1. What is an „unauthorized payment transaction“?
A payment transaction is authorized only if the payer has given their consent. The consent must be given in accordance with the agreed procedure. If this consent is missing, the payment transaction is unauthorized and there is fundamentally a right to a refund and correction.
In practice, this question is often discussed at the wrong point. Many banks refer early to the customer's „due diligence obligations.“ However, this does not concern the authorization itself. This concerns the liability level pursuant to Section 68 of the Payment Services Act (ZaDiG).
2. The basic rule: reimbursement „without undue delay“ pursuant to Section 67 ZaDiG 2018
In the event of an unauthorized payment transaction, the payer's payment service provider must refund the debited amount. The refund must be made „without undue delay.“ The bank must correct the account. The account must be put in the position as if the debit had never occurred.
Exception: Suspicion of fraud and report to the FMA: A refund may only be omitted in exceptional cases. Section 67 (2) ZaDiG specifies „legitimate grounds“ supporting a suspicion of fraud as an exception. In that case, the payment service provider must report this to the FMA in writing without delay. The system is strict. Section 67 does not provide for other statutory exceptions (in this logic).
3. Authorization vs. Authentication: This is frequently confused
Many cases revolve around online banking security mechanisms. From the bank's side, the argument is often raised: „The payment was authenticated.“ That is not the same as „authorized.“.
Authentication means: The system checks whether a specific procedure has been followed. For example, via app approval or TAN.
Authorization means: The payer has consented to the specific payment.
An authentication that is technically „correct“ can therefore exist. Nevertheless, consent may be missing. This is particularly relevant in social engineering attacks.
4. Deadlines: „Without undue delay“ and 13 months – and why both matter
Many affected individuals only know the 13-month deadline. This deadline is important. However, it is not the only requirement.
Duty of immediate notification: The payment service user must inform the bank without undue delay after becoming aware of it. This is a subjective duty. It depends on the circumstances of the individual case.
The 13-month maximum limit: In addition, there is an objective maximum period of 13 months from the debit date. Anyone who informs later generally loses their claim.
ECJ: Claim can also be lost if reported within 13 months: The ECJ has clarified: „Without undue delay“ and „13 months“ are two separate requirements. The 13-month period does not replace the notification without undue delay.
This means:
Even if reported within 13 months, a claim can still be lost. This can happen in particular if the delay was intentional or grossly negligent. In the case of repeated incidents, it depends on the specific delay and the specific damages.
Practical consequence:
As soon as a suspicious activity is noticed, the report should be made immediately. Hesitating is a typical mistake.
5. Customer due diligence and liability pursuant to Section 68 ZaDiG 2018
§ 68 ZaDiG governs the liability of the payer towards the payment service provider. It concerns damages resulting from the unauthorized use of a payment instrument. A prerequisite is typically a culpable breach of duty pursuant to § 63 ZaDiG.
Simple negligence: Liability of the bank customer up to a maximum of 50 EUR: If the payer is only guilty of simple negligence, liability is generally limited. It amounts to a maximum of 50 EUR.
Gross negligence or intent: Liability of the bank customer fundamentally unlimited: In the event of an intentional or grossly negligent breach of duty, the payer can generally be held liable for the entire damage. This distinction is often the core of the dispute. It depends heavily on the specific sequence of events.
Important liability releases and loss sharing: The law contains several exceptions in which the bank customer has a right to reimbursement despite a breach of duty. Particularly relevant in practice is strong customer authentication.
No strong customer authentication required: If strong customer authentication was not required by the bank / payment service provider, the payer may be exempt from damages pursuant to Section 68 (5) ZaDiG and is entitled to a refund of the full amount. As a general rule, this also applies in cases of gross negligence.
Contributory negligence of the bank: If the bank is also at fault, liability may be apportioned.
Notification and blocking – The time of receipt can be crucial: In the event of loss, theft, or misuse, a report must be filed immediately. Upon receipt of the report, the bank must block any further use. The time of receipt may be decisive for the exemption from liability.
6. Obligations of the bank in suspicious circumstances
Unauthorized transactions affect not only online banking. Classic cases are also relevant, for example cash withdrawals or unusual payment orders.
Case law shows that in the event of suspicious circumstances, the bank's obligation to review goes beyond formal checks. A mere signature comparison for a „traditionally“ submitted transfer order may be insufficient. In conspicuous scenarios, the bank may be required to make inquiries with the account holder.
In practice, this means that suspicions trigger verification obligations for banks. These obligations are relevant for liability, contributory negligence, and the apportionment of damages.
7. Is the bank allowed to refuse the refund or offset it?
This is a common area of conflict.
Reimbursement under § 67 and liability under § 68 are different levels: Section 67 orders the reimbursement for unauthorized transactions. Section 68 regulates whether the customer owes the bank damages. This logic speaks in favor of a separation.
In the literature, a „two-stage process“ is discussed: A common approach is for the bank to first look for
reimburse § 67. The bank will then pursue any claims for damages separately pursuant to § 68.
Besides this, there are other views. In older case law, the possibility of set-off was also discussed. In recent discussions, it is emphasized that an immediate „devaluation“ of the chargeback can be problematic.
8. Distinction: Not every fraud is a ZaDiG case
Not every fraud scenario automatically leads to a claim pursuant to Section 67 ZaDiG.
Invoice fraud and email spoofing
In invoice fraud, the payment has often been initiated by the customer themselves. In such cases, the payment is frequently „authorized.“ The problem therefore lies in the underlying transaction, such as the question of whether the payment to the wrong recipient discharged the debt or whether claims for damages might exist against the correct recipient.
Crypto transfers
For pure wallet transfers without a traditional payment service provider, different regulations may apply. This can be outside the scope of the ZaDiG. For bank customers, this is particularly relevant if the asset outflow did not occur via a bank account, but rather through a wallet transaction.
9. Checklist: What those affected should do immediately
These steps have proven effective in practice and are often crucial for subsequent enforcement.
-
Block card and online banking immediately.
-
File a written complaint with the bank immediately.
-
Back up transaction data.
Date, time, amount, recipient, reference number. -
Secure communication.
Emails, text messages, push notifications, screenshots, call logs. -
Create a timeline.
When was what noticed. When was what reported. -
Request a refund pursuant to Section 67 of the German Payment Services Act (ZaDiG).
Clear phrasing. Clear deadline setting. -
Request a justification in case of rejection.
Especially regarding authorization, suspected fraud, strong customer authentication, and gross negligence.
10. FAQ
Must the bank refund my money in the event of unauthorized payments?
For unauthorized transactions, the general rule is that the bank must refund the debited money „immediately,“ no later than the end of the following business day. An exception applies if justified grounds support a suspicion of fraud and this is reported to the FMA.
I have confirmed a transfer using PushTAN. Have I thereby lost my claims against the bank?
No.
The decisive factor is whether there was consent to the specific payment. Social engineering cases in particular are frequently prone to disputes.
Is it enough if I make a claim within 13 months?
No.
Additionally, immediate notification upon discovery is required. In the event of delayed notification, a claim may be forfeited.
Can the bank simply refuse the refund due to gross negligence?
That depends on the legal classification.
Section 67 governs reimbursement.
Section 68 governs potential claims for damages by the bank.
In practice, it often needs to be clarified whether a refund must be made first and how any counterclaims may be enforced.
What is „strong customer authentication“?
Strong customer authentication is a security procedure in which the bank requires at least two independent factors. These factors must come from two different categories: knowledge (e.g., PIN), possession (e.g., smartphone/TAN generator), or biometrics (e.g., fingerprint). In the case of payments, the authorization is usually also tied to the amount and the recipient.
For further information and an initial assessment of your claims, please Roman Taudes and his team at any time at office@atb.law or by phone at 01 39 12345 available.