Disputing a transaction: the process
The cardholder's point of entry is always their own bank (the issuer), never the card network or the merchant's acquirer. The process then depends on the nature of the problem: an unauthorized transaction (fraud) or one that was authorized but is disputed (goods not received, a subscription that wasn't canceled, and so on). That initial classification determines which legal regime applies and how long the cardholder has to dispute.
- Blocking ≠ disputing: blocking stops future use of the card; a dispute seeks a refund for past transactions. A compromised card needs both.
- Perceval (a French Gendarmerie platform launched in 2018) lets cardholders report card fraud without filing a police complaint in person, as long as they still have the card; some banks ask for the receipt.
- Commercial dispute: the bank has no legal obligation to refund, but it can initiate a chargeback under the card network's rules. The cardholder must then provide proof of the steps already taken with the merchant (emails, a refund request).
The legal time limits to know
Dispute time limits are set by France's Monetary and Financial Code (CMF), which transposes PSD2. These legal time limits differ from the ones card networks apply to chargebacks, and the two regimes run in parallel. The bank must accept a dispute filed within the legal time limit even if the 120-day chargeback window has passed. It then absorbs the loss itself if it can no longer recover the funds from the acquirer.
| Case | Settlement time | Legal basis | Notes |
|---|---|---|---|
| Unauthorized card transaction, payee's PSP in the EEA | 13 months from the debit date | Art. L133-24 CMF | Hard deadline: after that, no recourse through the bank |
| Unauthorized transaction, payee's PSP outside the EEA | 70 days | Art. L133-24 para. 2 CMF | Can be extended by contract to up to 120 days |
| Authorized SEPA direct debit (no-questions-asked refund) | 8 weeks after the debit | Art. L133-25 CMF / SDD Core rulebook | Refund within 10 business days, no reason required |
| Unauthorized SEPA direct debit | 13 months | Art. L133-24 CMF | No mandate, or mandate revoked |
| SEPA B2B direct debit | No right to a refund | SDD B2B rulebook | Bank checks the mandate before debiting |
| Commercial dispute (network chargeback) | ~120 days (540 max for delayed delivery) | Visa/Mastercard/CB rules | Not a legal right: a contractual network mechanism |
Fraud refunds under the law
A refund is legally due when two conditions are met. The transaction must be unauthorized, and it must be reported within the time limit. The bank must then refund it “immediately after noting or being notified of the transaction, and in any event no later than the end of the following business day” (Article L133-18 CMF). The account is restored to the state it would have been in without the disputed transaction, including fees and overdraft interest, with the original value date. The only exception is when the bank suspects the cardholder of fraud, and it must notify the Banque de France (France's central bank) of that suspicion in writing.
- €50 liability cap (L133-19): the cardholder bears at most €50 of the losses incurred before blocking the card when the card is lost or stolen and its security credentials are used, unless the loss could not be detected or was the bank's fault. The cardholder bears nothing after the card is blocked, or when the card details are misused while the card stays in the cardholder's possession (remote fraud).
- Burden of proof on the bank (L133-23): the bank must prove that the transaction was authenticated and correctly recorded, and that the cardholder was grossly negligent. Use of the registered card is not, on its own, proof of negligence.
- Gross negligence: assessed case by case. Responding to crude phishing (spelling mistakes, an obviously fake URL) has been held to be gross negligence (Cass. com., January 18, 2017). By contrast, being fooled by spoofing of the bank's official phone number is not (Cass. com., October 23, 2024), and the bank must refund.
- No strong authentication: if the bank did not require SCA where PSD2 mandated it, it cannot claim the cardholder was negligent (L133-19 V), and the refund is owed, period.
Fraud or commercial dispute: the key distinction
Which legal regime applies turns on a single question: did the cardholder authorize the transaction? An authorized transaction that went wrong (a parcel that never arrived, a subscription that wasn't properly canceled, goods not as described) gives no legal right to a refund from the bank. It falls under consumer law and must be resolved with the merchant. A network chargeback, which the bank may initiate but is not required to, can potentially help resolve it.
| Fraud (unauthorized) | Commercial dispute (authorized) | |
|---|---|---|
| Legal basis | Law: L133-18 et seq. CMF (PSD2) | Private network rules + consumer law |
| Refunds | Mandatory, by D+1 business day at the latest | No right; chargeback at the bank's discretion |
| Settlement time | 13 months (EEA) / 70 days (outside the EEA) | ~120 days (network rules) |
| Evidence required | A simple statement (burden of proof on the bank) | Prior steps taken with the merchant, supporting documents |
| Who ultimately bears the loss | The bank (or the merchant via chargeback if the payment was not 3DS-authenticated) | The merchant, if the chargeback succeeds |
If the bank refuses: escalating the dispute
A refusal opens a tiered series of remedies, from the bank's complaints department all the way to the courts. An initial refusal does not end the dispute. The process is gradual, free up to and including the ombudsman, and statistically favors cardholders acting in good faith when the bank cannot document gross negligence.
- Written complaint to customer service, then to the bank's complaints department (under PSD2, a reply is due within 15 business days for a payment dispute, or 35 business days at most in exceptional cases).
- Banking ombudsman (contact details must appear on statements and the bank's website): free to use if the bank's answer is unsatisfactory or has not arrived after 2 months; an opinion is normally issued within 90 days. Banks follow the ombudsman's opinion in the vast majority of cases.
- ACPR (France's banking supervisor): it does not rule on individual disputes, but a documented report feeds into its reviews of refund practices. File one alongside the other steps, not instead of them.
- Courts: the tribunal judiciaire (France's general civil court), or its local chamber depending on the amount, within the 5-year limitation period (Article 2224 of the Civil Code). The 13-month reporting bar still applies.
Elsewhere in the world. The same mechanism, elsewhere.
How long a cardholder has to dispute an unauthorized transaction
Regulation 74 of the Payment Services Regulations 2017 keeps the 13-month limit: users are entitled to redress only if they report the unauthorized or incorrectly executed transaction without undue delay, and in any case no later than 13 months after the debit date.
The Payment Services Regulations 2017 (SI 2017/752), reg. 74, https://www.legislation.gov.uk/uksi/2017/752/part/7
The deadline is much shorter and runs from the statement, not the debit. Under Regulation E (12 CFR 1005.6), consumers must report an unauthorized transaction that appears on a periodic statement within 60 days after the statement is sent. After that, they are liable for transactions made after the 60-day period if the bank shows those transactions would have been prevented by a timely report.
CFPB, Regulation E, 12 CFR § 1005.6, https://www.consumerfinance.gov/rules-policy/regulations/1005/6/
The Reserve Bank of India counts in working days, not months. Customers have zero liability when the fraud stems from a third-party breach and they notify their bank within 3 working days. Liability is capped for reports made within 4 to 7 working days. Beyond that, it depends on the policy approved by the bank's board. The bank must credit the account within 10 working days of the report, with the value date of the disputed transaction.
Reserve Bank of India, circular DBR.No.Leg.BC.78/09.07.005/2017-18 of July 6, 2017, https://www.rbi.org.in/commonman/english/scripts/Notification.aspx?Id=2336
ASIC's ePayments Code sets no hard cutoff. The account holder is liable only if the provider proves, on the balance of probability, that the holder contributed to the loss by unreasonably delaying reporting the compromise (clause 11.5). Even then, the holder is liable only for losses incurred between the time they became aware of the compromise (or reasonably should have) and the time they reported it.
ASIC, ePayments Code (June 2022), clauses 10.3 and 11.5, https://download.asic.gov.au/media/lloeicwb/epayments-code-published-02-june-2022.pdf
How much of a fraud loss the cardholder bears
Regulation 77 of the Payment Services Regulations 2017 caps the payer's liability at £35 for unauthorized transactions resulting from a lost, stolen, or misappropriated payment instrument. The payer owes nothing after notification, when the provider failed to require strong customer authentication where it was mandatory, or when the instrument was used in connection with a distance contract.
The Payment Services Regulations 2017 (SI 2017/752), reg. 77, https://www.legislation.gov.uk/uksi/2017/752/regulation/77
Two regimes apply, depending on the instrument. Credit cards: the cardholder's liability is limited to $50 or the amount charged before notification, whichever is lower (Regulation Z, 12 CFR 1026.12(b)). Debit cards and electronic fund transfers: $50 if the consumer reports within 2 business days of learning of the loss, $500 if they report later, and unlimited liability for transfers made after the 60-day period following the statement (Regulation E, 12 CFR 1005.6).
CFPB, Regulation Z, 12 CFR § 1026.12(b), https://www.consumerfinance.gov/rules-policy/regulations/1026/12/
For a report made between the 4th and 7th working day, the customer's liability is capped by account type: ₹25,000 for other current accounts and credit cards with a limit above ₹5 lakh, ₹10,000 for savings accounts, prepaid instruments, and credit cards with lower limits, and ₹5,000 for a basic savings bank deposit (BSBD) account.
Reserve Bank of India, circular DBR.No.Leg.BC.78/09.07.005/2017-18 of July 6, 2017, https://www.rbi.org.in/commonman/english/scripts/Notification.aspx?Id=2336
When a passcode was required to make the transaction, clause 11.7 of the ePayments Code limits the holder's liability to the lowest of three amounts: $150, the balance available in the account (including any prearranged credit), or the actual loss at the time of the report, excluding any portion above the daily transaction limits. Clause 11.8(b) states that access to the account with the correct device and passcode does not, on its own, prove that the user contributed to the loss.
ASIC, ePayments Code (June 2022), clauses 11.7 and 11.8, https://download.asic.gov.au/media/lloeicwb/epayments-code-published-02-june-2022.pdf
Refunds for fraud where the customer approved the payment (bank impersonation, manipulation)
Since October 7, 2024, reimbursement has been mandatory for victims of authorized push payment (APP) scams on Faster Payments and CHAPS, covering consumers, microenterprises, and charities. Reimbursement is capped at £85,000 per claim, in line with the Financial Services Compensation Scheme limit. The gross negligence exception is interpreted narrowly, the provider bears the burden of proof, and the exception does not apply to vulnerable customers.
Payment Systems Regulator, PS24/7, https://www.psr.org.uk/publications/policy-statements/ps247-faster-payments-app-scams-reimbursement-requirement-confirming-the-maximum-level-of-reimbursement/
The Shared Responsibility Framework from the MAS and IMDA, in force since December 16, 2024, covers phishing scams in which consumers are tricked into handing over their credentials. Responsibility follows a waterfall: the financial institution first, then the telecom operator, and each must compensate the victim if it breached its own duties. If both met their duties, the framework requires no payout.
Monetary Authority of Singapore, Guidelines on Shared Responsibility Framework, https://www.mas.gov.sg/regulation/guidelines/guidelines-on-shared-responsibility-framework
The Scams Prevention Framework Act 2025, enacted on February 20, 2025, sets no reimbursement schedule. Instead, it requires designated sectors (banks, telecom operators, digital platforms) to prevent, detect, disrupt, respond to, and report scams, with fines of up to A$50 million.
Scams Prevention Framework Act 2025, https://www.legislation.gov.au/C2025A00015/asmade; Treasury, “Scams Prevention Framework,” https://treasury.gov.au/publication/p2025-623966