+34 93 218 40 00 info@gimenez-salinas.es

PDF version

The expansion of electronic banking has given rise to an uncomfortable paradox: as digital payment services become more accessible, faster and less costly, the methods used by fraudsters to exploit that same accessibility have become increasingly sophisticated and profitable.

Phishing, smishing, vishing, SIM swapping and authorised payment fraud — commonly referred to in Anglo-American legal and regulatory literature as Authorised Push Payment (APP) fraud — can no longer be regarded as marginal phenomena. In the European Union, losses arising from payment fraud amounted to 4.3 billion euros in 2022 and 2.0 billion euros in the first half of 2023, according to the 2024 joint report published by the European Banking Authority (EBA) and the European Central Bank (ECB) [1]. In Spain, 80% of consumers received at least one attempted digital scam in 2024, while 7% of victims reported losses exceeding 5,000 euros [2].

Against this background, legal systems on both sides of the Atlantic have developed distinct responses, grounded in different legal principles and regulatory choices. These frameworks diverge in significant respects, particularly in relation to the allocation of liability and the criteria used to determine which party must ultimately bear the loss. This article considers the principal similarities and differences between the Spanish and European regime — based on Royal Decree-Law 19/2018 and Directive PSD2 — and the United States regime, which is primarily structured around the Electronic Fund Transfer Act (EFTA) and its implementing regulation, Regulation E.

[1] European Banking Authority and European Central Bank, 2024 Report on Payment Fraud, 1 August 2024. [2] FICO, 8 out of 10 Spanish consumers have received attempted scams, press release, 20 November 2024.

I.A common starting point: the burden of proof rests with the bank

Despite their differences, both systems share a fundamental structural principle: where an unauthorised transfer takes place, the burden of proving that the transaction was legitimate lies with the financial institution, not with the consumer. This point, which may at first appear to be a mere procedural technicality, has far-reaching practical consequences.

In Spain, Article 44 of Royal Decree-Law 19/2018 — which transposes Directive (EU) 2015/2366, PSD2 — provides that, where a payment service user denies having authorised an executed payment transaction, or alleges that it was executed incorrectly, it is for the payment service provider (PSP) to prove that the transaction was authenticated, accurately recorded and not affected by any technical breakdown or other deficiency in the service. The fact that the bank’s IT system has recorded the transaction as completed is not, in itself, sufficient to prove either that the customer authorised it or that the customer acted with gross negligence. In Spain, this position has been confirmed by the Supreme Court in Judgment No. 571/2025 of 9 April [3], which now constitutes the principal judicial reference on the matter.

European legal systems are, in essence, structured around a convergent approach. Beyond the technical particularities of each national legal order, they all share the same underlying logic: where a user denies having authorised a payment transaction, the payment service provider cannot simply rely on the electronic record of the transaction. It must positively demonstrate that the authentication process was properly carried out, that the payment order was genuinely issued by the account holder, and that there was no failure attributable to the system or to the institution.

Under French law, the same principle is enshrined in Articles L.133-18 et seq. of the Code monétaire et financier (CMF). The bank’s reimbursement mechanism, directly inspired by PSD2, has been interpreted by the case law of the Cour de cassation [4] as establishing a true principle of immediate restitution of the amount of unauthorised transactions, unless the institution is able to prove that the transaction was properly authenticated, recorded and accounted for, that there was no technical or other deficiency, and that the user acted fraudulently or with gross negligence.

Similarly, under Italian law, this principle is grounded in Article 10 of Legislative Decree No. 11/2010, which implemented the Payment Services Directive into domestic law and was subsequently aligned with PSD2, and in Article 12, concerning unauthorised payment transactions. The recent Sentenza n. 3780 del 12 febbraio 2024 de la Corte di Cassazione, Sezione III Civile [5], confirmed this approach by holding that a bank’s liability for transactions carried out through electronic instruments is contractual in nature and must be assessed by reference to the technical standard of the accorto banchiere, that is, the qualified professional diligence required of the institution. The Court further held that the risk of phishing fraud forms part of the professional risk borne by the payment service provider and cannot be automatically shifted to the customer.

Outside continental Europe, the position in the United States is broadly consistent on this point. Pursuant to Section 909(b) of the EFTA, the burden of proving that an alleged error was, in fact, an authorised transaction rests with the financial institution. Accordingly, where the financial institution is unable to establish that valid authorisation existed for the transaction, it must credit the amount to the consumer’s account.

For its part, the Consumer Financial Protection Bureau (CFPB) has brought enforcement actions against a number of institutions requiring them to remedy unlawful practices consisting of denying consumer reimbursements without conducting reasonable investigations into the specific circumstances of the case. One example is the action brought against USAA Federal Savings Bank, in which the CFPB found that the institution systematically denied error claims where the consumer had previously authorised transactions with the same merchant, without considering other relevant information in the bank’s own records, including the consumer’s allegation that the transfer was unauthorised or made for an incorrect amount. That investigation culminated in a Consent Order [6], pursuant to which USAA Federal Savings Bank undertook to correct such practices.

[3] Spanish Supreme Court Judgment No. 571/2025, Civil Chamber, of 9 April 2025, ECLI:ES:TS:2025:1671. [4] Cass. com. nº 17-21.395, 3 octobre 2018; Cass. com. nº 24-10.149, 30 avril 2025; Cass. com. n.º 19-12.112, 12 noviembre 2020. [5] Cass. civ. nº 3780, Sez. III, 12 febbrairo 2024, ric. nº 11492/2022. [6] Bureau of Consumer Financial Protection, Consent Order, USAA Federal Savings Bank, Case No. 2019-BCFP-0001, of 3 January 2019.

II.Liability regimes: quasi-objective liability in Europe and a tiered liability model in the United States

The first, and most significant, substantive divergence begins here.

The European model: quasi-objective liability and reversal of the burden of proof

The regime established by Royal Decree-Law 19/2018 [7] — and endorsed by case law that is now settled authority among the Appeal Courts [8] and by the Supreme Court itself — creates what legal doctrine describes as the quasi-objective liability of the payment service provider. Where a customer denies having authorised a transaction, there is a legal presumption that the customer did not, in fact, authorise it. The bank may only be released from its obligation to provide an immediate refund — which Article 45.1 of Royal Decree-Law 19/2018 requires to be made no later than the end of the following business day after the bank became aware of the transaction — if it is able to prove that the user acted fraudulently.

Judgment No. 571/2025 of 9 April of the First Chamber of the Spanish Supreme Court [9] made clear that a “deficiency in the service” is not confined to technical failures in the strict sense. Rather, it extends to any failure to exercise due diligence, or to any malpractice in the provision of the service, including a failure to react to obvious indicators of fraud, such as transfers of an unusual amount — particularly where they are made repeatedly within a very short period of time — access from unknown devices, or password changes at atypical times.

As the Supreme Court has stated, the bank must act with the diligence required of an “orderly and expert trader”, a standard far higher than that of the “reasonable person” applicable to ordinary diligence. Generic warnings on the bank’s website or standardised information messages do not meet that requirement; rather, in the words used by certain Appeal Courts [10], they amount to “pre-drafted formulae devoid of substantive content”.

Commission Delegated Regulation (EU) 2018/389 [11], which supplements PSD2 as regards strong customer authentication (SCA), is equally demanding: PSPs must implement monitoring mechanisms capable of analysing the user’s normal transactional behaviour, the device used, the amount of the transactions and known fraud patterns.

Where a bank fails to detect that a customer who has never made international transfers is suddenly sending thousands of euros abroad, or that transactions are being authorised above the agreed daily limit, it breaches its technical monitoring obligations and cannot shift the resulting loss onto the customer.

In this context, it should also be noted that a request for a preliminary ruling is currently pending before the Court of Justice of the European Union in Case C-70/25, N. O. v PKO BP S.A., concerning precisely the scope of the obligation to provide an immediate refund in the event of unauthorised transactions and the possibility of relying on the user’s gross negligence as a defence. The recent Opinion of the Advocate General [12] favours a particularly protective interpretation for the account holder, taking the view that the payment service provider must, in all cases, make an immediate refund, without prejudice to its ability subsequently to recover the amount from the customer if it proves such gross negligence.

[7] Royal Decree-Law 19/2018 of 23 November on payment services and other urgent measures in financial matters. [8] Judgment of the Provincial Court of Badajoz, Second Section, of 14 February 2025, ECLI:ES:APBA:2025:221; Judgment of the Provincial Court of Gijón, Seventh Section, of 20 May 2021, ECLI:ES:APO:2021:1892. [9] Spanish Supreme Court Judgment No. 571/2025, Civil Chamber, of 9 April 2025, ECLI:ES:TS:2025:1671. [10] Judgment of the Provincial Court of Huesca, First Section, of 30 June 2024, ECLI:ES:APHU:2024:175. [11] Commission Delegated Regulation (EU) 2018/389 of 27 November 2017 supplementing Directive (EU) 2015/2366 with regard to regulatory technical standards for strong customer authentication and common and secure open standards of communication. [12] Opinion of Advocate General Tukowiecka, 5 March 2026, Case C-70/25, ECLI:EU:C:2026:153.

The United States model: three levels of consumer liability depending on notification periods

The United States system is based on a different rationale. The EFTA, as implemented by Regulation E, does not establish a regime of quasi-objective liability on the part of the bank. Instead, it creates a tiered framework which adjusts the consumer’s liability according to how promptly the consumer notifies the loss or the unauthorised access.

The three-tier structure is as follows:

First tier — up to USD 50: If the consumer notifies the financial institution within two business days of becoming aware of the loss or theft of the access device, the consumer’s liability is capped at USD 50, or the amount of the unauthorised transfers carried out before notification, whichever is lower.

Second tier — up to USD 500: If the consumer fails to notify the institution within that two-business-day period, the consumer’s liability may increase to a maximum of USD 500. This amount is calculated as the sum of the USD 50 applicable under the first tier plus the amount of any unauthorised transfers that occurred between the expiry of the two-day period and the date of notification, provided that the institution proves that those transfers would not have occurred had timely notice been given.

Third tier — unlimited liability: If the consumer fails to report an unauthorised transaction appearing on a periodic statement within 60 calendar days of the date on which that statement was sent, the consumer may be exposed to unlimited liability for unauthorised transfers occurring after that 60-day period and before notification.

This system, however, does not operate automatically. Federal case law — for example, Widjaja v JPMorgan Chase, Ninth Circuit, 2021 [13] — has clarified that, even after the 60-day period has expired, the financial institution may only attribute liability to the consumer if it proves that the subsequent transfers would not have occurred if the consumer had notified the institution in time.

The difference from the European system is, in any event, substantial. In Spain, the timing of notification is relevant — there is a 13-month period within which to bring a claim — but the allocation of liability does not depend on when notice was given. Rather, it turns on whether the bank can prove gross negligence on the part of the user. By contrast, in the United States, time plays a structural role in the allocation of losses between the bank and the customer.

[13] U.S. Ct. App. 9th Cir., Margaretha Widjaja v. JPMorgan Chase Bank, N.A., No. 20-55862, 20 December 2021.

III. Gross negligence: a concept interpreted in markedly different ways

Where the contrast between the two systems is most striking, it is in the treatment of the user’s gross negligence as a ground for exempting the bank from liability.

Spain: gross negligence as a concept approaching fraudulent conduct

Under the Spanish and European framework, gross negligence is the only circumstance — alongside fraud — in which the bank may be released from its reimbursement obligation. The case law of both the Supreme Court and the Appeal Courts interprets this concept in an extremely restrictive manner, bringing it close, in conceptual terms, to wilful misconduct or inexcusable carelessness.

Directive (EU) 2015/2366 [14] itself anticipates this approach in Recital 72, which states that gross negligence should mean more than mere negligence, involving conduct exhibiting a significant degree of carelessness. The example of gross negligence provided by the legislative text is illustrative: keeping the credentials used to authorise a payment transaction together with the payment device, in a format that is open and easily detectable by third parties.

Spanish courts have developed this criterion with notable consistency. Supreme Court Judgment No. 571/2025 emphasised that the mere fact that a user entered an authentication code after having been deceived, in the context of a sophisticated phishing attack, does not amount to gross negligence. The Provincial Court of Navarre [15] expressed the point with precision: the reasonableness of the user’s conduct cannot be assessed with hindsight, but must be assessed at the time of the phishing attack, when the claimant was deceived by means of impersonation. In other words, the relevant benchmark is that of an ordinary person who places trust in the digital environment provided by their bank, not that of a cybersecurity expert.

Accordingly, the courts have rejected findings of gross negligence in cases involving conduct such as clicking on a link received by SMS within the same message thread as genuine communications from the bank; entering credentials on a website that faithfully reproduced the bank’s appearance; providing a one-time password to a person who identified themselves as a bank employee and called from an apparently official number; or accessing the bank’s application from an unfamiliar device in response to a sense of urgency deliberately created by the fraudster. Only in genuinely extreme cases — such as repeatedly and imprudently handing over access credentials to a third party voluntarily and knowingly, in the absence of any deception or in the face of an obvious and unsophisticated deception — has such conduct been capable of being characterised as gross negligence.

It should be noted, however, that this standard is not applied uniformly to all users, but is calibrated by reference to the specific personal circumstances of each victim. Article 1.104 of the Spanish Civil Code, expressly relied upon by certain Appeal Courts in this context [16], requires diligence to be assessed according to the nature of the obligation and the circumstances of the persons, the time and the place.

Factors such as advanced age, limited technological literacy, the user’s profession or their limited familiarity with digital banking services are taken into account by the courts when assessing whether the victim’s reaction to the deception was what could reasonably be expected of a person in those particular circumstances. An elderly person with no IT knowledge who follows the instructions of someone purporting to be an employee of their bank is not negligent in the same sense as a technology-sector professional would be in identical circumstances.

Ultimately, the existence of gross negligence should not be assessed by reference to a universal standard, but by reference to the actual profile and circumstances of the user.

[14] Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market. [15] Judgment of the Provincial Court of Navarre, Third Section, of 18 October 2024, ECLI:ES:APNA:2024:1531. [16] Judgment of the Provincial Court of Badajoz, Third Section, of 19 February 2025, ECLI:ES:APBA:2025:328.

United States: consumer negligence as a legally irrelevant factor

Under the EFTA and Regulation E, consumer negligence is not a legally relevant criterion for modifying the consumer’s liability.

The CFPB’s official commentary on § 1005.6(b) of Regulation E [17] is unequivocal: negligence by the consumer cannot be used as the basis for imposing greater liability than is permissible under Regulation E. The example given in the commentary is telling: writing the PIN on the debit card, or on a piece of paper kept together with the card, does not affect the extent of the consumer’s liability for unauthorised transfers.

This means that, under the United States framework, the question whether the consumer acted with a greater or lesser degree of care is, strictly speaking, irrelevant for the purposes of allocating liability. What matters is whether the transfer was authorised and when it was reported. The criterion is therefore temporal and objective, in contrast to the approach adopted in Spain.

The only crucial distinction drawn by Regulation E in this area is between voluntary authorisation and access obtained by fraud. If a consumer voluntarily gives their access device to a family member or acquaintance, and that third party carries out transfers exceeding the authority granted, the bank may attribute liability to the consumer. However, where access was obtained by deception, the official commentary leaves no room for doubt: an unauthorised electronic fund transfer includes one initiated by a person who obtained the consumer’s access device through fraud or robbery. The fraud committed by the scammer breaks the chain of authorisation, and the transfer must be treated as unauthorised.

This apparently technical distinction has very significant consequences in the context of digital fraud. If a user gives an access code to someone impersonating a bank employee, or enters credentials on a website that perfectly imitates the bank’s own site, the resulting transaction is — under Regulation E and as interpreted by the CFPB — an unauthorised transfer, irrespective of whether the consumer’s conduct was more or less prudent.

[17] Consumer Financial Protection Bureau, Comment for 1005.6 Liability of Consumer for Unauthorized Transfers.

 

Concluding remarks

The comparison between the two systems reveals two distinct philosophies as to where the risks inherent in financial digitalisation should lie.

The European model starts from the premise that the bank, as the architect and beneficiary of the system, must act as the ultimate guarantor of its integrity. The bank’s liability is quasi-objective, and the user’s gross negligence constitutes an exception which is interpreted very restrictively.

The United States model, by contrast, objectifies the issue and detaches it from the consumer’s conduct. Liability is adjusted by reference to the timing of notification, thereby providing predictability, but at the risk of leaving insufficiently protected those who fail to act with the utmost speed.

Both legal systems, however, converge on one crucial point: the increasing sophistication of fraud requires constant regulatory evolution. While Europe is moving towards a more prescriptive framework through the PSR and the IPR, the United States awaits judicial decisions that may redefine the scope of its regulation. Consumer protection in the digital age remains, on both sides of the Atlantic, a work in progress.

 

This article is for general information purposes only and does not constitute legal advice. For further information or to request legal advice, please contact info@gimenez-salinas.es.

 

Write us an email

Privacy Policy