Skip to content
Coverage

Card and bank billing

PSD2 — unauthorised transactions and direct-debit refunds (Directive (EU) 2015/2366)

SupranationalEURead off primary law

European Union and wider EEA

Rule id
billing.eu-psd2
Version
1.0.0
In force from
January 13, 2018
Last read against its sources
August 5, 2026
Countries bound
30 countries

In plain language

What this regime says.

PSD2 gives anyone paying from an account in the EEA a hard-edged right: tell your bank about an unauthorised payment and it must refund you by the end of the next business day, then investigate. Your own exposure is capped at EUR 50 and is nil where the bank did not apply strong customer authentication. Direct debits carry a separate, no-questions-asked eight-week refund right.

Who is covered

Payment service users in the EEA, for payments in any currency where both providers are in the Union, and for the Union-side legs of payments to and from third countries. It covers cards, credit transfers, direct debits and wallets alike.

What you get

The unauthorised amount back with value dating restored, capped exposure of EUR 50 before you notify and nothing after, a full refund for an unexpected direct debit within eight weeks, and free access to a national ADR body if the provider refuses.

Where claims go wrong

  • Letting the bank hold the money "pending investigation". Article 73(1) fixes the sequence: refund first.
  • Accepting "you were negligent". The threshold is gross negligence, and the burden of proving it is on the bank.
  • Treating a successful 3-D Secure challenge as the end of the argument. Authentication is not authorisation.
  • Missing the eight-week direct-debit window when a no-reason refund was there for the asking.
  • Assuming the 13-month bar always runs. It only runs where the bank actually gave you the transaction information.
The official claim route

Authority

Every citation,
with its pinpoint.

A claim that cites “EU law” gets filed. A claim that cites Article 7(1)(c) gets answered. These are the exact coordinates this entry rests on.
  1. Directive (EU) 2015/2366 (PSD2)Directive (EU) 2015/2366 of the European Parliament and of the Council on payment services in the internal market
  2. PSD2, Article 71(1)Directive (EU) 2015/2366Art. 71(1) — the payer obtains rectification only if it notifies its provider without undue delay on becoming aware, and no later than 13 months after the debit date
  3. PSD2, Article 73(1)Directive (EU) 2015/2366Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been in
  4. PSD2, Article 74Directive (EU) 2015/2366Art. 74(1) — maximum payer liability of EUR 50 for unauthorised transactions from a lost, stolen or misappropriated instrument, with exceptions; Art. 74(2) — no liability at all where the provider does not require strong customer authentication
  5. PSD2, Articles 76-77Directive (EU) 2015/2366Art. 76(1) — refund of an authorised payee-initiated transaction requested within 8 weeks of the debit date; Art. 76(4) — the unconditional SEPA direct-debit refund; Art. 77(1) — the provider must refund or justify refusal within 10 business days

Sources

Where a figure is indexed, converted or published by a regulator rather than fixed in the instrument, the provenance is recorded separately. Anything marked as a modelled estimate is exactly that — a model, not a statutory number.

What it imposes

Clocks, defences and the ladder.

A rule module builds these while it evaluates, because a limitation period depends on which forum is open to you. What follows is the structure this regime produces — deliberately with no dates and no figures, because those belong to your facts rather than to the law.

The clocks it starts

  • Notify the provider (without undue delay, and at the latest 13 months)Fatal if missedArticle 71(1) requires notification without undue delay on becoming aware, and in any event no later than 13 months after the debit date. The 13 months is generous by design and runs from the debit, not from when you noticed. Read Article 71(1) to the end, though: the time limit applies only where the provider actually gave you the transaction information required by Title III. If it never sent you statements, the bar does not run against you.PSD2, Article 71(1) — Art. 71(1) — the payer obtains rectification only if it notifies its provider without undue delay on becoming aware, and no later than 13 months after the debit dateNotice period
  • Provider must refund by the end of the next business dayArticle 73(1): the provider must refund the amount "immediately, and in any event no later than by the end of the following business day" after noting or being notified of the transaction, and must restore the debited account to the state in which it would have been had the transaction not taken place — value date included. It may reverse the credit later if it establishes fraud, but it must pay first. (Period: 1 business day. We need the start date to work out your exact deadline.)PSD2, Article 73(1) — Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been inResponse due

What it entitles you to, beyond money

  • Refund first, investigate afterwardsArticle 73(1) is not conditional on the outcome of an investigation. If the provider suspects fraud by you it may, after refunding, investigate and reverse — but the sequence is fixed by the Directive and putting it the other way round is a breach.Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been in
  • No strong customer authentication means no liabilityArticle 97 makes strong customer authentication mandatory for remote electronic payments. Article 74(2) provides that where the provider does not require it, the payer bears no financial consequences unless the payer acted fraudulently. Ask the provider, in writing, to confirm whether SCA was applied to this transaction and to produce the authentication record. An evasive answer is usually the answer.Art. 74(1) — maximum payer liability of EUR 50 for unauthorised transactions from a lost, stolen or misappropriated instrument, with exceptions; Art. 74(2) — no liability at all where the provider does not require strong customer authentication
  • The bank has to prove it, not youArticle 72(1) puts the burden on the provider to prove that the transaction was authenticated, accurately recorded and not affected by a technical breakdown. Article 72(2) adds that the mere fact the provider recorded use of the instrument "is not in itself necessarily sufficient" to prove authorisation, fraud, intent or gross negligence.Art. 72(1)-(2) — the burden is on the provider to prove authentication and authorisation; use of the instrument recorded by the provider is not in itself sufficient to prove authorisation, fraud, intent or gross negligence
  • Interest and value dating restoredRestoring the account "to the state in which it would have been" includes the credit value date being no later than the date the amount was debited, so any overdraft interest or fees the debit triggered must come back too.Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been in

What the other side will say

Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.

"You were grossly negligent, so you bear the whole loss"

high likelihood

The provider says you gave away a code, clicked a link, or ignored a warning, and refuses the refund outright.

What answers it

Article 74(1) removes the EUR 50 cap only where the payer acted fraudulently or failed with intent or gross negligence to comply with Article 69. Ordinary carelessness is not enough, and Article 72(2) provides that the provider's own record of the instrument being used "is not in itself necessarily sufficient" to prove gross negligence. Ask what evidence of gross negligence it holds, and note that the burden under Article 72(1) is on the provider throughout.

PSD2, Article 72 — Art. 72(1)-(2) — the burden is on the provider to prove authentication and authorisation; use of the instrument recorded by the provider is not in itself sufficient to prove authorisation, fraud, intent or gross negligence

"We must investigate before we can refund"

high likelihood

The provider holds the money for weeks or months pending a fraud investigation.

What answers it

Article 73(1) requires the refund immediately and in any event by the end of the following business day. The Directive expressly contemplates the provider investigating afterwards and reversing the credit if it establishes fraud. Give a date, quote the Article, and say that continued retention will go to the national ADR body and the competent authority.

PSD2, Article 73(1) — Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been in

"The payment was authenticated with 3-D Secure, so it was authorised"

high likelihood

The provider treats a successful SCA challenge as proof that the payer consented.

What answers it

Authentication and authorisation are different things and PSD2 keeps them apart. Article 72(1) requires the provider to prove that the transaction was authenticated and that the payer authorised it. A one-time code intercepted or socially engineered out of you authenticates the transaction and proves nothing about consent. Ask for the authentication log and the device and IP data behind it.

PSD2, Article 72 — Art. 72(1)-(2) — the burden is on the provider to prove authentication and authorisation; use of the instrument recorded by the provider is not in itself sufficient to prove authorisation, fraud, intent or gross negligence

"You are outside the 13 months"

medium likelihood

The provider refuses on the ground that too long has passed since the debit.

What answers it

Article 71(1) makes the 13-month bar conditional: it applies only "where applicable" — that is, where the provider actually gave you the transaction information required by Title III. If statements were not sent, or the transaction was not itemised on them, the bar has not started to run. Ask the provider to evidence when and how it gave you the information.

PSD2, Article 71(1) — Art. 71(1) — the payer obtains rectification only if it notifies its provider without undue delay on becoming aware, and no later than 13 months after the debit date

"That is a dispute with the merchant, not with us"

medium likelihood

The provider tries to recharacterise an unauthorised transaction as a commercial disagreement.

What answers it

The distinction is whether you gave consent under Article 64. If you never consented, Articles 71-74 apply and the provider's obligations are direct and immediate, whatever the merchant says. If you did consent but the amount was unexpected on a direct debit, Article 76 applies. Either way it is a payment-services question, not a sales question.

PSD2, Article 73(1) — Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been in

Where to take it next

  1. Written notification to your payment service providerState the transaction date, amount and payee, say that you did not authorise it (or that you are exercising the Article 76 refund right), and require the refund under Article 73(1) by the end of the next business day. Ask expressly whether strong customer authentication was applied and for a copy of the authentication record.Claim directtypically 2 days
  2. Formal complaint under the provider's Article 101 procedureArticle 101 requires providers to have a complaints procedure and to reply in a durable medium, addressing every point raised, within 15 business days (extendable to 35 in exceptional cases). Insist on a written reply that engages with Articles 73 and 74 by name — it is the document the ADR body will read first.Internal appealtypically 15 days
  3. National alternative dispute resolution bodyArticle 102 obliges Member States to provide ADR for payment-service disputes. Ireland has the Financial Services and Pensions Ombudsman, Italy the Arbitro Bancario Finanziario, Germany the Bundesbank and the private banking ombudsmen, France the Médiateur de l'AMF or the bank's own médiateur, Spain the Banco de España. Almost all are free to consumers.Alternative dispute resolutiontypically 90 days
  4. FIN-NET for a cross-border disputeIf your provider is established in a different EEA state from the one you live in, FIN-NET will route the complaint to the right national scheme. It is a Commission-run network and costs nothing.Alternative dispute resolutiontypically 120 daysofficial page
  5. National competent authorityEach Member State designates an authority to supervise PSD2 compliance — BaFin, the ACPR, the Central Bank of Ireland, De Nederlandsche Bank, the Banca d'Italia. They do not award you compensation, but a supervisory complaint about a provider that systematically ignores Article 73(1) has weight.Regulatortypically 120 days
  6. National court or the European Small Claims ProcedureFor a cross-border claim up to EUR 5,000, Regulation (EC) No 861/2007 provides a written, form-based procedure in your own courts with a judgment enforceable across the Union. Domestic small-claims routes are usually cheaper still.Small claimstypically 180 days

Documents

What this regime can produce.

Every one of these is a document you send yourself, in your own name. Duesday never writes to anybody on your behalf and is never anyone’s agent.

The same claim type elsewhere

Card scheme chargeback rules (Visa, Mastercard, American Express, Discover)SCHEMESupranationalparty states varyVisa Core Rules and Visa Product and Service RulesConfidence: mediumNorway — Financial Contracts Act 2020 and FinansklagenemndaNONationalNorwayLov om finansavtaler (finansavtaleloven), LOV-2020-12-18-146Confidence: mediumRussia — Federal Law 161-FZ on the National Payment System and the financial ombudsmanRUNationalRussiaФедеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», ст. 9Confidence: mediumSwitzerland — Financial Services Act ombudsman affiliation and the Swiss Banking OmbudsmanCHNationalSwitzerlandFinancial Services Act (FinSA / FIDLEG), SR 950.1Confidence: mediumTürkiye — Bank Cards and Credit Cards Law No. 5464 and the Consumer Arbitration CommitteesTRNationalTürkiyeBanka Kartları ve Kredi Kartları Kanunu No. 5464Confidence: mediumConsumer Credit Act 1974 s.75 (and s.75A) — creditor joint and several liabilityGBNationalUnited KingdomConsumer Credit Act 1974, s.75Confidence: highCanada — payment card codes of conduct, provincial consumer protection and OBSICANationalCanadaCode of Conduct for the Payment Card Industry in CanadaConfidence: mediumFair Credit Billing Act (Regulation Z billing-error resolution and claims-and-defences)USNationalUnited StatesFair Credit Billing Act, 15 U.S.C. § 1666Confidence: high

Other rights in the same countries

Austria — ÖBB FahrgastrechteATNationalAustriaRegulation (EU) 2021/782 as applied in AustriaConfidence: lowAustria — rental deposit (Allgemeines Bürgerliches Gesetzbuch (ABGB) § 16b, and the Mietrechtsgesetz (MRG))ATNationalAustriaAllgemeines Bürgerliches Gesetzbuch (ABGB) § 16b, and the Mietrechtsgesetz (MRG)Confidence: lowBelgium — action en réparation collective (Code de droit économique, Book XVII)BENationalBelgiumCode de droit économique / Wetboek van economisch recht, Livre XVII, Titre 2 (arts. XVII.35 et seq.)Confidence: lowBelgium — rental deposit (Regional housing codes: Vlaams Woninghuurdecreet, Décret wallon relatif au bail d’habitation, Code bruxellois du Logement)BENationalBelgiumRegional housing codes: Vlaams Woninghuurdecreet, Décret wallon relatif au bail d’habitation, Code bruxellois du LogementConfidence: lowBelgium — SNCB/NMBS compensation for delays and for repeated delays on season ticketsBENationalBelgiumRegulation (EU) 2021/782 as applied in BelgiumConfidence: lowBulgaria — rental deposit (Закон за задълженията и договорите (Obligations and Contracts Act), наем)BGNationalBulgariaЗакон за задълженията и договорите (Obligations and Contracts Act), наемConfidence: lowCroatia — rental deposit (Zakon o najmu stanova and the Zakon o obveznim odnosima)HRNationalCroatiaZakon o najmu stanova and the Zakon o obveznim odnosimaConfidence: lowCyprus — rental deposit (Rent Control Law of 1983 (23/1983) for controlled tenancies, and the general law of contract)CYNationalCyprusRent Control Law of 1983 (23/1983) for controlled tenancies, and the general law of contractConfidence: low

Does this one reach your facts?

The engine runs every regime that could apply at once and reconciles them, rather than making you guess which page to read.

Not a law firm. Not legal advice. You send it yourself. This page describes a law; it is not advice about your situation and no outcome is promised.