Section 69(3)
A payment initiation service provider must— not hold a payer's funds in connection with the provision of the payment initiation service at any time; ensure that a payer's personalised security credentials are— not accessible to other parties, with the exception of the issuer of the credentials; and transmitted through safe and efficient channels; ensure that any other information about a payer is not provided to any person except a payee, and is provided to the payee only with the payer's explicit consent; each time it initiates a payment order, identify itself to the account servicing payment service provider and communicate with the account servicing payment service provider, the payer and the payee in a secure way in accordance with the technical standards made under regulation 106A; not store sensitive payment data of the payment service user; not request any information from a payer except information required to provide the payment initiation service; not use, access or store any information for any purpose except for the provision of a payment initiation service explicitly requested by a payer; not change the amount, the payee or any other feature of a transaction notified to it by the payer.
← 2 · All articles · 70 →
Source: legislation.gov.uk · retrieved 2026-09-04