# OB-AIS-006 — Holder name and identifier are not sensitive

> For AISPs and PISPs, the account owner's name and the account's unique identifier are not sensitive payment data.

- Article: PSR 36(5a)
- Who is bound: ASPSP, AISP, PISP
- Who it is for: Compliance, API
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: No EBA mandate covers this obligation.
- Origin: New, with no equivalent in PSD2 or in the 2018 RTS.

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: Out of spec

The text classifies the data and describes no exchange. In STET, holder names depend on the `owners` access sent with `PUT /consents`.

- <https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put>
- <https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/accounts-owners-get>

## Sources

- [Council doc. 8221/26, page 247](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=247)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-ais-006
