Your Liability Limits: Credit Cards vs. Debit and Electronic Transfers
In the US, two different federal regimes govern unauthorized transactions, and they set genuinely different maximum liability: credit cards are covered by the Truth in Lending Act and Regulation Z, which cap your liability at $50 — reduced to $0 if the transaction was "card not present" or if you report before any unauthorized use occurs. Debit cards, ATM transactions, and other electronic fund transfers are covered instead by the Electronic Fund Transfer Act and Regulation E, which use a tiered liability schedule based on how quickly you report the loss or theft.
Many banks and card networks also voluntarily offer "zero liability" policies that go further than the federal minimums — but these are voluntary issuer policies, not federal law, and can carry exclusions (for example, some exclude certain PIN-based or business-account transactions). verify your specific card’s zero-liability terms and any exclusions before relying on it instead of the federal floor
Why Reporting Speed Changes Your Maximum Liability (Debit Cards / EFT, Regulation E)
US Electronic Fund Transfer Act, 12 CFR § 1005.6 — liability tiers for lost or stolen debit cards/access devices
Reported within 2 business days of discovering the loss or theft
Liability capped at the lesser of $50 or the amount of unauthorized transfers that occurred before you notified the institution.
Reported after 2 business days but within 60 days of the statement
Liability capped at $500, provided the institution can show the loss would not have occurred had you reported within 2 business days.
Reported more than 60 days after the statement was sent
Potentially unlimited liability for transfers occurring after the 60-day period — this is the tier that makes prompt statement review genuinely important.
If You Bank in the EU or UK
The EU’s Payment Services Directive 2 (PSD2), and the UK’s equivalent Payment Services Regulations 2017 (retained after Brexit), work differently from the US tiered system. Before you notify your bank or card provider of a lost, stolen, or compromised payment instrument, your liability for unauthorized transactions is capped — €50 in the EU under PSD2, and £35 in the UK under Regulation 77 of the Payment Services Regulations 2017 — unless you acted fraudulently or with gross negligence (for example, writing your PIN on the card), in which case liability can be uncapped. You are also not liable at all if the loss, theft, or misappropriation wasn’t detectable by you before the payment (absent fraud on your part).
Once you notify your provider, your liability for any further unauthorized transactions drops to zero. Providers must also refund an unauthorized transaction promptly — generally by the end of the next business day — unless they have reasonable grounds to suspect fraud by you, pending investigation. This "refund first, investigate after" structure is generally more consumer-favorable on speed than the US dispute-and-investigate model.
A PSD3/Payment Services Regulation reform package reached provisional political agreement between the European Parliament and Council in late November 2025, and legislative text work continued into 2026, but as of July 2026 it had not yet entered into force — the new rules are expected to generally apply roughly 21 months after formal publication in the EU Official Journal, which itself has not yet happened. PSD2’s rules are what currently apply. verify current PSD3/PSR status before assuming any changed liability rules are already in effect
When Liability Limits Don’t Fully Protect You
These liability caps apply to transactions you didn’t authorize — they generally do not cover a payment you did authorize but now regret (for example, willingly wiring money to a scammer), which is a fundamentally different, much harder problem: authorized transactions are not "unauthorized transactions" under Regulation E, Regulation Z, PSD2, or the UK rules, even though they may feel identical to the victim.
Peer-to-peer payment apps (Zelle, Venmo, and similar) sit in a genuinely contested area: if you were tricked into authorizing the transfer yourself, banks have often argued Regulation E’s unauthorized-transaction protections don’t apply, though this has drawn regulatory scrutiny from the Consumer Financial Protection Bureau. verify current CFPB guidance and any recent enforcement action on P2P fraud liability, since this area has been actively changing
Business accounts often have reduced or different consumer-protection coverage than personal accounts under both the US and EU/UK frameworks — check your account type before assuming the consumer liability caps above apply.
How to Dispute It, Step by Step
What to do, in order, and what happens at each stage
Report the unauthorized transaction to your bank or card issuer immediately, by phone
Call the number on the back of your card or your bank’s fraud line as soon as you notice the charge or transfer. This starts your protection clock and, for debit/EFT claims, directly determines which liability tier applies.
Ask the representative to freeze or cancel the compromised card or account access
This limits further unauthorized activity while the dispute is investigated. Get a reference or case number for the call.
Follow up in writing within the deadline that applies to your payment type
For credit cards, the Fair Credit Billing Act requires a written dispute within 60 days of the first statement showing the error to preserve your full billing-dispute rights — a phone call alone may not be enough to trigger the formal process.
Track the investigation deadlines your provider must meet
Under the Fair Credit Billing Act, a credit card issuer must acknowledge your dispute within 30 days and resolve it within 90 days. Under Regulation E, a bank generally must investigate within 10 business days (extendable to 45 days in some cases, with provisional credit given during the extension).
If the provider denies your dispute or misapplies the liability rules, escalate
File a complaint with the Consumer Financial Protection Bureau at consumerfinance.gov/complaint (US), or with your national financial ombudsman (EU/UK) — for example, the UK’s Financial Ombudsman Service.
Monitor your account and credit report going forward
Request a fraud alert or credit freeze if the unauthorized transaction suggests broader identity theft, not just a single compromised card number.
Documents to gather
- Statement or transaction record showing the unauthorized charge/transfer
- Reference or case number from your initial fraud report
- Any written dispute letter or online dispute confirmation
- Correspondence from the bank/issuer about the investigation outcome
- Records showing when you first discovered the loss/theft, to establish your reporting timeline
Timelines and Limitation Periods
The reporting deadline determines your liability tier; the dispute-filing deadline determines whether you keep your rights at all
These two clocks are different and both matter — reporting late can raise your maximum liability even if you still file a technically timely dispute afterward. verify current deadlines and caps with your specific card issuer’s cardholder agreement, since some voluntary protections exceed the federal/EU/UK floor
| Jurisdiction | Limitation Period |
|---|---|
| US credit card (Reg Z / FCBA) | Written dispute within 60 days of the statement showing the error; liability capped at $50 ($0 if card-not-present or reported before use) |
| US debit card / EFT (Reg E) | 2 business days for the $50 cap; 60 days from the statement for the $500 cap; unlimited liability risk after that |
| EU (PSD2) | Notify "without undue delay" on discovery; liability capped at €50 before notification (absent gross negligence/fraud), €0 after |
| United Kingdom (Payment Services Regulations 2017) | Notify promptly; liability capped at £35 before notification (absent fraud), £0 after |
Realistic Outcomes and Caveats
Straightforward unauthorized-transaction disputes — reported promptly, clearly not authorized by the accountholder, no gross negligence — are typically resolved with a full refund or credit, often provisionally during the investigation itself.
Disputes involving P2P apps, authorized-but-fraudulently-induced transfers, or claims of gross negligence are considerably harder and less reliably resolved in the consumer’s favor, since the core liability protections are generally built around "unauthorized," not "regretted," transactions.
This page can help identify your liability tier and the deadlines that apply — it cannot predict whether your specific bank will accept your account of events, whether a P2P transfer will be treated as unauthorized, or what a regulator will find if you escalate.
Common Pitfalls
Assuming a phone call alone preserves your rights
For credit cards especially, failing to follow up in writing within 60 days can weaken your formal dispute rights under the Fair Credit Billing Act, even if you called right away.
Not checking your statement regularly
For debit cards/EFT, the difference between the $500 cap and potentially unlimited liability is whether you reported within 60 days of the statement.
Confusing an unauthorized transaction with a transaction you regret
A purchase you authorized but now wish you hadn’t made — even under a scammer’s influence — generally isn’t covered by these liability caps the same way a truly unauthorized charge is.
Assuming zero-liability marketing guarantees $0
Card network zero-liability policies are voluntary and can exclude certain transaction or account types — check the actual cardholder agreement.
Treating EU/UK and US liability rules as interchangeable
The tiers, notification standards, refund-timing obligations, and exact caps (€50 vs. £35) differ — apply the rules for the country where the account is actually held.
Organize Your Dispute
Gather your transaction record, fraud-report reference number, and any written dispute correspondence, then check the liability tier and deadline that applies above.
Organize Your Dispute
Gather your transaction record, fraud-report reference number, and any written dispute correspondence, then check the liability tier and deadline that applies above.
This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.
Official and Legal References
- CFPB — Regulation E, 12 CFR § 1005.6 (Liability of consumer for unauthorized transfers)
- CFPB — Regulation Z / Fair Credit Billing Act, 12 CFR § 1026.12
- CFPB — "What’s the difference between a Regulation E and a Regulation Z dispute?"
- EU Payment Services Directive 2 (EU) 2015/2366, Article 74 — EUR-Lex
- UK Payment Services Regulations 2017, Regulation 77 (liability) — legislation.gov.uk
US Tiered Liability vs. EU/UK Flat Cap
The US system ties your maximum liability to how quickly you report (escalating from $50 to $500 to potentially unlimited for debit/EFT, with a simpler flat $50/$0 structure for credit cards). The EU/UK system instead uses a flat cap before notification (€50 in the EU, £35 in the UK) and zero liability after, with a fast mandatory refund timeline. Always confirm which country’s rules apply to your specific account and the current cap figures, since both frameworks are periodically updated — the EU’s PSD3/PSR reform is in progress but not yet in force as of July 2026.
Frequently Asked Questions
Real edge cases, answered in plain language
Someone used my card number online but never had my physical card — how much am I liable for?
I was tricked into sending money via a P2P app myself — is that "unauthorized"?
My bank says I was "grossly negligent" and is denying my EU/UK dispute — what does that mean?
Organize Your Dispute
Gather your transaction record, fraud-report reference number, and any written dispute correspondence, then check the liability tier and deadline that applies above.