Article 66
Rules on access to payment account in the case of payment initiation services
The payment initiation service provider shall:
not hold at any time the payer’s funds in connection with the provision of the payment initiation service;
ensure that the personalised security credentials of the payment service user are not, with the exception of the user and the issuer of the personalised security credentials, accessible to other parties and that they are transmitted by the payment initiation service provider through safe and efficient channels;
ensure that any other information about the payment service user, obtained when providing payment initiation services, is only provided to the payee and only with the payment service user’s explicit consent;
every time a payment is initiated, identify itself towards the account servicing payment service provider of the payer and communicate with the account servicing payment service provider, the payer and the payee in a secure way, in accordance with point (d) of Article 98(1);
not store sensitive payment data of the payment service user;
not request from the payment service user any data other than those necessary to provide the payment initiation service;
not use, access or store any data for purposes other than for the provision of the payment initiation service as explicitly requested by the payer;
not modify the amount, the payee or any other feature of the transaction.
The account servicing payment service provider shall:
communicate securely with payment initiation service providers in accordance with point (d) of Article 98(1);
immediately after receipt of the payment order from a payment initiation service provider, provide or make available all information on the initiation of the payment transaction and all information accessible to the account servicing payment service provider regarding the execution of the payment transaction to the payment initiation service provider;
treat payment orders transmitted through the services of a payment initiation service provider without any discrimination other than for objective reasons, in particular in terms of timing, priority or charges vis-à-vis payment orders transmitted directly by the payer.