Breaking news

Banks Under European Scrutiny: Immediate Reimbursement For Unauthorized Transactions Required

Heightened Vigilance In A Digital Age

Banks in the European Union may be required to reimburse customers for unauthorized transactions unless fraud by the customer is proven. The interpretation relates to the Payment Services Directive (PSD2). The issue has gained attention following a legal opinion by Athanasios Rantos.

Judicial Clarity On Bank Liability

Rantos stated that banks cannot automatically refuse reimbursement after an unauthorized payment. According to his opinion, financial institutions must restore the customer’s funds unless there is evidence of fraudulent behaviour by the account holder. The opinion was issued in relation to a case involving a Polish customer who reported a phishing scam.

An Instructive Case Study

The incident in question involved a Polish customer deceived through a spoofed online auction portal, which mimicked her bank’s website. Despite her prompt notification to the bank, the institution contended that her oversight in protecting sensitive banking information absolved it of liability. However, judicial inquiry has now placed the onus on banks to prove that the customer acted fraudulently, thereby shifting the balance of responsibility.

Implications For The Banking Sector

Looking ahead, the ramifications of this interpretation are extensive, especially as reported electronically facilitated financial fraud escalates. The evolving legal landscape, supplemented by guidelines from the European Securities and Markets Authority, mandates that banks must ensure rebuilding consumer trust by offering immediate reimbursement for unauthorized transactions. This stance will likely curtail banks’ ability to dismiss compensation claims without full investigation of all the circumstances surrounding the breach.

Enhanced Security Measures And Future Outlook

Financial institutions have introduced additional security systems, including multi-factor authentication and transaction verification tools. Further consumer protection measures are expected under the upcoming Payment Services Directive 3 (PSD3) and related payment regulations. Banks continue to advise customers not to share passwords, PIN codes or verification messages with third parties. EU payment rules define how responsibility is shared between banks and customers in cases of fraud.

Conclusion

EU payment rules define how banks must respond to unauthorized transactions. The legal interpretation highlighted in the case could influence how financial institutions assess liability in phishing and online fraud cases across the European Union.

Meta’s $18 Billion Settlement Limits State Claims Over Children’s Data

Meta’s $18 billion settlement with attorneys general from 29 U.S. states includes a provision limiting future state claims over the company’s use of children’s data for age-assurance systems.

Under the agreement, Meta must develop, train and begin testing a system to identify users under 13 within a year of the settlement taking effect. The company already uses AI-based age-detection tools, although the agreement does not require the new system to use AI.

States Agree To Limits On Future Claims

The Children’s Online Privacy Protection Act (COPPA) generally restricts the collection and retention of personal data from children under 13. Under the settlement, the 29 state attorneys general agreed not to bring past, present or future claims under COPPA or similar state laws over the specified use of children’s data.

Meta will not be permitted to use information from users under 13 for advertising, marketing or algorithmic optimisation.

Federal Enforcement Remains Unclear

COPPA is primarily enforced by the Federal Trade Commission, which is not a party to the agreement. That leaves open the possibility of separate federal action over how Meta collects or uses children’s data.

Another issue is whether Meta can keep age-assurance data isolated from its other systems. An independent auditor will monitor compliance, but the settlement does not fully specify what data Meta can retain for training, how long it can be stored or whether derived insights can be used elsewhere.

Legal Risks Remain

Joshua Wurtzel, a partner at Schlam Stone & Dolan, said states could still pursue claims if Meta uses the data outside the settlement’s limits. Such cases could depend on how those limits are interpreted.

Peter Jackson, a data and intellectual property attorney at Greenberg Glusker, said the provision could “disincentivize future enforcement actions.”

The agreement gives Meta greater legal certainty around using children’s data for age assurance, but questions remain over federal enforcement, data retention and secondary use.

Uol
Aretilaw firm
The Future Forbes Realty Global Properties
eCredo

Become a Speaker

Become a Speaker

Become a Partner

Subscribe for our weekly newsletter