🎓 CoursesMarkets & internationalIntermediate⏱ 60 min
📅
Making subscriptions work internationally. 7 chapters and a final quiz.
The day-to-day craft of collecting recurring payments across several countries. Choose between a card mandate and a bank mandate based on the full cost of each collected charge, wire and audit a CIT/MIT chain, open a local direct debit rail with the paperwork it requires, enroll a native mandate on e-NACH, UPI AutoPay, PayTo or Pix Automático, and write a retry policy that stays under scheme caps. Then close cleanly: a single cancellation flow, and VAT on digital services.
Choose between a card mandate and a bank mandate market by market, based on the full cost of each collected charge
Wire a CIT/MIT chain and produce the audit that proves, with numbers, that the flagging holds
Open a local direct debit rail: the document to obtain, the format to produce, the notice to give, the return file to process
Enroll a native mandate on e-NACH, UPI AutoPay, PayTo and Pix Automático, and process revocation events
Chapter 1. Choosing the instrument, market by market.
An international subscription business is managed on the full cost of each collected charge, not on the headline transaction price. That cost has four components: the unit price of the movement, first-attempt failures, retries, and the returns reserve. The fourth is the one most often forgotten. Yet it varies the most from one market to the next, because it depends on a local rule, not on a negotiable price list.
Trade-off worksheet: fill it in for each market before choosing a rail
1 Average charge amount ..................... product data
2 Unit price of the movement ................ PSP or bank price list
3 Success rate on the FIRST attempt ......... demand it from the provider
MARKET BY MARKET. A global
average is useless.
4 Cost of one retry attempt ................. PSP price list + bank reject
fees, where there are any
5 Return window of the rail ................. 8 weeks, no reason needed, on
SEPA Direct Debit Core,
13 months if the debit is
disputed as unauthorized
(EPC rulebook);
no cap and no time limit in
the UK (Direct Debit
Guarantee, Pay.UK);
60 calendar days on consumer
ACH (return code R10,
Nacha rules);
none on Pix Automatico
(Banco Central do Brasil)
6 Who can stop the series without telling you
card ............... nobody, but the credential dies on its own
SEPA, Bacs ......... the payer's bank, on the payer's instruction
PayTo, Pix Automatico,
UPI AutoPay ........ the payer, self-service
FULL COST OF ONE COLLECTED CHARGE
= 2
+ (1 - 3) x average number of retries x 4
+ returns reserve applied to 1
Market
Recurring rail to wire
Operator, since
Who can stop the series
What the creditor monitors
SEPA area
SEPA Direct Debit Core and B2B
European Payments Council, 2009
The payer's bank, on the payer's instruction
Funds in the account on the presentation date, and mandates lapsing after 36 months without a debit
United Kingdom
Direct Debit on Bacs
Pay.UK, on Vocalink infrastructure (Mastercard), 1968
The payer's bank, which reports it in the ADDACS file
Proof that the advance notice was sent, without which the indemnity claim is lost
United States
ACH debit, SEC codes PPD and WEB
Nacha (rules), FedACH and EPN (clearing), 1972
The account holder, by reporting the debit as unauthorized
The unauthorized return rate, with a Nacha threshold of 0.5%
Brazil
Pix Automático
Banco Central do Brasil, June 16, 2025
The payer, self-service, with immediate effect
Churn, since there is no refund window to reserve for
India
UPI AutoPay and e-NACH
National Payments Corporation of India, 2020 and 2016
The payer, transaction by transaction, from the pre-notification onward
Explicit refusals the day before the debit, as distinct from technical rejects
Australia
PayTo, with BECS direct debit still in service
NPP Australia (Australian Payments Plus), 2022
The payer, in real time, in their banking app
Mandate status changes, the only alert channel available
Singapore
GIRO, with mandates set up through eGIRO
Banking Computer Services, 1984
The payer, through their bank
The domestic rail still dominates recurring bills, despite PayNow
United Arab Emirates
UAEDDS
Central Bank of the UAE, 2012
The payer, by canceling the registered mandate
The mandate lives at the central bank, not in your database
Denmark
Betalingsservice
Mastercard Payment Services, 1974
The payer, through centralized mandate management
The monthly cycle is imposed: the billing date is not yours to choose
Switzerland
LSV+ and Debit Direct
SIX (LSV+) and PostFinance (Debit Direct)
The payer, through their bank
Non-SEPA schemes: the Swiss franc flow is integrated separately from the euro flow
The recurring rail to wire in each market, and who can stop it
🔑
Three questions decide the rail, and price comes fourth
Three questions decide the choice of rail: who can stop the series, how quickly you find out, and how long the money collected can still be clawed back. A cheap rail with an eight-week return window ties up more cash than an expensive rail that settles same-day. Redo the calculation every time you open a country. A global average decides nothing.
The decision tree, in the order the questions come up
1. Ticket size
Compare the charge amount with the unit price of the movement
A small monthly ticket copes badly with a fixed per-transaction fee. A large ticket copes badly with a failure.
➜
2. Audience
Separate consumer payers from business payers
SDD B2B removes the refund right. In return, the mandate must be registered with the debtor's bank before the first debit.
➜
3. Country
Look for the rail the payer recognizes, not the one your team knows
In Australia, India or Brazil, a direct debit form asks payers for a step they no longer take.
➜
4. Returns
Put a number on how long the money can still be clawed back
It sets the reserve, and therefore the working capital requirement. Eight weeks, 60 days, no time limit, or none at all: four different balance sheets.
➜
5. Exit
Check how you find out that a customer has stopped the series
A return file, a real-time event, or just a reject on the next due date. The answer drives the entire retry mechanism.
35.2B
ACH payments in the US in 2025, payroll and debits combined
Nacha, 2026
5.0B
Direct Debit payments in the UK in 2025
Pay.UK, 2025 annual statistics
117 000
*service users* registered with UK Direct Debit at the end of 2025
Pay.UK
79.8B
Pix transactions in Brazil in 2025, on the rail that carries Pix Automático
Banco Central do Brasil, via ClearingPost, 2026
The trade-off rarely yields a single instrument. It yields a combination, with an order of presentation. The domestic rail goes first wherever it dominates recurring billing, and cards remain the fallback for payers without a local account. A global program therefore ends up with several rails wired in, each with its own success rate, return window and reserve. The discipline lies in measuring them separately.
🎯 Quick question
Two rails quote the same unit price. One settles same-day with no right of return; the other exposes you to eight weeks of no-questions-asked refunds. What separates them economically?
Chapter 2. Wiring the card mandate, then proving it holds.
The card mandate appears in no national statute. It is created by an authenticated transaction and then kept alive by a reference. That reference is the only proof of the mandate the issuer ever receives, and it travels in every subsequent authorization: the Transaction ID at Visa, the Trace ID at Mastercard. A program that cannot measure how often it appears in its own authorizations is flying blind.
The chain audit, to run on one month of authorizations
SELECT
marche,
psp,
COUNT(*) AS echeances,
AVG(reference_chainee IS NOT NULL) AS part_chainee,
AVG(indicateur_mit IS NOT NULL) AS part_marquee,
AVG(mode_saisie = 10) AS part_credential_stocke,
AVG(approuvee) AS taux_acceptation
FROM autorisations
WHERE type_operation = 'echeance_abonnement'
GROUP BY marche, psp;
-- How to read the result
--
-- part_chainee < 1
-- part of the card base has lost its original reference.
-- Most frequent cause: a provider migration.
--
-- part_marquee < part_chainee
-- the reference is stored but not sent. That is an
-- integration defect, not a data defect.
--
-- taux_acceptation gap between chained and unchained rows
-- this figure, in percentage points, is the annual cost of the defect.
-- It is the only argument that unlocks an integration budget.
The acceptance test plan for a card mandate
Authenticated enrollment CIT: check that the response actually carries the chaining identifier, and that the identifier is saved before anything is returned to the user.
First charge as an MIT: the reference comes back, the entry mode indicates a stored credential, and the CVV is absent. Its absence is normal.
A charge with no chaining reference, on purpose: the sandbox must decline it with an authentication-required code, and the alert must fire.
Amount change: the charge leaves the fixed-amount series. The flag must change, or the issuer will read something other than what you think you are sending.
Frequency change: switching from monthly to annual opens a new series. The original reference does not cover it.
Retry after a decline: it carries a separate MIT type, resubmission, and the amount of the original charge.
Reissued card: simulate the update from the scheme's updater service, then replay a charge on the refreshed credential.
Cancellation: the revocation of the stored credential must be verifiable, and the test must confirm that no charge goes out after the effective date.
What changed
What the issuer sees
Measurable symptom
Fix
Provider migration
An unauthenticated card-not-present sale, with no mandate
Success rate collapses on the first cycle after the cutover, with no change to the checkout flow
Require portability of tokens and network references in the contract, before signing
The amount changes
A fixed-amount recurring series contradicted by the message
Declines concentrated on accounts whose price changed the previous month
Reclassify the flag when the price changes, not at the next cycle
Monthly becomes annual
A new series presented as the continuation of an old one
Declines on the first annual charge, even from long-standing customers
Open a new series with an authenticated CIT, and archive the new reference
Usage becomes variable
A threshold-triggered debit presented as a subscription
Disputes citing an unexpected, off-cycle debit
Switch to unscheduled credential on file, never to recurring
Retry with the wrong type
A new sale, not a new attempt
Abnormal consumption of the retry budget, and the fees that come with it
Flag the retry as a resubmission, with the original amount
Five chain breaks, how they show up in production, and how to fix them
⚠️
Negotiate the portability clause before you sign
The chaining identifier belongs to the network, but in practice it is held by the provider that processed the enrollment transaction. A poorly prepared migration loses it across the entire subscriber base, and the success rate collapses on the next cycle. Write into the contract the portability of tokens and of network references, the export format and the delivery deadline. Once you have signed, you have no leverage left.
Region
Applicable law
At enrollment
For subsequent payments
European Economic Area
Delegated Regulation (EU) 2018/389, art. 14; European Banking Authority opinion of June 2019 on merchant-initiated transactions
Strong customer authentication of the payer
None, provided the series is flagged and chained
India
Digital Payments – E-mandate Framework, 2026, Reserve Bank of India
Strong authentication required, no exceptions
Pre-notification 24 hours before each debit; authentication above ₹15,000, raised to ₹1 lakh for insurance premiums, mutual fund subscriptions and credit card bill payments
United States
Nacha rules for ACH; Regulation E (12 CFR 1005) for consumer debits
No strong authentication required; account validation on the first WEB debit
None; the unauthorized-debit return stays open for 60 calendar days
Brazil
Pix Automático, Resolução BCB nº 402 of July 22, 2024
Authorization given in the payer's app
None; cards are not the standard rail for local recurring billing
What card enrollment requires, region by region
That leaves maintenance of the card base. Scheme updater services, such as Visa Account Updater or Mastercard's Automatic Billing Updater, refresh a reissued credential. Network tokens issued under the EMVCo specification survive card reissuance. These tools must be purchased; they do not come with storage. None of them recovers a card the customer has deliberately removed. Their coverage varies by market, so a refresh rate observed in one country cannot be extrapolated to others.
🎯 Quick question
After a switch to a new provider, subscription charges are declined en masse with a code meaning “authentication required,” even though the checkout flow has not changed. What is the most likely cause?
Chapter 3. Opening a local direct debit rail.
A direct debit rail is not opened with an API key but with an application. A bank, an operator or a central bank agrees, or refuses, to let you pull funds from your customers' accounts. The review takes weeks, and it must start while the engineering team is building, never afterward. A plan that schedules the rail opening after technical acceptance testing pushes go-live back by a full quarter.
Market
Document to obtain
Obtained from
What it unlocks
SEPA area
SEPA Creditor Identifier (SCI) and collection agreement
The creditor's bank, following the national allocation procedure
Submit an accepted pain.008, and identify each mandate by the pair SCI + unique mandate reference (UMR)
SEPA area, B2B variant
SDD B2B agreement, in addition to the SCI
The creditor's bank; not every bank offers the scheme
Collect with no refund right, provided the debtor registers the mandate with its own bank
United Kingdom
Service User Number (SUN) and sponsorship agreement
The sponsor bank, or an approved bureau
Submit Bacs files and lodge mandates through AUDDIS
United States
Origination agreement and choice of SEC code
The creditor's bank, acting as Originating Depository Financial Institution
Originate entries into the ACH network; the bank carries the risk and applies its own risk appetite
Netherlands
Incassomachtigen access
Currence, through the creditor's bank
Get the SEPA mandate signed through online banking authentication, with no paper
Singapore
GIRO billing organization application, mandates through eGIRO
Banking Computer Services, through the creditor's bank
Collect on the rail that local recurring bills still mostly use
Sweden
Autogiro agreement
Bankgirot
Collect in Swedish kronor on a domestic rail that was never migrated to SEPA
Denmark
Betalingsservice agreement
Mastercard Payment Services
Join a fixed monthly cycle, with centralized mandate management
United Arab Emirates
UAEDDS mandate registration
The creditor's bank, through the Central Bank of the UAE's system
Replace postdated checks with an electronic mandate
The document to obtain before the first submission, rail by rail
Before the first charge
AUDDIS: lodging the mandate
The mandate is sent to the payer's bank, which accepts or rejects it. A rejected mandate generates no debit, and silence does not mean acceptance.
D-10 business days
Advance notice to payer
The amount and date are notified to the payer. The default notice period is set in the sponsorship agreement.
Day 1
File submission
The file is submitted before the agreed cutoff time. One minute late pushes the charge back by 24 hours.
Day 2
Processing
Bacs sorts the transactions and sends them to the payers' banks.
Day 3
Debit, settlement and ARUDD
The payer's account is debited and the creditor's account credited. The ARUDD file of unpaid items arrives the same day. Treasury plans for it; it should never come as a surprise.
At any time
ADDACS and DDICA
ADDACS reports that the payer has canceled or amended an instruction. DDICA carries indemnity claims under the Direct Debit Guarantee. Both files must be processed automatically.
Same due date, three submission calendars
Shared goal: debit the payer's account on the 5th of the month
SEPA Direct Debit Core
pre-notification ........ 14 calendar days before the debit by default;
can be shortened by agreement with the payer
pain.008 submission ..... no later than D-1 (business day), Core and B2B
interbank return ........ up to 5 business days after settlement in Core,
2 business days in B2B
refund right ............ 8 weeks with no reason, 13 months if unauthorized
Direct Debit on Bacs
advance notice .......... 10 business days by default, set in the
sponsorship agreement
file submission ......... day 1 of a 3-business-day cycle, so
2 business days before the debit date
unpaid items ............ ARUDD file, on settlement day
guarantee ............... Direct Debit Guarantee, no cap and no time limit
ACH debit, SEC codes PPD and WEB
advance notice .......... 10 calendar days before any debit whose
amount differs from the previous one
account validation ...... mandatory on the first WEB debit
unauthorized return ..... code R10, 60 calendar days after settlement
monitoring .............. Nacha threshold of 0.5% unauthorized returns
OPERATIONAL CONSEQUENCE
The billing date is not the debit date. The billing engine must
compute a submission date per rail and per market, then work the
advance notice back from it.
A mandate has a shelf life. In SEPA, it lapses after 36 months without a debit. Reusing it after that exposes you to a reject for an invalid mandate.
The return file is not optional. ARUDD, ADDACS and their equivalents must be processed automatically, or the series keeps running on a dead mandate.
Keep the advance notice. On Bacs, without proof that it was sent, you lose the indemnity claim without any review of the merits.
The local calendar comes first. Betalingsservice imposes a monthly cycle: you don't choose the billing date, you live with it.
European B2B has a condition precedent. If the debtor has not registered the mandate with its bank, the first charge is rejected.
In the US, your counterparty is your bank. There is no standardized creditor identifier and no sequence control: the originating bank carries the risk and sets its own limits.
⚠️
Advance notice turns a surprise debit into an expected one
Announcing the amount and date before each debit is a scheme obligation on Bacs, as it is on SEPA. Its defensive value far exceeds the cost of sending it: an expected debit gets disputed far less often than one discovered on a statement. Store the proof of sending with the charge, not in your email tool, because that is the document you will be asked for.
One last difference sets US ACH apart from every other rail in this chapter. There is no mandate in the European sense: no standardized creditor identifier, no reference carried in the message, no sequence control. What takes its place is an authorization whose form depends on the channel, declared by a three-letter code. The risk sits with the bank that originates the entry into the network.
🎯 Quick question
A UK creditor receives an indemnity claim under the Direct Debit Guarantee. Which document decides the outcome?
On these rails, the mandate no longer lives in your files. It lives in the payer's banking app, where the payer can view, suspend and revoke it in three taps. Settlement is instant, so is collection, and success rates are higher as a result. In exchange, you lose control of the exit channel, which changes how the whole operation runs.
System
Operator, since
Enrollment
What to store
How you learn the series was stopped
UPI AutoPay
National Payments Corporation of India, 2020
In the payer's UPI app, in a few seconds
Mandate ID, cap, frequency
Immediate reject, actionable the same day
e-NACH
National Payments Corporation of India, 2016
Aadhaar, net banking or debit card; a longer flow
Mandate reference, maximum authorized amount
NACH cycle return, with its reason code
PayTo
NPP Australia (Australian Payments Plus), 2022
In the banking app, with the cap and frequency displayed
Agreement ID, cap, frequency, status
Agreement status change, in real time
Pix Automático
Banco Central do Brasil, June 16, 2025
In the payer's app, through one of four defined flows
Authorization ID, declared frequency
Immediate revocation, then rejection of subsequent charges
Four mandates held on the payer's side, and their impact on the creditor
From payment screen to first debit on a native mandate
Merchant
Publishes a mandate request
Payee, cap, frequency, duration, reference. The cap is not the price: it is the price plus the headroom needed for tax and price increases.
➜
Payer
Authorizes in their app
The payer reads the payee name, the cap and the frequency. An unreadable payee name makes the authorization fail before the first debit even happens.
➜
Operator
Returns a mandate ID and a status
This ID replaces the stored credential. Keep it like an accounting record, with its date and source.
➜
Merchant
Initiates the charge within the scheduled window
Pix Automático imposes settlement windows. India's framework requires pre-notification at least 24 hours in advance.
➜
Operator
Settles or rejects immediately
The result is known right away. A retry can therefore go out the same day, which no batch rail allows.
➜
Payer
Suspends or revokes whenever they choose
You find out through a status event, or at the next reject. You are owed no notice.
The mandate object and the events to process, whatever the native rail
MANDATE OBJECT - the minimum to store
mandate_id ............ ID returned by the operator;
never regenerated, never recomputed
rail .................. upi_autopay | enach | payto | pix_automatico
status ................ pending | active | suspended | revoked | expired
cap ................... maximum amount per charge, in local currency
frequency ............. declared at authorization; changing it
requires a new authorization on several rails
valid_until ........... end date; open-ended authorizations are not
available everywhere
last_charge ........... date, amount, outcome
status_source ......... operator event, or inferred after a reject
(log the difference: it matters in a dispute)
EVENTS TO PROCESS, OR YOU BILL INTO THE VOID
mandate.active -> open the service
mandate.suspended -> stop presenting, keep the contract
mandate.revoked -> stop the series AND trigger the product-side
exit flow
mandate.cap_changed -> recompute the charge BEFORE presenting
charge.rejected -> classify the reason before any retry
CLASSIC TRAP
A revoked mandate is not a contract cancellation. Should the service
be cut off? Does the debt keep running? Settle both questions once,
in the terms and conditions, not case by case.
🔑
The mandate cap is a product setting
On PayTo, UPI AutoPay and Pix Automático, the payer authorizes a maximum amount per charge. Set at the exact price, the cap breaks at the first tax or price increase, and the charge is rejected even though nothing changed on your side. Set too high, it makes the payer hesitate at authorization, and enrollment fails. The value is decided with the product and tax teams, not in the code.
Pix Automático is the best-documented case of this generation. The payment instruction goes out 2 to 10 days before the scheduled settlement date. Settlement runs in two mandatory windows: midnight to 8 a.m., then 6 p.m. to 9 p.m., Brasília time. A failure triggers a new attempt the same day, preceded by a notification asking the payer to top up their account, and retries can continue for up to seven days if the authorization allows it.
Ask the local provider for its event catalog, and check that it exposes suspension, not just revocation.
Ask for the propagation delay between the payer's action and the event you receive. It determines how many charges go out into the void.
Check how the cap can be changed: some rails allow it without a new authorization, others do not.
Test the payee name as it appears in the payer's banking app. It is the leading cause of drop-off at enrollment.
In Malaysia, the direct debit component is called DuitNow AutoDebit, operated by Payments Network Malaysia under Bank Negara Malaysia supervision. DuitNow Transfer and FPX are payer-initiated and are no substitute for a mandate.
In the UK, Open Banking Limited's Variable Recurring Payments are live for sweeping. The commercial use case has not yet been rolled out at scale.
🎯 Quick question
A creditor coming from the SEPA world launches in Brazil on Pix Automático. Which risk line should it remove from its model, and which should it add?
Chapter 5. Running dunning across multiple markets.
A failed charge falls into one of three families, and confusing them wrecks a retry policy. If the instrument is dead, no attempt will ever succeed. If it is alive but funds are short, a later attempt stands a chance. If the flag is wrong, the failure comes from the integration, not the payment. Retrying the first family costs money and draws the schemes' attention.
Rail
What the rule allows
What gets charged
Declines never to replay
Card, Visa
Up to 15 attempts in 30 days on a declined transaction
Attempts beyond the cap
Stolen card, invalid number, suspected fraud
Card, Mastercard
A monitoring program for excessive attempts, similar in scope
Excess attempts, under the applicable program
Same hard-decline reasons
SEPA Direct Debit
Re-presentation allowed within rulebook limits, for a temporary reason
Bank reject fees, on both the creditor and debtor side
MD01 invalid mandate, AC04 account closed
ACH
Up to two re-presentments after an R01 (Nacha rules)
Return fees, and a worsening monitored rate
R10, debit reported as unauthorized by the account holder
Direct Debit on Bacs
Depends on the reason code in the ARUDD file
Cycle fees, and your standing with the sponsor bank
Any canceled instruction reported by ADDACS
Pix Automático
Retries for up to seven days if the authorization allows it, with notice to the payer
–
Authorization revoked
UPI AutoPay
Reject known immediately, same-day retry possible
–
Explicit refusal by the payer at pre-notification
What a retry is allowed to do, rail by rail
One retry function, three inputs
input 1: reason family dead_instrument | insufficient_funds | flagging
input 2: rail card | sepa | bacs | ach | native
input 3: market local payday calendar
if family = dead_instrument:
0 attempts.
Repair first: credential update through the scheme's updater service,
new bank details, new mandate. Then, and only then,
present again.
if family = flagging:
0 attempts.
An "authentication required" decline is never replayed: no cardholder
is in session. Fix the integration, then restart the series.
if family = insufficient_funds:
n attempts, with n strictly below the scheme cap,
spaced out and timed to a local payday.
Documented example: in Brazil, wages are due no later than the
fifth business day of the following month
(Consolidacao das Leis do Trabalho, art. 459, par. 1).
in all cases:
notify the payer before retrying;
log the decision AND its reason;
stop as soon as a return file reports a cancellation.
⚠️
The retry cap is a scheme constraint, not a conversion setting
Visa limits retries on a declined transaction to 15 in 30 days, with fees beyond that, and Mastercard runs a comparable monitoring program. Replaying a hard decline exposes you to acquirer penalties. Set your own cap below the network's, and enforce it in code rather than through a team guideline.
Measuring a retry policy
Publish two rates, never one. The first-attempt rate measures the quality of the instrument and the flagging. The post-retry rate measures the policy. The gap between them measures what the policy earns.
Break it down by market, rail and provider. A global average hides exactly the market that is bleeding.
Separate explicit refusals from technical rejects. In India, the payer can refuse a charge after reading the pre-notification, 24 hours before the debit. That is not a funds problem.
Count the cost of attempts, bank reject fees included, and subtract it from the amount recovered. An aggressive policy can post a good rate and still destroy margin.
Track the lag between the return file and stopping the series. Every day of lag produces a charge into the void, then a dispute.
A retry model imported from Europe or the US is built around reject codes. India's framework moves the breaking point: part of the failure happens not at the debit but the day before, when the payer reads the notification. The customer is not short of funds. The customer chooses to refuse, and the remedy is a clearer message, never another attempt.
🎯 Quick question
A card charge is declined with a code meaning “strong authentication required.” What should the retry engine do?
Chapter 6. Building a single exit flow.
Cancellation has changed category. It used to be a customer service matter; it is now a compliance and engineering matter. Several markets require that stopping be as easy as signing up, through the same channel. The laws converge on that principle, and diverge on labels, deadlines and evidence, which differ from one statute to the next.
Market
Legal basis
What it requires
Impact on payments
Germany
§ 312k BGB, known as the Kündigungsbutton, in force since July 1, 2022
A legible, always-accessible “Verträge hier kündigen” button, then a “jetzt kündigen” confirmation
Cancellation becomes a timestamped, legally binding product event, not an email exchange
California
Automatic Renewal Law, as amended by AB 2863
Cancellation through the sign-up channel, an annual reminder, 7 to 30 days' notice before any price change
Applies to contracts entered into, amended, or renewed on or after July 1, 2025
Clear disclosure before billing, express consent, a simple way to stop
The FTC's click-to-cancel rule was vacated by the US Court of Appeals for the Eighth Circuit in July 2025; ROSCA remains the basis for enforcement
European Union
Directive 2011/83/EU on consumer rights
14-day withdrawal period for distance contracts
The right applies to the contract, not the mandate: the mandate must be stopped separately
United Kingdom
Digital Markets, Competition and Consumers Act 2024
A chapter on subscription contracts, whose entry into force depends on implementing regulations
Design the exit flow now, or redo the work in a rush later
Brazil
Código de Defesa do Consumidor, Lei nº 8.078/1990, art. 49; Pix Automático, Resolução BCB nº 402
Seven-day cooling-off period for contracts concluded off-premises; immediate revocation of the authorization from the payer's app
No refund window: the mandate ends, and charges already settled remain final
India
Digital Payments – E-mandate Framework, 2026, Reserve Bank of India
Pre-notification 24 hours before each debit, refusal possible transaction by transaction, revocation with strong authentication
Some churn is triggered the day before the debit, not when the contract term ends
Australia
PayTo rules, NPP Australia
Real-time mandate suspension and revocation in the banking app
The creditor finds out through a status event, or at the next reject
Exit obligations, and what they require of the collection system
The exit flow, from click to mandate shutdown
Customer
Starts the cancellation online
Through the sign-up channel. In Germany, the wording of the button and of the confirmation page is prescribed word for word.
➜
System
Timestamps, confirms, notifies
A written confirmation stating the effective date. It is the first document requested in a subscription dispute.
➜
Fees
Stops the series
No charge goes out after the effective date. Disputes almost always arise in that gap.
➜
Collection
Shuts down the mandate
Revoke the native mandate, delete the direct debit mandate, erase the stored credential. A canceled contract stops nothing on its own.
➜
Instrument
Handles the reverse case
A mandate revoked by the payer is not a cancellation. The contract continues, so does the service, and the amount owed keeps accruing.
One flow, aligned with the strictest regime, with mandatory local wording layered on top.
One effective date, pushed to the billing engine and the collection engine in the same transaction.
A retained enrollment log: timestamp, IP address, version of the terms accepted. It is the document missing from most lost dispute cases.
Shutdown documented in both directions: a cancellation that stops the series, and a mandate revocation that triggers a product decision.
One metric: the time between the cancellation request and the actual end of debits, measured by market.
⚠️
One flow per jurisdiction becomes unmanageable by the third country
The approach that works is to apply the strictest regime everywhere, then add only the mandatory wording locally. German law prescribes its wording word for word, a constraint you handle like a translation. The marginal cost is low. The alternative is paid for in litigation and lost subscription disputes, in the very markets you had planned to deal with later.
This table yields two lessons. First, recent statutes target the flow, not the contract: a button, a confirmation page, an effective date. Second, the law and the plumbing are out of step. Canceling a contract never automatically shuts down a payment mandate, and revoking a mandate cancels no contract. The two breaks therefore call for two treatments, triggered by two separate events.
🎯 Quick question
A software company is launching in Germany. Beyond a contact form, what must its cancellation flow provide?
Chapter 7. VAT on digital services, from the collections side.
Indirect tax is not a month-end issue for the accounting team; it determines the amount debited. A subscription sold at the same pre-tax price produces different charges depending on the customer's country, and that variation runs through the whole chain: card flagging, pre-notification, mandate cap. Treating it as payment data prevents rejects that nothing on the product side can explain.
Market
Applicable regime
Registration threshold
Source
European Union
VAT due at the rate of the consumer's country, reported through the OSS one-stop shop
€10,000 in cross-border sales per year for a seller established in a single member state
Directive 2006/112/EC, art. 58 and 59c; OSS extended on July 1, 2021
United Kingdom
UK VAT registration
No threshold for a business not established in the UK; £90,000 for an established business
gov.uk, accessed August 2026
Switzerland
Swiss VAT register, outside OSS; standard rate 8.1%
CHF 100,000 in annual revenue
Swiss Federal Tax Administration
Australia
GST at 10% on imported digital services and products
A$75,000 in sales over 12 months
Australian Taxation Office, 2026
New Zealand
GST at 15% on remote services
NZ$60,000
Inland Revenue / New Zealand Customs Service
India
OIDAR regime: the foreign supplier registers and collects IGST
Registration required for any foreign supplier serving Indian consumers
IGST Act, 2017
United States
No VAT: sales tax set state by state, and whether software is taxable varies from one state to another
Economic nexus, defined by each state
South Dakota v. Wayfair, US Supreme Court, 2018
Digital services sold to consumers: regime and threshold, market by market
Part of the proof of location comes from the payment chain. Implementing Regulation (EU) No 282/2011 accepts, among other things, the billing address, the IP address, the customer's bank details, the mobile country code of the SIM card and the location of the landline.
Two non-contradictory pieces of evidence are required. Below €100,000 in annual sales of these services, one is enough (Implementing Regulation (EU) 2017/2459, in force since January 1, 2019).
The card's issuing country is tax data. Store it with the subscription, not just with the transaction.
In intra-EU B2B, the customer accounts for the tax under the reverse charge, provided its VAT number has been validated. A failed validation turns a tax-exclusive invoice into a VAT liability.
The price shown to consumers is an all-in price, tax included (Directive 2011/83/EU, art. 6(1)(e)). The amount debited therefore follows the local rate, not the reference price.
The “VAT in the Digital Age” package was adopted through Directive (EU) 2025/516 of March 11, 2025, with milestones phased in from January 1, 2027, and then July 1, 2028.
From price to amount debited, and to the mandate cap
Same offer, same pre-tax price of 20.00 in local currency
Market A, standard rate 20%
pre-tax base ........... 20.00
displayed price ........ 24.00 (all-in price, tax included)
amount debited ......... 24.00
Market B, standard rate 19%
pre-tax base ........... 20.00
displayed price ........ 23.80
amount debited ......... 23.80
TWO CONSEQUENCES FOR COLLECTION
1. The amount debited differs from one market to another for the same offer.
A card series flagged "recurring" at a fixed amount must be declared
PER MARKET. A global declaration misleads the network.
2. A rate increase changes the amount in the middle of a series.
- Card: the fixed-amount flag no longer holds; it must be reclassified.
- SEPA, Bacs: the pre-notification must show the NEW amount.
- ACH: a debit whose amount differs from the previous one requires
10 calendar days of advance notice.
- PayTo, UPI AutoPay, Pix Automatico: the mandate cap must have
been set higher. Otherwise the charge is rejected.
⚠️
A rate increase is a payment incident, not just an accounting entry
When a local tax rate goes up, the charge amount goes up too. On a capped mandate, the charge exceeds the authorized cap and is rejected. On a card series flagged as fixed-amount, the flag becomes wrong. On a rail that requires advance notice, the notice must go out again with the new amount. Put rate changes on the payments team's calendar, just like a price increase.
That leaves the merchant of record trade-off, in which a third party becomes the official seller and handles tax compliance for you. The gain is real in markets you don't want to take on yourself. In exchange, the statement descriptor becomes theirs, the disputes belong to them and the mandate is signed in their name, so the portability of your subscriber base disappears with the contract.
🎯 Quick question
A software company sells a subscription in Australia on a PayTo mandate capped at the exact charge amount. What happens if the price goes up?