# OB-AIS-007 — The AISP accesses designated accounts only

> The AISP accesses only information from designated accounts and their transactions, with mechanisms that prevent any other access, in line with the user's consent.

- Article: PSR 47(1)(d) (See also PSR 47(1)(e))
- Who is bound: AISP
- Who it is for: API, Audit and pentest
- Application: 21 months after entry into force, the general application date (Article 112).
- Level 2: No EBA mandate covers this obligation.
- Origin: PSD2, Art. 67(2)(d); RTS 2018/389, Art. 36(3)

Provisional numbering of the April 2026 compromise (Council doc. 8221/26). The final numbering will be added when the Official Journal publishes the text, without changing the id.

## STET 1.6.3: Covered

`PUT /consents` lists, for each data type, the accounts the user designated, and the bank uses it to limit access.

- <https://openfinanceguide.com/en/stet/1.6.3/endpoints/aisp/consents-put>
- <https://openfinanceguide.com/en/stet/1.6.3/flows/6-2-consent-forwarding>

## Sources

- [Council doc. 8221/26, page 269](https://data.consilium.europa.eu/doc/document/ST-8221-2026-INIT/en/pdf#page=269)

Checked on 2026-10-04. https://openfinanceguide.com/en/dsp3/obligations/ob-ais-007
