<Legislation xmlns="http://www.legislation.gov.uk/namespaces/legislation" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" DocumentURI="http://www.legislation.gov.uk/eur/2018/389" IdURI="http://www.legislation.gov.uk/id/eur/2018/389" NumberOfProvisions="38" xsi:schemaLocation="http://www.legislation.gov.uk/namespaces/legislation http://www.legislation.gov.uk/schema/legislation.xsd" SchemaVersion="2.0" RestrictExtent="E+W+S+N.I." RestrictStartDate="2023-07-11"><ukm:Metadata xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:dct="http://purl.org/dc/terms/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:ukm="http://www.legislation.gov.uk/namespaces/metadata">
					<dc:identifier>http://www.legislation.gov.uk/eur/2018/389/body</dc:identifier><dc:title>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)</dc:title><dct:alternative>Commission Delegated Regulation (EU) 2018/389</dct:alternative><dc:description>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)</dc:description><dc:publisher>King's Printer of Acts of Parliament</dc:publisher><dc:source>https://webarchive.nationalarchives.gov.uk/eu-exit/https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32018R0389</dc:source><dc:type>text</dc:type><dc:format>text/xml</dc:format><dc:language>en</dc:language><dc:modified>2024-07-04</dc:modified><dc:contributor>Expert Participation</dc:contributor><dct:valid>2023-07-11</dct:valid>
					
					<atom:link rel="self" href="http://www.legislation.gov.uk/eur/2018/389/body/data.xml" type="application/xml"/><atom:link rel="http://www.legislation.gov.uk/def/navigation/resources" href="http://www.legislation.gov.uk/eur/2018/389/resources" title="More Resources"/>
					
					
					
					<atom:link rel="http://www.legislation.gov.uk/def/navigation/act" href="http://www.legislation.gov.uk/eur/2018/389" title="whole act"/><atom:link rel="http://www.legislation.gov.uk/def/navigation/introduction" href="http://www.legislation.gov.uk/eur/2018/389/introduction" title="introduction"/><atom:link rel="http://www.legislation.gov.uk/def/navigation/signature" href="http://www.legislation.gov.uk/eur/2018/389/signature" title="signature"/>
					<atom:link rel="http://www.legislation.gov.uk/def/navigation/body" href="http://www.legislation.gov.uk/eur/2018/389/body" title="body"/>
					<atom:link rel="http://www.legislation.gov.uk/def/navigation/annexes" href="http://www.legislation.gov.uk/eur/2018/389/annexes" title="annexes"/>
					
					<atom:link rel="http://www.legislation.gov.uk/def/date/euexitday" href="http://www.legislation.gov.uk/eur/2018/389/body/2020-01-31" title="2020-01-31"/><atom:link rel="http://www.legislation.gov.uk/def/date/euexitTransitionEnd" href="http://www.legislation.gov.uk/eur/2018/389/body/2020-12-31" title="2020-12-31"/>					
					<atom:link rel="http://www.legislation.gov.uk/def/powerToAmend" href="http://www.legislation.gov.uk/id/uksi/2018/1115" title="XXXX may be subject to amendment by EU Exit Instruments made by the Financial Conduct Authority under powers set out in The Financial Regulators' Powers (Technical Standards etc.) (Amendment etc.) (EU Exit) Regulations 2018 (S.I. 2018/1115), regs. 2, 3, Sch. Pt. 1. These amendments are not currently available on legislation.gov.uk. Details of relevant amending instruments can be found on their website/s."/>
					<atom:link rel="http://www.legislation.gov.uk/def/legislation/EffectsApplied" href="https://www.legislation.gov.uk/changes/applied/affected/eur/2018/389" title="Amended by UK"/>
					
					<atom:link rel="alternate" type="application/rdf+xml" href="http://www.legislation.gov.uk/eur/2018/389/body/data.rdf" title="RDF/XML"/><atom:link rel="alternate" type="application/akn+xml" href="http://www.legislation.gov.uk/eur/2018/389/body/data.akn" title="AKN"/><atom:link rel="alternate" type="application/xhtml+xml" href="http://www.legislation.gov.uk/eur/2018/389/body/data.xht" title="HTML snippet"/><atom:link rel="alternate" type="text/html" href="http://www.legislation.gov.uk/eur/2018/389/body/data.htm" title="Website (XHTML) Default View"/><atom:link rel="alternate" type="text/csv" href="http://www.legislation.gov.uk/eur/2018/389/body/data.csv" title="CSV"/><atom:link rel="alternate" type="application/pdf" href="http://www.legislation.gov.uk/eur/2018/389/body/data.pdf" title="PDF"/>
					<atom:link rel="alternate" type="application/akn+xhtml" href="http://www.legislation.gov.uk/eur/2018/389/body/data.html" title="HTML5 snippet"/>

					
					<atom:link rel="http://purl.org/dc/terms/tableOfContents" hreflang="en" href="http://www.legislation.gov.uk/eur/2018/389/contents" title="Table of Contents"/>
					
					<atom:link rel="http://purl.org/dc/terms/hasVersion" href="http://www.legislation.gov.uk/eur/2018/389/body/adopted" title="adopted"/><atom:link rel="http://purl.org/dc/terms/hasVersion" href="http://www.legislation.gov.uk/eur/2018/389/body/2017-11-27" title="2017-11-27"/>
					
					<atom:link rel="up" href="http://www.legislation.gov.uk/eur/2018/389" title="Entire legislation"/><atom:link rel="prev" href="http://www.legislation.gov.uk/eur/2018/389/introduction" title="Introduction; Introduction"/><atom:link rel="prevInForce" href="http://www.legislation.gov.uk/eur/2018/389/introduction" title="Introduction; Introduction"/><atom:link rel="next" href="http://www.legislation.gov.uk/eur/2018/389/annex" title="Annex; Annex"/><atom:link rel="nextInForce" href="http://www.legislation.gov.uk/eur/2018/389/annex" title="Annex; Annex"/>
					<ukm:EUMetadata><ukm:DocumentClassification>
            <ukm:DocumentCategory Value="euretained"/>
            <ukm:DocumentMainType Value="EuropeanUnionRegulation"/>
            <ukm:DocumentStatus Value="revised"/>
         </ukm:DocumentClassification><ukm:Year Value="2018"/><ukm:Number Value="389"/><ukm:EURLexIdentifiers>
            <ukm:Cellar Value="28c2f705-268d-11e8-ac73-01aa75ed71a1"/>
            <ukm:ELI Value="reg_del:2018:389:oj"/>
            <ukm:OfficialJournal Value="JOL_2018_069_R_0006"/>
            <ukm:CELEX Value="32018R0389"/>
         </ukm:EURLexIdentifiers><ukm:EnactmentDate Date="2017-11-27"/><ukm:EURLexModified Date="2020-05-13T05:13:10Z"/><ukm:EURLexExtracted Date="2020-05-13T09:54:05Z"/><ukm:XMLGenerated Date="2020-12-12T17:49:56Z"/><ukm:XMLImported Date="2020-12-12T23:20:43Z"/><ukm:Treaty Title="Treaty on the Functioning of the European Union (consolidated version 2012)" Code="TFEU_2012"/><ukm:CreatedBy Label="European Commission" URI="http://publications.europa.eu/resource/authority/corporate-body/COM"/><ukm:CreatedBy Label="Directorate-General for Financial Stability, Financial Services and Capital Markets Union" URI="http://publications.europa.eu/resource/authority/corporate-body/FISMA"/><ukm:Subject Scheme="EuroVoc" Label="financial legislation" URI="http://eurovoc.europa.eu/560"/><ukm:Subject Scheme="EuroVoc" Label="financial services" URI="http://eurovoc.europa.eu/8469"/><ukm:Subject Scheme="EuroVoc" Label="electronic money" URI="http://eurovoc.europa.eu/1971"/><ukm:Subject Scheme="EuroVoc" Label="electronic banking" URI="http://eurovoc.europa.eu/3248"/><ukm:Subject Scheme="DirectoryCode" Label="Banks" URI="http://publications.europa.eu/resource/authority/fd_555/06202020"/><ukm:Subject Scheme="DirectoryCode" Label="Sectoral application" URI="http://publications.europa.eu/resource/authority/fd_555/0620"/><ukm:Subject Scheme="DirectoryCode" Label="Right of establishment and freedom to provide services" URI="http://publications.europa.eu/resource/authority/fd_555/06"/><ukm:Subject Scheme="DirectoryCode" Label="Service activities" URI="http://publications.europa.eu/resource/authority/fd_555/062020"/><ukm:Subject Scheme="EuroVoc" Label="safety standard" URI="http://eurovoc.europa.eu/5234"/><ukm:Subject Scheme="DirectoryCode" Label="Free movement of capital" URI="http://publications.europa.eu/resource/authority/fd_555/1040"/><ukm:Subject Scheme="DirectoryCode" Label="Economic and monetary policy and free movement of capital" URI="http://publications.europa.eu/resource/authority/fd_555/10"/><ukm:Subject Scheme="EuroVoc" Label="information security" URI="http://eurovoc.europa.eu/c_04ae3ba8"/><ukm:Subject Scheme="EuroVoc" Label="payment system" URI="http://eurovoc.europa.eu/c_e749c083"/><ukm:Subject Scheme="EuroVoc" Label="provision of services" URI="http://eurovoc.europa.eu/2602"/><ukm:Subject Scheme="EuroVoc" Label="consumer protection" URI="http://eurovoc.europa.eu/2836"/><ukm:Subject Scheme="EuroVoc" Label="technical standard" URI="http://eurovoc.europa.eu/5235"/><ukm:Subject Scheme="SubjectMatter" Label="Free movement of capital" URI="http://publications.europa.eu/resource/authority/fd_070/LCC"/><ukm:Subject Scheme="SubjectMatter" Label="Freedom of establishment" URI="http://publications.europa.eu/resource/authority/fd_070/LES"/><ukm:Subject Scheme="SubjectMatter" Label="Internal market - Principles" URI="http://publications.europa.eu/resource/authority/fd_070/MARI"/><ukm:EURLexMetadata>
            <WORK xmlns="">
               <URI>
                  <VALUE>http://publications.europa.eu/resource/cellar/28c2f705-268d-11e8-ac73-01aa75ed71a1</VALUE>
                  <IDENTIFIER>28c2f705-268d-11e8-ac73-01aa75ed71a1</IDENTIFIER>
                  <TYPE>cellar</TYPE>
               </URI>
               <SAMEAS>
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/eli/reg_del/2018/389/oj</VALUE>
                     <IDENTIFIER>reg_del:2018:389:oj</IDENTIFIER>
                     <TYPE>eli</TYPE>
                  </URI>
               </SAMEAS>
               <SAMEAS>
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/oj/JOL_2018_069_R_0006</VALUE>
                     <IDENTIFIER>JOL_2018_069_R_0006</IDENTIFIER>
                     <TYPE>oj</TYPE>
                  </URI>
               </SAMEAS>
               <SAMEAS>
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/celex/32018R0389</VALUE>
                     <IDENTIFIER>32018R0389</IDENTIFIER>
                     <TYPE>celex</TYPE>
                  </URI>
               </SAMEAS>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/560</VALUE>
                        <IDENTIFIER>560</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>560</IDENTIFIER>
                     <PREFLABEL>financial legislation</PREFLABEL>
                     <ALTLABEL>transaction regulations</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/1630</VALUE>
                        <IDENTIFIER>1630</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>1630</IDENTIFIER>
                     <PREFLABEL>free movement of capital</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100148</VALUE>
                        <IDENTIFIER>100148</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>24</IDENTIFIER>
                     <PREFLABEL>24 FINANCE</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100201</VALUE>
                        <IDENTIFIER>100201</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2421</IDENTIFIER>
                     <PREFLABEL>2421 free movement of capital</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <YEAR type="data">
                  <VALUE>2018</VALUE>
               </YEAR>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/fd_555/06202020</VALUE>
                     <IDENTIFIER>06202020</IDENTIFIER>
                     <TYPE>fd_555</TYPE>
                  </URI>
                  <OP-CODE>06202020</OP-CODE>
                  <IDENTIFIER>06202020</IDENTIFIER>
                  <PREFLABEL>Banks</PREFLABEL>
               </IS_ABOUT>
               <CREATED_BY type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/corporate-body/FISMA</VALUE>
                     <IDENTIFIER>FISMA</IDENTIFIER>
                     <TYPE>corporate-body</TYPE>
                  </URI>
                  <OP-CODE>FISMA</OP-CODE>
                  <IDENTIFIER>FISMA</IDENTIFIER>
                  <PREFLABEL>Directorate-General for Financial Stability, Financial Services and Capital Markets Union</PREFLABEL>
                  <ALTLABEL>FISMA</ALTLABEL>
                  <ALTLABEL>DG Financial Stability, Financial Services and Capital Markets Union</ALTLABEL>
               </CREATED_BY>
               <RESOURCE_LEGAL_YEAR type="data">
                  <VALUE>2018</VALUE>
               </RESOURCE_LEGAL_YEAR>
               <DATE_DOCUMENT type="date">
                  <VALUE>2017-11-27</VALUE>
                  <YEAR>2017</YEAR>
                  <MONTH>11</MONTH>
                  <DAY>27</DAY>
               </DATE_DOCUMENT>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/8469</VALUE>
                        <IDENTIFIER>8469</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>8469</IDENTIFIER>
                     <PREFLABEL>financial services</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/8469</VALUE>
                        <IDENTIFIER>8469</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>8469</IDENTIFIER>
                     <PREFLABEL>financial services</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100148</VALUE>
                        <IDENTIFIER>100148</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>24</IDENTIFIER>
                     <PREFLABEL>24 FINANCE</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100200</VALUE>
                        <IDENTIFIER>100200</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2416</IDENTIFIER>
                     <PREFLABEL>2416 financial institutions and credit</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <WORK_HAS_RESOURCE-TYPE type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/resource-type/REG_DEL</VALUE>
                     <IDENTIFIER>REG_DEL</IDENTIFIER>
                     <TYPE>resource-type</TYPE>
                  </URI>
                  <OP-CODE>REG_DEL</OP-CODE>
                  <IDENTIFIER>REG_DEL</IDENTIFIER>
                  <PREFLABEL>Delegated regulation</PREFLABEL>
               </WORK_HAS_RESOURCE-TYPE>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/1971</VALUE>
                        <IDENTIFIER>1971</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>1971</IDENTIFIER>
                     <PREFLABEL>electronic money</PREFLABEL>
                     <ALTLABEL>defered debit card</ALTLABEL>
                     <ALTLABEL>cash card</ALTLABEL>
                     <ALTLABEL>multiservices card</ALTLABEL>
                     <ALTLABEL>credit card</ALTLABEL>
                     <ALTLABEL>delayed debit card</ALTLABEL>
                     <ALTLABEL>charge card</ALTLABEL>
                     <ALTLABEL>debit card</ALTLABEL>
                     <ALTLABEL>electronic purse</ALTLABEL>
                     <ALTLABEL>auto-bank card</ALTLABEL>
                     <ALTLABEL>e-money</ALTLABEL>
                     <ALTLABEL>payment card</ALTLABEL>
                     <ALTLABEL>e-money payment</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/1809</VALUE>
                        <IDENTIFIER>1809</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>1809</IDENTIFIER>
                     <PREFLABEL>money market</PREFLABEL>
                     <ALTLABEL>international money market</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100148</VALUE>
                        <IDENTIFIER>100148</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>24</IDENTIFIER>
                     <PREFLABEL>24 FINANCE</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100199</VALUE>
                        <IDENTIFIER>100199</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2411</IDENTIFIER>
                     <PREFLABEL>2411 monetary economics</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/3248</VALUE>
                        <IDENTIFIER>3248</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>3248</IDENTIFIER>
                     <PREFLABEL>electronic banking</PREFLABEL>
                     <ALTLABEL>home and office banking service</ALTLABEL>
                     <ALTLABEL>ATM</ALTLABEL>
                     <ALTLABEL>cash dispenser</ALTLABEL>
                     <ALTLABEL>online banking</ALTLABEL>
                     <ALTLABEL>self-service bank</ALTLABEL>
                     <ALTLABEL>internet banking</ALTLABEL>
                     <ALTLABEL>home banking</ALTLABEL>
                     <ALTLABEL>automatic teller machine</ALTLABEL>
                     <ALTLABEL>auto-bank</ALTLABEL>
                     <ALTLABEL>HOBS</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/2149</VALUE>
                        <IDENTIFIER>2149</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2149</IDENTIFIER>
                     <PREFLABEL>banking</PREFLABEL>
                     <ALTLABEL>banking operation</ALTLABEL>
                     <ALTLABEL>banking services</ALTLABEL>
                     <ALTLABEL>banking transaction</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100148</VALUE>
                        <IDENTIFIER>100148</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>24</IDENTIFIER>
                     <PREFLABEL>24 FINANCE</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100200</VALUE>
                        <IDENTIFIER>100200</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2416</IDENTIFIER>
                     <PREFLABEL>2416 financial institutions and credit</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <WORK_CREATED_BY_AGENT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/corporate-body/COM</VALUE>
                     <IDENTIFIER>COM</IDENTIFIER>
                     <TYPE>corporate-body</TYPE>
                  </URI>
                  <OP-CODE>COM</OP-CODE>
                  <IDENTIFIER>COM</IDENTIFIER>
                  <PREFLABEL>European Commission</PREFLABEL>
                  <ALTLABEL>EC</ALTLABEL>
                  <ALTLABEL>Commission of the European Communities</ALTLABEL>
                  <ALTLABEL>European Commission</ALTLABEL>
                  <ALTLABEL>Commission</ALTLABEL>
               </WORK_CREATED_BY_AGENT>
               <DATE type="date">
                  <VALUE>2019-03-14</VALUE>
                  <YEAR>2019</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>14</DAY>
               </DATE>
               <ID_CELEX type="data">
                  <VALUE>32018R0389</VALUE>
               </ID_CELEX>
               <DATE type="date">
                  <VALUE>9999-12-31</VALUE>
                  <YEAR>9999</YEAR>
                  <MONTH>12</MONTH>
                  <DAY>31</DAY>
               </DATE>
               <WORK_CITES_WORK type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/23b61856-2e82-11e4-8c3c-01aa75ed71a1</VALUE>
                     <IDENTIFIER>23b61856-2e82-11e4-8c3c-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2014_257_R_0002</VALUE>
                        <IDENTIFIER>JOL_2014_257_R_0002</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/eli/reg/2014/910/oj</VALUE>
                        <IDENTIFIER>reg:2014:910:oj</IDENTIFIER>
                        <TYPE>eli</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/32014R0910</VALUE>
                        <IDENTIFIER>32014R0910</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/planjo/20140723-001</VALUE>
                        <IDENTIFIER>20140723-001</IDENTIFIER>
                        <TYPE>planjo</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/immc/planjo%3A20140723-001</VALUE>
                        <IDENTIFIER>planjo:20140723-001</IDENTIFIER>
                        <TYPE>immc</TYPE>
                     </URI>
                  </SAMEAS>
               </WORK_CITES_WORK>
               <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE type="concept_level">
                  <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_4 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_555/06202020</VALUE>
                        <IDENTIFIER>06202020</IDENTIFIER>
                        <TYPE>fd_555</TYPE>
                     </URI>
                     <OP-CODE>06202020</OP-CODE>
                     <IDENTIFIER>06202020</IDENTIFIER>
                     <PREFLABEL>Banks</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_4>
                  <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_2 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_555/0620</VALUE>
                        <IDENTIFIER>0620</IDENTIFIER>
                        <TYPE>fd_555</TYPE>
                     </URI>
                     <OP-CODE>0620</OP-CODE>
                     <IDENTIFIER>0620</IDENTIFIER>
                     <PREFLABEL>Sectoral application</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_2>
                  <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_1 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_555/06</VALUE>
                        <IDENTIFIER>06</IDENTIFIER>
                        <TYPE>fd_555</TYPE>
                     </URI>
                     <OP-CODE>06</OP-CODE>
                     <IDENTIFIER>06</IDENTIFIER>
                     <PREFLABEL>Right of establishment and freedom to provide services</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_1>
                  <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_3 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_555/062020</VALUE>
                        <IDENTIFIER>062020</IDENTIFIER>
                        <TYPE>fd_555</TYPE>
                     </URI>
                     <OP-CODE>062020</OP-CODE>
                     <IDENTIFIER>062020</IDENTIFIER>
                     <PREFLABEL>Service activities</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_3>
               </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE>
               <RESOURCE_LEGAL_TYPE type="data">
                  <VALUE>R</VALUE>
               </RESOURCE_LEGAL_TYPE>
               <DATE type="date">
                  <VALUE>2021-03-14</VALUE>
                  <YEAR>2021</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>14</DAY>
               </DATE>
               <LASTMODIFICATIONDATE type="date">
                  <VALUE>2020-05-13T07:13:10.337+02:00</VALUE>
                  <YEAR>2020</YEAR>
                  <MONTH>05</MONTH>
                  <DAY>13</DAY>
               </LASTMODIFICATIONDATE>
               <RESOURCE_LEGAL_HAS_TYPE_ACT_CONCEPT_TYPE_ACT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/resource-type/REG_DEL</VALUE>
                     <IDENTIFIER>REG_DEL</IDENTIFIER>
                     <TYPE>resource-type</TYPE>
                  </URI>
                  <OP-CODE>REG_DEL</OP-CODE>
                  <IDENTIFIER>REG_DEL</IDENTIFIER>
                  <PREFLABEL>Delegated regulation</PREFLABEL>
               </RESOURCE_LEGAL_HAS_TYPE_ACT_CONCEPT_TYPE_ACT>
               <RESOURCE_LEGAL_DATE_END-OF-VALIDITY type="date">
                  <VALUE>9999-12-31</VALUE>
                  <YEAR>9999</YEAR>
                  <MONTH>12</MONTH>
                  <DAY>31</DAY>
               </RESOURCE_LEGAL_DATE_END-OF-VALIDITY>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/2836</VALUE>
                     <IDENTIFIER>2836</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>2836</IDENTIFIER>
                  <PREFLABEL>consumer protection</PREFLABEL>
                  <ALTLABEL>consumerism</ALTLABEL>
                  <ALTLABEL>consumer policy action plan</ALTLABEL>
                  <ALTLABEL>consumers' rights</ALTLABEL>
               </IS_ABOUT>
               <RESOURCE_LEGAL_ID_CELEX type="data">
                  <VALUE>32018R0389</VALUE>
               </RESOURCE_LEGAL_ID_CELEX>
               <VERSION type="data">
                  <VALUE>1.41</VALUE>
               </VERSION>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/5234</VALUE>
                        <IDENTIFIER>5234</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>5234</IDENTIFIER>
                     <PREFLABEL>safety standard</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/3641</VALUE>
                        <IDENTIFIER>3641</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>3641</IDENTIFIER>
                     <PREFLABEL>technical regulations</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100158</VALUE>
                        <IDENTIFIER>100158</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>64</IDENTIFIER>
                     <PREFLABEL>64 PRODUCTION, TECHNOLOGY AND RESEARCH</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100261</VALUE>
                        <IDENTIFIER>100261</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>6411</IDENTIFIER>
                     <PREFLABEL>6411 technology and technical regulations</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <DATE type="date">
                  <VALUE>2018-03-13</VALUE>
                  <YEAR>2018</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>13</DAY>
               </DATE>
               <RESOURCE_LEGAL_PRODUCED_BY_DOSSIER type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/d4378737-da05-11e7-a506-01aa75ed71a1</VALUE>
                     <IDENTIFIER>d4378737-da05-11e7-a506-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/internal_proc/9BD1C223BC0EDCE04277F399BD0DE33FF22FAEBE7ACF041795925D0D83F6BDBC</VALUE>
                        <IDENTIFIER>9BD1C223BC0EDCE04277F399BD0DE33FF22FAEBE7ACF041795925D0D83F6BDBC</IDENTIFIER>
                        <TYPE>internal_proc</TYPE>
                     </URI>
                  </SAMEAS>
               </RESOURCE_LEGAL_PRODUCED_BY_DOSSIER>
               <RESOURCE_LEGAL_DATE_ENTRY-INTO-FORCE type="date">
                  <VALUE>2018-03-14</VALUE>
                  <YEAR>2018</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>14</DAY>
                  <ANNOTATION>
                     <TYPE_OF_DATE>{EV|http://publications.europa.eu/resource/authority/fd_335/EV}</TYPE_OF_DATE>
                     <COMMENT_ON_DATE>{DATPUB|http://publications.europa.eu/resource/authority/fd_335/DATPUB} +1 {V|http://publications.europa.eu/resource/authority/fd_335/V} {ART|http://publications.europa.eu/resource/authority/fd_335/ART} 38.1</COMMENT_ON_DATE>
                  </ANNOTATION>
               </RESOURCE_LEGAL_DATE_ENTRY-INTO-FORCE>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/fd_070/LCC</VALUE>
                     <IDENTIFIER>LCC</IDENTIFIER>
                     <TYPE>fd_070</TYPE>
                  </URI>
                  <OP-CODE>LCC</OP-CODE>
                  <IDENTIFIER>LCC</IDENTIFIER>
                  <PREFLABEL>Free movement of capital</PREFLABEL>
               </IS_ABOUT>
               <WORK_ID_DOCUMENT type="data">
                  <VALUE>oj:JOL_2018_069_R_0006</VALUE>
               </WORK_ID_DOCUMENT>
               <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE type="concept_level">
                  <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_2 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_555/1040</VALUE>
                        <IDENTIFIER>1040</IDENTIFIER>
                        <TYPE>fd_555</TYPE>
                     </URI>
                     <OP-CODE>1040</OP-CODE>
                     <IDENTIFIER>1040</IDENTIFIER>
                     <PREFLABEL>Free movement of capital</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_2>
                  <RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_1 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_555/10</VALUE>
                        <IDENTIFIER>10</IDENTIFIER>
                        <TYPE>fd_555</TYPE>
                     </URI>
                     <OP-CODE>10</OP-CODE>
                     <IDENTIFIER>10</IDENTIFIER>
                     <PREFLABEL>Economic and monetary policy and free movement of capital</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE_1>
               </RESOURCE_LEGAL_IS_ABOUT_CONCEPT_DIRECTORY-CODE>
               <RESOURCE_LEGAL_NUMBER_NATURAL_CELEX type="data">
                  <VALUE>0389</VALUE>
               </RESOURCE_LEGAL_NUMBER_NATURAL_CELEX>
               <RESOURCE_LEGAL_DATE_ENTRY-INTO-FORCE type="date">
                  <VALUE>2019-09-14</VALUE>
                  <YEAR>2019</YEAR>
                  <MONTH>09</MONTH>
                  <DAY>14</DAY>
                  <ANNOTATION>
                     <TYPE_OF_DATE>{MA|http://publications.europa.eu/resource/authority/fd_335/MA}</TYPE_OF_DATE>
                     <COMMENT_ON_DATE>{V|http://publications.europa.eu/resource/authority/fd_335/V} {ART|http://publications.europa.eu/resource/authority/fd_335/ART} 38.2</COMMENT_ON_DATE>
                  </ANNOTATION>
               </RESOURCE_LEGAL_DATE_ENTRY-INTO-FORCE>
               <WORK_ID_DOCUMENT type="data">
                  <VALUE>celex:32018R0389</VALUE>
               </WORK_ID_DOCUMENT>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/5235</VALUE>
                     <IDENTIFIER>5235</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>5235</IDENTIFIER>
                  <PREFLABEL>technical standard</PREFLABEL>
               </IS_ABOUT>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/2602</VALUE>
                     <IDENTIFIER>2602</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>2602</IDENTIFIER>
                  <PREFLABEL>provision of services</PREFLABEL>
               </IS_ABOUT>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/fd_555/1040</VALUE>
                     <IDENTIFIER>1040</IDENTIFIER>
                     <TYPE>fd_555</TYPE>
                  </URI>
                  <OP-CODE>1040</OP-CODE>
                  <IDENTIFIER>1040</IDENTIFIER>
                  <PREFLABEL>Free movement of capital</PREFLABEL>
               </IS_ABOUT>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/fd_070/MARI</VALUE>
                     <IDENTIFIER>MARI</IDENTIFIER>
                     <TYPE>fd_070</TYPE>
                  </URI>
                  <OP-CODE>MARI</OP-CODE>
                  <IDENTIFIER>MARI</IDENTIFIER>
                  <PREFLABEL>Internal market - Principles</PREFLABEL>
               </IS_ABOUT>
               <ELI type="data">
                  <VALUE>http://data.europa.eu/eli/reg_del/2018/389/oj</VALUE>
               </ELI>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/c_04ae3ba8</VALUE>
                        <IDENTIFIER>c_04ae3ba8</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>c_04ae3ba8</IDENTIFIER>
                     <PREFLABEL>information security</PREFLABEL>
                     <ALTLABEL>cybersafety</ALTLABEL>
                     <ALTLABEL>infosec</ALTLABEL>
                     <ALTLABEL>cyber-security</ALTLABEL>
                     <ALTLABEL>cybersecurity</ALTLABEL>
                     <ALTLABEL>Internet security</ALTLABEL>
                     <ALTLABEL>Internet safety</ALTLABEL>
                     <ALTLABEL>breach of information security</ALTLABEL>
                     <ALTLABEL>NIS</ALTLABEL>
                     <ALTLABEL>information assurance</ALTLABEL>
                     <ALTLABEL>information security incident</ALTLABEL>
                     <ALTLABEL>cyber-safety</ALTLABEL>
                     <ALTLABEL>network and Internet security</ALTLABEL>
                     <ALTLABEL>digital safety</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/5922</VALUE>
                        <IDENTIFIER>5922</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>5922</IDENTIFIER>
                     <PREFLABEL>computer system</PREFLABEL>
                     <ALTLABEL>data-processing system</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100150</VALUE>
                        <IDENTIFIER>100150</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>32</IDENTIFIER>
                     <PREFLABEL>32 EDUCATION AND COMMUNICATIONS</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100223</VALUE>
                        <IDENTIFIER>100223</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>3236</IDENTIFIER>
                     <PREFLABEL>3236 information technology and data processing</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <WORK_ID_DOCUMENT type="data">
                  <VALUE>immc:C(2017)7782/952445</VALUE>
               </WORK_ID_DOCUMENT>
               <RESOURCE_LEGAL_BASED_ON_CONCEPT_TREATY type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/treaty/TFEU_2012</VALUE>
                     <IDENTIFIER>TFEU_2012</IDENTIFIER>
                     <TYPE>treaty</TYPE>
                  </URI>
                  <OP-CODE>TFEU_2012</OP-CODE>
                  <IDENTIFIER>TFEU_2012</IDENTIFIER>
                  <PREFLABEL>Treaty on the Functioning of the European Union (consolidated version 2012)</PREFLABEL>
                  <ALTLABEL>TFEU (2012)</ALTLABEL>
                  <ALTLABEL>Consolidated version of the Treaty on the Functioning of the European Union (2012)</ALTLABEL>
               </RESOURCE_LEGAL_BASED_ON_CONCEPT_TREATY>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/fd_070/LES</VALUE>
                     <IDENTIFIER>LES</IDENTIFIER>
                     <TYPE>fd_070</TYPE>
                  </URI>
                  <OP-CODE>LES</OP-CODE>
                  <IDENTIFIER>LES</IDENTIFIER>
                  <PREFLABEL>Freedom of establishment</PREFLABEL>
               </IS_ABOUT>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/c_e749c083</VALUE>
                        <IDENTIFIER>c_e749c083</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>c_e749c083</IDENTIFIER>
                     <PREFLABEL>payment system</PREFLABEL>
                     <ALTLABEL>securities settlement system</ALTLABEL>
                     <ALTLABEL>electronic funds transfer system</ALTLABEL>
                     <ALTLABEL>funds transfer system</ALTLABEL>
                     <ALTLABEL>FTS</ALTLABEL>
                     <ALTLABEL>EFTS</ALTLABEL>
                     <ALTLABEL>interbank funds transfer system</ALTLABEL>
                     <ALTLABEL>payment and settlement system</ALTLABEL>
                     <ALTLABEL>clearing and settlement system</ALTLABEL>
                     <ALTLABEL>IFTS</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/1804</VALUE>
                        <IDENTIFIER>1804</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>1804</IDENTIFIER>
                     <PREFLABEL>financial market</PREFLABEL>
                     <ALTLABEL>international financial market</ALTLABEL>
                     <ALTLABEL>securities market</ALTLABEL>
                     <ALTLABEL>financial activity</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100148</VALUE>
                        <IDENTIFIER>100148</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>24</IDENTIFIER>
                     <PREFLABEL>24 FINANCE</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100201</VALUE>
                        <IDENTIFIER>100201</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2421</IDENTIFIER>
                     <PREFLABEL>2421 free movement of capital</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <RESOURCE_LEGAL_COMPLETES_RESOURCE_LEGAL type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/dd85ef2e-a953-11e5-b528-01aa75ed71a1</VALUE>
                     <IDENTIFIER>dd85ef2e-a953-11e5-b528-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/immc/planjo%3A20151123-007</VALUE>
                        <IDENTIFIER>planjo:20151123-007</IDENTIFIER>
                        <TYPE>immc</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2015_337_R_0002</VALUE>
                        <IDENTIFIER>JOL_2015_337_R_0002</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/eli/dir/2015/2366/oj</VALUE>
                        <IDENTIFIER>dir:2015:2366:oj</IDENTIFIER>
                        <TYPE>eli</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/32015L2366</VALUE>
                        <IDENTIFIER>32015L2366</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
                  <ANNOTATION>
                     <START_OF_VALIDITY>2019-09-14</START_OF_VALIDITY>
                     <TYPE_OF_LINK_TARGET>MS</TYPE_OF_LINK_TARGET>
                  </ANNOTATION>
               </RESOURCE_LEGAL_COMPLETES_RESOURCE_LEGAL>
               <RESOURCE_LEGAL_NUMBER_NATURAL type="data">
                  <VALUE>389</VALUE>
               </RESOURCE_LEGAL_NUMBER_NATURAL>
               <BASED_ON type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/dd85ef2e-a953-11e5-b528-01aa75ed71a1</VALUE>
                     <IDENTIFIER>dd85ef2e-a953-11e5-b528-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/immc/planjo%3A20151123-007</VALUE>
                        <IDENTIFIER>planjo:20151123-007</IDENTIFIER>
                        <TYPE>immc</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2015_337_R_0002</VALUE>
                        <IDENTIFIER>JOL_2015_337_R_0002</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/eli/dir/2015/2366/oj</VALUE>
                        <IDENTIFIER>dir:2015:2366:oj</IDENTIFIER>
                        <TYPE>eli</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/32015L2366</VALUE>
                        <IDENTIFIER>32015L2366</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
               </BASED_ON>
               <SERVICE_RESPONSIBLE type="data">
                  <VALUE>FISMA</VALUE>
               </SERVICE_RESPONSIBLE>
               <IDENTIFIER type="data">
                  <VALUE>http://data.europa.eu/eli/reg_del/2018/389/oj</VALUE>
               </IDENTIFIER>
               <WORK_CREATED_BY_AGENT type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/corporate-body/FISMA</VALUE>
                     <IDENTIFIER>FISMA</IDENTIFIER>
                     <TYPE>corporate-body</TYPE>
                  </URI>
                  <OP-CODE>FISMA</OP-CODE>
                  <IDENTIFIER>FISMA</IDENTIFIER>
                  <PREFLABEL>Directorate-General for Financial Stability, Financial Services and Capital Markets Union</PREFLABEL>
                  <ALTLABEL>FISMA</ALTLABEL>
                  <ALTLABEL>DG Financial Stability, Financial Services and Capital Markets Union</ALTLABEL>
               </WORK_CREATED_BY_AGENT>
               <RESOURCE_LEGAL_INFORMATION_MISCELLANEOUS type="data">
                  <VALUE>{P/EEE|http://publications.europa.eu/resource/authority/fd_400/P%2FEEE}</VALUE>
               </RESOURCE_LEGAL_INFORMATION_MISCELLANEOUS>
               <IDENTIFIER type="data">
                  <VALUE>immc:C(2017)7782/952445</VALUE>
               </IDENTIFIER>
               <RESOURCE_LEGAL_CONSOLIDATED_BY_ACT_CONSOLIDATED type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/b2a4f2a0-946a-11ea-aac4-01aa75ed71a1</VALUE>
                     <IDENTIFIER>b2a4f2a0-946a-11ea-aac4-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/02018R0389-20180313</VALUE>
                        <IDENTIFIER>02018R0389-20180313</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/consolidation/2018R0389%2F20180313</VALUE>
                        <IDENTIFIER>2018R0389/20180313</IDENTIFIER>
                        <TYPE>consolidation</TYPE>
                     </URI>
                  </SAMEAS>
               </RESOURCE_LEGAL_CONSOLIDATED_BY_ACT_CONSOLIDATED>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/2602</VALUE>
                        <IDENTIFIER>2602</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2602</IDENTIFIER>
                     <PREFLABEL>provision of services</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/5268</VALUE>
                        <IDENTIFIER>5268</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>5268</IDENTIFIER>
                     <PREFLABEL>commercial transaction</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100147</VALUE>
                        <IDENTIFIER>100147</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>20</IDENTIFIER>
                     <PREFLABEL>20 TRADE</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100196</VALUE>
                        <IDENTIFIER>100196</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2031</IDENTIFIER>
                     <PREFLABEL>2031 marketing</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <RESOURCE_LEGAL_IN-FORCE type="data">
                  <VALUE>true</VALUE>
               </RESOURCE_LEGAL_IN-FORCE>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/c_e749c083</VALUE>
                     <IDENTIFIER>c_e749c083</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>c_e749c083</IDENTIFIER>
                  <PREFLABEL>payment system</PREFLABEL>
                  <ALTLABEL>securities settlement system</ALTLABEL>
                  <ALTLABEL>electronic funds transfer system</ALTLABEL>
                  <ALTLABEL>funds transfer system</ALTLABEL>
                  <ALTLABEL>FTS</ALTLABEL>
                  <ALTLABEL>EFTS</ALTLABEL>
                  <ALTLABEL>interbank funds transfer system</ALTLABEL>
                  <ALTLABEL>payment and settlement system</ALTLABEL>
                  <ALTLABEL>clearing and settlement system</ALTLABEL>
                  <ALTLABEL>IFTS</ALTLABEL>
               </IS_ABOUT>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/c_04ae3ba8</VALUE>
                     <IDENTIFIER>c_04ae3ba8</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>c_04ae3ba8</IDENTIFIER>
                  <PREFLABEL>information security</PREFLABEL>
                  <ALTLABEL>cybersafety</ALTLABEL>
                  <ALTLABEL>infosec</ALTLABEL>
                  <ALTLABEL>cyber-security</ALTLABEL>
                  <ALTLABEL>cybersecurity</ALTLABEL>
                  <ALTLABEL>Internet security</ALTLABEL>
                  <ALTLABEL>Internet safety</ALTLABEL>
                  <ALTLABEL>breach of information security</ALTLABEL>
                  <ALTLABEL>NIS</ALTLABEL>
                  <ALTLABEL>information assurance</ALTLABEL>
                  <ALTLABEL>information security incident</ALTLABEL>
                  <ALTLABEL>cyber-safety</ALTLABEL>
                  <ALTLABEL>network and Internet security</ALTLABEL>
                  <ALTLABEL>digital safety</ALTLABEL>
               </IS_ABOUT>
               <RESOURCE_LEGAL_DATE_ENTRY-INTO-FORCE type="date">
                  <VALUE>2019-03-14</VALUE>
                  <YEAR>2019</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>14</DAY>
                  <ANNOTATION>
                     <TYPE_OF_DATE>{MA|http://publications.europa.eu/resource/authority/fd_335/MA}</TYPE_OF_DATE>
                     <COMMENT_ON_DATE>{MA/PART|http://publications.europa.eu/resource/authority/fd_335/MA%2FPART} {V|http://publications.europa.eu/resource/authority/fd_335/V} {ART|http://publications.europa.eu/resource/authority/fd_335/ART} 38.3</COMMENT_ON_DATE>
                  </ANNOTATION>
               </RESOURCE_LEGAL_DATE_ENTRY-INTO-FORCE>
               <IDENTIFIER type="data">
                  <VALUE>oj:JOL_2018_069_R_0006</VALUE>
               </IDENTIFIER>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/5234</VALUE>
                     <IDENTIFIER>5234</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>5234</IDENTIFIER>
                  <PREFLABEL>safety standard</PREFLABEL>
               </IS_ABOUT>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/2836</VALUE>
                        <IDENTIFIER>2836</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2836</IDENTIFIER>
                     <PREFLABEL>consumer protection</PREFLABEL>
                     <ALTLABEL>consumerism</ALTLABEL>
                     <ALTLABEL>consumer policy action plan</ALTLABEL>
                     <ALTLABEL>consumers' rights</ALTLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/138</VALUE>
                        <IDENTIFIER>138</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>138</IDENTIFIER>
                     <PREFLABEL>consumer</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100147</VALUE>
                        <IDENTIFIER>100147</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>20</IDENTIFIER>
                     <PREFLABEL>20 TRADE</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100195</VALUE>
                        <IDENTIFIER>100195</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>2026</IDENTIFIER>
                     <PREFLABEL>2026 consumption</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <IDENTIFIER type="data">
                  <VALUE>celex:32018R0389</VALUE>
               </IDENTIFIER>
               <RESOURCE_LEGAL_PUBLISHED_IN_OFFICIAL-JOURNAL type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/b759d4e5-268a-11e8-ac73-01aa75ed71a1</VALUE>
                     <IDENTIFIER>b759d4e5-268a-11e8-ac73-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2018_069_R</VALUE>
                        <IDENTIFIER>JOL_2018_069_R</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
               </RESOURCE_LEGAL_PUBLISHED_IN_OFFICIAL-JOURNAL>
               <CREATED_BY type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/corporate-body/COM</VALUE>
                     <IDENTIFIER>COM</IDENTIFIER>
                     <TYPE>corporate-body</TYPE>
                  </URI>
                  <OP-CODE>COM</OP-CODE>
                  <IDENTIFIER>COM</IDENTIFIER>
                  <PREFLABEL>European Commission</PREFLABEL>
                  <ALTLABEL>EC</ALTLABEL>
                  <ALTLABEL>Commission of the European Communities</ALTLABEL>
                  <ALTLABEL>European Commission</ALTLABEL>
                  <ALTLABEL>Commission</ALTLABEL>
               </CREATED_BY>
               <WORK_IS_ABOUT_CONCEPT_EUROVOC type="concept_facet">
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/5235</VALUE>
                        <IDENTIFIER>5235</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>5235</IDENTIFIER>
                     <PREFLABEL>technical standard</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_CONCEPT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_TT type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/3641</VALUE>
                        <IDENTIFIER>3641</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>3641</IDENTIFIER>
                     <PREFLABEL>technical regulations</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_TT>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100158</VALUE>
                        <IDENTIFIER>100158</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>64</IDENTIFIER>
                     <PREFLABEL>64 PRODUCTION, TECHNOLOGY AND RESEARCH</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_DOM>
                  <WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH type="concept">
                     <URI>
                        <VALUE>http://eurovoc.europa.eu/100261</VALUE>
                        <IDENTIFIER>100261</IDENTIFIER>
                        <TYPE>EUROVOC</TYPE>
                     </URI>
                     <IDENTIFIER>6411</IDENTIFIER>
                     <PREFLABEL>6411 technology and technical regulations</PREFLABEL>
                  </WORK_IS_ABOUT_CONCEPT_EUROVOC_MTH>
               </WORK_IS_ABOUT_CONCEPT_EUROVOC>
               <IDENTIFIER type="data">
                  <VALUE>32018R0389</VALUE>
               </IDENTIFIER>
               <RESOURCE_LEGAL_BASIS_FOR_ACT_CONSOLIDATED type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/b2a4f2a0-946a-11ea-aac4-01aa75ed71a1</VALUE>
                     <IDENTIFIER>b2a4f2a0-946a-11ea-aac4-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/02018R0389-20180313</VALUE>
                        <IDENTIFIER>02018R0389-20180313</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/consolidation/2018R0389%2F20180313</VALUE>
                        <IDENTIFIER>2018R0389/20180313</IDENTIFIER>
                        <TYPE>consolidation</TYPE>
                     </URI>
                  </SAMEAS>
               </RESOURCE_LEGAL_BASIS_FOR_ACT_CONSOLIDATED>
               <RESOURCE_LEGAL_COMMENT_INTERNAL type="data">
                  <VALUE>MAN2</VALUE>
               </RESOURCE_LEGAL_COMMENT_INTERNAL>
               <CREATIONDATE type="date">
                  <VALUE>2018-03-13T08:07:20.915+01:00</VALUE>
                  <YEAR>2018</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>13</DAY>
               </CREATIONDATE>
               <DATE_CREATION_LEGACY type="date">
                  <VALUE>2018-03-13</VALUE>
                  <YEAR>2018</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>13</DAY>
               </DATE_CREATION_LEGACY>
               <RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER type="concept_level">
                  <RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER_1 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_070/LCC</VALUE>
                        <IDENTIFIER>LCC</IDENTIFIER>
                        <TYPE>fd_070</TYPE>
                     </URI>
                     <OP-CODE>LCC</OP-CODE>
                     <IDENTIFIER>LCC</IDENTIFIER>
                     <PREFLABEL>Free movement of capital</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER_1>
               </RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER>
               <RESOURCE_LEGAL_DATE_DEADLINE type="date">
                  <VALUE>2021-03-14</VALUE>
                  <YEAR>2021</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>14</DAY>
                  <ANNOTATION>
                     <COMMENT_ON_DATE>{B-19.12|http://publications.europa.eu/resource/authority/fd_335/B-19.12} {V|http://publications.europa.eu/resource/authority/fd_335/V} {ART|http://publications.europa.eu/resource/authority/fd_335/ART} 37</COMMENT_ON_DATE>
                  </ANNOTATION>
               </RESOURCE_LEGAL_DATE_DEADLINE>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/3248</VALUE>
                     <IDENTIFIER>3248</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>3248</IDENTIFIER>
                  <PREFLABEL>electronic banking</PREFLABEL>
                  <ALTLABEL>home and office banking service</ALTLABEL>
                  <ALTLABEL>ATM</ALTLABEL>
                  <ALTLABEL>cash dispenser</ALTLABEL>
                  <ALTLABEL>online banking</ALTLABEL>
                  <ALTLABEL>self-service bank</ALTLABEL>
                  <ALTLABEL>internet banking</ALTLABEL>
                  <ALTLABEL>home banking</ALTLABEL>
                  <ALTLABEL>automatic teller machine</ALTLABEL>
                  <ALTLABEL>auto-bank</ALTLABEL>
                  <ALTLABEL>HOBS</ALTLABEL>
               </IS_ABOUT>
               <RESOURCE_LEGAL_CORRECTED_BY_RESOURCE_LEGAL type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/a56d94bd-6d98-11ea-b735-01aa75ed71a1</VALUE>
                     <IDENTIFIER>a56d94bd-6d98-11ea-b735-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/32018R0389R%2801%29</VALUE>
                        <IDENTIFIER>32018R0389R(01)</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2020_088_R_0006</VALUE>
                        <IDENTIFIER>JOL_2020_088_R_0006</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
                  <ANNOTATION>
                     <TYPE_OF_LINK_TARGET>MS</TYPE_OF_LINK_TARGET>
                     <LANGUAGE_LIST>BG, ES, DE, HR, RO, SL</LANGUAGE_LIST>
                  </ANNOTATION>
               </RESOURCE_LEGAL_CORRECTED_BY_RESOURCE_LEGAL>
               <ID_SECTOR type="data">
                  <VALUE>3</VALUE>
               </ID_SECTOR>
               <BASED_ON type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/treaty/TFEU_2012</VALUE>
                     <IDENTIFIER>TFEU_2012</IDENTIFIER>
                     <TYPE>treaty</TYPE>
                  </URI>
                  <OP-CODE>TFEU_2012</OP-CODE>
                  <IDENTIFIER>TFEU_2012</IDENTIFIER>
                  <PREFLABEL>Treaty on the Functioning of the European Union (consolidated version 2012)</PREFLABEL>
                  <ALTLABEL>TFEU (2012)</ALTLABEL>
                  <ALTLABEL>Consolidated version of the Treaty on the Functioning of the European Union (2012)</ALTLABEL>
               </BASED_ON>
               <RESOURCE_LEGAL_BASIS_FOR_ACT_CONSOLIDATED type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/9b83ed5d-946a-11ea-aac4-01aa75ed71a1</VALUE>
                     <IDENTIFIER>9b83ed5d-946a-11ea-aac4-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/consolidation/2018R0389%2F20180313_0000010</VALUE>
                        <IDENTIFIER>2018R0389/20180313_0000010</IDENTIFIER>
                        <TYPE>consolidation</TYPE>
                     </URI>
                  </SAMEAS>
               </RESOURCE_LEGAL_BASIS_FOR_ACT_CONSOLIDATED>
               <DATE type="date">
                  <VALUE>2019-09-14</VALUE>
                  <YEAR>2019</YEAR>
                  <MONTH>09</MONTH>
                  <DAY>14</DAY>
               </DATE>
               <WORK_DATE_DOCUMENT type="date">
                  <VALUE>2017-11-27</VALUE>
                  <YEAR>2017</YEAR>
                  <MONTH>11</MONTH>
                  <DAY>27</DAY>
                  <ANNOTATION>
                     <COMMENT_ON_DATE>{DATADOPT|http://publications.europa.eu/resource/authority/fd_365/DATADOPT}</COMMENT_ON_DATE>
                  </ANNOTATION>
               </WORK_DATE_DOCUMENT>
               <RESOURCE_LEGAL_ELI type="data">
                  <VALUE>http://data.europa.eu/eli/reg_del/2018/389/oj</VALUE>
               </RESOURCE_LEGAL_ELI>
               <RESOURCE_LEGAL_CONSOLIDATED_BY_ACT_CONSOLIDATED type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/9b83ed5d-946a-11ea-aac4-01aa75ed71a1</VALUE>
                     <IDENTIFIER>9b83ed5d-946a-11ea-aac4-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/consolidation/2018R0389%2F20180313_0000010</VALUE>
                        <IDENTIFIER>2018R0389/20180313_0000010</IDENTIFIER>
                        <TYPE>consolidation</TYPE>
                     </URI>
                  </SAMEAS>
               </RESOURCE_LEGAL_CONSOLIDATED_BY_ACT_CONSOLIDATED>
               <DATE type="date">
                  <VALUE>2017-11-27</VALUE>
                  <YEAR>2017</YEAR>
                  <MONTH>11</MONTH>
                  <DAY>27</DAY>
               </DATE>
               <RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER type="concept_level">
                  <RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER_1 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_070/LES</VALUE>
                        <IDENTIFIER>LES</IDENTIFIER>
                        <TYPE>fd_070</TYPE>
                     </URI>
                     <OP-CODE>LES</OP-CODE>
                     <IDENTIFIER>LES</IDENTIFIER>
                     <PREFLABEL>Freedom of establishment</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER_1>
               </RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER>
               <WORK_CITES_WORK type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/c2eecef2-5a33-4525-931e-53cf6e6f96c7</VALUE>
                     <IDENTIFIER>c2eecef2-5a33-4525-931e-53cf6e6f96c7</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2010_331_R_0012_01</VALUE>
                        <IDENTIFIER>JOL_2010_331_R_0012_01</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/eli/reg/2010/1093/oj</VALUE>
                        <IDENTIFIER>reg:2010:1093:oj</IDENTIFIER>
                        <TYPE>eli</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/32010R1093</VALUE>
                        <IDENTIFIER>32010R1093</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
               </WORK_CITES_WORK>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/560</VALUE>
                     <IDENTIFIER>560</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>560</IDENTIFIER>
                  <PREFLABEL>financial legislation</PREFLABEL>
                  <ALTLABEL>transaction regulations</ALTLABEL>
               </IS_ABOUT>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/1971</VALUE>
                     <IDENTIFIER>1971</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>1971</IDENTIFIER>
                  <PREFLABEL>electronic money</PREFLABEL>
                  <ALTLABEL>defered debit card</ALTLABEL>
                  <ALTLABEL>cash card</ALTLABEL>
                  <ALTLABEL>multiservices card</ALTLABEL>
                  <ALTLABEL>credit card</ALTLABEL>
                  <ALTLABEL>delayed debit card</ALTLABEL>
                  <ALTLABEL>charge card</ALTLABEL>
                  <ALTLABEL>debit card</ALTLABEL>
                  <ALTLABEL>electronic purse</ALTLABEL>
                  <ALTLABEL>auto-bank card</ALTLABEL>
                  <ALTLABEL>e-money</ALTLABEL>
                  <ALTLABEL>payment card</ALTLABEL>
                  <ALTLABEL>e-money payment</ALTLABEL>
               </IS_ABOUT>
               <DATE type="date">
                  <VALUE>2018-03-14</VALUE>
                  <YEAR>2018</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>14</DAY>
               </DATE>
               <IS_ABOUT type="concept">
                  <URI>
                     <VALUE>http://eurovoc.europa.eu/8469</VALUE>
                     <IDENTIFIER>8469</IDENTIFIER>
                     <TYPE>EUROVOC</TYPE>
                  </URI>
                  <IDENTIFIER>8469</IDENTIFIER>
                  <PREFLABEL>financial services</PREFLABEL>
               </IS_ABOUT>
               <WORK_CITES_WORK type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/2ff66fd7-df0b-11e2-9165-01aa75ed71a1</VALUE>
                     <IDENTIFIER>2ff66fd7-df0b-11e2-9165-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2013_176_R_0338_01</VALUE>
                        <IDENTIFIER>JOL_2013_176_R_0338_01</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/32013L0036</VALUE>
                        <IDENTIFIER>32013L0036</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/eli/dir/2013/36/oj</VALUE>
                        <IDENTIFIER>dir:2013:36:oj</IDENTIFIER>
                        <TYPE>eli</TYPE>
                     </URI>
                  </SAMEAS>
               </WORK_CITES_WORK>
               <RESOURCE_LEGAL_BASED_ON_RESOURCE_LEGAL type="link">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/cellar/dd85ef2e-a953-11e5-b528-01aa75ed71a1</VALUE>
                     <IDENTIFIER>dd85ef2e-a953-11e5-b528-01aa75ed71a1</IDENTIFIER>
                     <TYPE>cellar</TYPE>
                  </URI>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/immc/planjo%3A20151123-007</VALUE>
                        <IDENTIFIER>planjo:20151123-007</IDENTIFIER>
                        <TYPE>immc</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/oj/JOL_2015_337_R_0002</VALUE>
                        <IDENTIFIER>JOL_2015_337_R_0002</IDENTIFIER>
                        <TYPE>oj</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/eli/dir/2015/2366/oj</VALUE>
                        <IDENTIFIER>dir:2015:2366:oj</IDENTIFIER>
                        <TYPE>eli</TYPE>
                     </URI>
                  </SAMEAS>
                  <SAMEAS>
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/celex/32015L2366</VALUE>
                        <IDENTIFIER>32015L2366</IDENTIFIER>
                        <TYPE>celex</TYPE>
                     </URI>
                  </SAMEAS>
                  <ANNOTATION>
                     <SUBPARAGRAPH>2</SUBPARAGRAPH>
                     <PARAGRAPH>4</PARAGRAPH>
                     <ARTICLE>98</ARTICLE>
                     <COMMENT_ON_LEGAL_BASIS>A98P4L2</COMMENT_ON_LEGAL_BASIS>
                  </ANNOTATION>
               </RESOURCE_LEGAL_BASED_ON_RESOURCE_LEGAL>
               <RESOURCE_LEGAL_REPERTOIRE type="data">
                  <VALUE>REP</VALUE>
               </RESOURCE_LEGAL_REPERTOIRE>
               <RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER type="concept_level">
                  <RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER_1 type="concept">
                     <URI>
                        <VALUE>http://publications.europa.eu/resource/authority/fd_070/MARI</VALUE>
                        <IDENTIFIER>MARI</IDENTIFIER>
                        <TYPE>fd_070</TYPE>
                     </URI>
                     <OP-CODE>MARI</OP-CODE>
                     <IDENTIFIER>MARI</IDENTIFIER>
                     <PREFLABEL>Internal market - Principles</PREFLABEL>
                  </RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER_1>
               </RESOURCE_LEGAL_IS_ABOUT_SUBJECT-MATTER>
               <TYPE>R</TYPE>
               <TYPE>cdm:legislation_secondary</TYPE>
               <TYPE>cdm:resource_legal</TYPE>
               <TYPE>cdm:work</TYPE>
            </WORK>
            <EXPRESSION xmlns="">
               <URI>
                  <VALUE>http://publications.europa.eu/resource/cellar/28c2f705-268d-11e8-ac73-01aa75ed71a1.0006</VALUE>
                  <IDENTIFIER>28c2f705-268d-11e8-ac73-01aa75ed71a1.0006</IDENTIFIER>
                  <TYPE>cellar</TYPE>
               </URI>
               <SAMEAS>
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/uriserv/OJ.L_.2018.069.01.0023.01.ENG</VALUE>
                     <IDENTIFIER>OJ.L_.2018.069.01.0023.01.ENG</IDENTIFIER>
                     <TYPE>uriserv</TYPE>
                  </URI>
               </SAMEAS>
               <SAMEAS>
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/celex/32018R0389.ENG</VALUE>
                     <IDENTIFIER>32018R0389.ENG</IDENTIFIER>
                     <TYPE>celex</TYPE>
                  </URI>
               </SAMEAS>
               <SAMEAS>
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/oj/JOL_2018_069_R_0006.ENG</VALUE>
                     <IDENTIFIER>JOL_2018_069_R_0006.ENG</IDENTIFIER>
                     <TYPE>oj</TYPE>
                  </URI>
               </SAMEAS>
               <LANG type="data">
                  <VALUE>eng</VALUE>
               </LANG>
               <TITLE type="data">
                  <VALUE>C/2017/7782</VALUE>
               </TITLE>
               <EXPRESSION_USES_LANGUAGE type="concept">
                  <URI>
                     <VALUE>http://publications.europa.eu/resource/authority/language/ENG</VALUE>
                     <IDENTIFIER>ENG</IDENTIFIER>
                     <TYPE>language</TYPE>
                  </URI>
                  <OP-CODE>ENG</OP-CODE>
                  <IDENTIFIER>ENG</IDENTIFIER>
                  <PREFLABEL>English</PREFLABEL>
                  <ALTLABEL>English</ALTLABEL>
               </EXPRESSION_USES_LANGUAGE>
               <TITLE type="data">
                  <VALUE>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance. )</VALUE>
               </TITLE>
               <LASTMODIFICATIONDATE type="date">
                  <VALUE>2018-03-13T08:28:46.656+01:00</VALUE>
                  <YEAR>2018</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>13</DAY>
               </LASTMODIFICATIONDATE>
               <CREATIONDATE type="date">
                  <VALUE>2018-03-13T08:07:20.916+01:00</VALUE>
                  <YEAR>2018</YEAR>
                  <MONTH>03</MONTH>
                  <DAY>13</DAY>
               </CREATIONDATE>
               <LANG type="data">
                  <VALUE>en</VALUE>
               </LANG>
               <EXPRESSION_TITLE type="data">
                  <VALUE>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance. )</VALUE>
               </EXPRESSION_TITLE>
               <EXPRESSION_SUBTITLE type="data">
                  <VALUE>C/2017/7782</VALUE>
               </EXPRESSION_SUBTITLE>
            </EXPRESSION>
         </ukm:EURLexMetadata><ukm:DocumentCurrentStatus><ukm:UKAmended Value="true"/></ukm:DocumentCurrentStatus><ukm:UnappliedEffects><ukm:UnappliedEffect AffectedProvisions="Regulation" AffectingProvisions="Sch. 1 Pt. 3" Row="1157" AffectingNumber="29" Comments="made under Directive 2015/2366/EC Sch. 1 para. (v) Researched using EU Publications Office data" AffectingURI="http://www.legislation.gov.uk/id/ukpga/2023/29" AffectingClass="UnitedKingdomPublicGeneralAct" EffectId="key-1ef30993eda9b70c677fcab1eb9989d7" Modified="2026-03-02T11:20:22Z" RequiresApplied="true" AffectedYear="2018" AffectedNumber="389" AffectingYear="2023" Type="revoked" AffectedClass="EuropeanUnionRegulation" AffectedURI="http://www.legislation.gov.uk/id/eur/2018/389" URI="http://www.legislation.gov.uk/id/effect/key-1ef30993eda9b70c677fcab1eb9989d7"><ukm:AffectedTitle>Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 of the European Parliament and of the Council with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication (Text with EEA relevance)</ukm:AffectedTitle><ukm:AffectedProvisions>Regulation</ukm:AffectedProvisions><ukm:AffectingTitle>Financial Services and Markets Act 2023</ukm:AffectingTitle><ukm:AffectingProvisions><ukm:Section Ref="schedule-1" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/schedule/1">Sch. 1 </ukm:Section><ukm:Section Ref="schedule-1-part-3" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/schedule/1/part/3">Pt. 3</ukm:Section></ukm:AffectingProvisions><ukm:Savings><ukm:Section Ref="section-1-4" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/section/1/4">s. 1(4)</ukm:Section></ukm:Savings><ukm:CommencementAuthority><ukm:Section Ref="section-86-3" URI="http://www.legislation.gov.uk/id/ukpga/2023/29/section/86/3">s. 86(3)</ukm:Section></ukm:CommencementAuthority><ukm:InForceDates><ukm:InForce Applied="false" Prospective="true" Qualification=""/></ukm:InForceDates></ukm:UnappliedEffect></ukm:UnappliedEffects></ukm:EUMetadata>
					

                    
									 
					<ukm:Alternatives><ukm:Alternative URI="http://www.legislation.gov.uk/eur/2018/389/pdfs/eur_20180389_adopted_en.pdf" Date="2017-11-27" Size="493802"/> </ukm:Alternatives>
					
					<ukm:Statistics>
									<ukm:TotalParagraphs Value="38"/>
									<ukm:BodyParagraphs Value="38"/>
									<ukm:ScheduleParagraphs Value="0"/>
									<ukm:AttachmentParagraphs Value="0"/>
									<ukm:TotalImages Value="0"/>
								</ukm:Statistics>
				</ukm:Metadata><EURetained><EUBody DocumentURI="http://www.legislation.gov.uk/eur/2018/389/body" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/body" NumberOfProvisions="38" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
         <EUChapter DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/I" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/I" NumberOfProvisions="3" id="chapter-I" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
            <Number>CHAPTER I</Number>
            <Title>
               <Strong>GENERAL PROVISIONS</Strong>
            </Title>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Subject matter</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/1" id="article-1">
                  <Pnumber>Article 1</Pnumber>
                  <P1para>
                     <Text>This Regulation establishes the requirements to be complied with by payment service providers for the purpose of implementing security measures which enable them to do the following:</Text>
                  </P1para>
                  <P1para>
                     <OrderedList Type="alpha" Decoration="parens">
                        <ListItem NumberOverride="(a)">
                           <Para>
                              <Text>apply the procedure of strong customer authentication in accordance with Article 97 of Directive (EU) 2015/2366;</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(b)">
                           <Para>
                              <Text>exempt the application of the security requirements of strong customer authentication, subject to specified and limited conditions based on the level of risk, the amount and the recurrence of the payment transaction and of the payment channel used for its execution;</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(c)">
                           <Para>
                              <Text>protect the confidentiality and the integrity of the payment service user's personalised security credentials;</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(d)">
                           <Para>
                              <Text>establish common and secure open standards for the communication between account servicing payment service providers, payment initiation service providers, account information service providers, payers, payees and other payment service providers in relation to the provision and use of payment services in application of Title IV of Directive (EU) 2015/2366.</Text>
                           </Para>
                        </ListItem>
                     </OrderedList>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>General authentication requirements</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/2" id="article-2">
                  <Pnumber>Article 2</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/2/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/2/1" id="article-2-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall have transaction monitoring mechanisms in place that enable them to detect unauthorised or fraudulent payment transactions for the purpose of the implementation of the security measures referred to in points (a) and (b) of Article 1.</Text>
                        </P2para>
                        <P2para>
                           <Text>Those mechanisms shall be based on the analysis of payment transactions taking into account elements which are typical of the payment service user in the circumstances of a normal use of the personalised security credentials.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/2/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/2/2" id="article-2-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall ensure that the transaction monitoring mechanisms take into account, at a minimum, each of the following risk-based factors:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>lists of compromised or stolen authentication elements;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the amount of each payment transaction;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>known fraud scenarios in the provision of payment services;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">d</Pnumber>
                              <P3para>
                                 <Text>signs of malware infection in any sessions of the authentication procedure;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">e</Pnumber>
                              <P3para>
                                 <Text>in case the access device or the software is provided by the payment service provider, a log of the use of the access device or the software provided to the payment service user and the abnormal use of the access device or the software.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Review of the security measures</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/3" id="article-3">
                  <Pnumber>Article 3</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/3/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/3/1" id="article-3-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>The implementation of the security measures referred to in Article 1 shall be documented, periodically tested, evaluated and audited in accordance with the applicable legal framework of the payment service provider by auditors with expertise in IT security and payments and operationally independent within or from the payment service provider.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/3/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/3/2" id="article-3-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>The period between the audits referred to in paragraph 1 shall be determined taking into account the relevant accounting and statutory audit framework applicable to the payment service provider.</Text>
                        </P2para>
                        <P2para>
                           <Text>However, payment service providers that make use of the exemption referred to in Article 18 shall be subject to an audit of the methodology, the model and the reported fraud rates at a minimum on a yearly basis. The auditor performing this audit shall have expertise in IT security and payments and be operationally independent within or from the payment service provider. During the first year of making use of the exemption under Article 18 and at least every 3 years thereafter, or more frequently at the competent authority's request, this audit shall be carried out by an independent and qualified external auditor.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/3/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/3/3" id="article-3-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>This audit shall present an evaluation and report on the compliance of the payment service provider's security measures with the requirements set out in this Regulation.</Text>
                        </P2para>
                        <P2para>
                           <Text>The entire report shall be made available to competent authorities upon their request.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
         </EUChapter>
         <EUChapter DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/II" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/II" NumberOfProvisions="6" id="chapter-II" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
            <Number>CHAPTER II</Number>
            <Title>
               <Strong>SECURITY MEASURES FOR THE APPLICATION OF STRONG CUSTOMER AUTHENTICATION</Strong>
            </Title>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Authentication code</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/4" id="article-4">
                  <Pnumber>Article 4</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/4/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/4/1" id="article-4-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Where payment service providers apply strong customer authentication in accordance with Article 97(1) of Directive (EU) 2015/2366, the authentication shall be based on two or more elements which are categorised as knowledge, possession and inherence and shall result in the generation of an authentication code.</Text>
                        </P2para>
                        <P2para>
                           <Text>The authentication code shall be only accepted once by the payment service provider when the payer uses the authentication code to access its payment account online, to initiate an electronic payment transaction or to carry out any action through a remote channel which may imply a risk of payment fraud or other abuses.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/4/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/4/2" id="article-4-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>For the purpose of paragraph 1, payment service providers shall adopt security measures ensuring that each of the following requirements is met:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>no information on any of the elements referred to in paragraph 1 can be derived from the disclosure of the authentication code;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>it is not possible to generate a new authentication code based on the knowledge of any other authentication code previously generated;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>the authentication code cannot be forged.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/4/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/4/3" id="article-4-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall ensure that the authentication by means of generating an authentication code includes each of the following measures:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>where the authentication for remote access, remote electronic payments and any other actions through a remote channel which may imply a risk of payment fraud or other abuses has failed to generate an authentication code for the purposes of paragraph 1, it shall not be possible to identify which of the elements referred to in that paragraph was incorrect;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the number of failed authentication attempts that can take place consecutively, after which the actions referred to in Article 97(1) of Directive (EU) 2015/2366 shall be temporarily or permanently blocked, shall not exceed five within a given period of time;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>the communication sessions are protected against the capture of authentication data transmitted during the authentication and against manipulation by unauthorised parties in accordance with the requirements in Chapter V;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">d</Pnumber>
                              <P3para>
                                 <Text>the maximum time without activity by the payer after being authenticated for accessing its payment account online shall not exceed 5 minutes.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/4/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/4/4" id="article-4-4">
                        <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                        <P2para>
                           <Text>Where the block referred to in paragraph 3(b) is temporary, the duration of that block and the number of retries shall be established based on the characteristics of the service provided to the payer and all the relevant risks involved, taking into account, at a minimum, the factors referred to in Article 2(2).</Text>
                        </P2para>
                        <P2para>
                           <Text>The payer shall be alerted before the block is made permanent.</Text>
                        </P2para>
                        <P2para>
                           <Text>Where the block has been made permanent, a secure procedure shall be established allowing the payer to regain use of the blocked electronic payment instruments.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Dynamic linking</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/5" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/5" id="article-5">
                  <Pnumber>Article 5</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/5/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/5/1" id="article-5-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366, in addition to the requirements of Article 4 of this Regulation, they shall also adopt security measures that meet each of the following requirements:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the payer is made aware of the amount of the payment transaction and of the payee;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the authentication code generated is specific to the amount of the payment transaction and the payee agreed to by the payer when initiating the transaction;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>the authentication code accepted by the payment service provider corresponds to the original specific amount of the payment transaction and to the identity of the payee agreed to by the payer;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">d</Pnumber>
                              <P3para>
                                 <Text>any change to the amount or the payee results in the invalidation of the authentication code generated.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/5/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/5/2" id="article-5-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>For the purpose of paragraph 1, payment service providers shall adopt security measures which ensure the confidentiality, authenticity and integrity of each of the following:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the amount of the transaction and the payee throughout all of the phases of the authentication;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the information displayed to the payer throughout all of the phases of the authentication including the generation, transmission and use of the authentication code.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/5/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/5/3" id="article-5-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>For the purpose of paragraph 1(b) and where payment service providers apply strong customer authentication in accordance with Article 97(2) of Directive (EU) 2015/2366 the following requirements for the authentication code shall apply:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>in relation to a card-based payment transaction for which the payer has given consent to the exact amount of the funds to be blocked pursuant to Article 75(1) of that Directive, the authentication code shall be specific to the amount that the payer has given consent to be blocked and agreed to by the payer when initiating the transaction;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>in relation to payment transactions for which the payer has given consent to execute a batch of remote electronic payment transactions to one or several payees, the authentication code shall be specific to the total amount of the batch of payment transactions and to the specified payees.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Requirements of the elements categorised as knowledge</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/6" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/6" id="article-6">
                  <Pnumber>Article 6</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/6/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/6/1" id="article-6-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as knowledge are uncovered by, or disclosed to, unauthorised parties.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/6/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/6/2" id="article-6-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>The use by the payer of those elements shall be subject to mitigation measures in order to prevent their disclosure to unauthorised parties.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Requirements of the elements categorised as possession</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/7" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/7" id="article-7">
                  <Pnumber>Article 7</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/7/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/7/1" id="article-7-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall adopt measures to mitigate the risk that the elements of strong customer authentication categorised as possession are used by unauthorised parties.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/7/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/7/2" id="article-7-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>The use by the payer of those elements shall be subject to measures designed to prevent replication of the elements.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Requirements of devices and software linked to elements categorised as inherence</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/8" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/8" id="article-8">
                  <Pnumber>Article 8</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/8/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/8/1" id="article-8-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall adopt measures to mitigate the risk that the authentication elements categorised as inherence and read by access devices and software provided to the payer are uncovered by unauthorised parties. At a minimum, the payment service providers shall ensure that those access devices and software have a very low probability of an unauthorised party being authenticated as the payer.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/8/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/8/2" id="article-8-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>The use by the payer of those elements shall be subject to measures ensuring that those devices and the software guarantee resistance against unauthorised use of the elements through access to the devices and the software.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Independence of the elements</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/9" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/9" id="article-9">
                  <Pnumber>Article 9</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/9/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/9/1" id="article-9-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall ensure that the use of the elements of strong customer authentication referred to in Articles 6, 7 and 8 is subject to measures which ensure that, in terms of technology, algorithms and parameters, the breach of one of the elements does not compromise the reliability of the other elements.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/9/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/9/2" id="article-9-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall adopt security measures, where any of the elements of strong customer authentication or the authentication code itself is used through a multi-purpose device, to mitigate the risk which would result from that multi-purpose device being compromised.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/9/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/9/3" id="article-9-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>For the purposes of paragraph 2, the mitigating measures shall include each of the following:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the use of separated secure execution environments through the software installed inside the multi-purpose device;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>mechanisms to ensure that the software or device has not been altered by the payer or by a third party;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>where alterations have taken place, mechanisms to mitigate the consequences thereof.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
         </EUChapter>
         <EUChapter DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/III" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/III" NumberOfProvisions="12" id="chapter-III" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
            <Number>CHAPTER III</Number>
            <Title>
               <Strong>EXEMPTIONS FROM STRONG CUSTOMER AUTHENTICATION</Strong>
            </Title>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Payment account information</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/10" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/10" id="article-10">
                  <Pnumber>Article 10</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/10/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/10/1" id="article-10-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2 and to paragraph 2 of this Article and, where a payment service user is limited to accessing either or both of the following items online without disclosure of sensitive payment data:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the balance of one or more designated payment accounts;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the payment transactions executed in the last 90 days through one or more designated payment accounts.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/10/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/10/2" id="article-10-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>For the purpose of paragraph 1, payment service providers shall not be exempted from the application of strong customer authentication where either of the following condition is met:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the payment service user is accessing online the information specified in paragraph 1 for the first time;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>more than 90 days have elapsed since the last time the payment service user accessed online the information specified in paragraph 1(b) and strong customer authentication was applied.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Contactless payments at point of sale</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/11" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/11" id="article-11">
                  <Pnumber>Article 11</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where the payer initiates a contactless electronic payment transaction provided that the following conditions are met:</Text>
                  </P1para>
                  <P1para>
                     <OrderedList Type="alpha" Decoration="parens">
                        <ListItem NumberOverride="(a)">
                           <Para>
                              <Text>the individual amount of the contactless electronic payment transaction does not exceed EUR 50; and</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(b)">
                           <Para>
                              <Text>the cumulative amount of previous contactless electronic payment transactions initiated by means of a payment instrument with a contactless functionality from the date of the last application of strong customer authentication does not exceed EUR 150; or</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(c)">
                           <Para>
                              <Text>the number of consecutive contactless electronic payment transactions initiated via the payment instrument offering a contactless functionality since the last application of strong customer authentication does not exceed five.</Text>
                           </Para>
                        </ListItem>
                     </OrderedList>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Unattended terminals for transport fares and parking fees</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/12" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/12" id="article-12">
                  <Pnumber>Article 12</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where the payer initiates an electronic payment transaction at an unattended payment terminal for the purpose of paying a transport fare or a parking fee.</Text>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Trusted beneficiaries</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/13" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/13" id="article-13">
                  <Pnumber>Article 13</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/13/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/13/1" id="article-13-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall apply strong customer authentication where a payer creates or amends a list of trusted beneficiaries through the payer's account servicing payment service provider.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/13/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/13/2" id="article-13-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the general authentication requirements, where the payer initiates a payment transaction and the payee is included in a list of trusted beneficiaries previously created by the payer.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Recurring transactions</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/14" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/14" id="article-14">
                  <Pnumber>Article 14</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/14/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/14/1" id="article-14-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall apply strong customer authentication when a payer creates, amends, or initiates for the first time, a series of recurring transactions with the same amount and with the same payee.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/14/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/14/2" id="article-14-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the general authentication requirements, for the initiation of all subsequent payment transactions included in the series of payment transactions referred to in paragraph 1.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Credit transfers between accounts held by the same natural or legal person</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/15" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/15" id="article-15">
                  <Pnumber>Article 15</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall be allowed not to apply strong customer authentication, subject to compliance with the requirements laid down in Article 2, where the payer initiates a credit transfer in circumstances where the payer and the payee are the same natural or legal person and both payment accounts are held by the same account servicing payment service provider.</Text>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Low-value transactions</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/16" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/16" id="article-16">
                  <Pnumber>Article 16</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall be allowed not to apply strong customer authentication, where the payer initiates a remote electronic payment transaction provided that the following conditions are met:</Text>
                  </P1para>
                  <P1para>
                     <OrderedList Type="alpha" Decoration="parens">
                        <ListItem NumberOverride="(a)">
                           <Para>
                              <Text>the amount of the remote electronic payment transaction does not exceed EUR 30; and</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(b)">
                           <Para>
                              <Text>the cumulative amount of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed EUR 100; or</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(c)">
                           <Para>
                              <Text>the number of previous remote electronic payment transactions initiated by the payer since the last application of strong customer authentication does not exceed five consecutive individual remote electronic payment transactions.</Text>
                           </Para>
                        </ListItem>
                     </OrderedList>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Secure corporate payment processes and protocols</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/17" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/17" id="article-17">
                  <Pnumber>Article 17</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall be allowed not to apply strong customer authentication, in respect of legal persons initiating electronic payment transactions through the use of dedicated payment processes or protocols that are only made available to payers who are not consumers, where the competent authorities are satisfied that those processes or protocols guarantee at least equivalent levels of security to those provided for by Directive (EU) 2015/2366.</Text>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Transaction risk analysis</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/18" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/18" id="article-18">
                  <Pnumber>Article 18</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/18/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/18/1" id="article-18-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall be allowed not to apply strong customer authentication where the payer initiates a remote electronic payment transaction identified by the payment service provider as posing a low level of risk according to the transaction monitoring mechanisms referred to in Article 2 and in paragraph 2(c) of this Article.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/18/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/18/2" id="article-18-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>An electronic payment transaction referred to in paragraph 1 shall be considered as posing a low level of risk where all the following conditions are met:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the fraud rate for that type of transaction, reported by the payment service provider and calculated in accordance with Article 19, is equivalent to or below the reference fraud rates specified in the table set out in the Annex for ‘remote electronic card-based payments’ and ‘remote electronic credit transfers’ respectively;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the amount of the transaction does not exceed the relevant exemption threshold value (‘ETV’) specified in the table set out in the Annex;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>payment service providers as a result of performing a real time risk analysis have not identified any of the following:</Text>
                              </P3para>
                              <P3para>
                                 <OrderedList Type="roman" Decoration="parens">
                                    <ListItem NumberOverride="(i)">
                                       <Para>
                                          <Text>abnormal spending or behavioural pattern of the payer;</Text>
                                       </Para>
                                    </ListItem>
                                    <ListItem NumberOverride="(ii)">
                                       <Para>
                                          <Text>unusual information about the payer's device/software access;</Text>
                                       </Para>
                                    </ListItem>
                                    <ListItem NumberOverride="(iii)">
                                       <Para>
                                          <Text>malware infection in any session of the authentication procedure;</Text>
                                       </Para>
                                    </ListItem>
                                    <ListItem NumberOverride="(iv)">
                                       <Para>
                                          <Text>known fraud scenario in the provision of payment services;</Text>
                                       </Para>
                                    </ListItem>
                                    <ListItem NumberOverride="(v)">
                                       <Para>
                                          <Text>abnormal location of the payer;</Text>
                                       </Para>
                                    </ListItem>
                                    <ListItem NumberOverride="(vi)">
                                       <Para>
                                          <Text>high-risk location of the payee.</Text>
                                       </Para>
                                    </ListItem>
                                 </OrderedList>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/18/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/18/3" id="article-18-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>Payment service providers that intend to exempt electronic remote payment transactions from strong customer authentication on the ground that they pose a low risk shall take into account at a minimum, the following risk-based factors:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the previous spending patterns of the individual payment service user;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the payment transaction history of each of the payment service provider's payment service users;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>the location of the payer and of the payee at the time of the payment transaction in cases where the access device or the software is provided by the payment service provider;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">d</Pnumber>
                              <P3para>
                                 <Text>the identification of abnormal payment patterns of the payment service user in relation to the user's payment transaction history.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                        <P2para>
                           <Text>The assessment made by a payment service provider shall combine all those risk-based factors into a risk scoring for each individual transaction to determine whether a specific payment should be allowed without strong customer authentication.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Calculation of fraud rates</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/19" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/19" id="article-19">
                  <Pnumber>Article 19</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/19/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/19/1" id="article-19-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>For each type of transaction referred to in the table set out in the Annex, the payment service provider shall ensure that the overall fraud rates covering both payment transactions authenticated through strong customer authentication and those executed under any of the exemptions referred to in Articles 13 to 18 are equivalent to, or lower than, the reference fraud rate for the same type of payment transaction indicated in the table set out in the Annex.</Text>
                        </P2para>
                        <P2para>
                           <Text>The overall fraud rate for each type of transaction shall be calculated as the total value of unauthorised or fraudulent remote transactions, whether the funds have been recovered or not, divided by the total value of all remote transactions for the same type of transactions, whether authenticated with the application of strong customer authentication or executed under any exemption referred to in Articles 13 to 18 on a rolling quarterly basis (90 days).</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/19/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/19/2" id="article-19-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>The calculation of the fraud rates and resulting figures shall be assessed by the audit review referred to in Article 3(2), which shall ensure that they are complete and accurate.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/19/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/19/3" id="article-19-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>The methodology and any model, used by the payment service provider to calculate the fraud rates, as well as the fraud rates themselves, shall be adequately documented and made fully available to competent authorities and to EBA, with prior notification to the relevant competent authority(ies), upon their request.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Cessation of exemptions based on transaction risk analysis</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/20" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/20" id="article-20">
                  <Pnumber>Article 20</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/20/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/20/1" id="article-20-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers that make use of the exemption referred to in Article 18 shall immediately report to the competent authorities where one of their monitored fraud rates, for any type of payment transactions indicated in the table set out in the Annex, exceeds the applicable reference fraud rate and shall provide to the competent authorities a description of the measures that they intend to adopt to restore compliance of their monitored fraud rate with the applicable reference fraud rates.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/20/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/20/2" id="article-20-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall immediately cease to make use of the exemption referred to in Article 18 for any type of payment transactions indicated in the table set out in the Annex in the specific exemption threshold range where their monitored fraud rate exceeds for two consecutive quarters the reference fraud rate applicable for that payment instrument or type of payment transaction in that exemption threshold range.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/20/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/20/3" id="article-20-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>Following the cessation of the exemption referred to in Article 18 in accordance with paragraph 2 of this Article, payment service providers shall not use that exemption again, until their calculated fraud rate equals to, or is below, the reference fraud rates applicable for that type of payment transaction in that exemption threshold range for one quarter.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/20/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/20/4" id="article-20-4">
                        <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                        <P2para>
                           <Text>Where payment service providers intend to make use again of the exemption referred to in Article 18, they shall notify the competent authorities in a reasonable timeframe and shall before making use again of the exemption, provide evidence of the restoration of compliance of their monitored fraud rate with the applicable reference fraud rate for that exemption threshold range in accordance with paragraph 3 of this Article.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Monitoring</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/21" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/21" id="article-21">
                  <Pnumber>Article 21</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/21/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/21/1" id="article-21-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>In order to make use of the exemptions set out in Articles 10 to 18, payment service providers shall record and monitor the following data for each type of payment transactions, with a breakdown for both remote and non-remote payment transactions, at least on a quarterly basis:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the total value of unauthorised or fraudulent payment transactions in accordance with Article 64(2) of Directive (EU) 2015/2366, the total value of all payment transactions and the resulting fraud rate, including a breakdown of payment transactions initiated through strong customer authentication and under each of the exemptions;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the average transaction value, including a breakdown of payment transactions initiated through strong customer authentication and under each of the exemptions;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>the number of payment transactions where each of the exemptions was applied and their percentage in respect of the total number of payment transactions.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/21/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/21/2" id="article-21-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall make the results of the monitoring in accordance with paragraph 1 available to competent authorities and to EBA, with prior notification to the relevant competent authority(ies), upon their request.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
         </EUChapter>
         <EUChapter DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/IV" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/IV" NumberOfProvisions="6" id="chapter-IV" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
            <Number>CHAPTER IV</Number>
            <Title>
               <Strong>CONFIDENTIALITY AND INTEGRITY OF THE PAYMENT SERVICE USERS' PERSONALISED SECURITY CREDENTIALS</Strong>
            </Title>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>General requirements</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/22" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/22" id="article-22">
                  <Pnumber>Article 22</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/22/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/22/1" id="article-22-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall ensure the confidentiality and integrity of the personalised security credentials of the payment service user, including authentication codes, during all phases of the authentication.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/22/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/22/2" id="article-22-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>personalised security credentials are masked when displayed and are not readable in their full extent when input by the payment service user during the authentication;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>personalised security credentials in data format, as well as cryptographic materials related to the encryption of the personalised security credentials are not stored in plain text;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>secret cryptographic material is protected from unauthorised disclosure.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/22/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/22/3" id="article-22-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall fully document the process related to the management of cryptographic material used to encrypt or otherwise render unreadable the personalised security credentials.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/22/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/22/4" id="article-22-4">
                        <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall ensure that the processing and routing of personalised security credentials and of the authentication codes generated in accordance with Chapter II take place in secure environments in accordance with strong and widely recognised industry standards.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Creation and transmission of credentials</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/23" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/23" id="article-23">
                  <Pnumber>Article 23</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall ensure that the creation of personalised security credentials is performed in a secure environment.</Text>
                  </P1para>
                  <P1para>
                     <Text>They shall mitigate the risks of unauthorised use of the personalised security credentials and of the authentication devices and software following their loss, theft or copying before their delivery to the payer.</Text>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Association with the payment service user</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/24" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/24" id="article-24">
                  <Pnumber>Article 24</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/24/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/24/1" id="article-24-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall ensure that only the payment service user is associated, in a secure manner, with the personalised security credentials, the authentication devices and the software.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/24/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/24/2" id="article-24-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>For the purpose of paragraph 1, payment service providers shall ensure that each of the following requirements is met:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>the association of the payment service user's identity with personalised security credentials, authentication devices and software is carried out in secure environments under the payment service provider's responsibility comprising at least the payment service provider's premises, the internet environment provided by the payment service provider or other similar secure websites used by the payment service provider and its automated teller machine services, and taking into account risks associated with devices and underlying components used during the association process that are not under the responsibility of the payment service provider;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>the association by means of a remote channel of the payment service user's identity with the personalised security credentials and with authentication devices or software is performed using strong customer authentication.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Delivery of credentials, authentication devices and software</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/25" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/25" id="article-25">
                  <Pnumber>Article 25</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/25/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/25/1" id="article-25-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>Payment service providers shall ensure that the delivery of personalised security credentials, authentication devices and software to the payment service user is carried out in a secure manner designed to address the risks related to their unauthorised use due to their loss, theft or copying.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/25/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/25/2" id="article-25-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>For the purpose of paragraph 1, payment service providers shall at least apply each of the following measures:</Text>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                              <P3para>
                                 <Text>effective and secure delivery mechanisms ensuring that the personalised security credentials, authentication devices and software are delivered to the legitimate payment service user;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                              <P3para>
                                 <Text>mechanisms that allow the payment service provider to verify the authenticity of the authentication software delivered to the payment services user by means of the internet;</Text>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                              <P3para>
                                 <Text>arrangements ensuring that, where the delivery of personalised security credentials is executed outside the premises of the payment service provider or through a remote channel:</Text>
                              </P3para>
                              <P3para>
                                 <OrderedList Type="roman" Decoration="parens">
                                    <ListItem NumberOverride="(i)">
                                       <Para>
                                          <Text>no unauthorised party can obtain more than one feature of the personalised security credentials, the authentication devices or software when delivered through the same channel;</Text>
                                       </Para>
                                    </ListItem>
                                    <ListItem NumberOverride="(ii)">
                                       <Para>
                                          <Text>the delivered personalised security credentials, authentication devices or software require activation before usage;</Text>
                                       </Para>
                                    </ListItem>
                                 </OrderedList>
                              </P3para>
                           </P3>
                           <P3>
                              <Pnumber PuncBefore="(" PuncAfter=")">d</Pnumber>
                              <P3para>
                                 <Text>arrangements ensuring that, in cases where the personalised security credentials, the authentication devices or software have to be activated before their first use, the activation shall take place in a secure environment in accordance with the association procedures referred to in Article 24.</Text>
                              </P3para>
                           </P3>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Renewal of personalised security credentials</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/26" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/26" id="article-26">
                  <Pnumber>Article 26</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall ensure that the renewal or re-activation of personalised security credentials adhere to the procedures for the creation, association and delivery of the credentials and of the authentication devices in accordance with Articles 23, 24 and 25.</Text>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Destruction, deactivation and revocation</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/27" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/27" id="article-27">
                  <Pnumber>Article 27</Pnumber>
                  <P1para>
                     <Text>Payment service providers shall ensure that they have effective processes in place to apply each of the following security measures:</Text>
                  </P1para>
                  <P1para>
                     <OrderedList Type="alpha" Decoration="parens">
                        <ListItem NumberOverride="(a)">
                           <Para>
                              <Text>the secure destruction, deactivation or revocation of the personalised security credentials, authentication devices and software;</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(b)">
                           <Para>
                              <Text>where the payment service provider distributes reusable authentication devices and software, the secure re-use of a device or software is established, documented and implemented before making it available to another payment services user;</Text>
                           </Para>
                        </ListItem>
                        <ListItem NumberOverride="(c)">
                           <Para>
                              <Text>the deactivation or revocation of information related to personalised security credentials stored in the payment service provider's systems and databases and, where relevant, in public repositories.</Text>
                           </Para>
                        </ListItem>
                     </OrderedList>
                  </P1para>
               </P1>
            </P1group>
         </EUChapter>
         <EUChapter DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/V" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/V" NumberOfProvisions="9" id="chapter-V" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
            <Number>CHAPTER V</Number>
            <Title>
               <Strong>COMMON AND SECURE OPEN STANDARDS OF COMMUNICATION</Strong>
            </Title>
            <EUSection DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/V/section/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/V/section/1" NumberOfProvisions="2" id="chapter-V-section-1" RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Number>
                  <Expanded>Section 1</Expanded>
               </Number>
               <Title>
                  <Strong>
                     <Expanded>General requirements for communication</Expanded>
                  </Strong>
               </Title>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Requirements for identification</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/28" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/28" id="article-28">
                     <Pnumber>Article 28</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/28/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/28/1" id="article-28-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>Payment service providers shall ensure secure identification when communicating between the payer's device and the payee's acceptance devices for electronic payments, including but not limited to payment terminals.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/28/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/28/2" id="article-28-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>Payment service providers shall ensure that the risks of misdirection of communication to unauthorised parties in mobile applications and other payment services users' interfaces offering electronic payment services are effectively mitigated.</Text>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Traceability</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/29" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/29" id="article-29">
                     <Pnumber>Article 29</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/29/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/29/1" id="article-29-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>Payment service providers shall have processes in place which ensure that all payment transactions and other interactions with the payment services user, with other payment service providers and with other entities, including merchants, in the context of the provision of the payment service are traceable, ensuring knowledge <Emphasis>ex post</Emphasis> of all events relevant to the electronic transaction in all the various stages.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/29/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/29/2" id="article-29-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>For the purpose of paragraph 1, payment service providers shall ensure that any communication session established with the payment services user, other payment service providers and other entities, including merchants, relies on each of the following:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>a unique identifier of the session;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>security mechanisms for the detailed logging of the transaction, including transaction number, timestamps and all relevant transaction data;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                                 <P3para>
                                    <Text>timestamps which shall be based on a unified time-reference system and which shall be synchronised according to an official time signal.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
            </EUSection>
            <EUSection DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/V/section/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/V/section/2" NumberOfProvisions="7" id="chapter-V-section-2" RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Number>
                  <Expanded>Section 2</Expanded>
               </Number>
               <Title>
                  <Strong>
                     <Expanded>Specific requirements for the common and secure open standards of communication</Expanded>
                  </Strong>
               </Title>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>General obligations for access interfaces</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/30" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/30" id="article-30">
                     <Pnumber>Article 30</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/30/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/30/1" id="article-30-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers that offer to a payer a payment account that is accessible online shall have in place at least one interface which meets each of the following requirements:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>account information service providers, payment initiation service providers and payment service providers issuing card-based payment instruments are able to identify themselves towards the account servicing payment service provider;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>account information service providers are able to communicate securely to request and receive information on one or more designated payment accounts and associated payment transactions;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                                 <P3para>
                                    <Text>payment initiation service providers are able to communicate securely to initiate a payment order from the payer's payment account and receive all information on the initiation of the payment transaction and all information accessible to the account servicing payment service providers regarding the execution of the payment transaction.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/30/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/30/2" id="article-30-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>For the purposes of authentication of the payment service user, the interface referred to in paragraph 1 shall allow account information service providers and payment initiation service providers to rely on all the authentication procedures provided by the account servicing payment service provider to the payment service user.</Text>
                           </P2para>
                           <P2para>
                              <Text>The interface shall at least meet all of the following requirements:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>a payment initiation service provider or an account information service provider shall be able to instruct the account servicing payment service provider to start the authentication based on the consent of the payment service user;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>communication sessions between the account servicing payment service provider, the account information service provider, the payment initiation service provider and any payment service user concerned shall be established and maintained throughout the authentication;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                                 <P3para>
                                    <Text>the integrity and confidentiality of the personalised security credentials and of authentication codes transmitted by or through the payment initiation service provider or the account information service provider shall be ensured.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/30/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/30/3" id="article-30-3">
                           <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers shall ensure that their interfaces follow standards of communication which are issued by international or European standardisation organisations.</Text>
                           </P2para>
                           <P2para>
                              <Text>Account servicing payment service providers shall also ensure that the technical specification of any of the interfaces is documented specifying a set of routines, protocols, and tools needed by payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments for allowing their software and applications to interoperate with the systems of the account servicing payment service providers.</Text>
                           </P2para>
                           <P2para>
                              <Text>Account servicing payment service providers shall at a minimum, and no less than 6 months before the application date referred to in Article 38(2), or before the target date for the market launch of the access interface when the launch takes place after the date referred to in Article 38(2), make the documentation available, at no charge, upon request by authorised payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments or payment service providers that have applied to their competent authorities for the relevant authorisation, and shall make a summary of the documentation publicly available on their website.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/30/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/30/4" id="article-30-4">
                           <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                           <P2para>
                              <Text>In addition to paragraph 3, account servicing payment service providers shall ensure that, except for emergency situations, any change to the technical specification of their interface is made available to authorised payment initiation service providers, account information service providers and payment service providers issuing card-based payment instruments, or payment service providers that have applied to their competent authorities for the relevant authorisation, in advance as soon as possible and not less than 3 months before the change is implemented.</Text>
                           </P2para>
                           <P2para>
                              <Text>Payment service providers shall document emergency situations where changes were implemented and make the documentation available to competent authorities on request.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/30/5" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/30/5" id="article-30-5">
                           <Pnumber PuncBefore="" PuncAfter=".">5</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers shall make available a testing facility, including support, for connection and functional testing to enable authorised payment initiation service providers, payment service providers issuing card-based payment instruments and account information service providers, or payment service providers that have applied for the relevant authorisation, to test their software and applications used for offering a payment service to users. This testing facility should be made available no later than 6 months before the application date referred to in Article 38(2) or before the target date for the market launch of the access interface when the launch takes place after the date referred to in Article 38(2).</Text>
                           </P2para>
                           <P2para>
                              <Text>However, no sensitive information shall be shared through the testing facility.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/30/6" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/30/6" id="article-30-6">
                           <Pnumber PuncBefore="" PuncAfter=".">6</Pnumber>
                           <P2para>
                              <Text>Competent authorities shall ensure that account servicing payment service providers comply at all times with the obligations included in these standards in relation to the interface(s) that they put in place. In the event that an account servicing payment services provider fails to comply with the requirements for interfaces laid down in these standards, competent authorities shall ensure that the provision of payment initiation services and account information services is not prevented or disrupted to the extent that the respective providers of such services comply with the conditions defined under Article 33(5).</Text>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Access interface options</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/31" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/31" id="article-31">
                     <Pnumber>Article 31</Pnumber>
                     <P1para>
                        <Text>Account servicing payment service providers shall establish the interface(s) referred to in Article 30 by means of a dedicated interface or by allowing the use by the payment service providers referred to in Article 30(1) of the interfaces used for authentication and communication with the account servicing payment service provider's payment services users.</Text>
                     </P1para>
                  </P1>
               </P1group>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Obligations for a dedicated interface</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/32" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/32" id="article-32">
                     <Pnumber>Article 32</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/32/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/32/1" id="article-32-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>Subject to compliance with Article 30 and 31, account servicing payment service providers that have put in place a dedicated interface shall ensure that the dedicated interface offers at all times the same level of availability and performance, including support, as the interfaces made available to the payment service user for directly accessing its payment account online.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/32/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/32/2" id="article-32-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers that have put in place a dedicated interface shall define transparent key performance indicators and service level targets, at least as stringent as those set for the interface used by their payment service users both in terms of availability and of data provided in accordance with Article 36. Those interfaces, indicators and targets shall be monitored by the competent authorities and stress-tested.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/32/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/32/3" id="article-32-3">
                           <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers that have put in place a dedicated interface shall ensure that this interface does not create obstacles to the provision of payment initiation and account information services. Such obstacles, may include, among others, preventing the use by payment service providers referred to in Article 30(1) of the credentials issued by account servicing payment service providers to their customers, imposing redirection to the account servicing payment service provider's authentication or other functions, requiring additional authorisations and registrations in addition to those provided for in Articles 11, 14 and 15 of Directive (EU) 2015/2366, or requiring additional checks of the consent given by payment service users to providers of payment initiation and account information services.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/32/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/32/4" id="article-32-4">
                           <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                           <P2para>
                              <Text>For the purpose of paragraphs 1 and 2, account servicing payment service providers shall monitor the availability and performance of the dedicated interface. Account servicing payment service providers shall publish on their website quarterly statistics on the availability and performance of the dedicated interface and of the interface used by its payment service users.</Text>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Contingency measures for a dedicated interface</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33" id="article-33">
                     <Pnumber>Article 33</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33/1" id="article-33-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers shall include, in the design of the dedicated interface, a strategy and plans for contingency measures for the event that the interface does not perform in compliance with Article 32, that there is unplanned unavailability of the interface and that there is a systems breakdown. Unplanned unavailability or a systems breakdown may be presumed to have arisen when five consecutive requests for access to information for the provision of payment initiation services or account information services are not replied to within 30 seconds.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33/2" id="article-33-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>Contingency measures shall include communication plans to inform payment service providers making use of the dedicated interface of measures to restore the system and a description of the immediately available alternative options payment service providers may have during this time.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33/3" id="article-33-3">
                           <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                           <P2para>
                              <Text>Both the account servicing payment service provider and the payment service providers referred to in Article 30(1) shall report problems with dedicated interfaces as described in paragraph 1 to their respective competent national authorities without delay.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33/4" id="article-33-4">
                           <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                           <P2para>
                              <Text>As part of a contingency mechanism, payment service providers referred to in Article 30(1) shall be allowed to make use of the interfaces made available to the payment service users for the authentication and communication with their account servicing payment service provider, until the dedicated interface is restored to the level of availability and performance provided for in Article 32.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33/5" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33/5" id="article-33-5">
                           <Pnumber PuncBefore="" PuncAfter=".">5</Pnumber>
                           <P2para>
                              <Text>For this purpose, account servicing payment service providers shall ensure that the payment service providers referred to in Article 30(1) can be identified and can rely on the authentication procedures provided by the account servicing payment service provider to the payment service user. Where the payment service providers referred to in Article 30(1) make use of the interface referred to in paragraph 4 they shall:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>take the necessary measures to ensure that they do not access, store or process data for purposes other than for the provision of the service as requested by the payment service user;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>continue to comply with the obligations following from Article 66(3) and Article 67(2) of Directive (EU) 2015/2366 respectively;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                                 <P3para>
                                    <Text>log the data that are accessed through the interface operated by the account servicing payment service provider for its payment service users, and provide, upon request and without undue delay, the log files to their competent national authority;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">d</Pnumber>
                                 <P3para>
                                    <Text>duly justify to their competent national authority, upon request and without undue delay, the use of the interface made available to the payment service users for directly accessing its payment account online;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">e</Pnumber>
                                 <P3para>
                                    <Text>inform the account servicing payment service provider accordingly.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33/6" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33/6" id="article-33-6">
                           <Pnumber PuncBefore="" PuncAfter=".">6</Pnumber>
                           <P2para>
                              <Text>Competent authorities, after consulting EBA to ensure a consistent application of the following conditions, shall exempt the account servicing payment service providers that have opted for a dedicated interface from the obligation to set up the contingency mechanism described under paragraph 4 where the dedicated interface meets all of the following conditions:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>it complies with all the obligations for dedicated interfaces as set out in Article 32;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>it has been designed and tested in accordance with Article 30(5) to the satisfaction of the payment service providers referred to therein;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                                 <P3para>
                                    <Text>it has been widely used for at least 3 months by payment service providers to offer account information services, payment initiation services and to provide confirmation on the availability of funds for card-based payments;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">d</Pnumber>
                                 <P3para>
                                    <Text>any problem related to the dedicated interface has been resolved without undue delay.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/33/7" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/33/7" id="article-33-7">
                           <Pnumber PuncBefore="" PuncAfter=".">7</Pnumber>
                           <P2para>
                              <Text>Competent authorities shall revoke the exemption referred to in paragraph 6 where the conditions (a) and (d) are not met by the account servicing payment service providers for more than 2 consecutive calendar weeks. Competent authorities shall inform EBA of this revocation and shall ensure that the account servicing payment service provider establishes, within the shortest possible time and at the latest within 2 months, the contingency mechanism referred to in paragraph 4.</Text>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Certificates</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/34" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/34" id="article-34">
                     <Pnumber>Article 34</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/34/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/34/1" id="article-34-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>For the purpose of identification, as referred to in Article 30(1)(a), payment service providers shall rely on qualified certificates for electronic seals as referred to in Article 3(30) of Regulation (EU) No 910/2014 or for website authentication as referred to in Article 3(39) of that Regulation.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/34/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/34/2" id="article-34-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>For the purpose of this Regulation, the registration number as referred to in the official records in accordance with Annex III (c) or Annex IV (c) to Regulation (EU) No 910/2014 shall be the authorisation number of the payment service provider issuing card-based payment instruments, the account information service providers and payment initiation service providers, including account servicing payment service providers providing such services, available in the public register of the home Member State pursuant to Article 14 of Directive (EU) 2015/2366 or resulting from the notifications of every authorisation granted under Article 8 of Directive 2013/36/EU of the European Parliament and of the Council<FootnoteRef Ref="f00004"/> in accordance with Article 20 of that Directive.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/34/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/34/3" id="article-34-3">
                           <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                           <P2para>
                              <Text>For the purposes of this Regulation, qualified certificates for electronic seals or for website authentication referred to in paragraph 1 shall include, in a language customary in the sphere of international finance, additional specific attributes in relation to each of the following:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>the role of the payment service provider, which maybe one or more of the following:</Text>
                                 </P3para>
                                 <P3para>
                                    <OrderedList Type="roman" Decoration="parens">
                                       <ListItem NumberOverride="(i)">
                                          <Para>
                                             <Text>account servicing;</Text>
                                          </Para>
                                       </ListItem>
                                       <ListItem NumberOverride="(ii)">
                                          <Para>
                                             <Text>payment initiation;</Text>
                                          </Para>
                                       </ListItem>
                                       <ListItem NumberOverride="(iii)">
                                          <Para>
                                             <Text>account information;</Text>
                                          </Para>
                                       </ListItem>
                                       <ListItem NumberOverride="(iv)">
                                          <Para>
                                             <Text>issuing of card-based payment instruments;</Text>
                                          </Para>
                                       </ListItem>
                                    </OrderedList>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>the name of the competent authorities where the payment service provider is registered.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/34/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/34/4" id="article-34-4">
                           <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                           <P2para>
                              <Text>The attributes referred to in paragraph 3 shall not affect the interoperability and recognition of qualified certificates for electronic seals or website authentication.</Text>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Security of communication session</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/35" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/35" id="article-35">
                     <Pnumber>Article 35</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/35/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/35/1" id="article-35-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers, payment service providers issuing card-based payment instruments, account information service providers and payment initiation service providers shall ensure that, when exchanging data by means of the internet, secure encryption is applied between the communicating parties throughout the respective communication session in order to safeguard the confidentiality and the integrity of the data, using strong and widely recognised encryption techniques.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/35/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/35/2" id="article-35-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>Payment service providers issuing card-based payment instruments, account information service providers and payment initiation service providers shall keep the access sessions offered by account servicing payment service providers as short as possible and they shall actively terminate any such session as soon as the requested action has been completed.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/35/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/35/3" id="article-35-3">
                           <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                           <P2para>
                              <Text>When maintaining parallel network sessions with the account servicing payment service provider, account information service providers and payment initiation service providers shall ensure that those sessions are securely linked to relevant sessions established with the payment service user(s) in order to prevent the possibility that any message or information communicated between them could be misrouted.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/35/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/35/4" id="article-35-4">
                           <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                           <P2para>
                              <Text>Account information service providers, payment initiation service providers and payment service providers issuing card-based payment instruments with the account servicing payment service provider shall contain unambiguous references to each of the following items:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>the payment service user or users and the corresponding communication session in order to distinguish several requests from the same payment service user or users;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>for payment initiation services, the uniquely identified payment transaction initiated;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                                 <P3para>
                                    <Text>for confirmation on the availability of funds, the uniquely identified request related to the amount necessary for the execution of the card-based payment transaction.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/35/5" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/35/5" id="article-35-5">
                           <Pnumber PuncBefore="" PuncAfter=".">5</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers, account information service providers, payment initiation service providers and payment service providers issuing card-based payment instruments shall ensure that where they communicate personalised security credentials and authentication codes, these are not readable, directly or indirectly, by any staff at any time.</Text>
                           </P2para>
                           <P2para>
                              <Text>In case of loss of confidentiality of personalised security credentials under their sphere of competence, those providers shall inform without undue delay the payment services user associated with them and the issuer of the personalised security credentials.</Text>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
               <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
                  <Title>Data exchanges</Title>
                  <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/36" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/36" id="article-36">
                     <Pnumber>Article 36</Pnumber>
                     <P1para>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/36/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/36/1" id="article-36-1">
                           <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                           <P2para>
                              <Text>Account servicing payment service providers shall comply with each of the following requirements:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>they shall provide account information service providers with the same information from designated payment accounts and associated payment transactions made available to the payment service user when directly requesting access to the account information, provided that this information does not include sensitive payment data;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>they shall, immediately after receipt of the payment order, provide payment initiation service providers with the same information on the initiation and execution of the payment transaction provided or made available to the payment service user when the transaction is initiated directly by the latter;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">c</Pnumber>
                                 <P3para>
                                    <Text>they shall, upon request, immediately provide payment service providers with a confirmation in a simple ‘yes’ or ‘no’ format, whether the amount necessary for the execution of a payment transaction is available on the payment account of the payer.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/36/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/36/2" id="article-36-2">
                           <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                           <P2para>
                              <Text>In case of an unexpected event or error occurring during the process of identification, authentication, or the exchange of the data elements, the account servicing payment service provider shall send a notification message to the payment initiation service provider or the account information service provider and the payment service provider issuing card-based payment instruments which explains the reason for the unexpected event or error.</Text>
                           </P2para>
                           <P2para>
                              <Text>Where the account servicing payment service provider offers a dedicated interface in accordance with Article 32, the interface shall provide for notification messages concerning unexpected events or errors to be communicated by any payment service provider that detects the event or error to the other payment service providers participating in the communication session.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/36/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/36/3" id="article-36-3">
                           <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                           <P2para>
                              <Text>Account information service providers shall have in place suitable and effective mechanisms that prevent access to information other than from designated payment accounts and associated payment transactions, in accordance with the user's explicit consent.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/36/4" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/36/4" id="article-36-4">
                           <Pnumber PuncBefore="" PuncAfter=".">4</Pnumber>
                           <P2para>
                              <Text>Payment initiation service providers shall provide account servicing payment service providers with the same information as requested from the payment service user when initiating the payment transaction directly.</Text>
                           </P2para>
                        </P2>
                        <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/36/5" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/36/5" id="article-36-5">
                           <Pnumber PuncBefore="" PuncAfter=".">5</Pnumber>
                           <P2para>
                              <Text>Account information service providers shall be able to access information from designated payment accounts and associated payment transactions held by account servicing payment service providers for the purposes of performing the account information service in either of the following circumstances:</Text>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">a</Pnumber>
                                 <P3para>
                                    <Text>whenever the payment service user is actively requesting such information;</Text>
                                 </P3para>
                              </P3>
                              <P3>
                                 <Pnumber PuncBefore="(" PuncAfter=")">b</Pnumber>
                                 <P3para>
                                    <Text>where the payment service user does not actively request such information, no more than four times in a 24-hour period, unless a higher frequency is agreed between the account information service provider and the account servicing payment service provider, with the payment service user's consent.</Text>
                                 </P3para>
                              </P3>
                           </P2para>
                        </P2>
                     </P1para>
                  </P1>
               </P1group>
            </EUSection>
         </EUChapter>
         <EUChapter DocumentURI="http://www.legislation.gov.uk/eur/2018/389/chapter/VI" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/chapter/VI" NumberOfProvisions="2" id="chapter-VI" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
            <Number>CHAPTER VI</Number>
            <Title>
               <Strong>FINAL PROVISIONS</Strong>
            </Title>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Review</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/37" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/37" id="article-37">
                  <Pnumber>Article 37</Pnumber>
                  <P1para>
                     <Text>Without prejudice to Article 98(5) of Directive (EU) 2015/2366, EBA shall review by 14 March 2021 the fraud rates referred to in the Annex to this Regulation as well as the exemptions granted under Article 33(6) in relation to dedicated interfaces and, if appropriate, submit draft updates thereto to the Commission in accordance with Article 10 of Regulation (EU) No 1093/2010.</Text>
                  </P1para>
               </P1>
            </P1group>
            <P1group RestrictStartDate="2017-11-27" RestrictExtent="E+W+S+N.I.">
               <Title>Entry into force</Title>
               <P1 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/38" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/38" id="article-38">
                  <Pnumber>Article 38</Pnumber>
                  <P1para>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/38/1" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/38/1" id="article-38-1">
                        <Pnumber PuncBefore="" PuncAfter=".">1</Pnumber>
                        <P2para>
                           <Text>This Regulation shall enter into force on the day following that of its publication in the <Emphasis>Official Journal of the European Union</Emphasis>.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/38/2" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/38/2" id="article-38-2">
                        <Pnumber PuncBefore="" PuncAfter=".">2</Pnumber>
                        <P2para>
                           <Text>This Regulation shall apply from 14 September 2019.</Text>
                        </P2para>
                     </P2>
                     <P2 DocumentURI="http://www.legislation.gov.uk/eur/2018/389/article/38/3" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/article/38/3" id="article-38-3">
                        <Pnumber PuncBefore="" PuncAfter=".">3</Pnumber>
                        <P2para>
                           <Text>However, paragraphs 3 and 5 of Article 30 shall apply from 14 March 2019.</Text>
                        </P2para>
                     </P2>
                  </P1para>
               </P1>
            </P1group>
         </EUChapter>
         <SignedSection DocumentURI="http://www.legislation.gov.uk/eur/2018/389/signature" IdURI="http://www.legislation.gov.uk/id/eur/2018/389/signature" RestrictExtent="E+W+S+N.I." RestrictStartDate="2017-11-27">
            <Para>
               <Text>This Regulation shall be binding in its entirety and directly applicable in all Member States.</Text>
            </Para>
            <Signatory>
               <Para>
                  <Text>Done at Brussels, 27 November 2017.</Text>
               </Para>
               <Signee>
                  <Para>
                     <Text>
                        <Emphasis>For the Commission</Emphasis>
                     </Text>
                  </Para>
                  <Para>
                     <Text>
                        <Emphasis>The President</Emphasis>
                     </Text>
                  </Para>
                  <Para>
                     <Text>Jean-Claude <Uppercase>Juncker</Uppercase>
                     </Text>
                  </Para>
               </Signee>
            </Signatory>
         </SignedSection>
      </EUBody></EURetained><Footnotes><Footnote id="f00004">
         <FootnoteText>
            <Para>
               <Text>Directive 2013/36/EU of the European Parliament and of the Council of 26 June 2013 on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing Directives 2006/48/EC and 2006/49/EC (<Citation id="c00004" Class="EuropeanUnionOfficialJournal" Year="2013" URI="https://webarchive.nationalarchives.gov.uk/eu-exit/https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:OJ.L_.2013.176.01.0338.01.ENG" Date="2013-06-27">OJ L 176, 27.6.2013, p. 338</Citation>).</Text>
            </Para>
         </FootnoteText>
      </Footnote></Footnotes></Legislation>