ELEN

New 2023 Law on Bank Liability for Online Fraud

The new 2023 law has capped at €1,000 the liability of account holders who fall victim to online fraud. In recent years, the phenomenon of phishing has expanded considerably owing to the proliferation of electronic banking (debit, credit and prepaid cards, standing orders, bank and postal cheques, e-banking, e-wallets, PayPal). Banks and customers alike have been unprepared for the security challenges of such transactions. In light of the need to protect the consumer public, the new Law 5019/2023 introduced limitations on the liability of account holders who carry out payment operations — that is, transactions involving the disposal, transfer or withdrawal of funds (hereinafter “account holders”) — where they fall victim to phishing.

What is phishing?

Phishing — also referred to as unauthorised payment operations — comprises deceptive practices using fake websites, electronic messages or notifications, by which perpetrators obtain or extract from account holders their secret credentials (PIN, TAN) for online transactions and then transfer funds out of their accounts.

Who is covered by phishing protection?

It covers account holders, namely natural or legal persons who hold a payment account and authorise a payment order from that account or, where there is no payment account, the natural or legal person who issues the payment order.

What measures protect account holders?

Under the previous statutory regime, the account holder was liable for all losses arising from phishing that were attributable to intent or gross negligence. Under the new law, the principal rules on the payer’s liability remain in force; however, cases of limitation of liability are now introduced where there is no intent. In particular, it is provided that:

  1. The account holder is liable up to a maximum amount of fifty euros (€50) for losses from phishing arising from the use of a lost, stolen or misappropriated payment instrument (e.g. a debit card).
  2. The account holder is not liable for losses from phishing where the loss, theft or misappropriation of the payment instrument could not have been detected by the payer prior to the execution of a payment operation, or where the loss was caused by acts or omissions of, in particular, an employee or branch of a payment service provider (e.g. a credit institution).
  3. The account holder who is a consumer is liable up to a maximum amount of one thousand euros (€1,000) where the losses from phishing are due to gross negligence.
  4. The account holder is liable for all losses from phishing where the payment service provider applies, beyond what is required for strong authentication of transactions, additional security measures (e.g. telephone confirmation) for transactions capable of causing damage exceeding one thousand euros (€1,000).
  5. The account holder is liable for all losses connected with phishing where these were caused by his or her own intent.
  6. The account holder is liable for all losses from phishing where he or she has, with intent, breached the obligations imposed by law on payment service users (e.g. the duty to notify the credit institution immediately of the loss of a credit card).

The provision limiting payers’ liability takes effect from 1 September 2023.

Limitation of the payer’s liability for unauthorised payment operations (phishing)

According to the explanatory memorandum, the purpose of the new provision is to protect the consumer in cases of phishing — that is, deceptive practices (using fake websites, electronic messages or notifications) by which perpetrators obtain or extract from consumers their secret credentials (PIN, TAN) for online transactions and money transfers.

The fifth subparagraph of Article 74(1) of Directive (EU) 2015/2366 permits Member States to reduce the limit of the payer’s liability where there is no intent, thereby allowing the legislative limitation of the payer’s liability in cases of gross negligence — an option which had not, however, been adopted in Law 4537/2018 (Government Gazette A’ 84).

Taking into account the experience of other countries that have provided for a quantitative statutory limitation of consumer liability in cases of gross negligence (Sweden, Denmark and Norway), as well as the need to protect the consumer public in view of the scale of the phishing phenomenon, the introduction of the proposed provision was deemed necessary.

It should be noted that, in any event, the duty of care owed by the provider entails an obligation of consistent supervision and security of the system and account so as to safeguard transactions.

Where the provider has implemented heightened security and diligence measures that go beyond those required by the provisions on strong authentication of transactions, then, exceptionally, the proposed limitation of the provider’s liability in cases of gross negligence does not apply.

Is the new law effective against online fraud?

A new addition was made before the enactment of the new Law 5019/2023 which is highly burdensome for consumers and effectively nullifies the banks’ liability, since it leaves it to their discretion to demonstrate that they maintain and apply sophisticated transaction-monitoring mechanisms — something the consumer is unable to verify. In substance, the consumer’s compensation claim is rendered practically unworkable, and consequently the regime is not in the consumer’s interest, with the risk of disproportionately undermining the consumer’s economic interests. The loss should be borne by the bank, as the entity responsible for adopting adequate and effective security measures within its systems, and only in cases of intent should the consumer bear liability.

The banks’ overall approach is also out of step with the spirit of the proposed revision of the European Payment Services Directive PSD2 (Law 4537/2018, “Liability of the payer for unauthorised payment operations”), under which national authorities are called upon to adopt a coordinated approach for regulating liability and loss allocation, whereby the larger share of the loss following online financial fraud should be shifted from consumers to financial institutions.

What we have observed in fraud cases:

  • Legislative gaps regarding the shifting of losses onto the customer in light of whether or not gross negligence is present.
  • Gaps and inadequate banking security. Banks have no internal procedure for such cases nor any security-incident management policy.
  • Consumers feel vulnerable, exposed and angry.
  • A lack of guidance on the next steps the defrauded consumer should take immediately (e.g. submitting a dispute application to the bank, filing a criminal complaint against unknown perpetrators with the Cybercrime Division, blocking the bank account, changing credentials, etc.).
  • Most consumers are not familiar with electronic transactions and the bank should therefore inform them adequately so that they are not exposed to risk.
  • In most cases, banks do not compensate fraud victims.
  • Indifference on the part of banks in halting suspicious activity and failure to activate One-Time Passwords (OTP), which would require their customers to authorise transactions with a code.
  • In every instance, consumers who detected the fraud contacted the bank to cancel the transactions, but bank staff referred them to call back the next day.
  • Failure by banks to use strong authentication credentials.

 

FREQUENTLY ASKED QUESTIONS ON THE NEW 2023 LAW AND BANK LIABILITY FOR ONLINE FRAUD

1. What changes for the phishing victim under Law 5019/2023?

Law 5019/2023 limits the liability of the consumer who falls victim to online fraud. Where there is no intent but only gross negligence, the victim’s liability does not exceed €1,000 — the remainder is borne by the bank. In the case of mere use of a stolen or lost payment instrument, liability is capped at €50.

Before the new law, the account holder was burdened with the full amount of the loss whenever gross negligence was found. The provision applies to transactions carried out from 1 September 2023 and constitutes a powerful instrument of redress against the credit institution.

2. What can I do to recover my money?

The first step is to lodge an immediate written dispute of the transaction with the bank, requesting a refund of the amount. In parallel, a criminal complaint against unknown perpetrators is filed with the Public Prosecutor’s Office at the Court of First Instance, which forwards it to the Cybercrime Prosecution Division, and the Hellenic Banking Ombudsman is notified in writing.

If the bank refuses compensation, a lawsuit is filed before the Athens Multi-Member Court of First Instance for the return of the amount and pecuniary compensation for moral damages. The legal bases are Law 4537/2018 (PSD2), Law 5019/2023, the consumer protection provisions, and the bank’s tortious liability for inadequate security measures.

3. How long will it take to obtain compensation from the bank?

The dispute of the transaction must be submitted to the bank without undue delay and in any event within 13 months of the debit. If the bank considers the request well-founded, the refund is generally made within a few weeks.

Where the matter is taken to court, the hearing of the lawsuit at the Court of First Instance typically takes 18 to 30 months, and where an appeal is lodged, the total time can reach four years. The criminal proceedings progress in parallel and independently, without suspending the claim against the bank.

4. What documents do I need to bring a claim?

Essential are the account statements showing the disputed debits, screenshots of the suspicious message or website, the SMS or email file of the phishing attack, the dispute application submitted to the bank and the relevant reply, and the criminal complaint together with the filing receipt from the Cybercrime Division.

Also useful are the e-banking contract, the card terms of use, a detailed log of communications with the customer service line (call times, names of staff) and any evidence demonstrating that the account holder promptly activated the prescribed notification procedures.

5. What are my chances of winning against the bank?

The chances are significantly enhanced where it is shown that the bank did not apply Strong Customer Authentication under Directive PSD2, did not activate One-Time Password, did not detect a suspicious transaction in a country or at a time unusual for the customer, or was slow to respond to the victim’s notification.

The case-law of the Greek courts is increasingly moving in favour of consumers, particularly where security gaps in the bank’s systems are documented. Each case is, of course, decided on its own facts and requires careful technical and legal analysis.

6. What is the lawyer’s role in a phishing case?

The lawyer drafts the dispute letter to the bank with substantiated reliance on the provisions of Law 5019/2023 and Directive PSD2, files the criminal complaint against unknown perpetrators with the Public Prosecutor’s Office at the Court of First Instance, monitors the case file at the Cybercrime Prosecution Division and refers the matter to the Hellenic Banking Ombudsman.

If compensation is refused, the lawyer files a lawsuit before the competent Court of First Instance and represents the client at every stage. Our office has handled numerous phishing cases, identifies the security gaps in banks’ systems and draws on the most favourable provisions of the new law for the account holder.