16 March 2023
We have made minor amendments to some provisions of the Code of Practice under Paragraph 6.4.51* in order to address typographical errors and provide additional clarity.
These changes do not alter the meaning of the Code provisions that have been amended or place any further obligations on providers.
Requirements 3.9.9 and 3.10.9
The reference in these paragraphs to ‘third-party content verification’ is a typographical error and has been changed to ‘third-party consent verification’ as originally intended.
The amended wording of Requirement 3.9.9 is as follows:
“Intermediary providers have contracts in place that allow them to suspend or terminate their relationships with merchant providers, or third-party content consent verification providers where they discover the existence of activities that do not comply with one or more provisions of this Code, or where they reasonably suspect that any such non-compliant activities have occurred or are occurring.”
The amended wording of Requirement 3.10.9 is as follows:
“Intermediary providers must have contracts in place that allow them to suspend or terminate a payment facility to any merchant provider or third-party content consent verification platform:
a. on the basis of a technical security threat or issue; and/or
b. where they discover the existence of activities that do not comply with one or more provisions of this Code, or where they reasonably suspect that any such non-compliant activities have occurred or are occurring.”
Requirement 5.3.5
Warning Letters generally include action plans and therefore we are clarifying that PSA may publish either or both as necessary and proportionate.
The correct wording of Requirement 5.3.5. is as follows:
“The PSA may publish warning letters and/or action plans (or any extract taken therefrom) where it considers that it would be necessary and proportionate to do so in order to prevent or reduce potential or actual harm to consumers. Before it publishes any document under this paragraph, the PSA will:
a) send a notice to the relevant PRS provider providing details of the warning letters and/or action plans (or any extracts therefrom) which it proposes to publish, and setting out in brief the PSA’s reasons for proposing to publish it;
b) specify a reasonable period (not shorter than two working days but not longer than 10 working days) for the relevant PRS provider to make representations;
c) consider any representations made within the specified period, paying particular regard to any representations concerning any potential prejudicial effect of any such publication on any relevant persons;
d) decide whether and how to publish the warning letters and/or action plans (or any extracts therefrom) in an appropriate manner and form, taking into account any representations made.
The PSA will not publish any confidential information under this paragraph.”
Requirement 5.5.3 refers to Requirement 5.7.6 which allows an associated individual to either request an oral hearing as at 5.7.6 (a) or require an oral hearing as at 5.7.6 (b). For clarity we have amended 5.5.3 to clearly indicate both types of request are available under 5.7.6.
The correct wording of Requirement 5.5.3 is as follows:
Where an oral hearing is requested or required under paragraph 5.7.6 below, but before the matter is determined by a Tribunal, the Relevant Party and the PSA may seek to reach agreement on:
b. any admissions concerning the alleged breaches; and/or
c. any agreement over sanctions that might be imposed by the Tribunal.
The list of criteria defining a network operator lacked an “or” at the end of D.1.4(c). For clarity this has been added to more clearly indicate that for an organisation to meet the criteria of a network only one of the criteria at D.1.4(a)-(d) need be met. Similarly, at D.1.4(e) the words “any of” have been added to make clear that it applies where any of the criteria at D.1.4(a)-(d) are met. In addition, as the text at D.1.4(e) is separate to the criteria at D.1.4(a)-(d) the sub-bullet letter “(e)” has been removed so that the text stands as a separate paragraph within D.1.4.
The correct wording of paragraph D.1.4 is as follows:
“Subject to paragraphs D.1.5 and D.1.6 below, network operator means, for the purposes of this Code and in respect of any PRS, a person who falls within section 120(10) or 120(11) of the Act and:
b. has a direct network connection and has direct billing arrangements in respect of that connection with the lead network;
c. through arrangements made with a lead network, provides electronic communications services to the public and bills the public directly; or,
d. through arrangements made with a person falling within sub-paragraphs D.1.4(a)-(c):
i. provides electronic communications services to other PRS providers;
ii. terminates PRS calls on their platform; and
iii. can perform or can require the performance of the Standards and Requirements set out in Section 3 of this Code.
A direct network connection exists when a person provides switching equipment (to currently accepted industry standards), which by interconnection arrangements made between that person and the lead network, enables the conveyance of signals between the lead network and that person.”
Annex 2, 2.3(p)
Finally, Annex 2, 2.3(p) as published, required intermediary and merchant providers to evidence only the policies and procedures in place that manage due diligence and risk assessment. However, this lacked the specificity to also evidence ‘control on clients’. Paragraph 3.9.6 requires that intermediaries have full due diligence, risk assessment and control (DDRAC) policies in place and Paragraph 3.9.12 requires intermediaries to ensure that any persons they contract with, including merchants include DDRAC obligations in their own contracts. Therefore, this amendment does not place further obligation on providers, but merely clarifies that control on clients must also be evidenced.
The amended wording of Annex 2, 2.3(p) is as follows:
“p. documentation evidencing the policies and procedures the intermediary provider or merchant provider has in place to manage due diligence and risk assessment DDRAC, as required by paragraph 3.9.6 of the Code, or as required contractually under paragraph 3.9.12 of the Code, respectively.”
*Paragraph 6.4.5 of Code 15 enables the PSA to make minor clarificatory changes that do not alter the substance and meaning of a provision without the need for consultation or approval by Ofcom. Paragraph 6.4.5 requires the PSA to publish any such changes in order to bring them to the attention of those likely to be affected by them.