Civil Law And Contactless Payment Error Disputes In Europe .
Civil Law and Contactless Payment Error Disputes in Europe
1. Introduction
Contactless payment error disputes arise when a contactless card, mobile wallet, wearable device or other NFC-enabled payment instrument is used and the transaction is:
incorrectly executed;
duplicated;
charged for the wrong amount;
charged to the wrong account;
processed without the customer's authorisation;
processed after a card has been lost or stolen;
incorrectly recorded by the payment service provider;
disputed because authentication did not occur in the usual manner;
affected by a technical or communication failure.
The subject sits at the intersection of European payment-services law, consumer protection, contract law, banking law and civil liability.
A particularly important CJEU authority is DenizBank, C-287/19, which directly concerned NFC/contactless functionality on a bank card. The Court considered whether NFC functionality constituted a payment instrument and examined the special rules applicable to low-value contactless transactions. (InfoCuria)
2. Meaning of Contactless Payment
A contactless payment normally uses Near Field Communication (NFC) or another short-range technology.
The consumer may use:
contactless debit cards;
credit cards;
prepaid cards;
smartphones;
smartwatches;
wearable payment devices;
virtual cards;
NFC-enabled banking applications.
Unlike a conventional card transaction, a low-value contactless transaction may occur without entering a PIN.
This creates an important legal question:
If no PIN was entered, was the transaction nevertheless authorised?
European payment-services law provides specific rules for answering this question.
3. Main European Legal Framework
The principal EU framework is the Payment Services Directive 2015/2366 (PSD2).
It regulates:
payment transactions;
payment instruments;
authentication;
strong customer authentication;
unauthorised transactions;
incorrectly executed transactions;
payment-service-provider liability;
consumer notification duties;
refund obligations;
security credentials;
low-value payment instruments.
PSD2 replaced the earlier Payment Services Directive 2007/64/EC.
Older CJEU cases therefore frequently interpret the earlier Directive, while their principles remain important for understanding the development of European payment law.
4. Authorised vs Unauthorised Transaction
This is the starting point in almost every payment-error dispute.
Authorised transaction
The payer has given consent to the execution of the payment transaction.
Unauthorised transaction
The payment transaction was executed without the payer's consent.
This distinction is fundamental because the EU liability regime treats the two situations differently.
The CJEU has emphasised that national courts cannot simply bypass this classification and apply a competing general liability regime to obtain reimbursement. (curia)
5. What Is a Payment Instrument?
PSD2 defines a payment instrument broadly enough to cover technological means used to initiate payment transactions.
This became particularly important in DenizBank.
The case involved a bank card with an NFC/contactless function.
The CJEU held that the NFC functionality of the personalised multifunctional bank card constituted a payment instrument for the purposes of PSD2. (InfoCuria)
Importance
This means contactless technology is not outside the ordinary European payment-services legal framework merely because:
no physical insertion occurs;
no PIN is entered for small transactions;
the transaction takes place through NFC.
6. Contactless Payments and Low-Value Transactions
Contactless payments often involve low-value transactions.
PSD2 permits certain limited exemptions from the ordinary authentication requirements for low-value payments, subject to specified conditions.
This creates a practical difference:
Ordinary card transaction
Possible:
Card → terminal → authentication/PIN → transaction
Low-value contactless transaction
Possible:
Card/NFC device → terminal → transaction
without the customer entering a PIN.
But the absence of a PIN does not automatically mean that the transaction is unauthorised.
7. DenizBank: The Most Important Contactless Case
Case 1 — DenizBank AG v Verein für Konsumenteninformation
CJEU, Case C-287/19, judgment of 11 November 2020
Country: Austria
This is the leading European case directly concerning contactless/NFC payment functionality.
Facts
DenizBank issued multifunctional bank cards equipped with NFC functionality.
The dispute concerned contractual terms dealing with:
contactless low-value payments;
information requirements;
changes to framework-contract conditions;
liability for contactless transactions;
inability to block certain low-value transactions;
anonymous use of contactless functionality.
CJEU ruling
The Court held that the NFC functionality constituted a payment instrument.
It also examined the special rules applicable to low-value payment instruments and contactless transactions. (InfoCuria)
Importance
This case establishes the foundation for analysing modern contactless-payment disputes.
Key principle
NFC functionality on a personalised bank card can constitute a payment instrument under EU payment-services law.
8. Case 2 — DM and LR v CRCAM
CJEU, Case C-337/20, judgment of 2 September 2021
Country: France
This case concerned unauthorised payment transactions and the notification requirement.
Issue
The question concerned the relationship between:
notification of an unauthorised payment;
payment-service-provider liability;
claims brought by a person connected to the payment user.
Principle
The CJEU interpreted the notification and liability provisions of the earlier Payment Services Directive.
The case demonstrates the importance of promptly notifying the payment service provider after discovering an unauthorised transaction. (InfoCuria)
Importance for contactless payments
Suppose a consumer discovers several unexplained contactless transactions.
The consumer should not simply wait.
The timing and manner of notification can materially affect the consumer's rights.
9. Case 3 — ZG v Beobank SA
CJEU, Case C-351/21, judgment of 16 March 2023
Country: Belgium
This is an important case involving unauthorised payment transactions and information concerning the payee.
Principle
The CJEU examined the information that a payment service provider must provide to the payer concerning the payment transaction and payee.
The Court also confirmed that the PSD liability framework is highly structured and that a claimant cannot simply replace the Directive's specific liability mechanism with a different competing claim seeking reimbursement for the same operative event.
Importance
For contactless disputes, transaction records may be crucial.
A consumer may ask:
Who received the payment?
When was it made?
What amount was processed?
Was the transaction authenticated?
Was the transaction actually authorised?
10. Case 4 — UA v Eurobank Bulgaria
CJEU, Case C-409/22, judgment of 11 July 2024
Country: Bulgaria
The case concerned:
payment instruments;
authentication;
unauthorised payment transactions;
liability of the payment service provider;
burden of proof.
Principle
The CJEU examined whether particular circumstances constituted a payment instrument and how authentication and unauthorised transactions should be assessed. (InfoCuria)
Importance
The case demonstrates that:
Authentication and authorisation are related but legally distinct concepts.
A bank showing that a technical authentication process occurred does not necessarily end the legal inquiry into whether the payment was actually authorised.
11. Case 5 — Mediterranean Shipping Company (Portugal) v Banco Comercial Português
CJEU, Case C-295/18, judgment of 11 April 2019
Country: Portugal
The dispute involved a payment order and the question of whether a payment transaction was authorised.
Principle
The CJEU considered the scope of the Payment Services Directive and the concept of a payment-service user in the context of an allegedly unauthorised direct debit. (InfoCuria)
Importance
Although this was not a contactless-card case, it is an important analogous authority for determining whether a payment instruction was actually authorised.
12. Case 6 — Veracash, C-665/23
CJEU, judgment of 1 August 2025
Country: France
This is a particularly important recent authority concerning notification of unauthorised transactions.
Facts
A consumer claimed that transactions had been carried out using a payment card without authorisation.
The consumer did not notify the payment institution immediately after becoming aware of the transactions.
Principle
The CJEU held that where the user becomes aware of an unauthorised transaction but delays notification intentionally or through gross negligence, the right to reimbursement can be lost even if notification occurs within the longer 13-month period. (curia)
Importance
For contactless disputes:
Prompt notification is legally important.
A consumer who sees unexplained contactless transactions on a banking application should notify the provider without undue delay.
13. Case 7 — DenizBank and the Allocation of Risk
DenizBank is particularly important because it also dealt with contractual terms attempting to allocate the risk of misuse of contactless functionality to the cardholder.
The Court examined the special rules for low-value payment instruments and the circumstances in which derogations from ordinary liability rules can operate. (InfoCuria)
The important lesson is:
A bank cannot simply contract out of mandatory consumer-protection rules by inserting a general disclaimer into its terms and conditions.
Any derogation must satisfy the conditions established by EU payment-services law.
14. Case 8 — Tukowiecka, C-70/25
CJEU — pending as of September 2026
This is an important current case, although it should not be treated as settled case law.
The case concerns a Polish consumer who was the victim of phishing and an allegedly unauthorised payment transaction.
The Advocate General's opinion of 5 March 2026 considered whether a bank can refuse the immediate refund required by PSD2 because it considers the consumer grossly negligent.
The Advocate General proposed that the bank should generally make the immediate refund first, while potentially pursuing the consumer later if the statutory conditions concerning intentional or grossly negligent conduct are established. The opinion is not binding on the CJEU, and judgment remains pending. (InfoCuria)
Relevance
Although this is phishing rather than contactless payment, it is highly relevant to the developing European concept of:
consumer negligence → authentication → unauthorised transaction → refund → allocation of loss.
15. Payment Error vs Payment Fraud
These should not automatically be treated as the same thing.
Payment error
Example:
Consumer taps €20, but the terminal processes €200.
Possible issue:
incorrectly executed transaction.
Unauthorised payment
Example:
Someone uses the consumer's contactless card without permission.
Possible issue:
unauthorised transaction.
Duplicate transaction
Example:
Consumer taps once but the system records two payments.
Possible issue:
incorrect execution / duplicate processing.
Technical failure
Example:
Terminal shows "declined", but the consumer's account is nevertheless debited.
Possible issue:
incorrect execution and reimbursement.
16. Incorrectly Executed Payment
A payment can be problematic even where the customer initially authorised it.
For example:
Customer authorises €30.
But the payment provider processes:
€300.
The customer did give consent to a transaction, but the transaction was incorrectly executed.
The legal analysis therefore differs from a completely unauthorised payment.
17. Contactless Payment Duplication
Duplicate payments are a common technological risk.
Example:
The customer taps a card once.
The terminal processes:
€25.00;
€25.00.
The customer therefore faces:
one authorisation attempt → two debits.
The legal questions include:
Was one transaction or two authorised?
Did the terminal malfunction?
Was the second transaction properly initiated?
What records exist?
Did the merchant receive one payment or two?
What refund mechanism applies?
18. Wrong Amount Disputes
A contactless payment may be disputed because the amount shown on the terminal differs from the amount actually debited.
Evidence may include:
terminal receipt;
bank statement;
electronic transaction record;
merchant records;
card-network data;
digital-wallet record.
The issue is essentially one of correct execution of an authorised payment.
19. Lost or Stolen Contactless Card
This is particularly important because contactless cards may permit multiple low-value payments without PIN entry.
Example:
Customer loses card at 10:00.
Several contactless transactions occur at 10:30.
Customer notifies bank at 14:00.
The legal questions include:
when the consumer discovered the loss;
when the consumer notified the bank;
whether the transactions were authorised;
whether the consumer acted fraudulently;
whether gross negligence occurred;
whether low-value-payment derogations apply.
The EU framework provides specific rules concerning the payer's liability and notification.
20. Consumer's Duty to Protect Security Credentials
Payment users have duties concerning personalised security credentials and payment instruments.
Examples include:
protecting the card;
protecting PINs;
protecting mobile-device credentials;
notifying the bank of loss;
notifying the provider of unauthorised transactions.
However, gross negligence is not the same thing as ordinary carelessness.
This distinction can be decisive.
The 2026 Advocate General's opinion in Tukowiecka illustrates the continuing importance of the distinction between ordinary consumer error and gross negligence in unauthorised-payment disputes. (curia)
21. Burden of Proof
A major issue is:
Who must prove that the transaction was properly authenticated and authorised?
Payment-service law places significant evidentiary responsibilities on the provider.
The recent Eurobank Bulgaria case specifically concerned authentication, unauthorised transactions and the burden of proof. (InfoCuria)
The provider will normally need to produce relevant technical and transaction evidence.
Examples:
authentication records;
terminal records;
timestamps;
transaction identifiers;
card status;
security information;
payment-network records.
22. Authentication Is Not Necessarily Consent
This is an important examination point.
Suppose:
A contactless card was physically used.
That establishes that the payment instrument was involved.
But the legal question remains:
Did the payer consent to the transaction?
Similarly:
A technical system may show that a transaction was processed successfully.
That does not necessarily resolve every legal question about authorisation.
This distinction appears prominently in the CJEU's payment-services jurisprudence, including Eurobank Bulgaria. (InfoCuria)
23. Contactless Payment and Strong Customer Authentication
PSD2 generally introduced stronger authentication requirements for electronic payments, but provides specified exemptions.
Low-value contactless payments can benefit from an exemption when the statutory conditions are met.
The purpose is to balance:
security
against
convenience and speed.
This is why contactless payments can sometimes occur without PIN entry without automatically becoming legally defective.
24. Consumer Protection and Contract Terms
Banks commonly use standard-form terms covering:
contactless functionality;
transaction limits;
notification;
liability;
card blocking;
lost-card procedures;
authentication;
dispute procedures.
Such terms must comply with applicable mandatory EU and national consumer-protection rules.
DenizBank is especially important because the CJEU examined terms concerning NFC/contactless payments and changes to framework contracts. (InfoCuria)
25. Liability of the Merchant
The merchant can also become relevant.
For example:
Customer pays €50.
Merchant's terminal records €500.
Potential defendants may include:
merchant;
acquiring bank;
payment processor;
issuing bank;
card scheme;
technology provider.
The appropriate defendant depends upon where the error occurred.
26. Liability of the Payment Service Provider
A payment service provider may face liability where:
an unauthorised transaction occurs;
an authorised transaction is incorrectly executed;
the provider fails to comply with mandatory refund rules;
payment instructions are improperly processed;
statutory information duties are violated.
The provider's liability is therefore not limited to traditional bank negligence.
27. Liability of the Consumer
The consumer can potentially bear some loss where the statutory conditions are satisfied, especially where there is:
fraud;
intentional conduct;
gross negligence;
failure to protect security credentials;
unjustified delay in reporting an unauthorised transaction.
However, the applicable statutory requirements must be satisfied.
Veracash illustrates that deliberate or grossly negligent delay in notifying the provider can have serious consequences for the right to reimbursement. (curia)
28. Notification Requirement
The consumer should notify the payment provider without undue delay after becoming aware of an unauthorised or incorrectly executed payment.
This serves two purposes:
protecting the consumer;
allowing the bank to stop further misuse.
For example:
Monday — card stolen.
Tuesday — consumer notices three contactless payments.
Tuesday afternoon — bank notified.
The court may examine whether the notification was sufficiently prompt.
29. 13-Month Rule
Under the relevant EU payment-services framework, notification of an unauthorised or incorrectly executed transaction is generally subject to a maximum 13-month period from the debit, subject to the Directive's conditions.
But Veracash makes an important point:
The existence of a 13-month outer period does not mean the consumer can deliberately or grossly negligently delay notification after becoming aware of the transaction. (curia)
30. Digital Wallets and Mobile Payments
Contactless payment disputes increasingly involve:
Apple Pay-type wallets;
Android-based wallets;
smartwatches;
tokenised cards;
virtual payment cards.
These systems create additional questions:
Is the phone itself the payment instrument?
Who authenticated the transaction?
Was biometric authentication used?
Was the card token compromised?
Was the physical card involved?
Was the device lost?
Was the transaction properly authorised?
The underlying EU payment-services principles remain highly relevant.
31. Evidence in Contactless Payment Litigation
Important evidence may include:
Consumer evidence
bank statement;
SMS;
banking-app notifications;
card-loss report;
screenshots;
merchant receipt.
Bank evidence
transaction logs;
authentication records;
card status;
NFC transaction records;
terminal identifiers;
timestamps.
Merchant evidence
POS records;
CCTV;
receipt;
terminal logs;
refund records.
Technical evidence
payment processor logs;
network records;
tokenisation information;
device authentication.
32. Remedies
Depending on the circumstances, remedies can include:
immediate reimbursement;
correction of the payment account;
reversal of an incorrect debit;
refund of duplicated amounts;
compensation under applicable national law;
interest;
damages where independently recoverable;
cancellation or correction of the payment transaction.
The exact remedy depends on whether the transaction was:
unauthorised;
incorrectly executed;
duplicated;
technically erroneous;
properly authorised but contractually disputed.
33. Multi-Party Disputes
Contactless payment litigation can involve a chain:
Consumer → Issuing Bank → Card Scheme → Acquiring Bank → Merchant → Payment Terminal Provider
A technological failure may occur anywhere in this chain.
Therefore, determining liability requires identifying the point of failure.
34. Practical Example
Suppose a consumer taps a card at a supermarket.
The terminal displays:
€40
But the consumer's account is debited:
€400
The consumer immediately contacts the bank.
The legal analysis would ask:
Step 1
Was the €40 transaction authorised?
Yes.
Step 2
Was €400 authorised?
Possibly not.
Step 3
Was the transaction incorrectly executed?
Potentially yes.
Step 4
Where did the error occur?
terminal?
merchant system?
acquiring bank?
payment network?
issuing bank?
Step 5
What evidence exists?
Transaction logs and receipts become crucial.
Step 6
What remedy applies?
The payment-services liability regime may require correction/refund depending upon the legal classification.
35. Another Example: Stolen Contactless Card
A consumer loses a card.
Before it is blocked, someone makes:
€15;
€20;
€30;
€40
contactless payments.
The consumer reports the loss.
The legal questions include:
Were the transactions authorised?
Did the consumer act fraudulently?
Did the consumer breach security obligations?
Was there gross negligence?
When did the consumer discover the loss?
When was the bank notified?
Does a low-value contactless exemption apply?
What amount must the bank refund?
DenizBank is particularly important for the special treatment of low-value contactless transactions, while Veracash is important concerning delayed notification. (InfoCuria)
36. Comparative European Position
| Issue | General European position |
|---|---|
| Contactless NFC card | Can constitute a payment instrument |
| PIN-free low-value payment | May be permitted under statutory exemption |
| Unauthorised payment | Special statutory liability regime |
| Incorrect payment | Separate classification may apply |
| Consumer notification | Must generally be prompt |
| 13-month outer period | Relevant under EU framework |
| Gross negligence | Can affect consumer reimbursement rights |
| Authentication | Important evidence but not necessarily identical to consent |
| Bank evidence | Highly significant |
| Unfair contractual terms | Subject to consumer-protection rules |
| Mobile/wearable payments | Increasingly covered by payment-services framework |
37. Ten Important Case Laws — Revision Table
| Case | Country | Key principle |
|---|---|---|
| DenizBank, C-287/19 | Austria | NFC/contactless functionality can constitute a payment instrument |
| DM & LR v CRCAM, C-337/20 | France | Notification and liability concerning unauthorised transactions |
| ZG v Beobank, C-351/21 | Belgium | Information concerning payee and structured liability for unauthorised payments |
| UA v Eurobank Bulgaria, C-409/22 | Bulgaria | Authentication, authorisation, burden of proof and unauthorised transactions |
| Mediterranean Shipping Company, C-295/18 | Portugal | Scope of payment-services law and unauthorised payment orders |
| Veracash, C-665/23 | France | Grossly negligent delay in notifying unauthorised transactions can defeat reimbursement |
| Tukowiecka, C-70/25 | Poland | Pending case concerning gross negligence and immediate refund; AG opinion is not binding |
| DenizBank, C-287/19 | Austria | Special rules for low-value contactless instruments |
| ZG v Beobank, C-351/21 | Belgium | Refund claims must be analysed under the specific payment-services liability regime |
| Eurobank Bulgaria, C-409/22 | Bulgaria | Provider's proof concerning authentication and unauthorised transactions |
The repeated authorities above are included because their individual principles are directly relevant to different aspects of contactless-payment disputes; they are not separate cases.
38. Core Legal Principles
Principle 1 — Classification comes first
The court must determine whether the transaction was:
authorised, unauthorised, or incorrectly executed.
Principle 2 — Contactless is legally recognised
NFC functionality can constitute a payment instrument.
Principle 3 — No PIN does not automatically mean no authorisation
Low-value contactless transactions may fall within statutory authentication exemptions.
Principle 4 — Authentication and consent are distinct concepts
Technical authentication evidence does not necessarily resolve every issue concerning authorisation.
Principle 5 — Notification matters
Consumers should notify their payment provider without undue delay.
Principle 6 — Gross negligence matters
The consumer's serious failure to comply with payment-security obligations can affect reimbursement.
Principle 7 — Banks have evidentiary responsibilities
Transaction and authentication records can be critical to determining liability.
Principle 8 — Mandatory EU rules limit contractual exclusions
A bank cannot automatically transfer statutory payment risk to consumers merely through standard terms.
Principle 9 — Low-value payment rules create special treatment
Contactless transactions may receive specific treatment under PSD2.
Principle 10 — Technology does not eliminate civil liability
NFC, mobile wallets, tokenisation and wearable devices create new factual questions but remain subject to legal liability rules.
39. Conclusion
Contactless payment error disputes in Europe are governed principally by the EU payment-services framework, supplemented by national civil, contractual and consumer law.
The central legal issues are:
whether the payment was authorised;
whether it was correctly executed;
whether the NFC device constitutes a payment instrument;
whether an authentication exemption applies;
whether the consumer notified the bank promptly;
whether the consumer acted fraudulently or with gross negligence;
who bears the burden of proving authentication;
whether the bank must refund the amount;
whether contractual exclusions are legally effective.
The most directly relevant authority is DenizBank (C-287/19) because it specifically addresses NFC/contactless payment functionality. CRCAM, Beobank, Eurobank Bulgaria, Mediterranean Shipping Company and Veracash add important principles concerning unauthorised transactions, notification, authentication, evidence and reimbursement. The pending Tukowiecka (C-70/25) proceedings are also significant for the developing European approach to gross negligence and immediate reimbursement, but the Advocate General's 2026 opinion should not be treated as the final judgment. (InfoCuria)
Exam Revision Keywords
Contactless payment — NFC — payment instrument — PSD2 — payment services — authorised transaction — unauthorised transaction — incorrectly executed transaction — authentication — consent — strong customer authentication — low-value payment — contactless exemption — PIN — card security — gross negligence — fraud — notification — 13-month period — refund — reimbursement — burden of proof — payment service provider — issuing bank — acquiring bank — merchant — payment processor — mobile wallet — tokenisation — duplicate transaction — wrong amount — technical error — consumer protection — civil liability — contractual liability — DenizBank — CRCAM — Beobank — Eurobank Bulgaria — Veracash.

comments