Article 35
Security of communication session
Account information service providers, payment initiation service providers and payment service providers issuing card-based payment instruments with the account servicing payment service provider shall contain unambiguous references to each of the following items:
the payment service user or users and the corresponding communication session in order to distinguish several requests from the same payment service user or users;
for payment initiation services, the uniquely identified payment transaction initiated;
for confirmation on the availability of funds, the uniquely identified request related to the amount necessary for the execution of the card-based payment transaction.
In case of loss of confidentiality of personalised security credentials under their sphere of competence, those providers shall inform without undue delay the payment services user associated with them and the issuer of the personalised security credentials.