Article 10
Access to the payment account information directly with the account servicing payment service provider
Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where a payment service user is accessing its payment account online directly, provided that access is limited to one of the following items online without disclosure of sensitive payment data:
the balance of one or more designated payment accounts;
the payment transactions executed in the last 90 days through one or more designated payment accounts.
By way of derogation from paragraph 1, payment service providers shall not be exempted from the application of strong customer authentication where one of the following conditions is met:
the payment service user is accessing online the information specified in paragraph 1 for the first time;
more than 180 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1 and strong customer authentication was applied.