This post is also available in:
Through a concrete case of a lost bank card and fraudulent transactions on a client’s account, we revisit the respective responsibilities of the bank and the client in payment services matters, much as in phishing cases.
The client who believed his card had been swallowed
A client carried out banking operations at an ATM inside a bank branch. His card was swallowed by the machine, or so he believed. In reality, according to the record of his later police interview, the client had been distracted while collecting his account statements. A man behind him pointed out two 5 EUR notes lying on the floor. After picking them up, the client noticed that the ATM screen had changed and was asking him to insert his card.
Believing his card had been swallowed, and unable to retrieve it, he left the branch. The next morning, back at the branch, he discovered that his card had in fact been used fraudulently during the night [1]. He then reported the loss or theft, had the card blocked, and sought compensation from the bank under Article 36 of the Act of 10 December 2009 on payment services [2].
The bank refused, a position shared by Ombudsfin, invoking Article 37 of the Act: the client had been grossly negligent because blocking the card only the day after the facts was late. The Brussels Court of First Instance agreed and dismissed the claim. For that court, the card should have been blocked immediately on the evening of the facts.
On appeal: a card believed swallowed is not a lost or stolen card
Although the Act of 10 December 2009 has since been replaced [3], the concepts used in this decision remain current, notably in phishing matters.
For the Brussels Court of Appeal, the finding, or the belief, that a card has been swallowed is not strictly the same as the loss, theft, misappropriation or unauthorised use of the card within the meaning of the Act. In this case, only a contractual provision at the end of the bank’s general terms and conditions mentioned, as a prudence recommendation rather than a contractual obligation, that Card Stop should be notified of any incident involving the use of a payment card.
In the circumstances, the court held that gross negligence on the client’s part was not established. The manoeuvres to which he had been subjected in the branch were precisely designed to make him believe his card had been swallowed and to prevent him from realising it had been stolen.
The principles: liability for fraudulent card use
Under current law, as with phishing, where a payment is made with a stolen bank card, the cardholder bears liability for transactions occurring before notification to the bank only up to EUR 50. Where the unauthorised transactions result from fraudulent or grossly negligent conduct of the holder, the holder bears full liability.
Negligence is a subjective notion left to the court’s assessment. The holder of a payment instrument is nonetheless expected to use it in accordance with its terms of issue, to take all reasonable steps to keep the instrument and its associated data secure, and to notify the issuer immediately of any loss, theft or unlawful or unauthorised use [4].
Should the victim’s perception of the facts matter?
Professor Steennot commented on this decision, which raises an important question: should the cardholder’s perception of the facts be taken into account when assessing possible negligence [5]?
Like that author, we consider it preferable, and consistent with civil liability law and legal certainty, to assess the situation objectively, not through the way the holder says he perceived it. The analysis must weigh all the circumstances of the case and the conduct a prudent person would adopt in an identical situation.
[1] This type of case is frequent. In 2019, Ombudsfin recorded 95 fraud files involving lost or stolen cards, against 221 files concerning unauthorised remote payment transactions. See the annual report at ombudsfin.be. The appellate decision: Brussels, 14 November 2019, D.B.F., 2020/2, pp. 71 et seq., note R. Steennot.
[2] These rules now sit in Book VII of the Code of Economic Law, as amended following the transposition of the PSD2 Directive (EU) 2015/2366 by the Acts of 11 March 2018 and 19 July 2018.
[3] See above; the substance of the provisions remains comparable.
[4] Article VII.38 of the Code of Economic Law.
[5] R. Steennot, “Niet-toegestane betalingstransacties: de kennisgevingsverplichting eng ingevuld”, D.B.F., 2020/2, p. 75.
This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.
On the same topic
- Phishing, Internet Fraud and Bank Liability: Do the Client’s Age and Perception Matter?
- The Bank Is Not an Automatic Insurer Against Phishing
- Phishing and Fraudulent Use of Payment Instruments
- Phishing: Where Recent Belgian Case Law Now Stands
- Banking Phishing: Is the Bank the Temporary Financier of Uncertainty?
Leave a Reply