10.5.2019
EN
Official Journal of the European Union
L 123/19
(7)
Fraud is not only used to fund criminal groups, but also limits the development of the digital single market and
makes citizens more reluctant to make online purchases.
(8)
Common definitions in the areas of fraud and of counterfeiting of non-cash means of payment are important to
ensure a consistent approach in Member States' application of this Directive and to facilitate information
exchange and cooperation between competent authorities. The definitions should cover new types of non-cash
payment instruments which allow for transfers of electronic money and virtual currencies. The definition of noncash payment instruments should acknowledge that a non-cash payment instrument may consist of different
elements acting together, for example a mobile payment application and a corresponding authorisation (e.g.
a password). Where this Directive uses the concept of a non-cash payment instrument, it should be understood
that the instrument puts the holder or user of the instrument in a position to actually enable a transfer of money
or monetary value or to initiate a payment order. For example, unlawfully obtaining a mobile payment
application without the necessary authorisation should not be considered as an unlawful obtainment of a noncash payment instrument as it does not actually enable the user to transfer money or monetary value.
(9)
This Directive should apply to non-cash payment instruments only insofar as the instrument's payment function
is concerned.
(10)
This Directive should cover virtual currencies only insofar as they can be commonly used for making
payments. The Member States should be encouraged to ensure in their national law that future currencies of
a virtual nature issued by their central banks or other public authorities will enjoy the same level of protection
against fraudulent offences as non-cash means of payment in general. Digital wallets that allow the transfer of
virtual currencies should be covered by this Directive to the same extent as non-cash payment instruments. The
definition of the term ‘digital means of exchange’ should acknowledge that digital wallets for transferring virtual
currencies may provide, but do not necessarily provide, the features of a payment instrument and should not
extend the definition of a payment instrument.
(11)
Sending fake invoices to obtain payment credentials should be considered as an attempt at unlawful appropriation
within the scope of this Directive.
(12)
By using criminal law to give legal protection primarily to payment instruments that make use of special forms
of protection against imitation or abuse, the intention is to encourage operators to provide such special forms of
protection to payment instruments issued by them.
(13)
Effective and efficient criminal law measures are essential to protect non-cash means of payment against fraud
and counterfeiting. In particular, a common criminal law approach is needed as regards the constituent elements
of criminal conduct that contribute to or prepare the way for the actual fraudulent use of a non-cash means of
payment. Conduct such as the collection and possession of payment instruments with the intention to commit
fraud, through, for instance, phishing, skimming or directing or redirecting payment service users to imitation
websites, and their distribution, for example by selling credit card information on the internet, should thus be
made a criminal offence in its own right without requiring the actual fraudulent use of a non-cash means of
payment. Such criminal conduct should therefore cover circumstances where possession, procurement or
distribution does not necessarily lead to fraudulent use of such payment instruments. However, where this
Directive criminalises possession or holding, it should not criminalise mere omission. This Directive should not
sanction the legitimate use of a payment instrument, including and in relation to the provision of innovative
payment services, such as services commonly developed by fintech companies.
(14)
With regard to the criminal offences referred to in this Directive, the concept of intent applies to all elements
constituting those criminal offences in accordance with national law. It is possible for the intentional nature of an
act, as well as any knowledge or purpose required as an element of an offence, to be inferred from objective,
factual circumstances. Criminal offences which do not require intent should not be covered by this Directive.
(15)
This Directive refers to classical forms of conduct, like fraud, forgery, theft and unlawful appropriation that had
already been shaped by national law before the era of digitalisation. The extended scope of this Directive with
regard to non-corporeal payment instruments therefore requires the definition of equivalent forms of conduct in
the digital sphere, complementing and reinforcing Directive 2013/40/EU of the European Parliament and of the
Council (4). The unlawful obtainment of a non-corporeal non-cash payment instrument should be a criminal
(4) Directive 2013/40/EU of the European Parliament and of the Council of 12 August 2013 on attacks against information systems and
replacing Council Framework Decision 2005/222/JHA (OJ L 218, 14.8.2013, p. 8).