Civil Law And Banking Digital Identity Fraud Recovery Claims In Europe .
Civil Law and Banking Digital Identity Fraud Recovery Claims in Europe
1. Introduction
Banking digital identity fraud occurs when criminals obtain or misuse a person's digital identity, banking credentials, authentication information, device access, SIM card, biometric information, or other personal data to obtain money or initiate unauthorised banking transactions.
Typical examples include:
phishing;
smishing;
vishing;
SIM-swap fraud;
account takeover;
stolen online-banking credentials;
fake banking applications;
remote-access fraud;
malware;
social engineering;
fraudulent digital identity documents;
misuse of biometric authentication;
unauthorised bank transfers; and
fraudulent card or mobile-wallet transactions.
In European civil law, recovery claims are principally governed by the Payment Services Directive (PSD2), national implementing legislation, contractual principles, consumer protection law, and the GDPR where personal-data breaches are involved.
A major feature of the European framework is that authentication of a transaction is not automatically the same thing as proof that the customer authorised it. PSD2 expressly places significant evidentiary responsibility on the payment service provider. (Eur-Lex)
2. Meaning of Digital Identity Fraud in Banking
Digital identity fraud occurs when a third party uses information or credentials associated with another person to impersonate that person.
Example
A fraudster obtains:
customer's name;
bank login;
password;
mobile number;
OTP;
device information.
The fraudster then accesses online banking and transfers €25,000.
The customer tells the bank:
"I did not authorise this transaction."
The central legal question becomes:
Who should bear the financial loss?
European payment law generally starts from the principle that the payment service provider must refund an unauthorised transaction, subject to statutory exceptions such as fraud or certain forms of customer misconduct. (Eur-Lex)
3. Main European Legal Framework
A. PSD2 — Directive (EU) 2015/2366
PSD2 is the central legal framework.
Important provisions include:
Article 72 — Evidence
When a customer denies authorising a payment, the payment service provider must prove that the transaction was:
authenticated;
accurately recorded;
entered in the accounts; and
not affected by a technical breakdown or other deficiency.
Importantly, merely showing that a payment instrument was used is not necessarily sufficient to prove authorisation or customer fraud/gross negligence. (Eur-Lex)
B. Article 73 — Refund
For an unauthorised payment transaction, the payment service provider generally must refund the amount immediately and no later than the end of the following business day after becoming aware of or being notified of the transaction.
There is an exception where the provider has reasonable grounds to suspect fraud and communicates those grounds to the competent authority. (Infocuria)
C. Article 74 — Customer Liability
The customer may bear losses in specified circumstances, particularly where the customer:
acted fraudulently; or
intentionally or with gross negligence failed to comply with relevant security obligations.
The distinction between ordinary negligence and gross negligence is therefore extremely important. (Eur-Lex)
4. Strong Customer Authentication
PSD2 requires strong customer authentication for various electronic banking activities.
It generally involves at least two elements from categories such as:
Knowledge — password/PIN;
Possession — phone/security device;
Inherence — fingerprint/face/other biometric characteristic.
For remote electronic payments, authentication is designed to be dynamically linked to the specific amount and payee. (Eur-Lex)
The technical regulatory standards also require transaction-monitoring mechanisms capable of detecting unauthorised or fraudulent transactions. (Eur-Lex)
5. Important Principle: Authentication ≠ Authorisation
This is one of the most important rules for examination purposes.
Suppose:
A fraudster obtains the victim's password and OTP through phishing.
The bank's records may show:
"Correct password + correct OTP."
That does not automatically prove that the genuine customer authorised the payment.
Article 72 specifically provides that use of a payment instrument recorded by the provider is not, by itself, necessarily sufficient to prove authorisation or fraud/gross negligence by the customer. (Eur-Lex)
6. Case Law 1 — CRCAM Alpes-Provence
CJEU, Case C-337/20, 2 September 2021
Facts
The dispute involved unauthorised payment transactions and the liability of the payment service provider under the earlier Payment Services Directive.
Decision
The CJEU clarified the relationship between:
notification requirements;
unauthorised transactions;
payment-provider liability; and
other forms of civil liability.
The Court held that the statutory payment-services regime is important in determining the provider's liability when the user has failed to comply with the notification requirement. (Infocuria)
Principle
A customer must generally notify the bank of an unauthorised transaction without undue delay and within the statutory long-stop period.
Importance
This case establishes the importance of prompt notification in digital identity fraud.
7. Case Law 2 — Beobank v ZG
CJEU, Case C-351/21, 16 March 2023
Facts
A Belgian customer had a debit card.
After one legitimate transaction of €100, two further transactions of approximately €991 and €993 were made using the card.
The customer disputed the transactions.
Issue
The case concerned the bank's obligations in relation to unauthorised transactions and the information that must be provided concerning the relevant payee.
Decision
The CJEU interpreted the payment-services framework concerning the bank's refund obligation and information duties. The judgment emphasizes the significance of information about the payee when determining whether an unauthorised transaction can be properly investigated.
Principle
The bank's obligations are not exhausted by simply recording that a payment occurred.
Relevance to identity fraud
Where a fraudster has impersonated a customer, information concerning:
beneficiary;
transaction;
payment route;
authentication;
transaction records;
may be crucial in establishing what actually happened.
8. Case Law 3 — UA v Eurobank Bulgaria
CJEU, Case C-409/22, 11 July 2024
This is one of the most relevant recent cases.
Issue
The case concerned:
a payment instrument;
an agent acting under a power of attorney;
authentication;
consent;
unauthorised payment transactions; and
the burden of proof.
The Bulgarian court asked the CJEU how authentication and consent should be assessed. (Infocuria)
Principle
The legal concept of authentication must not simply be equated with the customer's substantive consent to the transaction.
Importance
This is highly relevant to digital identity fraud because a fraudster can potentially pass an authentication procedure while still acting without the genuine account holder's authorisation.
9. Case Law 4 — Veracash
CJEU, Case C-665/23, 1 August 2025
Facts
A customer held an account with Veracash.
A new payment/withdrawal card was sent to the customer's address.
The customer stated that he never received the card and did not authorise withdrawals.
Numerous withdrawals were made over a period of almost two months.
The customer eventually notified Veracash.
Decision
The CJEU held that where a customer delays notification of an unauthorised transaction with intent or gross negligence, the customer can lose the right to obtain reimbursement under the applicable payment-services regime, even where notification occurs within the overall 13-month period. (curia)
Principle
There are two different concepts:
13-month long-stop period
and
notification without undue delay.
Meeting the 13-month deadline does not necessarily satisfy the separate requirement of prompt notification.
Importance
A victim of digital identity fraud should therefore notify the bank immediately upon discovering the fraud.
10. Case Law 5 — DenizBank v Verein für Konsumenteninformation
CJEU, Case C-287/19, 11 November 2020
Facts
The case involved personalised multifunctional bank cards with NFC/contactless functionality.
The dispute concerned:
payment instruments;
low-value payments;
authentication;
consumer information;
contractual changes; and
allocation of risk for unauthorised transactions.
Decision
The CJEU examined how PSD2 applies to modern payment instruments and the special rules concerning low-value/contactless payments. (Infocuria)
Principle
Not every transaction necessarily requires identical authentication procedures; EU law permits carefully defined exceptions for certain low-risk/low-value transactions.
Relevance
This is important because a fraudster may exploit:
contactless payments;
mobile wallets;
low-value transactions;
repeated transactions.
Banks must therefore comply with the security and risk-monitoring framework even where a particular transaction falls within an authentication exemption.
11. Case Law 6 — JU and SO v Scalable Capital
CJEU, Joined Cases C-182/22 and C-189/22, 20 June 2024
This case is particularly important for the identity-theft component of banking fraud.
Facts
Personal data stored by an investment/trading application was stolen.
The dispute concerned whether the data theft and risk of identity theft could produce compensable damage under Article 82 GDPR.
Decision
The CJEU held that:
identity theft requires actual misuse of the person's identity by a third party;
however, compensation for non-material damage caused by personal-data theft does not require proof that the stolen data subsequently resulted in identity theft or fraud;
compensation requires unlawful processing, damage and a causal link. (Eur-Lex)
Principle
Data theft and identity theft are not identical concepts.
Relevance to banking
Suppose a bank suffers a data breach and criminals obtain:
names;
account information;
addresses;
identification documents;
contact details.
A customer may potentially have:
a payment-law claim if money was actually taken; and
a GDPR compensation claim if the unlawful processing caused compensable damage.
These are separate legal routes.
12. Case Law 7 — Österreichische Post
CJEU, Case C-300/21, 4 May 2023
This case is an important foundation for GDPR compensation.
Principle
Article 82 GDPR requires:
infringement of GDPR;
damage; and
causal connection between the infringement and damage.
The CJEU subsequently relied upon these principles in Scalable Capital. (Eur-Lex)
Relevance
A banking customer whose identity information has been exposed cannot automatically claim damages merely because a breach occurred.
The claimant must establish legally compensable damage and causation.
13. Case Law 8 — Spanish Supreme Court, Judgment No. 571/2025
Tribunal Supremo, 9 April 2025
This national case is particularly relevant to modern phishing and SIM-swap fraud.
Facts
The dispute involved a sophisticated banking fraud involving phishing and SIM-related identity compromise.
Principle
The Spanish Supreme Court applied the European payment-services framework and emphasized that where the customer disputes authorisation, the payment service provider must prove relevant authentication and proper operation of its systems.
The mere recording of the transaction does not by itself establish that the customer authorised it or acted fraudulently or with gross negligence. (curia)
Importance
This is a useful example of how the CJEU's principles are being applied by national European courts to modern phishing and identity-fraud scenarios.
14. Case Law 9 — Tukowiecka
CJEU, Case C-70/25 — pending in 2026
This is a very important current case, but it should be described accurately as pending.
Facts
A Polish customer was the victim of phishing.
A third party impersonated a buyer on an online sales platform and sent the customer a fraudulent link resembling her bank's website.
The customer entered her banking credentials.
The fraudster subsequently used the information to make an unauthorised payment. (curia)
2026 development
On 5 March 2026, Advocate General Rantos delivered an Opinion.
He considered that the bank cannot refuse the immediate refund merely because it alleges gross negligence by the customer; the question of ultimate allocation of the loss can arise subsequently. (Infocuria)
Important qualification
This is an Advocate General's Opinion, not yet a final CJEU judgment.
Therefore, it should not be presented as settled CJEU law.
Importance
It directly addresses the increasingly common situation:
phishing → customer discloses credentials → fraudster makes unauthorised payment → bank alleges gross negligence.
15. Core Legal Rule for Recovery
The European framework can be simplified as follows:
Stage 1
Customer says:
"I did not authorise this payment."
Stage 2
Bank must establish:
authentication;
correct recording;
accounting;
absence of technical deficiency.
Stage 3
Bank cannot rely merely on:
"The correct password/OTP was used."
The evidence must go further where authorisation is disputed. PSD2 expressly addresses this burden of proof. (Eur-Lex)
Stage 4
The customer may be liable where:
fraud is established; or
statutory requirements concerning intentional/grossly negligent conduct are satisfied.
16. Digital Identity Fraud Methods
A. Phishing
Fraudster sends a fake bank link.
Customer enters:
username;
password;
OTP.
The fraudster then accesses the account.
Legal issue
Was the customer merely deceived, or did the customer act with the degree of fault required by the applicable payment-services rules?
B. Smishing
The fraud is conducted through fraudulent SMS messages.
Example:
"Your bank account will be blocked. Verify immediately."
The victim clicks the link.
C. Vishing
Fraudster calls pretending to be:
bank employee;
police officer;
fraud department;
financial regulator.
The victim provides security information.
D. SIM-Swap
Fraudster obtains control of the victim's mobile number.
The fraudster then receives:
OTPs;
security messages;
account-recovery codes.
This can create difficult questions concerning:
telecommunications providers;
bank authentication;
mobile security;
customer negligence;
bank fraud-monitoring systems.
17. Account Takeover
Account takeover occurs where the fraudster obtains sufficient credentials to control the victim's banking account.
Potential indicators include:
new device;
unusual IP address;
foreign location;
unusual beneficiary;
unusually large payment;
multiple rapid transactions;
unusual transaction timing.
PSD2's technical standards specifically contemplate transaction-monitoring mechanisms based on normal user behaviour and abnormal payment patterns. (Eur-Lex)
18. Bank's Duty of Security
Banks must operate payment systems consistent with the European security framework.
This includes:
strong customer authentication where required;
protection of personalised security credentials;
transaction monitoring;
fraud detection;
secure authentication mechanisms;
appropriate technical and organisational safeguards.
PSD2 Article 97 requires strong customer authentication for specified online-access and electronic-payment situations. (Eur-Lex)
19. Bank's Fraud-Monitoring Obligation
Strong authentication alone does not necessarily solve every fraud problem.
The regulatory technical standards require transaction-monitoring mechanisms capable of detecting unauthorised or fraudulent transactions.
Relevant indicators include:
abnormal spending;
unusual device/software use;
malware;
known fraud scenarios;
abnormal location;
unusual transaction history. (Eur-Lex)
Thus, a dispute may involve not only:
"Was OTP authentication used?"
but also:
"Did the bank's systems identify obvious abnormal behaviour?"
20. Gross Negligence
Gross negligence is a particularly important concept.
It is generally more serious than ordinary carelessness.
A court may examine:
exactly what information the customer disclosed;
whether the message was obviously fraudulent;
whether warnings were ignored;
whether the bank had issued specific warnings;
whether the fraud was sophisticated;
whether the customer was deceived through impersonation;
whether the customer acted immediately after discovering the fraud.
The bank generally cannot simply label conduct "gross negligence" without supporting evidence.
PSD2 places significant evidentiary responsibility on the payment service provider. (Eur-Lex)
21. Notification Duty
The customer should notify the bank:
without undue delay.
The law also establishes a maximum notification period, generally 13 months from the debit date for the PSD2 framework.
Veracash demonstrates that merely notifying within 13 months does not necessarily satisfy the separate requirement of notification without undue delay. (curia)
22. Immediate Refund
Under Article 73 PSD2, the normal rule is:
Unauthorised transaction → immediate refund.
The provider generally must refund no later than the end of the following business day after becoming aware of or being notified of the transaction, subject to the statutory exception concerning reasonable grounds for suspected fraud. (Infocuria)
This is an important consumer-protection feature.
23. Can the Bank Simply Refuse the Refund?
The answer depends upon the circumstances and applicable national implementation.
The bank may seek to rely upon:
fraud by the customer;
intentional breach;
gross negligence;
failure to notify promptly;
other statutory exceptions.
But the bank must satisfy the applicable evidentiary requirements.
The 2026 Tukowiecka Advocate General Opinion is especially significant because it takes the view that gross negligence should not simply allow a bank to bypass the immediate-refund mechanism; the ultimate allocation of losses can be addressed subsequently. Again, this remains an Opinion rather than a final CJEU judgment. (Infocuria)
24. Relationship Between PSD2 and GDPR
Digital identity fraud can involve two different types of legal harm.
Payment fraud
Money is taken from the account.
→ PSD2 / national payment-services law.
Personal-data breach
Identity information is stolen.
→ GDPR / national data-protection law.
Both can occur together
Example:
Bank database hacked → customer identity information stolen → fraudster uses data to access account → €30,000 transferred.
Possible claims:
GDPR claim + PSD2 payment-recovery claim + contractual claim where available.
The legal causes of action must be kept separate.
25. GDPR Compensation for Identity Theft
Under Scalable Capital, actual identity theft means the person's identity has actually been misused.
However, compensation for the unlawful theft of personal data does not require proof that the data were subsequently used for identity theft or fraud, provided the Article 82 requirements of infringement, damage and causation are established. (Eur-Lex)
This is particularly important for banking data breaches.
26. Causation
A claimant must connect the bank's breach or data-processing failure to the damage.
For example:
Bank security failure
↓
Credentials compromised
↓
Fraudster obtains account access
↓
Unauthorised transfer
↓
Financial loss
The court may then ask:
Was the bank's failure a legally relevant cause of the loss?
27. Contributory Conduct
A difficult case arises where both sides contributed.
Bank
inadequate authentication;
weak fraud monitoring;
failure to detect abnormal transaction;
delayed blocking.
Customer
disclosed OTP;
clicked phishing link;
delayed notification.
The court must apply the applicable PSD2 rules concerning allocation of loss.
This is why gross negligence, rather than merely ordinary negligence, can become decisive.
28. Digital Identity Fraud and Biometric Authentication
Modern banks increasingly use:
facial recognition;
fingerprint authentication;
voice recognition;
behavioural biometrics.
A fraudster might nevertheless exploit:
stolen devices;
deepfakes;
synthetic identity;
biometric spoofing;
compromised authentication devices.
The legal question remains:
Was the payment actually authorised by the customer?
The presence of biometric or multi-factor authentication does not automatically eliminate the need to examine authorisation and fraud.
29. Deepfake Banking Fraud
A future category of European civil litigation may involve:
Fraudster uses AI-generated voice/video to impersonate the customer.
For example:
Fraudster creates synthetic voice.
Bank's voice-authentication system accepts it.
Fraudster requests account changes.
Large transfer follows.
Customer disputes transaction.
Potential issues include:
authentication reliability;
AI-system negligence;
bank cybersecurity duties;
transaction monitoring;
causation;
PSD2 allocation of loss.
30. Liability of Different Participants
| Participant | Potential legal issue |
|---|---|
| Bank | Unauthorised transaction, security failure |
| Payment initiation provider | Authentication/execution failure |
| Card issuer | Unauthorised card transaction |
| Telecom provider | SIM-swap/security failure |
| Identity provider | Identity-verification failure |
| Software provider | Security/software defect |
| Cloud provider | Service failure |
| Data processor | GDPR breach |
| Customer | Fraud, intent or gross negligence |
| Fraudster | Primary unlawful conduct |
31. Payment Initiation Services
PSD2 also covers payment initiation service providers.
Where a payment is initiated through such a provider, PSD2 allocates evidentiary and reimbursement responsibilities according to the respective provider's sphere of competence. (Eur-Lex)
This matters for open-banking fraud.
Example
Customer uses:
Bank account → third-party payment app → merchant
A fraudulent payment may require determining whether the failure occurred at:
bank;
payment initiation provider;
authentication stage; or
merchant/payment recipient.
32. Contractual Banking Duties
The bank-customer relationship is also contractual.
The contract may contain obligations concerning:
account security;
authentication;
notification;
payment execution;
fraud reporting;
electronic banking.
However, contractual terms cannot simply override mandatory consumer-protection provisions of EU payment law.
33. Evidence in Digital Identity Fraud Litigation
A claimant should preserve:
Banking records
transaction statement;
transaction ID;
beneficiary details;
payment timestamp;
authentication records;
device information;
IP address;
login history.
Communication evidence
SMS;
emails;
phishing links;
call records;
bank warnings;
fraud-reporting correspondence.
Technical evidence
device logs;
SIM-change records;
authentication records;
malware reports;
IP/geolocation information.
Police evidence
fraud complaint;
investigation report;
cybercrime report.
34. Burden of Proof
The burden of proof is particularly significant.
Under Article 72 PSD2, when the user denies authorisation, the payment service provider must establish that the transaction was:
authenticated;
accurately recorded;
entered in the accounts; and
free from technical breakdown or deficiency.
Moreover, authentication evidence alone is not necessarily sufficient to prove authorisation or gross negligence. (Eur-Lex)
This is a major protection for victims of sophisticated digital identity fraud.
35. Recovery from the Fraudster
The bank may refund the customer while separately pursuing the fraudster.
Possible recovery mechanisms include:
civil proceedings;
criminal restitution;
freezing orders;
tracing;
recovery from recipient accounts;
unjust enrichment claims;
asset recovery.
However, recovery from the fraudster is a separate question from the bank's statutory obligation to the customer.
36. Remedies
Potential remedies include:
1. Refund
Recovery of the unauthorised amount.
2. Restoration of account
The account is restored as if the unauthorised transaction had not occurred.
3. Interest
Where permitted by applicable national law.
4. Additional contractual damages
Where legally available.
5. GDPR compensation
For qualifying non-material or material damage resulting from unlawful processing.
6. Injunctive relief
Potentially relevant to prevent continuing misuse of identity information.
37. Important Distinction: Fraudulent Payment vs Fraudulent Identity
These concepts should not be confused.
Fraudulent payment
Money is transferred without genuine authorisation.
Identity fraud
A third party impersonates the customer.
Both may occur together.
Example:
Fraudster steals identity → obtains bank access → makes unauthorised transfer.
The payment-services claim concerns the unauthorised transaction.
The GDPR claim may concern the personal-data breach and identity misuse.
38. Exam Analysis of a Hypothetical
Facts
A customer receives a fake bank SMS.
The customer clicks the link and enters:
username;
password;
OTP.
The fraudster makes a €20,000 transfer.
The customer discovers the transaction the next morning and immediately informs the bank.
The bank refuses reimbursement, saying:
"You disclosed the OTP, so you were grossly negligent."
Legal analysis
Step 1: Was the transaction authorised?
Customer denies authorisation.
Step 2: Bank must prove authentication and proper execution.
Step 3: Authentication alone does not necessarily prove authorisation.
Step 4: Examine whether the customer's conduct amounted to the legally required level of fault.
Step 5: Examine whether the customer notified the bank without undue delay.
Step 6: Apply Article 73/74 PSD2 and national implementing law.
Step 7: Consider whether the bank's fraud-monitoring systems detected abnormal activity.
Step 8: Determine whether the bank must refund.
The approach is consistent with the principles developed in CRCAM, Beobank, Eurobank Bulgaria and the broader PSD2 framework. (Infocuria)
39. Important Case-Law Table
| Case | Court/Year | Main principle |
|---|---|---|
| CRCAM Alpes-Provence, C-337/20 | CJEU, 2021 | Notification and statutory payment-provider liability |
| DenizBank, C-287/19 | CJEU, 2020 | Payment instruments, contactless transactions and authentication |
| Beobank, C-351/21 | CJEU, 2023 | Unauthorised transactions and information concerning payee |
| Scalable Capital, C-182/22 & C-189/22 | CJEU, 2024 | Identity theft, data breach and GDPR compensation |
| Eurobank Bulgaria, C-409/22 | CJEU, 2024 | Authentication, consent and burden of proof |
| Veracash, C-665/23 | CJEU, 2025 | Delayed notification and loss of refund entitlement |
| Österreichische Post, C-300/21 | CJEU, 2023 | GDPR damage and causation |
| Spanish Supreme Court No. 571/2025 | Spain, 2025 | Phishing/SIM-related fraud and bank's evidentiary burden |
| Tukowiecka, C-70/25 | CJEU, pending; AG Opinion 2026 | Phishing, gross negligence and immediate refund |
40. Current 2026 Position
The most important current development is C-70/25, Tukowiecka.
The Advocate General's 5 March 2026 Opinion addresses precisely the problem of a customer who was deceived through a phishing website and subsequently had an unauthorised payment made from the account. The Opinion considers that a bank should not refuse the immediate refund merely because it considers the customer grossly negligent; the question of ultimate loss allocation can be addressed subsequently. (curia)
However, this remains an Advocate General's Opinion and not a final CJEU judgment.
Therefore, the established PSD2 provisions and existing CJEU judgments should remain the primary legal foundation.
41. Practical Legal Formula
For a banking digital identity fraud recovery claim, examine:
1. Was the transaction authorised?
↓
2. Was the customer's identity/credential misused?
↓
3. Was strong customer authentication applied?
↓
4. Was the authentication technically valid?
↓
5. Does authentication actually prove customer authorisation?
↓
6. Did the bank's fraud-monitoring systems function properly?
↓
7. Did the customer act fraudulently or with the legally required level of gross negligence?
↓
8. Did the customer notify the bank without undue delay?
↓
9. Does Article 73 require immediate refund?
↓
10. Is there a separate GDPR data-breach claim?
↓
11. What additional contractual/national-law remedies are available?
42. Conclusion
Banking digital identity fraud recovery claims in Europe are primarily governed by the EU payment-services framework, supplemented by GDPR and national civil law.
The central principles are:
Unauthorised transactions generally trigger a refund obligation.
The bank carries an important burden of proof concerning authentication and execution.
Authentication does not automatically prove genuine customer authorisation.
The bank must generally refund an unauthorised transaction promptly, subject to statutory exceptions.
Fraudulent conduct and gross negligence can affect allocation of the loss.
Prompt notification by the customer is extremely important.
A 13-month outer period does not eliminate the requirement of notification without undue delay.
Strong customer authentication is an important security mechanism but is not an absolute defence for the bank.
Transaction-monitoring and fraud-detection obligations are also relevant.
Identity-data theft can generate a separate GDPR compensation claim where the Article 82 requirements are satisfied.
Phishing, SIM-swap, account takeover and deepfake fraud require fact-specific analysis.
The 2026 Tukowiecka Opinion is particularly significant for phishing cases, although the final CJEU judgment remains pending.
Ultra-short exam formula
Digital Banking Identity Fraud =
Unauthorised Transaction + Identity Misuse + PSD2 + Authentication + Authorisation + Bank's Burden of Proof + Strong Customer Authentication + Fraud Monitoring + Gross Negligence + Prompt Notification + Immediate Refund + GDPR + Causation + Damages + Recovery.

comments