user and the issuer of the personalised security credentials, accessible to other parties and that they are transmitted by the payment initiation service provider through safe and efficient channels; (c) ensure that any other information about the payment service user, obtained when providing payment initiation services, is only provided to the payee and only with the payment service user’s explicit consent; (d) every time a payment is initiated, identify itself towards the account servicing payment service provider of the payer and communicate with the account servicing payment service provider, the payer and the payee in a secure way, in accordance with point (d) of Article 98(1); (e) not store sensitive payment data of the payment service user; (f) not request from the payment service user any data other than those necessary to provide the payment initiation service; (g) not use, access or store any data for purposes other than for the provision of the payment initiation service as explicitly requested by the payer; (h) not modify the amount, the payee or any other feature of the transaction.
← 2 · All articles · 4 →
Source: EUR-Lex CELLAR · retrieved 2026-08-27