Civil Law And Banking Digital Identity Fraud Recovery Claims In Europe .

Civil Law and Banking Digital Identity Fraud Recovery Claims in Europe

1. Introduction

Banking digital identity fraud occurs when criminals obtain or misuse a person's digital identity, banking credentials, authentication information, device access, SIM card, biometric information, or other personal data to obtain money or initiate unauthorised banking transactions.

Typical examples include:

phishing;

smishing;

vishing;

SIM-swap fraud;

account takeover;

stolen online-banking credentials;

fake banking applications;

remote-access fraud;

malware;

social engineering;

fraudulent digital identity documents;

misuse of biometric authentication;

unauthorised bank transfers; and

fraudulent card or mobile-wallet transactions.

In European civil law, recovery claims are principally governed by the Payment Services Directive (PSD2), national implementing legislation, contractual principles, consumer protection law, and the GDPR where personal-data breaches are involved.

A major feature of the European framework is that authentication of a transaction is not automatically the same thing as proof that the customer authorised it. PSD2 expressly places significant evidentiary responsibility on the payment service provider. (Eur-Lex)

2. Meaning of Digital Identity Fraud in Banking

Digital identity fraud occurs when a third party uses information or credentials associated with another person to impersonate that person.

Example

A fraudster obtains:

customer's name;

bank login;

password;

mobile number;

OTP;

device information.

The fraudster then accesses online banking and transfers €25,000.

The customer tells the bank:

"I did not authorise this transaction."

The central legal question becomes:

Who should bear the financial loss?

European payment law generally starts from the principle that the payment service provider must refund an unauthorised transaction, subject to statutory exceptions such as fraud or certain forms of customer misconduct. (Eur-Lex)

3. Main European Legal Framework

A. PSD2 — Directive (EU) 2015/2366

PSD2 is the central legal framework.

Important provisions include:

Article 72 — Evidence

When a customer denies authorising a payment, the payment service provider must prove that the transaction was:

authenticated;

accurately recorded;

entered in the accounts; and

not affected by a technical breakdown or other deficiency.

Importantly, merely showing that a payment instrument was used is not necessarily sufficient to prove authorisation or customer fraud/gross negligence. (Eur-Lex)

B. Article 73 — Refund

For an unauthorised payment transaction, the payment service provider generally must refund the amount immediately and no later than the end of the following business day after becoming aware of or being notified of the transaction.

There is an exception where the provider has reasonable grounds to suspect fraud and communicates those grounds to the competent authority. (Infocuria)

C. Article 74 — Customer Liability

The customer may bear losses in specified circumstances, particularly where the customer:

acted fraudulently; or

intentionally or with gross negligence failed to comply with relevant security obligations.

The distinction between ordinary negligence and gross negligence is therefore extremely important. (Eur-Lex)

4. Strong Customer Authentication

PSD2 requires strong customer authentication for various electronic banking activities.

It generally involves at least two elements from categories such as:

Knowledge — password/PIN;

Possession — phone/security device;

Inherence — fingerprint/face/other biometric characteristic.

For remote electronic payments, authentication is designed to be dynamically linked to the specific amount and payee. (Eur-Lex)

The technical regulatory standards also require transaction-monitoring mechanisms capable of detecting unauthorised or fraudulent transactions. (Eur-Lex)

5. Important Principle: Authentication ≠ Authorisation

This is one of the most important rules for examination purposes.

Suppose:

A fraudster obtains the victim's password and OTP through phishing.

The bank's records may show:

"Correct password + correct OTP."

That does not automatically prove that the genuine customer authorised the payment.

Article 72 specifically provides that use of a payment instrument recorded by the provider is not, by itself, necessarily sufficient to prove authorisation or fraud/gross negligence by the customer. (Eur-Lex)

6. Case Law 1 — CRCAM Alpes-Provence

CJEU, Case C-337/20, 2 September 2021

Facts

The dispute involved unauthorised payment transactions and the liability of the payment service provider under the earlier Payment Services Directive.

Decision

The CJEU clarified the relationship between:

notification requirements;

unauthorised transactions;

payment-provider liability; and

other forms of civil liability.

The Court held that the statutory payment-services regime is important in determining the provider's liability when the user has failed to comply with the notification requirement. (Infocuria)

Principle

A customer must generally notify the bank of an unauthorised transaction without undue delay and within the statutory long-stop period.

Importance

This case establishes the importance of prompt notification in digital identity fraud.

7. Case Law 2 — Beobank v ZG

CJEU, Case C-351/21, 16 March 2023

Facts

A Belgian customer had a debit card.

After one legitimate transaction of €100, two further transactions of approximately €991 and €993 were made using the card.

The customer disputed the transactions.

Issue

The case concerned the bank's obligations in relation to unauthorised transactions and the information that must be provided concerning the relevant payee.

Decision

The CJEU interpreted the payment-services framework concerning the bank's refund obligation and information duties. The judgment emphasizes the significance of information about the payee when determining whether an unauthorised transaction can be properly investigated.

Principle

The bank's obligations are not exhausted by simply recording that a payment occurred.

Relevance to identity fraud

Where a fraudster has impersonated a customer, information concerning:

beneficiary;

transaction;

payment route;

authentication;

transaction records;

may be crucial in establishing what actually happened.

8. Case Law 3 — UA v Eurobank Bulgaria

CJEU, Case C-409/22, 11 July 2024

This is one of the most relevant recent cases.

Issue

The case concerned:

a payment instrument;

an agent acting under a power of attorney;

authentication;

consent;

unauthorised payment transactions; and

the burden of proof.

The Bulgarian court asked the CJEU how authentication and consent should be assessed. (Infocuria)

Principle

The legal concept of authentication must not simply be equated with the customer's substantive consent to the transaction.

Importance

This is highly relevant to digital identity fraud because a fraudster can potentially pass an authentication procedure while still acting without the genuine account holder's authorisation.

9. Case Law 4 — Veracash

CJEU, Case C-665/23, 1 August 2025

Facts

A customer held an account with Veracash.

A new payment/withdrawal card was sent to the customer's address.

The customer stated that he never received the card and did not authorise withdrawals.

Numerous withdrawals were made over a period of almost two months.

The customer eventually notified Veracash.

Decision

The CJEU held that where a customer delays notification of an unauthorised transaction with intent or gross negligence, the customer can lose the right to obtain reimbursement under the applicable payment-services regime, even where notification occurs within the overall 13-month period. (curia)

Principle

There are two different concepts:

13-month long-stop period

and

notification without undue delay.

Meeting the 13-month deadline does not necessarily satisfy the separate requirement of prompt notification.

Importance

A victim of digital identity fraud should therefore notify the bank immediately upon discovering the fraud.

10. Case Law 5 — DenizBank v Verein für Konsumenteninformation

CJEU, Case C-287/19, 11 November 2020

Facts

The case involved personalised multifunctional bank cards with NFC/contactless functionality.

The dispute concerned:

payment instruments;

low-value payments;

authentication;

consumer information;

contractual changes; and

allocation of risk for unauthorised transactions.

Decision

The CJEU examined how PSD2 applies to modern payment instruments and the special rules concerning low-value/contactless payments. (Infocuria)

Principle

Not every transaction necessarily requires identical authentication procedures; EU law permits carefully defined exceptions for certain low-risk/low-value transactions.

Relevance

This is important because a fraudster may exploit:

contactless payments;

mobile wallets;

low-value transactions;

repeated transactions.

Banks must therefore comply with the security and risk-monitoring framework even where a particular transaction falls within an authentication exemption.

11. Case Law 6 — JU and SO v Scalable Capital

CJEU, Joined Cases C-182/22 and C-189/22, 20 June 2024

This case is particularly important for the identity-theft component of banking fraud.

Facts

Personal data stored by an investment/trading application was stolen.

The dispute concerned whether the data theft and risk of identity theft could produce compensable damage under Article 82 GDPR.

Decision

The CJEU held that:

identity theft requires actual misuse of the person's identity by a third party;

however, compensation for non-material damage caused by personal-data theft does not require proof that the stolen data subsequently resulted in identity theft or fraud;

compensation requires unlawful processing, damage and a causal link. (Eur-Lex)

Principle

Data theft and identity theft are not identical concepts.

Relevance to banking

Suppose a bank suffers a data breach and criminals obtain:

names;

account information;

addresses;

identification documents;

contact details.

A customer may potentially have:

a payment-law claim if money was actually taken; and

a GDPR compensation claim if the unlawful processing caused compensable damage.

These are separate legal routes.

12. Case Law 7 — Österreichische Post

CJEU, Case C-300/21, 4 May 2023

This case is an important foundation for GDPR compensation.

Principle

Article 82 GDPR requires:

infringement of GDPR;

damage; and

causal connection between the infringement and damage.

The CJEU subsequently relied upon these principles in Scalable Capital. (Eur-Lex)

Relevance

A banking customer whose identity information has been exposed cannot automatically claim damages merely because a breach occurred.

The claimant must establish legally compensable damage and causation.

13. Case Law 8 — Spanish Supreme Court, Judgment No. 571/2025

Tribunal Supremo, 9 April 2025

This national case is particularly relevant to modern phishing and SIM-swap fraud.

Facts

The dispute involved a sophisticated banking fraud involving phishing and SIM-related identity compromise.

Principle

The Spanish Supreme Court applied the European payment-services framework and emphasized that where the customer disputes authorisation, the payment service provider must prove relevant authentication and proper operation of its systems.

The mere recording of the transaction does not by itself establish that the customer authorised it or acted fraudulently or with gross negligence. (curia)

Importance

This is a useful example of how the CJEU's principles are being applied by national European courts to modern phishing and identity-fraud scenarios.

14. Case Law 9 — Tukowiecka

CJEU, Case C-70/25 — pending in 2026

This is a very important current case, but it should be described accurately as pending.

Facts

A Polish customer was the victim of phishing.

A third party impersonated a buyer on an online sales platform and sent the customer a fraudulent link resembling her bank's website.

The customer entered her banking credentials.

The fraudster subsequently used the information to make an unauthorised payment. (curia)

2026 development

On 5 March 2026, Advocate General Rantos delivered an Opinion.

He considered that the bank cannot refuse the immediate refund merely because it alleges gross negligence by the customer; the question of ultimate allocation of the loss can arise subsequently. (Infocuria)

Important qualification

This is an Advocate General's Opinion, not yet a final CJEU judgment.

Therefore, it should not be presented as settled CJEU law.

Importance

It directly addresses the increasingly common situation:

phishing → customer discloses credentials → fraudster makes unauthorised payment → bank alleges gross negligence.

15. Core Legal Rule for Recovery

The European framework can be simplified as follows:

Stage 1

Customer says:

"I did not authorise this payment."

Stage 2

Bank must establish:

authentication;

correct recording;

accounting;

absence of technical deficiency.

Stage 3

Bank cannot rely merely on:

"The correct password/OTP was used."

The evidence must go further where authorisation is disputed. PSD2 expressly addresses this burden of proof. (Eur-Lex)

Stage 4

The customer may be liable where:

fraud is established; or

statutory requirements concerning intentional/grossly negligent conduct are satisfied.

16. Digital Identity Fraud Methods

A. Phishing

Fraudster sends a fake bank link.

Customer enters:

username;

password;

OTP.

The fraudster then accesses the account.

Legal issue

Was the customer merely deceived, or did the customer act with the degree of fault required by the applicable payment-services rules?

B. Smishing

The fraud is conducted through fraudulent SMS messages.

Example:

"Your bank account will be blocked. Verify immediately."

The victim clicks the link.

C. Vishing

Fraudster calls pretending to be:

bank employee;

police officer;

fraud department;

financial regulator.

The victim provides security information.

D. SIM-Swap

Fraudster obtains control of the victim's mobile number.

The fraudster then receives:

OTPs;

security messages;

account-recovery codes.

This can create difficult questions concerning:

telecommunications providers;

bank authentication;

mobile security;

customer negligence;

bank fraud-monitoring systems.

17. Account Takeover

Account takeover occurs where the fraudster obtains sufficient credentials to control the victim's banking account.

Potential indicators include:

new device;

unusual IP address;

foreign location;

unusual beneficiary;

unusually large payment;

multiple rapid transactions;

unusual transaction timing.

PSD2's technical standards specifically contemplate transaction-monitoring mechanisms based on normal user behaviour and abnormal payment patterns. (Eur-Lex)

18. Bank's Duty of Security

Banks must operate payment systems consistent with the European security framework.

This includes:

strong customer authentication where required;

protection of personalised security credentials;

transaction monitoring;

fraud detection;

secure authentication mechanisms;

appropriate technical and organisational safeguards.

PSD2 Article 97 requires strong customer authentication for specified online-access and electronic-payment situations. (Eur-Lex)

19. Bank's Fraud-Monitoring Obligation

Strong authentication alone does not necessarily solve every fraud problem.

The regulatory technical standards require transaction-monitoring mechanisms capable of detecting unauthorised or fraudulent transactions.

Relevant indicators include:

abnormal spending;

unusual device/software use;

malware;

known fraud scenarios;

abnormal location;

unusual transaction history. (Eur-Lex)

Thus, a dispute may involve not only:

"Was OTP authentication used?"

but also:

"Did the bank's systems identify obvious abnormal behaviour?"

20. Gross Negligence

Gross negligence is a particularly important concept.

It is generally more serious than ordinary carelessness.

A court may examine:

exactly what information the customer disclosed;

whether the message was obviously fraudulent;

whether warnings were ignored;

whether the bank had issued specific warnings;

whether the fraud was sophisticated;

whether the customer was deceived through impersonation;

whether the customer acted immediately after discovering the fraud.

The bank generally cannot simply label conduct "gross negligence" without supporting evidence.

PSD2 places significant evidentiary responsibility on the payment service provider. (Eur-Lex)

21. Notification Duty

The customer should notify the bank:

without undue delay.

The law also establishes a maximum notification period, generally 13 months from the debit date for the PSD2 framework.

Veracash demonstrates that merely notifying within 13 months does not necessarily satisfy the separate requirement of notification without undue delay. (curia)

22. Immediate Refund

Under Article 73 PSD2, the normal rule is:

Unauthorised transaction → immediate refund.

The provider generally must refund no later than the end of the following business day after becoming aware of or being notified of the transaction, subject to the statutory exception concerning reasonable grounds for suspected fraud. (Infocuria)

This is an important consumer-protection feature.

23. Can the Bank Simply Refuse the Refund?

The answer depends upon the circumstances and applicable national implementation.

The bank may seek to rely upon:

fraud by the customer;

intentional breach;

gross negligence;

failure to notify promptly;

other statutory exceptions.

But the bank must satisfy the applicable evidentiary requirements.

The 2026 Tukowiecka Advocate General Opinion is especially significant because it takes the view that gross negligence should not simply allow a bank to bypass the immediate-refund mechanism; the ultimate allocation of losses can be addressed subsequently. Again, this remains an Opinion rather than a final CJEU judgment. (Infocuria)

24. Relationship Between PSD2 and GDPR

Digital identity fraud can involve two different types of legal harm.

Payment fraud

Money is taken from the account.

→ PSD2 / national payment-services law.

Personal-data breach

Identity information is stolen.

→ GDPR / national data-protection law.

Both can occur together

Example:

Bank database hacked → customer identity information stolen → fraudster uses data to access account → €30,000 transferred.

Possible claims:

GDPR claim + PSD2 payment-recovery claim + contractual claim where available.

The legal causes of action must be kept separate.

25. GDPR Compensation for Identity Theft

Under Scalable Capital, actual identity theft means the person's identity has actually been misused.

However, compensation for the unlawful theft of personal data does not require proof that the data were subsequently used for identity theft or fraud, provided the Article 82 requirements of infringement, damage and causation are established. (Eur-Lex)

This is particularly important for banking data breaches.

26. Causation

A claimant must connect the bank's breach or data-processing failure to the damage.

For example:

Bank security failure

↓

Credentials compromised

↓

Fraudster obtains account access

↓

Unauthorised transfer

↓

Financial loss

The court may then ask:

Was the bank's failure a legally relevant cause of the loss?

27. Contributory Conduct

A difficult case arises where both sides contributed.

Bank

inadequate authentication;

weak fraud monitoring;

failure to detect abnormal transaction;

delayed blocking.

Customer

disclosed OTP;

clicked phishing link;

delayed notification.

The court must apply the applicable PSD2 rules concerning allocation of loss.

This is why gross negligence, rather than merely ordinary negligence, can become decisive.

28. Digital Identity Fraud and Biometric Authentication

Modern banks increasingly use:

facial recognition;

fingerprint authentication;

voice recognition;

behavioural biometrics.

A fraudster might nevertheless exploit:

stolen devices;

deepfakes;

synthetic identity;

biometric spoofing;

compromised authentication devices.

The legal question remains:

Was the payment actually authorised by the customer?

The presence of biometric or multi-factor authentication does not automatically eliminate the need to examine authorisation and fraud.

29. Deepfake Banking Fraud

A future category of European civil litigation may involve:

Fraudster uses AI-generated voice/video to impersonate the customer.

For example:

Fraudster creates synthetic voice.

Bank's voice-authentication system accepts it.

Fraudster requests account changes.

Large transfer follows.

Customer disputes transaction.

Potential issues include:

authentication reliability;

AI-system negligence;

bank cybersecurity duties;

transaction monitoring;

causation;

PSD2 allocation of loss.

30. Liability of Different Participants

ParticipantPotential legal issue
BankUnauthorised transaction, security failure
Payment initiation providerAuthentication/execution failure
Card issuerUnauthorised card transaction
Telecom providerSIM-swap/security failure
Identity providerIdentity-verification failure
Software providerSecurity/software defect
Cloud providerService failure
Data processorGDPR breach
CustomerFraud, intent or gross negligence
FraudsterPrimary unlawful conduct

31. Payment Initiation Services

PSD2 also covers payment initiation service providers.

Where a payment is initiated through such a provider, PSD2 allocates evidentiary and reimbursement responsibilities according to the respective provider's sphere of competence. (Eur-Lex)

This matters for open-banking fraud.

Example

Customer uses:

Bank account → third-party payment app → merchant

A fraudulent payment may require determining whether the failure occurred at:

bank;

payment initiation provider;

authentication stage; or

merchant/payment recipient.

32. Contractual Banking Duties

The bank-customer relationship is also contractual.

The contract may contain obligations concerning:

account security;

authentication;

notification;

payment execution;

fraud reporting;

electronic banking.

However, contractual terms cannot simply override mandatory consumer-protection provisions of EU payment law.

33. Evidence in Digital Identity Fraud Litigation

A claimant should preserve:

Banking records

transaction statement;

transaction ID;

beneficiary details;

payment timestamp;

authentication records;

device information;

IP address;

login history.

Communication evidence

SMS;

emails;

phishing links;

call records;

bank warnings;

fraud-reporting correspondence.

Technical evidence

device logs;

SIM-change records;

authentication records;

malware reports;

IP/geolocation information.

Police evidence

fraud complaint;

investigation report;

cybercrime report.

34. Burden of Proof

The burden of proof is particularly significant.

Under Article 72 PSD2, when the user denies authorisation, the payment service provider must establish that the transaction was:

authenticated;

accurately recorded;

entered in the accounts; and

free from technical breakdown or deficiency.

Moreover, authentication evidence alone is not necessarily sufficient to prove authorisation or gross negligence. (Eur-Lex)

This is a major protection for victims of sophisticated digital identity fraud.

35. Recovery from the Fraudster

The bank may refund the customer while separately pursuing the fraudster.

Possible recovery mechanisms include:

civil proceedings;

criminal restitution;

freezing orders;

tracing;

recovery from recipient accounts;

unjust enrichment claims;

asset recovery.

However, recovery from the fraudster is a separate question from the bank's statutory obligation to the customer.

36. Remedies

Potential remedies include:

1. Refund

Recovery of the unauthorised amount.

2. Restoration of account

The account is restored as if the unauthorised transaction had not occurred.

3. Interest

Where permitted by applicable national law.

4. Additional contractual damages

Where legally available.

5. GDPR compensation

For qualifying non-material or material damage resulting from unlawful processing.

6. Injunctive relief

Potentially relevant to prevent continuing misuse of identity information.

37. Important Distinction: Fraudulent Payment vs Fraudulent Identity

These concepts should not be confused.

Fraudulent payment

Money is transferred without genuine authorisation.

Identity fraud

A third party impersonates the customer.

Both may occur together.

Example:

Fraudster steals identity → obtains bank access → makes unauthorised transfer.

The payment-services claim concerns the unauthorised transaction.

The GDPR claim may concern the personal-data breach and identity misuse.

38. Exam Analysis of a Hypothetical

Facts

A customer receives a fake bank SMS.

The customer clicks the link and enters:

username;

password;

OTP.

The fraudster makes a €20,000 transfer.

The customer discovers the transaction the next morning and immediately informs the bank.

The bank refuses reimbursement, saying:

"You disclosed the OTP, so you were grossly negligent."

Legal analysis

Step 1: Was the transaction authorised?

Customer denies authorisation.

Step 2: Bank must prove authentication and proper execution.

Step 3: Authentication alone does not necessarily prove authorisation.

Step 4: Examine whether the customer's conduct amounted to the legally required level of fault.

Step 5: Examine whether the customer notified the bank without undue delay.

Step 6: Apply Article 73/74 PSD2 and national implementing law.

Step 7: Consider whether the bank's fraud-monitoring systems detected abnormal activity.

Step 8: Determine whether the bank must refund.

The approach is consistent with the principles developed in CRCAM, Beobank, Eurobank Bulgaria and the broader PSD2 framework. (Infocuria)

39. Important Case-Law Table

CaseCourt/YearMain principle
CRCAM Alpes-Provence, C-337/20CJEU, 2021Notification and statutory payment-provider liability
DenizBank, C-287/19CJEU, 2020Payment instruments, contactless transactions and authentication
Beobank, C-351/21CJEU, 2023Unauthorised transactions and information concerning payee
Scalable Capital, C-182/22 & C-189/22CJEU, 2024Identity theft, data breach and GDPR compensation
Eurobank Bulgaria, C-409/22CJEU, 2024Authentication, consent and burden of proof
Veracash, C-665/23CJEU, 2025Delayed notification and loss of refund entitlement
Österreichische Post, C-300/21CJEU, 2023GDPR damage and causation
Spanish Supreme Court No. 571/2025Spain, 2025Phishing/SIM-related fraud and bank's evidentiary burden
Tukowiecka, C-70/25CJEU, pending; AG Opinion 2026Phishing, gross negligence and immediate refund

40. Current 2026 Position

The most important current development is C-70/25, Tukowiecka.

The Advocate General's 5 March 2026 Opinion addresses precisely the problem of a customer who was deceived through a phishing website and subsequently had an unauthorised payment made from the account. The Opinion considers that a bank should not refuse the immediate refund merely because it considers the customer grossly negligent; the question of ultimate loss allocation can be addressed subsequently. (curia)

However, this remains an Advocate General's Opinion and not a final CJEU judgment.

Therefore, the established PSD2 provisions and existing CJEU judgments should remain the primary legal foundation.

41. Practical Legal Formula

For a banking digital identity fraud recovery claim, examine:

1. Was the transaction authorised?

↓

2. Was the customer's identity/credential misused?

↓

3. Was strong customer authentication applied?

↓

4. Was the authentication technically valid?

↓

5. Does authentication actually prove customer authorisation?

↓

6. Did the bank's fraud-monitoring systems function properly?

↓

7. Did the customer act fraudulently or with the legally required level of gross negligence?

↓

8. Did the customer notify the bank without undue delay?

↓

9. Does Article 73 require immediate refund?

↓

10. Is there a separate GDPR data-breach claim?

↓

11. What additional contractual/national-law remedies are available?

42. Conclusion

Banking digital identity fraud recovery claims in Europe are primarily governed by the EU payment-services framework, supplemented by GDPR and national civil law.

The central principles are:

Unauthorised transactions generally trigger a refund obligation.

The bank carries an important burden of proof concerning authentication and execution.

Authentication does not automatically prove genuine customer authorisation.

The bank must generally refund an unauthorised transaction promptly, subject to statutory exceptions.

Fraudulent conduct and gross negligence can affect allocation of the loss.

Prompt notification by the customer is extremely important.

A 13-month outer period does not eliminate the requirement of notification without undue delay.

Strong customer authentication is an important security mechanism but is not an absolute defence for the bank.

Transaction-monitoring and fraud-detection obligations are also relevant.

Identity-data theft can generate a separate GDPR compensation claim where the Article 82 requirements are satisfied.

Phishing, SIM-swap, account takeover and deepfake fraud require fact-specific analysis.

The 2026 Tukowiecka Opinion is particularly significant for phishing cases, although the final CJEU judgment remains pending.

Ultra-short exam formula

Digital Banking Identity Fraud =

Unauthorised Transaction + Identity Misuse + PSD2 + Authentication + Authorisation + Bank's Burden of Proof + Strong Customer Authentication + Fraud Monitoring + Gross Negligence + Prompt Notification + Immediate Refund + GDPR + Causation + Damages + Recovery.

LEAVE A COMMENT