OB-AIS-006PSR 36(5a)Account information

Holder name and identifier are not sensitive

What the text fixes

For AISPs and PISPs, the account owner's name and the account's unique identifier are not sensitive payment data.

Article
PSR 36(5a)Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.
Who is bound
ASPSP, AISP, PISP
Who it is for
Compliance, API
Application
21 months after entry into force, the general application date (Article 112).
Level 2
No EBA mandate covers this obligation.
Origin
New, with no equivalent in PSD2 or in the 2018 RTS.

STET 1.6.3

Out of spec

The text classifies the data and describes no exchange. In STET, holder names depend on the owners access sent with PUT /consents.

Handbook pages

Sources

Checked on October 4, 2026

The entry as JSON
{
  "id": "OB-AIS-006",
  "article": "PSR 36(5a)",
  "alsoIn": [],
  "articleFinal": null,
  "actors": [
    "aspsp",
    "aisp",
    "pisp"
  ],
  "roles": [
    "compliance",
    "api"
  ],
  "appliesAt": "T+21",
  "title": {
    "fr": "Nom du titulaire et identifiant ne sont pas sensibles",
    "en": "Holder name and identifier are not sensitive",
    "es": "El nombre del titular y el identificador no son sensibles",
    "pt-br": "Nome do titular e identificador não são sensíveis"
  },
  "level1": {
    "fr": "Pour les AISP et les PISP, le nom du titulaire et l'identifiant unique du compte ne sont pas des données de paiement sensibles.",
    "en": "For AISPs and PISPs, the account owner's name and the account's unique identifier are not sensitive payment data.",
    "es": "Para los AISP y los PISP, el nombre del titular y el identificador único de la cuenta no son datos de pago sensibles.",
    "pt-br": "Para AISPs e PISPs, o nome do titular e o identificador único da conta não são dados de pagamento sensíveis."
  },
  "level2": null,
  "origin": [],
  "stet": {
    "1.6.3": {
      "status": "out-of-scope",
      "note": {
        "fr": "Le texte qualifie la donnée et ne décrit aucun échange. Dans STET, le nom des titulaires dépend de l'accès `owners` transmis avec `PUT /consents`.",
        "en": "The text classifies the data and describes no exchange. In STET, holder names depend on the `owners` access sent with `PUT /consents`.",
        "es": "El texto califica el dato y no describe ningún intercambio. En STET, el nombre de los titulares depende del acceso `owners` enviado con `PUT /consents`.",
        "pt-br": "O texto qualifica o dado e não descreve nenhuma troca. No STET, o nome dos titulares depende do acesso `owners` enviado com `PUT /consents`."
      },
      "pages": [
        "endpoints/aisp/consents-put",
        "endpoints/aisp/accounts-owners-get"
      ]
    }
  },
  "verification": null,
  "sources": [
    {
      "document": "8221/26",
      "page": 247
    }
  ],
  "verifiedAt": "2026-10-04"
}