Civil Law And Contactless Payment Error Disputes In Europe .

Civil Law and Contactless Payment Error Disputes in Europe

1. Introduction

Contactless payment error disputes arise when a contactless card, mobile wallet, wearable device or other NFC-enabled payment instrument is used and the transaction is:

incorrectly executed;

duplicated;

charged for the wrong amount;

charged to the wrong account;

processed without the customer's authorisation;

processed after a card has been lost or stolen;

incorrectly recorded by the payment service provider;

disputed because authentication did not occur in the usual manner;

affected by a technical or communication failure.

The subject sits at the intersection of European payment-services law, consumer protection, contract law, banking law and civil liability.

A particularly important CJEU authority is DenizBank, C-287/19, which directly concerned NFC/contactless functionality on a bank card. The Court considered whether NFC functionality constituted a payment instrument and examined the special rules applicable to low-value contactless transactions. (InfoCuria)

2. Meaning of Contactless Payment

A contactless payment normally uses Near Field Communication (NFC) or another short-range technology.

The consumer may use:

contactless debit cards;

credit cards;

prepaid cards;

smartphones;

smartwatches;

wearable payment devices;

virtual cards;

NFC-enabled banking applications.

Unlike a conventional card transaction, a low-value contactless transaction may occur without entering a PIN.

This creates an important legal question:

If no PIN was entered, was the transaction nevertheless authorised?

European payment-services law provides specific rules for answering this question.

3. Main European Legal Framework

The principal EU framework is the Payment Services Directive 2015/2366 (PSD2).

It regulates:

payment transactions;

payment instruments;

authentication;

strong customer authentication;

unauthorised transactions;

incorrectly executed transactions;

payment-service-provider liability;

consumer notification duties;

refund obligations;

security credentials;

low-value payment instruments.

PSD2 replaced the earlier Payment Services Directive 2007/64/EC.

Older CJEU cases therefore frequently interpret the earlier Directive, while their principles remain important for understanding the development of European payment law.

4. Authorised vs Unauthorised Transaction

This is the starting point in almost every payment-error dispute.

Authorised transaction

The payer has given consent to the execution of the payment transaction.

Unauthorised transaction

The payment transaction was executed without the payer's consent.

This distinction is fundamental because the EU liability regime treats the two situations differently.

The CJEU has emphasised that national courts cannot simply bypass this classification and apply a competing general liability regime to obtain reimbursement. (curia)

5. What Is a Payment Instrument?

PSD2 defines a payment instrument broadly enough to cover technological means used to initiate payment transactions.

This became particularly important in DenizBank.

The case involved a bank card with an NFC/contactless function.

The CJEU held that the NFC functionality of the personalised multifunctional bank card constituted a payment instrument for the purposes of PSD2. (InfoCuria)

Importance

This means contactless technology is not outside the ordinary European payment-services legal framework merely because:

no physical insertion occurs;

no PIN is entered for small transactions;

the transaction takes place through NFC.

6. Contactless Payments and Low-Value Transactions

Contactless payments often involve low-value transactions.

PSD2 permits certain limited exemptions from the ordinary authentication requirements for low-value payments, subject to specified conditions.

This creates a practical difference:

Ordinary card transaction

Possible:

Card → terminal → authentication/PIN → transaction

Low-value contactless transaction

Possible:

Card/NFC device → terminal → transaction

without the customer entering a PIN.

But the absence of a PIN does not automatically mean that the transaction is unauthorised.

7. DenizBank: The Most Important Contactless Case

Case 1 — DenizBank AG v Verein für Konsumenteninformation

CJEU, Case C-287/19, judgment of 11 November 2020

Country: Austria

This is the leading European case directly concerning contactless/NFC payment functionality.

Facts

DenizBank issued multifunctional bank cards equipped with NFC functionality.

The dispute concerned contractual terms dealing with:

contactless low-value payments;

information requirements;

changes to framework-contract conditions;

liability for contactless transactions;

inability to block certain low-value transactions;

anonymous use of contactless functionality.

CJEU ruling

The Court held that the NFC functionality constituted a payment instrument.

It also examined the special rules applicable to low-value payment instruments and contactless transactions. (InfoCuria)

Importance

This case establishes the foundation for analysing modern contactless-payment disputes.

Key principle

NFC functionality on a personalised bank card can constitute a payment instrument under EU payment-services law.

8. Case 2 — DM and LR v CRCAM

CJEU, Case C-337/20, judgment of 2 September 2021

Country: France

This case concerned unauthorised payment transactions and the notification requirement.

Issue

The question concerned the relationship between:

notification of an unauthorised payment;

payment-service-provider liability;

claims brought by a person connected to the payment user.

Principle

The CJEU interpreted the notification and liability provisions of the earlier Payment Services Directive.

The case demonstrates the importance of promptly notifying the payment service provider after discovering an unauthorised transaction. (InfoCuria)

Importance for contactless payments

Suppose a consumer discovers several unexplained contactless transactions.

The consumer should not simply wait.

The timing and manner of notification can materially affect the consumer's rights.

9. Case 3 — ZG v Beobank SA

CJEU, Case C-351/21, judgment of 16 March 2023

Country: Belgium

This is an important case involving unauthorised payment transactions and information concerning the payee.

Principle

The CJEU examined the information that a payment service provider must provide to the payer concerning the payment transaction and payee.

The Court also confirmed that the PSD liability framework is highly structured and that a claimant cannot simply replace the Directive's specific liability mechanism with a different competing claim seeking reimbursement for the same operative event.

Importance

For contactless disputes, transaction records may be crucial.

A consumer may ask:

Who received the payment?

When was it made?

What amount was processed?

Was the transaction authenticated?

Was the transaction actually authorised?

10. Case 4 — UA v Eurobank Bulgaria

CJEU, Case C-409/22, judgment of 11 July 2024

Country: Bulgaria

The case concerned:

payment instruments;

authentication;

unauthorised payment transactions;

liability of the payment service provider;

burden of proof.

Principle

The CJEU examined whether particular circumstances constituted a payment instrument and how authentication and unauthorised transactions should be assessed. (InfoCuria)

Importance

The case demonstrates that:

Authentication and authorisation are related but legally distinct concepts.

A bank showing that a technical authentication process occurred does not necessarily end the legal inquiry into whether the payment was actually authorised.

11. Case 5 — Mediterranean Shipping Company (Portugal) v Banco Comercial Português

CJEU, Case C-295/18, judgment of 11 April 2019

Country: Portugal

The dispute involved a payment order and the question of whether a payment transaction was authorised.

Principle

The CJEU considered the scope of the Payment Services Directive and the concept of a payment-service user in the context of an allegedly unauthorised direct debit. (InfoCuria)

Importance

Although this was not a contactless-card case, it is an important analogous authority for determining whether a payment instruction was actually authorised.

12. Case 6 — Veracash, C-665/23

CJEU, judgment of 1 August 2025

Country: France

This is a particularly important recent authority concerning notification of unauthorised transactions.

Facts

A consumer claimed that transactions had been carried out using a payment card without authorisation.

The consumer did not notify the payment institution immediately after becoming aware of the transactions.

Principle

The CJEU held that where the user becomes aware of an unauthorised transaction but delays notification intentionally or through gross negligence, the right to reimbursement can be lost even if notification occurs within the longer 13-month period. (curia)

Importance

For contactless disputes:

Prompt notification is legally important.

A consumer who sees unexplained contactless transactions on a banking application should notify the provider without undue delay.

13. Case 7 — DenizBank and the Allocation of Risk

DenizBank is particularly important because it also dealt with contractual terms attempting to allocate the risk of misuse of contactless functionality to the cardholder.

The Court examined the special rules for low-value payment instruments and the circumstances in which derogations from ordinary liability rules can operate. (InfoCuria)

The important lesson is:

A bank cannot simply contract out of mandatory consumer-protection rules by inserting a general disclaimer into its terms and conditions.

Any derogation must satisfy the conditions established by EU payment-services law.

14. Case 8 — Tukowiecka, C-70/25

CJEU — pending as of September 2026

This is an important current case, although it should not be treated as settled case law.

The case concerns a Polish consumer who was the victim of phishing and an allegedly unauthorised payment transaction.

The Advocate General's opinion of 5 March 2026 considered whether a bank can refuse the immediate refund required by PSD2 because it considers the consumer grossly negligent.

The Advocate General proposed that the bank should generally make the immediate refund first, while potentially pursuing the consumer later if the statutory conditions concerning intentional or grossly negligent conduct are established. The opinion is not binding on the CJEU, and judgment remains pending. (InfoCuria)

Relevance

Although this is phishing rather than contactless payment, it is highly relevant to the developing European concept of:

consumer negligence → authentication → unauthorised transaction → refund → allocation of loss.

15. Payment Error vs Payment Fraud

These should not automatically be treated as the same thing.

Payment error

Example:

Consumer taps €20, but the terminal processes €200.

Possible issue:

incorrectly executed transaction.

Unauthorised payment

Example:

Someone uses the consumer's contactless card without permission.

Possible issue:

unauthorised transaction.

Duplicate transaction

Example:

Consumer taps once but the system records two payments.

Possible issue:

incorrect execution / duplicate processing.

Technical failure

Example:

Terminal shows "declined", but the consumer's account is nevertheless debited.

Possible issue:

incorrect execution and reimbursement.

16. Incorrectly Executed Payment

A payment can be problematic even where the customer initially authorised it.

For example:

Customer authorises €30.

But the payment provider processes:

€300.

The customer did give consent to a transaction, but the transaction was incorrectly executed.

The legal analysis therefore differs from a completely unauthorised payment.

17. Contactless Payment Duplication

Duplicate payments are a common technological risk.

Example:

The customer taps a card once.

The terminal processes:

€25.00;

€25.00.

The customer therefore faces:

one authorisation attempt → two debits.

The legal questions include:

Was one transaction or two authorised?

Did the terminal malfunction?

Was the second transaction properly initiated?

What records exist?

Did the merchant receive one payment or two?

What refund mechanism applies?

18. Wrong Amount Disputes

A contactless payment may be disputed because the amount shown on the terminal differs from the amount actually debited.

Evidence may include:

terminal receipt;

bank statement;

electronic transaction record;

merchant records;

card-network data;

digital-wallet record.

The issue is essentially one of correct execution of an authorised payment.

19. Lost or Stolen Contactless Card

This is particularly important because contactless cards may permit multiple low-value payments without PIN entry.

Example:

Customer loses card at 10:00.

Several contactless transactions occur at 10:30.

Customer notifies bank at 14:00.

The legal questions include:

when the consumer discovered the loss;

when the consumer notified the bank;

whether the transactions were authorised;

whether the consumer acted fraudulently;

whether gross negligence occurred;

whether low-value-payment derogations apply.

The EU framework provides specific rules concerning the payer's liability and notification.

20. Consumer's Duty to Protect Security Credentials

Payment users have duties concerning personalised security credentials and payment instruments.

Examples include:

protecting the card;

protecting PINs;

protecting mobile-device credentials;

notifying the bank of loss;

notifying the provider of unauthorised transactions.

However, gross negligence is not the same thing as ordinary carelessness.

This distinction can be decisive.

The 2026 Advocate General's opinion in Tukowiecka illustrates the continuing importance of the distinction between ordinary consumer error and gross negligence in unauthorised-payment disputes. (curia)

21. Burden of Proof

A major issue is:

Who must prove that the transaction was properly authenticated and authorised?

Payment-service law places significant evidentiary responsibilities on the provider.

The recent Eurobank Bulgaria case specifically concerned authentication, unauthorised transactions and the burden of proof. (InfoCuria)

The provider will normally need to produce relevant technical and transaction evidence.

Examples:

authentication records;

terminal records;

timestamps;

transaction identifiers;

card status;

security information;

payment-network records.

22. Authentication Is Not Necessarily Consent

This is an important examination point.

Suppose:

A contactless card was physically used.

That establishes that the payment instrument was involved.

But the legal question remains:

Did the payer consent to the transaction?

Similarly:

A technical system may show that a transaction was processed successfully.

That does not necessarily resolve every legal question about authorisation.

This distinction appears prominently in the CJEU's payment-services jurisprudence, including Eurobank Bulgaria. (InfoCuria)

23. Contactless Payment and Strong Customer Authentication

PSD2 generally introduced stronger authentication requirements for electronic payments, but provides specified exemptions.

Low-value contactless payments can benefit from an exemption when the statutory conditions are met.

The purpose is to balance:

security

against

convenience and speed.

This is why contactless payments can sometimes occur without PIN entry without automatically becoming legally defective.

24. Consumer Protection and Contract Terms

Banks commonly use standard-form terms covering:

contactless functionality;

transaction limits;

notification;

liability;

card blocking;

lost-card procedures;

authentication;

dispute procedures.

Such terms must comply with applicable mandatory EU and national consumer-protection rules.

DenizBank is especially important because the CJEU examined terms concerning NFC/contactless payments and changes to framework contracts. (InfoCuria)

25. Liability of the Merchant

The merchant can also become relevant.

For example:

Customer pays €50.

Merchant's terminal records €500.

Potential defendants may include:

merchant;

acquiring bank;

payment processor;

issuing bank;

card scheme;

technology provider.

The appropriate defendant depends upon where the error occurred.

26. Liability of the Payment Service Provider

A payment service provider may face liability where:

an unauthorised transaction occurs;

an authorised transaction is incorrectly executed;

the provider fails to comply with mandatory refund rules;

payment instructions are improperly processed;

statutory information duties are violated.

The provider's liability is therefore not limited to traditional bank negligence.

27. Liability of the Consumer

The consumer can potentially bear some loss where the statutory conditions are satisfied, especially where there is:

fraud;

intentional conduct;

gross negligence;

failure to protect security credentials;

unjustified delay in reporting an unauthorised transaction.

However, the applicable statutory requirements must be satisfied.

Veracash illustrates that deliberate or grossly negligent delay in notifying the provider can have serious consequences for the right to reimbursement. (curia)

28. Notification Requirement

The consumer should notify the payment provider without undue delay after becoming aware of an unauthorised or incorrectly executed payment.

This serves two purposes:

protecting the consumer;

allowing the bank to stop further misuse.

For example:

Monday — card stolen.

Tuesday — consumer notices three contactless payments.

Tuesday afternoon — bank notified.

The court may examine whether the notification was sufficiently prompt.

29. 13-Month Rule

Under the relevant EU payment-services framework, notification of an unauthorised or incorrectly executed transaction is generally subject to a maximum 13-month period from the debit, subject to the Directive's conditions.

But Veracash makes an important point:

The existence of a 13-month outer period does not mean the consumer can deliberately or grossly negligently delay notification after becoming aware of the transaction. (curia)

30. Digital Wallets and Mobile Payments

Contactless payment disputes increasingly involve:

Apple Pay-type wallets;

Android-based wallets;

smartwatches;

tokenised cards;

virtual payment cards.

These systems create additional questions:

Is the phone itself the payment instrument?

Who authenticated the transaction?

Was biometric authentication used?

Was the card token compromised?

Was the physical card involved?

Was the device lost?

Was the transaction properly authorised?

The underlying EU payment-services principles remain highly relevant.

31. Evidence in Contactless Payment Litigation

Important evidence may include:

Consumer evidence

bank statement;

SMS;

banking-app notifications;

card-loss report;

screenshots;

merchant receipt.

Bank evidence

transaction logs;

authentication records;

card status;

NFC transaction records;

terminal identifiers;

timestamps.

Merchant evidence

POS records;

CCTV;

receipt;

terminal logs;

refund records.

Technical evidence

payment processor logs;

network records;

tokenisation information;

device authentication.

32. Remedies

Depending on the circumstances, remedies can include:

immediate reimbursement;

correction of the payment account;

reversal of an incorrect debit;

refund of duplicated amounts;

compensation under applicable national law;

interest;

damages where independently recoverable;

cancellation or correction of the payment transaction.

The exact remedy depends on whether the transaction was:

unauthorised;

incorrectly executed;

duplicated;

technically erroneous;

properly authorised but contractually disputed.

33. Multi-Party Disputes

Contactless payment litigation can involve a chain:

Consumer → Issuing Bank → Card Scheme → Acquiring Bank → Merchant → Payment Terminal Provider

A technological failure may occur anywhere in this chain.

Therefore, determining liability requires identifying the point of failure.

34. Practical Example

Suppose a consumer taps a card at a supermarket.

The terminal displays:

€40

But the consumer's account is debited:

€400

The consumer immediately contacts the bank.

The legal analysis would ask:

Step 1

Was the €40 transaction authorised?

Yes.

Step 2

Was €400 authorised?

Possibly not.

Step 3

Was the transaction incorrectly executed?

Potentially yes.

Step 4

Where did the error occur?

terminal?

merchant system?

acquiring bank?

payment network?

issuing bank?

Step 5

What evidence exists?

Transaction logs and receipts become crucial.

Step 6

What remedy applies?

The payment-services liability regime may require correction/refund depending upon the legal classification.

35. Another Example: Stolen Contactless Card

A consumer loses a card.

Before it is blocked, someone makes:

€15;

€20;

€30;

€40

contactless payments.

The consumer reports the loss.

The legal questions include:

Were the transactions authorised?

Did the consumer act fraudulently?

Did the consumer breach security obligations?

Was there gross negligence?

When did the consumer discover the loss?

When was the bank notified?

Does a low-value contactless exemption apply?

What amount must the bank refund?

DenizBank is particularly important for the special treatment of low-value contactless transactions, while Veracash is important concerning delayed notification. (InfoCuria)

36. Comparative European Position

IssueGeneral European position
Contactless NFC cardCan constitute a payment instrument
PIN-free low-value paymentMay be permitted under statutory exemption
Unauthorised paymentSpecial statutory liability regime
Incorrect paymentSeparate classification may apply
Consumer notificationMust generally be prompt
13-month outer periodRelevant under EU framework
Gross negligenceCan affect consumer reimbursement rights
AuthenticationImportant evidence but not necessarily identical to consent
Bank evidenceHighly significant
Unfair contractual termsSubject to consumer-protection rules
Mobile/wearable paymentsIncreasingly covered by payment-services framework

37. Ten Important Case Laws — Revision Table

CaseCountryKey principle
DenizBank, C-287/19AustriaNFC/contactless functionality can constitute a payment instrument
DM & LR v CRCAM, C-337/20FranceNotification and liability concerning unauthorised transactions
ZG v Beobank, C-351/21BelgiumInformation concerning payee and structured liability for unauthorised payments
UA v Eurobank Bulgaria, C-409/22BulgariaAuthentication, authorisation, burden of proof and unauthorised transactions
Mediterranean Shipping Company, C-295/18PortugalScope of payment-services law and unauthorised payment orders
Veracash, C-665/23FranceGrossly negligent delay in notifying unauthorised transactions can defeat reimbursement
Tukowiecka, C-70/25PolandPending case concerning gross negligence and immediate refund; AG opinion is not binding
DenizBank, C-287/19AustriaSpecial rules for low-value contactless instruments
ZG v Beobank, C-351/21BelgiumRefund claims must be analysed under the specific payment-services liability regime
Eurobank Bulgaria, C-409/22BulgariaProvider's proof concerning authentication and unauthorised transactions

The repeated authorities above are included because their individual principles are directly relevant to different aspects of contactless-payment disputes; they are not separate cases.

38. Core Legal Principles

Principle 1 — Classification comes first

The court must determine whether the transaction was:

authorised, unauthorised, or incorrectly executed.

Principle 2 — Contactless is legally recognised

NFC functionality can constitute a payment instrument.

Principle 3 — No PIN does not automatically mean no authorisation

Low-value contactless transactions may fall within statutory authentication exemptions.

Principle 4 — Authentication and consent are distinct concepts

Technical authentication evidence does not necessarily resolve every issue concerning authorisation.

Principle 5 — Notification matters

Consumers should notify their payment provider without undue delay.

Principle 6 — Gross negligence matters

The consumer's serious failure to comply with payment-security obligations can affect reimbursement.

Principle 7 — Banks have evidentiary responsibilities

Transaction and authentication records can be critical to determining liability.

Principle 8 — Mandatory EU rules limit contractual exclusions

A bank cannot automatically transfer statutory payment risk to consumers merely through standard terms.

Principle 9 — Low-value payment rules create special treatment

Contactless transactions may receive specific treatment under PSD2.

Principle 10 — Technology does not eliminate civil liability

NFC, mobile wallets, tokenisation and wearable devices create new factual questions but remain subject to legal liability rules.

39. Conclusion

Contactless payment error disputes in Europe are governed principally by the EU payment-services framework, supplemented by national civil, contractual and consumer law.

The central legal issues are:

whether the payment was authorised;

whether it was correctly executed;

whether the NFC device constitutes a payment instrument;

whether an authentication exemption applies;

whether the consumer notified the bank promptly;

whether the consumer acted fraudulently or with gross negligence;

who bears the burden of proving authentication;

whether the bank must refund the amount;

whether contractual exclusions are legally effective.

The most directly relevant authority is DenizBank (C-287/19) because it specifically addresses NFC/contactless payment functionality. CRCAM, Beobank, Eurobank Bulgaria, Mediterranean Shipping Company and Veracash add important principles concerning unauthorised transactions, notification, authentication, evidence and reimbursement. The pending Tukowiecka (C-70/25) proceedings are also significant for the developing European approach to gross negligence and immediate reimbursement, but the Advocate General's 2026 opinion should not be treated as the final judgment. (InfoCuria)

Exam Revision Keywords

Contactless payment — NFC — payment instrument — PSD2 — payment services — authorised transaction — unauthorised transaction — incorrectly executed transaction — authentication — consent — strong customer authentication — low-value payment — contactless exemption — PIN — card security — gross negligence — fraud — notification — 13-month period — refund — reimbursement — burden of proof — payment service provider — issuing bank — acquiring bank — merchant — payment processor — mobile wallet — tokenisation — duplicate transaction — wrong amount — technical error — consumer protection — civil liability — contractual liability — DenizBank — CRCAM — Beobank — Eurobank Bulgaria — Veracash.

LEAVE A COMMENT