Civil Law And Unauthorized Payment Transaction Disputes In Europe .

Civil Law and Unauthorised Payment Transaction Disputes in Europe

Jurisdiction: European Union payment-services framework, with French case-law examples

An unauthorised payment dispute arises when money leaves a customer’s account without legally valid consent. Examples include stolen-card payments, fraudulent online transfers, account takeover and payments initiated through a forged mandate.

The main legal questions are whether the customer consented, what the payment provider can prove, whether the customer breached security obligations, and who must bear the loss.

The EU framework provides substantial common protection, but national implementing legislation and procedural rules remain important. European countries outside the EU require separate examination.

1. Legal framework

The principal EU instrument is Directive (EU) 2015/2366, commonly called PSD2, as implemented nationally. Its relevant provisions include:

ProvisionSubject
Article 64Consent and withdrawal of consent.
Article 69Customer obligations concerning payment instruments and security credentials.
Article 71Notification of unauthorised or incorrectly executed transactions.
Article 72Evidence of authentication and execution.
Article 73Provider’s refund obligations.
Article 74Customer’s potential liability.
Article 97Strong customer authentication.

For covered transactions, the customer generally must notify the provider without undue delay after discovery and within 13 months of the debit, subject to the statutory information exception.

Unauthorised payments generally require an immediate refund, at the latest by the end of the following business day after discovery or notification. A specified exception applies where the provider has reasonable grounds to suspect fraud and communicates them in writing to the relevant authority. The account must ordinarily be restored to its position without the transaction. EUR-Lex

2. Authentication is different from authorisation

Authentication concerns verification through the payment system—for example, a password, device, biometric check or one-time code.

Authorisation concerns the payer’s consent to the transaction.

Successful authentication does not necessarily establish authorisation. A fraudster may obtain credentials, register a device or exploit an account-recovery process. Conversely, a customer may genuinely instruct a payment after being deceived about its purpose.

PSD2 requires the provider to prove that a disputed transaction was authenticated, accurately recorded and unaffected by a relevant technical deficiency. Recorded use of an instrument does not necessarily prove consent, fraud or gross negligence; supporting evidence is required for the latter allegations. EUR-Lex

A court should therefore examine what was approved, rather than merely whether a code was entered.

3. Unauthorised payments versus authorised scam payments

This distinction often determines the available remedy.

SituationCentral issue
Fraudster initiates a transfer after taking over an accountWhether the customer consented to that transfer.
Customer approves registration of a beneficiary, believing it is a security measureWhether this amounted to consent to the subsequent payment.
Customer deliberately instructs a transfer to a supposed supplier who is a fraudsterWhether it was an authorised payment induced by deception.
Agent uses a disputed or forged power of attorneyWhether valid authority and consent existed.

Being defrauded does not automatically make a payment unauthorised. An authorised scam payment may require a different claim, such as one based on a specific national reimbursement scheme, contractual duty or alleged negligence.

Equally, approving a login or adding a beneficiary does not necessarily authorise every later transfer. The facts and agreed consent procedure matter.

4. Customer liability and gross negligence

Under PSD2, a customer may bear up to €50 for certain losses involving a lost, stolen or misappropriated instrument, subject to exceptions. This is not a universal deductible.

Broader liability can arise from customer fraud or an intentional or grossly negligent breach of specified security obligations. Where the provider does not require strong customer authentication, Article 74 generally protects the payer from financial loss unless the payer acted fraudulently. Protection also ordinarily applies after notification of loss or misuse, subject to the fraud exception. EUR-Lex

Gross negligence requires assessment of the circumstances. Relevant questions may include the warnings displayed, the apparent identity of the caller, the clarity of a payment prompt and whether the customer disclosed credentials despite obvious signs of fraud.

Neither “the customer shared information” nor “the customer was deceived” resolves the issue by itself.

5. Six relevant case laws

Several judgments below interpret the earlier Payment Services Directive, Directive 2007/64, rather than PSD2. They remain important for corresponding concepts, but current disputes require comparison with the legislation applicable on the transaction date.

A. DenizBank AG v Verein für Konsumenteninformation — Case C-287/19, judgment of 11 November 2020

Background: A consumer organisation challenged terms concerning contactless functionality on multifunction bank cards.

Decision: The Court treated the relevant NFC functionality as a payment instrument and examined PSD2’s special derogations for low-value instruments. A provider relying on an inability to block an instrument must satisfy the statutory conditions; merely describing blocking as impossible is insufficient.

Relevance: Contactless transactions require careful examination of the applicable low-value rules and contract terms. The judgment does not establish that every contactless payment is exempt from ordinary refund protection. EUR-Lex

B. DM and LR v Caisse régionale de Crédit agricole mutuel, Alpes-Provence — Case C-337/20, judgment of 2 September 2021

Background: The proceedings concerned allegedly unauthorised transactions and arguments raised in litigation involving a payment-service user and a guarantor.

Decision: The Court held that the user could not bypass the harmonised notification and liability framework through an alternative national liability claim. It distinguished the guarantor, who was not a payment-service user and whose ordinary-law claim was not excluded on the same basis.

Relevance: A claimant cannot assume that relabelling a payment dispute as ordinary contractual negligence avoids the statutory regime. The identity and legal position of the claimant also matter. EUR-Lex

C. ZG v Beobank SA — Case C-351/21, judgment of 16 March 2023

Background: A customer disputed debit-card transactions and sought information identifying the recipients.

Decision: The Court held that the provider must supply information enabling identification of the payee. The obligation was not merely to make reasonable efforts and provide information only if those efforts succeeded.

Relevance: Meaningful transaction information helps customers determine whether they approved a payment and investigate suspicious debits. The judgment addressed an information obligation; it did not automatically establish that every disputed payment in the proceedings was unauthorised. EUR-Lex

D. UA v Eurobank Bulgaria — Case C-409/22, judgment of 11 July 2024

Background: Payments were executed through a power of attorney presented as a notarised document bearing an apostille. The account holder disputed its validity and the resulting consent.

Decision: Formal regularity of the document was insufficient to presume authorisation. The provider had to demonstrate that the customer had validly expressed agreement through the consent procedure agreed with the provider.

Relevance: Documentary authentication is not conclusive proof of genuine authority. Banks must distinguish an apparently regular mandate from actual consent to dispose of the customer’s funds. EUR-Lex

E. Cour de cassation, Commercial Chamber, 25 October 2017 — Appeal No. 16-11.644, France

Background: A customer disclosed card and telephone-account information in response to phishing. Those details enabled misuse of the payment system.

Decision: The Court held that the lower court had not sufficiently examined whether the customer could have recognised the fraudulent message and whether disclosure amounted to gross negligence.

Relevance: The court must assess the actual deception and the customer’s conduct. The ruling did not establish that every response to phishing constitutes gross negligence; it required a fuller factual assessment. Légifrance

F. Cour de cassation, Commercial Chamber, 23 October 2024 — Appeal No. 23-16.267, France

Background: A fraudster impersonated a bank employee, with the bank adviser’s number appearing on the customer’s phone. The customer was persuaded to validate beneficiary changes supposedly needed to protect the account. Fraudulent transfers totalled €54,500.

Decision: The Court upheld the finding that gross negligence had not been established. It emphasised the provider’s burden of proof and the deceptive circumstances that placed the customer in apparent contact with the bank.

Relevance: Caller-ID spoofing and the purpose the customer believed they were approving can materially affect the assessment. This is a fact-sensitive French decision, not an EU-wide rule requiring reimbursement of every telephone scam. Légifrance

6. Evidence needed in litigation

A useful claim file should establish a clear sequence of events:

  • The disputed transactions, amounts and dates.
  • What the customer actually did and intended to approve.
  • When the customer discovered and reported the problem.
  • The bank’s response and reasons for refusing reimbursement.
  • Messages, call records, screenshots and security prompts.
  • Available device-registration, authentication and transaction records.

For the provider, relevant evidence may include the precise approval screen, the amount and payee displayed, authentication results and records of beneficiary or device changes.

A general statement that the system was secure may leave unanswered whether the customer consented to the particular transaction. Likewise, a police complaint records an allegation; it does not by itself decide civil liability.

7. Remedies and procedural routes

The main claim is usually restoration of the account and repayment of the unauthorised amount. Depending on national law and the statutory framework, associated interest, charges or additional compensation may also be available. Further damages require their own legal foundation and proof.

Customers may pursue the provider’s complaint process, an applicable financial ombudsman or alternative dispute-resolution body, and court proceedings. Regulatory complaints and criminal investigations perform different functions from a civil recovery action.

The 13-month notification period is not simply interchangeable with the national court-action limitation period. Both must be checked. Non-consumer contracts can also permit derogations from some protections, so a business account should not automatically be treated like a consumer account.

The strongest analysis separates three questions: Was the payment authorised? Has the provider proved the facts on which it relies? Do the applicable rules place the loss on the provider or the customer?

LEAVE A COMMENT