Reference⚖️ Disputes & chargebacksBeginner⏱ 13 min read

🙋 Cardholder disputes

Disputing a transaction: the process with your bank, PSD2 time limits, fraud refunds, fraud versus commercial disputes, and escalation options

Disputing a transaction: the process

The cardholder's point of entry is always their own bank (the issuer), never the card network or the merchant's acquirer. The process then depends on the nature of the problem: an unauthorized transaction (fraud) or one that was authorized but is disputed (goods not received, a subscription that wasn't canceled, and so on). That initial classification determines which legal regime applies and how long the cardholder has to dispute.

Typical fraud dispute process
Cardholder
Spots the suspicious transaction
statement, real-time alert from the banking app
Cardholder
Blocks the card if it has been compromised
banking app, France's interbank card-blocking line 0 892 705 705, or the bank, immediately
Cardholder
Files a written dispute with the bank
dispute form, exact list of the transactions disputed
Issuer
Refunds the unauthorized transaction
immediately, and by the end of the next business day at the latest (L133-18 CMF)
Cardholder
Reports the fraud on Perceval
service-public.fr, keep the receipt; the report does not replace the dispute with the bank
  • Blocking ≠ disputing: blocking stops future use of the card; a dispute seeks a refund for past transactions. A compromised card needs both.
  • Perceval (a French Gendarmerie platform launched in 2018) lets cardholders report card fraud without filing a police complaint in person, as long as they still have the card; some banks ask for the receipt.
  • Commercial dispute: the bank has no legal obligation to refund, but it can initiate a chargeback under the card network's rules. The cardholder must then provide proof of the steps already taken with the merchant (emails, a refund request).
ℹ️
Never share a code or a text message
A transaction approved with strong customer authentication (an app code, biometrics) at the request of a fraudster on the phone (the “fake bank advisor” scam) is still legally unauthorized if the consent was obtained by deception. Banks then typically argue gross negligence by the cardholder, and the burden of proving it falls on the bank. Approving a payment at someone else's direction therefore shifts the argument to the cardholder's conduct, with all the uncertainty of how that conduct will be judged. The only complete protection is never to approve a payment someone else dictates.

The legal time limits to know

Dispute time limits are set by France's Monetary and Financial Code (CMF), which transposes PSD2. These legal time limits differ from the ones card networks apply to chargebacks, and the two regimes run in parallel. The bank must accept a dispute filed within the legal time limit even if the 120-day chargeback window has passed. It then absorbs the loss itself if it can no longer recover the funds from the acquirer.

CaseSettlement timeLegal basisNotes
Unauthorized card transaction, payee's PSP in the EEA13 months from the debit dateArt. L133-24 CMFHard deadline: after that, no recourse through the bank
Unauthorized transaction, payee's PSP outside the EEA70 daysArt. L133-24 para. 2 CMFCan be extended by contract to up to 120 days
Authorized SEPA direct debit (no-questions-asked refund)8 weeks after the debitArt. L133-25 CMF / SDD Core rulebookRefund within 10 business days, no reason required
Unauthorized SEPA direct debit13 monthsArt. L133-24 CMFNo mandate, or mandate revoked
SEPA B2B direct debitNo right to a refundSDD B2B rulebookBank checks the mandate before debiting
Commercial dispute (network chargeback)~120 days (540 max for delayed delivery)Visa/Mastercard/CB rulesNot a legal right: a contractual network mechanism
Dispute time limits by situation
🔑
13 months: a hard bar, not a limitation period
After 13 months without a report, the cardholder is time-barred. The bank can then refuse any refund, even for proven fraud. The clock starts on the debit date, not when the transaction is discovered, so it keeps running while the fraud goes unnoticed. Banks routinely invoke this deadline against late disputes over small, recurring fraudulent charges, which only a monthly or more frequent review of statements will catch in time.

Fraud refunds under the law

A refund is legally due when two conditions are met. The transaction must be unauthorized, and it must be reported within the time limit. The bank must then refund it “immediately after noting or being notified of the transaction, and in any event no later than the end of the following business day” (Article L133-18 CMF). The account is restored to the state it would have been in without the disputed transaction, including fees and overdraft interest, with the original value date. The only exception is when the bank suspects the cardholder of fraud, and it must notify the Banque de France (France's central bank) of that suspicion in writing.

  • €50 liability cap (L133-19): the cardholder bears at most €50 of the losses incurred before blocking the card when the card is lost or stolen and its security credentials are used, unless the loss could not be detected or was the bank's fault. The cardholder bears nothing after the card is blocked, or when the card details are misused while the card stays in the cardholder's possession (remote fraud).
  • Burden of proof on the bank (L133-23): the bank must prove that the transaction was authenticated and correctly recorded, and that the cardholder was grossly negligent. Use of the registered card is not, on its own, proof of negligence.
  • Gross negligence: assessed case by case. Responding to crude phishing (spelling mistakes, an obviously fake URL) has been held to be gross negligence (Cass. com., January 18, 2017). By contrast, being fooled by spoofing of the bank's official phone number is not (Cass. com., October 23, 2024), and the bank must refund.
  • No strong authentication: if the bank did not require SCA where PSD2 mandated it, it cannot claim the cardholder was negligent (L133-19 V), and the refund is owed, period.
⚠️
Refusing with “you approved it, so it was you” is unlawful
France's highest court, the Cour de cassation, has held since at least a January 18, 2017, ruling (No. 15-18.102), reaffirmed on November 21, 2018 (No. 17-18.888), that use of the authentication device alone proves neither fraud nor gross negligence by the cardholder. A bank that refuses a refund must provide factual evidence (inconsistent statements, account history, circumstances). In practice, a significant share of initial refusals are overturned by the ombudsman or the courts.
€496M
card payment fraud in France in 2023
OSMP, 2024 annual report
~70 %
share of card fraud on remote payments
OSMP
D+1 business day
maximum legal time to refund an unauthorized transaction
Art. L133-18 CMF

Fraud or commercial dispute: the key distinction

Which legal regime applies turns on a single question: did the cardholder authorize the transaction? An authorized transaction that went wrong (a parcel that never arrived, a subscription that wasn't properly canceled, goods not as described) gives no legal right to a refund from the bank. It falls under consumer law and must be resolved with the merchant. A network chargeback, which the bank may initiate but is not required to, can potentially help resolve it.

Disputed transactiononly one question: was it authorized?noyesNOT authorized (fraud)Art. L133-18 et seq., French Monetary Code (PSD2)Authorized but disputedprivate scheme rules13 months (70 days outside the EEA)Mandatory refundby D+1 business day at the latestBurden of proof: the bankL133-23: gross negligence must be proven€50 maximum liability before the card is reported (L133-19)deadline set by the scheme, not by lawNo right to a refundchargeback at the issuer's discretionProof of prior attempts to resolveemails, refund requestSignalConso · consumer mediator · courtrecasting it as fraud = criminal deception (Art. 313-1, French Penal Code)Statutory regime (PSD2)Contractual regimethe bank's obligationBlocking a card isn't disputing a charge: one stops future payments, the other refunds past ones.
Fraud (unauthorized)Commercial dispute (authorized)
Legal basisLaw: L133-18 et seq. CMF (PSD2)Private network rules + consumer law
RefundsMandatory, by D+1 business day at the latestNo right; chargeback at the bank's discretion
Settlement time13 months (EEA) / 70 days (outside the EEA)~120 days (network rules)
Evidence requiredA simple statement (burden of proof on the bank)Prior steps taken with the merchant, supporting documents
Who ultimately bears the lossThe bank (or the merchant via chargeback if the payment was not 3DS-authenticated)The merchant, if the chargeback succeeds
Two very different regimes
⚠️
Claiming fake fraud is itself fraud
Claiming “I didn't make this purchase” to get a refund for a purchase you actually made, or that a family member made, is fraud under Article 313-1 of the French Criminal Code (Code pénal), punishable by up to 5 years in prison and a €375,000 fine. It can also get the account closed. Issuers now cross-check merchant data (Order Insight, Consumer Clarity) and spot repeat abusive disputes.

If the bank refuses: escalating the dispute

A refusal opens a tiered series of remedies, from the bank's complaints department all the way to the courts. An initial refusal does not end the dispute. The process is gradual, free up to and including the ombudsman, and statistically favors cardholders acting in good faith when the bank cannot document gross negligence.

  • Written complaint to customer service, then to the bank's complaints department (under PSD2, a reply is due within 15 business days for a payment dispute, or 35 business days at most in exceptional cases).
  • Banking ombudsman (contact details must appear on statements and the bank's website): free to use if the bank's answer is unsatisfactory or has not arrived after 2 months; an opinion is normally issued within 90 days. Banks follow the ombudsman's opinion in the vast majority of cases.
  • ACPR (France's banking supervisor): it does not rule on individual disputes, but a documented report feeds into its reviews of refund practices. File one alongside the other steps, not instead of them.
  • Courts: the tribunal judiciaire (France's general civil court), or its local chamber depending on the amount, within the 5-year limitation period (Article 2224 of the Civil Code). The 13-month reporting bar still applies.
ℹ️
For commercial disputes
Claims against the merchant follow their own ladder. It starts with a formal demand letter, followed by a report on SignalConso, the platform run by France's consumer protection authority (DGCCRF). Next comes the sector's consumer ombudsman (the FEVAD ombudsman for e-commerce), then the civil courts. A chargeback and a civil claim can run in parallel, but a double refund obtained through both routes must be paid back.
Typical escalation after a refusal
Cardholder
Written complaint with supporting arguments
cite L133-18/L133-23, attach the Perceval receipt
Bank
Reply within 15 business days
the refusal is often upheld at this stage
Ombudsman
Opinion within ~90 days
free, suspends the limitation period
Court
Court action if that fails
case law favors cardholders in spoofing cases or when SCA was missing

Elsewhere in the world. The same mechanism, elsewhere.

How long a cardholder has to dispute an unauthorized transaction

Regulation 74 of the Payment Services Regulations 2017 keeps the 13-month limit: users are entitled to redress only if they report the unauthorized or incorrectly executed transaction without undue delay, and in any case no later than 13 months after the debit date.

The Payment Services Regulations 2017 (SI 2017/752), reg. 74, https://www.legislation.gov.uk/uksi/2017/752/part/7

The deadline is much shorter and runs from the statement, not the debit. Under Regulation E (12 CFR 1005.6), consumers must report an unauthorized transaction that appears on a periodic statement within 60 days after the statement is sent. After that, they are liable for transactions made after the 60-day period if the bank shows those transactions would have been prevented by a timely report.

CFPB, Regulation E, 12 CFR § 1005.6, https://www.consumerfinance.gov/rules-policy/regulations/1005/6/

India

The Reserve Bank of India counts in working days, not months. Customers have zero liability when the fraud stems from a third-party breach and they notify their bank within 3 working days. Liability is capped for reports made within 4 to 7 working days. Beyond that, it depends on the policy approved by the bank's board. The bank must credit the account within 10 working days of the report, with the value date of the disputed transaction.

Reserve Bank of India, circular DBR.No.Leg.BC.78/09.07.005/2017-18 of July 6, 2017, https://www.rbi.org.in/commonman/english/scripts/Notification.aspx?Id=2336

Australia

ASIC's ePayments Code sets no hard cutoff. The account holder is liable only if the provider proves, on the balance of probability, that the holder contributed to the loss by unreasonably delaying reporting the compromise (clause 11.5). Even then, the holder is liable only for losses incurred between the time they became aware of the compromise (or reasonably should have) and the time they reported it.

ASIC, ePayments Code (June 2022), clauses 10.3 and 11.5, https://download.asic.gov.au/media/lloeicwb/epayments-code-published-02-june-2022.pdf

How much of a fraud loss the cardholder bears

Regulation 77 of the Payment Services Regulations 2017 caps the payer's liability at £35 for unauthorized transactions resulting from a lost, stolen, or misappropriated payment instrument. The payer owes nothing after notification, when the provider failed to require strong customer authentication where it was mandatory, or when the instrument was used in connection with a distance contract.

The Payment Services Regulations 2017 (SI 2017/752), reg. 77, https://www.legislation.gov.uk/uksi/2017/752/regulation/77

Two regimes apply, depending on the instrument. Credit cards: the cardholder's liability is limited to $50 or the amount charged before notification, whichever is lower (Regulation Z, 12 CFR 1026.12(b)). Debit cards and electronic fund transfers: $50 if the consumer reports within 2 business days of learning of the loss, $500 if they report later, and unlimited liability for transfers made after the 60-day period following the statement (Regulation E, 12 CFR 1005.6).

CFPB, Regulation Z, 12 CFR § 1026.12(b), https://www.consumerfinance.gov/rules-policy/regulations/1026/12/

India

For a report made between the 4th and 7th working day, the customer's liability is capped by account type: ₹25,000 for other current accounts and credit cards with a limit above ₹5 lakh, ₹10,000 for savings accounts, prepaid instruments, and credit cards with lower limits, and ₹5,000 for a basic savings bank deposit (BSBD) account.

Reserve Bank of India, circular DBR.No.Leg.BC.78/09.07.005/2017-18 of July 6, 2017, https://www.rbi.org.in/commonman/english/scripts/Notification.aspx?Id=2336

Australia

When a passcode was required to make the transaction, clause 11.7 of the ePayments Code limits the holder's liability to the lowest of three amounts: $150, the balance available in the account (including any prearranged credit), or the actual loss at the time of the report, excluding any portion above the daily transaction limits. Clause 11.8(b) states that access to the account with the correct device and passcode does not, on its own, prove that the user contributed to the loss.

ASIC, ePayments Code (June 2022), clauses 11.7 and 11.8, https://download.asic.gov.au/media/lloeicwb/epayments-code-published-02-june-2022.pdf

Refunds for fraud where the customer approved the payment (bank impersonation, manipulation)

Since October 7, 2024, reimbursement has been mandatory for victims of authorized push payment (APP) scams on Faster Payments and CHAPS, covering consumers, microenterprises, and charities. Reimbursement is capped at £85,000 per claim, in line with the Financial Services Compensation Scheme limit. The gross negligence exception is interpreted narrowly, the provider bears the burden of proof, and the exception does not apply to vulnerable customers.

Payment Systems Regulator, PS24/7, https://www.psr.org.uk/publications/policy-statements/ps247-faster-payments-app-scams-reimbursement-requirement-confirming-the-maximum-level-of-reimbursement/

Singapore

The Shared Responsibility Framework from the MAS and IMDA, in force since December 16, 2024, covers phishing scams in which consumers are tricked into handing over their credentials. Responsibility follows a waterfall: the financial institution first, then the telecom operator, and each must compensate the victim if it breached its own duties. If both met their duties, the framework requires no payout.

Monetary Authority of Singapore, Guidelines on Shared Responsibility Framework, https://www.mas.gov.sg/regulation/guidelines/guidelines-on-shared-responsibility-framework

Australia

The Scams Prevention Framework Act 2025, enacted on February 20, 2025, sets no reimbursement schedule. Instead, it requires designated sectors (banks, telecom operators, digital platforms) to prevent, detect, disrupt, respond to, and report scams, with fines of up to A$50 million.

Scams Prevention Framework Act 2025, https://www.legislation.gov.au/C2025A00015/asmade; Treasury, “Scams Prevention Framework,” https://treasury.gov.au/publication/p2025-623966