Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.
"You were grossly negligent, so you bear the whole loss"
high likelihoodThe provider says you gave away a code, clicked a link, or ignored a warning, and refuses the refund outright.
What answers it
Article 74(1) removes the EUR 50 cap only where the payer acted fraudulently or failed with intent or gross negligence to comply with Article 69. Ordinary carelessness is not enough, and Article 72(2) provides that the provider's own record of the instrument being used "is not in itself necessarily sufficient" to prove gross negligence. Ask what evidence of gross negligence it holds, and note that the burden under Article 72(1) is on the provider throughout.
PSD2, Article 72 — Art. 72(1)-(2) — the burden is on the provider to prove authentication and authorisation; use of the instrument recorded by the provider is not in itself sufficient to prove authorisation, fraud, intent or gross negligence
"We must investigate before we can refund"
high likelihoodThe provider holds the money for weeks or months pending a fraud investigation.
What answers it
Article 73(1) requires the refund immediately and in any event by the end of the following business day. The Directive expressly contemplates the provider investigating afterwards and reversing the credit if it establishes fraud. Give a date, quote the Article, and say that continued retention will go to the national ADR body and the competent authority.
PSD2, Article 73(1) — Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been in
"The payment was authenticated with 3-D Secure, so it was authorised"
high likelihoodThe provider treats a successful SCA challenge as proof that the payer consented.
What answers it
Authentication and authorisation are different things and PSD2 keeps them apart. Article 72(1) requires the provider to prove that the transaction was authenticated and that the payer authorised it. A one-time code intercepted or socially engineered out of you authenticates the transaction and proves nothing about consent. Ask for the authentication log and the device and IP data behind it.
PSD2, Article 72 — Art. 72(1)-(2) — the burden is on the provider to prove authentication and authorisation; use of the instrument recorded by the provider is not in itself sufficient to prove authorisation, fraud, intent or gross negligence
"You are outside the 13 months"
medium likelihoodThe provider refuses on the ground that too long has passed since the debit.
What answers it
Article 71(1) makes the 13-month bar conditional: it applies only "where applicable" — that is, where the provider actually gave you the transaction information required by Title III. If statements were not sent, or the transaction was not itemised on them, the bar has not started to run. Ask the provider to evidence when and how it gave you the information.
PSD2, Article 71(1) — Art. 71(1) — the payer obtains rectification only if it notifies its provider without undue delay on becoming aware, and no later than 13 months after the debit date
"That is a dispute with the merchant, not with us"
medium likelihoodThe provider tries to recharacterise an unauthorised transaction as a commercial disagreement.
What answers it
The distinction is whether you gave consent under Article 64. If you never consented, Articles 71-74 apply and the provider's obligations are direct and immediate, whatever the merchant says. If you did consent but the amount was unexpected on a direct debit, Article 76 applies. Either way it is a payment-services question, not a sales question.
PSD2, Article 73(1) — Art. 73(1) — refund immediately and in any event no later than by the end of the following business day, restoring the account to the state it would have been in