OB-1.1.13
An AISP must establish account information procedures to ensure:
(a) it does not provide account information services without the customer's explicit consent;
(b) that the customer's personalised security credentials are:
i. not accessible to other parties, with the exception of the issuer of the credentials; and
ii. transmitted through safe and efficient channels;
(c) for each communication session, communicate securely with licensee and the customer in accordance with the regulatory requirements of this Module;
(d) that it does not access any information other than information from designated accounts; and
(e) it cannot and does not use, access or store any information for any purpose except for the provision of the account information service explicitly requested by the customer .
Added: December 2018