Home/Financial Justice/Unauthorized Transaction
Financial — US & EU/UK Law

Unauthorized Transaction: Your Liability Limits and How to Get Your Money Back

How much you can be forced to absorb from a fraudulent charge or transfer depends heavily on two things: what kind of payment it was (credit card vs. debit/electronic transfer) and how quickly you reported it. The rules — and your maximum legal liability — are genuinely different for a stolen credit card number than for a compromised debit card or bank transfer, so identify which regime applies before assuming a specific dollar cap.

At a Glance

$50
Max US credit card liability (often $0 in practice)
$50–unlimited
US debit/EFT liability tiers by reporting speed
£35
UK liability cap before notifying your provider
60 days
US written-dispute deadline to preserve billing rights

Your Liability Limits: Credit Cards vs. Debit and Electronic Transfers

In the US, two different federal regimes govern unauthorized transactions, and they set genuinely different maximum liability: credit cards are covered by the Truth in Lending Act and Regulation Z, which cap your liability at $50 — reduced to $0 if the transaction was "card not present" or if you report before any unauthorized use occurs. Debit cards, ATM transactions, and other electronic fund transfers are covered instead by the Electronic Fund Transfer Act and Regulation E, which use a tiered liability schedule based on how quickly you report the loss or theft.

Many banks and card networks also voluntarily offer "zero liability" policies that go further than the federal minimums — but these are voluntary issuer policies, not federal law, and can carry exclusions (for example, some exclude certain PIN-based or business-account transactions). verify your specific card’s zero-liability terms and any exclusions before relying on it instead of the federal floor

Why Reporting Speed Changes Your Maximum Liability (Debit Cards / EFT, Regulation E)

US Electronic Fund Transfer Act, 12 CFR § 1005.6 — liability tiers for lost or stolen debit cards/access devices

Reported within 2 business days of discovering the loss or theft

Liability capped at the lesser of $50 or the amount of unauthorized transfers that occurred before you notified the institution.

Reported after 2 business days but within 60 days of the statement

Liability capped at $500, provided the institution can show the loss would not have occurred had you reported within 2 business days.

Reported more than 60 days after the statement was sent

Potentially unlimited liability for transfers occurring after the 60-day period — this is the tier that makes prompt statement review genuinely important.

Fraud without a lost or stolen card (account number only compromised): If your card or access device was never actually lost or stolen — someone obtained only your account number or made an unauthorized electronic transfer without physical access — liability is generally capped at $50 as long as you report within 60 days of the statement, and $0 if you notify before any unauthorized transfer occurs at all. Consumer negligence cannot be used to impose greater liability than these limits allow.

If You Bank in the EU or UK

The EU’s Payment Services Directive 2 (PSD2), and the UK’s equivalent Payment Services Regulations 2017 (retained after Brexit), work differently from the US tiered system. Before you notify your bank or card provider of a lost, stolen, or compromised payment instrument, your liability for unauthorized transactions is capped — €50 in the EU under PSD2, and £35 in the UK under Regulation 77 of the Payment Services Regulations 2017 — unless you acted fraudulently or with gross negligence (for example, writing your PIN on the card), in which case liability can be uncapped. You are also not liable at all if the loss, theft, or misappropriation wasn’t detectable by you before the payment (absent fraud on your part).

Once you notify your provider, your liability for any further unauthorized transactions drops to zero. Providers must also refund an unauthorized transaction promptly — generally by the end of the next business day — unless they have reasonable grounds to suspect fraud by you, pending investigation. This "refund first, investigate after" structure is generally more consumer-favorable on speed than the US dispute-and-investigate model.

A PSD3/Payment Services Regulation reform package reached provisional political agreement between the European Parliament and Council in late November 2025, and legislative text work continued into 2026, but as of July 2026 it had not yet entered into force — the new rules are expected to generally apply roughly 21 months after formal publication in the EU Official Journal, which itself has not yet happened. PSD2’s rules are what currently apply. verify current PSD3/PSR status before assuming any changed liability rules are already in effect

When Liability Limits Don’t Fully Protect You

These liability caps apply to transactions you didn’t authorize — they generally do not cover a payment you did authorize but now regret (for example, willingly wiring money to a scammer), which is a fundamentally different, much harder problem: authorized transactions are not "unauthorized transactions" under Regulation E, Regulation Z, PSD2, or the UK rules, even though they may feel identical to the victim.

Peer-to-peer payment apps (Zelle, Venmo, and similar) sit in a genuinely contested area: if you were tricked into authorizing the transfer yourself, banks have often argued Regulation E’s unauthorized-transaction protections don’t apply, though this has drawn regulatory scrutiny from the Consumer Financial Protection Bureau. verify current CFPB guidance and any recent enforcement action on P2P fraud liability, since this area has been actively changing

Business accounts often have reduced or different consumer-protection coverage than personal accounts under both the US and EU/UK frameworks — check your account type before assuming the consumer liability caps above apply.

How to Dispute It, Step by Step

What to do, in order, and what happens at each stage

1

Report the unauthorized transaction to your bank or card issuer immediately, by phone

Call the number on the back of your card or your bank’s fraud line as soon as you notice the charge or transfer. This starts your protection clock and, for debit/EFT claims, directly determines which liability tier applies.

2

Ask the representative to freeze or cancel the compromised card or account access

This limits further unauthorized activity while the dispute is investigated. Get a reference or case number for the call.

3

Follow up in writing within the deadline that applies to your payment type

For credit cards, the Fair Credit Billing Act requires a written dispute within 60 days of the first statement showing the error to preserve your full billing-dispute rights — a phone call alone may not be enough to trigger the formal process.

4

Track the investigation deadlines your provider must meet

Under the Fair Credit Billing Act, a credit card issuer must acknowledge your dispute within 30 days and resolve it within 90 days. Under Regulation E, a bank generally must investigate within 10 business days (extendable to 45 days in some cases, with provisional credit given during the extension).

5

If the provider denies your dispute or misapplies the liability rules, escalate

File a complaint with the Consumer Financial Protection Bureau at consumerfinance.gov/complaint (US), or with your national financial ombudsman (EU/UK) — for example, the UK’s Financial Ombudsman Service.

6

Monitor your account and credit report going forward

Request a fraud alert or credit freeze if the unauthorized transaction suggests broader identity theft, not just a single compromised card number.

Documents to gather

  • Statement or transaction record showing the unauthorized charge/transfer
  • Reference or case number from your initial fraud report
  • Any written dispute letter or online dispute confirmation
  • Correspondence from the bank/issuer about the investigation outcome
  • Records showing when you first discovered the loss/theft, to establish your reporting timeline

Timelines and Limitation Periods

The reporting deadline determines your liability tier; the dispute-filing deadline determines whether you keep your rights at all

These two clocks are different and both matter — reporting late can raise your maximum liability even if you still file a technically timely dispute afterward. verify current deadlines and caps with your specific card issuer’s cardholder agreement, since some voluntary protections exceed the federal/EU/UK floor

JurisdictionLimitation Period
US credit card (Reg Z / FCBA)Written dispute within 60 days of the statement showing the error; liability capped at $50 ($0 if card-not-present or reported before use)
US debit card / EFT (Reg E)2 business days for the $50 cap; 60 days from the statement for the $500 cap; unlimited liability risk after that
EU (PSD2)Notify "without undue delay" on discovery; liability capped at €50 before notification (absent gross negligence/fraud), €0 after
United Kingdom (Payment Services Regulations 2017)Notify promptly; liability capped at £35 before notification (absent fraud), £0 after

Realistic Outcomes and Caveats

Straightforward unauthorized-transaction disputes — reported promptly, clearly not authorized by the accountholder, no gross negligence — are typically resolved with a full refund or credit, often provisionally during the investigation itself.

Disputes involving P2P apps, authorized-but-fraudulently-induced transfers, or claims of gross negligence are considerably harder and less reliably resolved in the consumer’s favor, since the core liability protections are generally built around "unauthorized," not "regretted," transactions.

This page can help identify your liability tier and the deadlines that apply — it cannot predict whether your specific bank will accept your account of events, whether a P2P transfer will be treated as unauthorized, or what a regulator will find if you escalate.

Common Pitfalls

Assuming a phone call alone preserves your rights

For credit cards especially, failing to follow up in writing within 60 days can weaken your formal dispute rights under the Fair Credit Billing Act, even if you called right away.

Not checking your statement regularly

For debit cards/EFT, the difference between the $500 cap and potentially unlimited liability is whether you reported within 60 days of the statement.

Confusing an unauthorized transaction with a transaction you regret

A purchase you authorized but now wish you hadn’t made — even under a scammer’s influence — generally isn’t covered by these liability caps the same way a truly unauthorized charge is.

Assuming zero-liability marketing guarantees $0

Card network zero-liability policies are voluntary and can exclude certain transaction or account types — check the actual cardholder agreement.

Treating EU/UK and US liability rules as interchangeable

The tiers, notification standards, refund-timing obligations, and exact caps (€50 vs. £35) differ — apply the rules for the country where the account is actually held.

Organize Your Dispute

Gather your transaction record, fraud-report reference number, and any written dispute correspondence, then check the liability tier and deadline that applies above.

Organize Your Dispute

Gather your transaction record, fraud-report reference number, and any written dispute correspondence, then check the liability tier and deadline that applies above.

This stays in your private workspace until you choose a next step.

This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.

Official and Legal References

US Tiered Liability vs. EU/UK Flat Cap

The US system ties your maximum liability to how quickly you report (escalating from $50 to $500 to potentially unlimited for debit/EFT, with a simpler flat $50/$0 structure for credit cards). The EU/UK system instead uses a flat cap before notification (€50 in the EU, £35 in the UK) and zero liability after, with a fast mandatory refund timeline. Always confirm which country’s rules apply to your specific account and the current cap figures, since both frameworks are periodically updated — the EU’s PSD3/PSR reform is in progress but not yet in force as of July 2026.

Frequently Asked Questions

Real edge cases, answered in plain language

Someone used my card number online but never had my physical card — how much am I liable for?

I was tricked into sending money via a P2P app myself — is that "unauthorized"?

My bank says I was "grossly negligent" and is denying my EU/UK dispute — what does that mean?

This page provides general information about US, EU, and UK unauthorized-transaction liability rules as of July 2026. It is not legal advice. Liability caps, notification standards, and deadlines vary by country and account type, and change over time — confirm current rules with your specific bank or card issuer before relying on any figure above.

Organize Your Dispute

Gather your transaction record, fraud-report reference number, and any written dispute correspondence, then check the liability tier and deadline that applies above.

Start Organizing My Claim