Payment law under the spotlight. Our takeaways from the 12th Banking Law Congress 2026

A customer logs into their mobile banking app, completes two-factor authentication and approves a transfer via a push notification. Everything runs smoothly, yet moments later it emerges that their funds have landed in a fraudster’s account. Who will pay for that? And on what legal basis?

These are real challenges facing the industry today. Banks are contending with relentless changes in terms of regulation, technology, operations and governance. Successive CJEU judgments are redrawing the boundaries of liability, while EU regulations are changing the rules of the game before the sector has had a chance to fully implement and adapt to them. This is precisely why events such as the Banking Law Congress are important: to address these challenges head-on and devise effective solutions with practitioners and experts.

Authorisation ≠ authentication. A distinction worth millions

Liability for unauthorised payment transactions may appear to be a purely technical matter. In practice, however, we are still searching for the best answer to the question of who should bear the financial consequences of the growing number of fraudulent attacks on bank accounts.

Let’s return for a moment to the scenario outlined above: the customer does everything correctly – logs in, completes strong customer authentication and authorises the transaction. However, they are unaware that they have fallen victim to a fraudster who impersonated the bank’s helpline and redirected the authorisation to an entirely different transaction. The bank’s systems show no record of any malfunction or error, the log appears correct, and yet the customer is demanding a refund. So, what is the root cause of the problem?

The answer lies in a fundamental distinction: authorisation is not the same as authentication.

Authentication is merely a technical procedure that enables the payment service provider (in this particular case, the bank) to verify the identity of the payer (i.e. the customer) or the validity of the payment instrument itself.

Authorisation involves more than that. It is the payer’s conscious and freely given consent to a specific transaction. A bank is only liable for unauthorised transactions.

Accordingly, if a transaction is initiated using the payer’s credentials and from their account, but by a party other than the payer themselves, the transaction is unauthorised, regardless of how flawless the authentication process appeared or how many factors it involved.

The situation is different, however, where it is the payer themselves who initiates the payment, albeit at the instigation of a third party. In such cases, the transaction is deemed to have been properly authorised, and the ‘coerced’ consent remains legally effective.

So, what are the practical consequences of the distinction between authorisation and authentication? As mentioned above, the answer lies in the payment service provider’s liability (or lack thereof) for a given transaction. It’s worth noting that the bank is liable for the very occurrence of an unauthorised transaction carried out without the customer’s consent, rather than for any fault or negligence on its own part. Consequently, the bank cannot escape this liability by invoking, for instance, the exercise of due diligence or the correctness of its internal procedures, including proper authentication.

The D+1 rule – a simple principle, a complex dispute

The law requires banks to refund the amount of an unauthorised transaction by the end of the business day following the day on which it was identified. Straightforward enough. In practice, however, the D+1 rule has become one of the most contentious issues in Polish banking law.

On the one side, the President of the Office of Competition and Consumer Protection (UOKiK) and the Financial Ombudsman advocate an unconditional refund, whereby the bank returns the funds without conducting an in-depth analysis (unless it has documented and justified grounds to suspect fraud and reports the matter to the law enforcement authorities).

On the other side, a body of legal scholarship and case law suggests that the refund obligation should extend only to those payment transactions for which the payer bears no responsibility whatsoever. Accordingly, where the provider holds sufficient evidence that the payer has failed with intent or gross negligence to fulfil their obligations, or has deliberately brought about the execution of the payment transaction in question, the provider is released from liability and is not required to make a refund to the customer (while assuming the risk of having to pay interest should it ultimately be found liable).

This dispute has also given rise to two rulings from Luxembourg.

The Opinion of the Advocate General of the Court of Justice of the European Union of 5 March 2026 in Case C-70/25 (Tukowiecka) endorses the first of these positions, relying on a purposive and historical interpretation of the PSD2. The case is still awaiting the Court’s own judgment.

The CJEU judgment of 1 August 2025 in Case C-665/23 (IL v. Veracash), in turn, clarified the consequences of the payer’s failure to notify the payment service provider of unauthorised transactions without undue delay, holding that such failure constitutes an independent ground for the extinction of the claim.

Both rulings are set to shape Polish case law for years to come.

PSR: a new architecture of liability

A change is on the horizon, however, that will revolutionise the payment services market even further. The Payment Services Regulation (PSR) is still making its way through the legislative process, but it is already clear that it will fundamentally reshape the rules governing liability for unauthorised payment transactions and set a new course for the interpretation of EU law in this area.

These are the key changes that the PSR will introduce:

  • An expanded exception to the D+1 rule. The compromise version of the PSR allows the bank to withhold an immediate refund not only in cases of suspected fraud, but also where there are objectively justified grounds to believe that the customer acted with intent or gross negligence. The bank will have 15 business days to carry out its assessment and either issue a refund or provide a reasoned refusal setting out the avenues available to the customer for further pursuit of their claim.
  • A mandatory dialogue with the customer. Before issuing an unfavourable decision, the bank will be required to invite the customer to present their version of events, and to take it into account in reaching its determination. Moreover, a failure by the customer to respond will not, in itself, be sufficient to justify a refusal to issue a refund.
  • A separate regime for spoofing. The PSR creates a distinct, standalone legal basis for the payer to claim a refund of the transaction amount where the transaction resulted from fraudsters impersonating the bank, provided that the matter is reported to the law enforcement authorities without undue delay and the bank is notified accordingly. In such cases, the burden of proving fraud or gross negligence on the part of the customer will continue to rest with the provider. This is a significant systemic change, as it is precisely here that the PSR introduces provider liability for transactions that would otherwise be regarded as properly authorised.
  • IBAN and payee verification. Banks will be required to verify, free of charge, that the account number matches the payee’s details before the transfer is authorised. A failure to provide such a service will result in the bank being held liable, even where the customer authorised the transaction themselves.
  • An extended time limit for lodging claims. Until now, the payer has had 13 months to report an unauthorised transaction. The PSR extends this period to as long as 18 months.

Who pays and what must they prove?

Regardless of whether we are considering the current or the future legal regime, one thing remains constant: the burden of proof rests with the bank. It is the bank that must demonstrate either that the transaction was authorised, or that the customer breached their security obligations (and that the breach was serious), and that there was a causal link between that breach and the transaction.

For years, Polish courts interpreted the defence of gross negligence very narrowly, affording protection to consumers even in cases of serious lapses. A gradual shift is, however, becoming apparent: the case law is beginning to take an increasingly strict view of situations in which the customer disregarded repeated warnings from the bank or facilitated the fraud despite widespread public awareness of the type of attack in question.

The industry stands ready

The 12th Banking Law Congress showed that the industry is well aware of the scale and complexity of the challenges ahead: from a surge in fraud to a sea change in CJEU case law and a fundamental overhaul of European payment services legislation.

In such an environment, the ability to navigate change swiftly and stay ahead of the curve is a real competitive advantage.

Any questions? Contact us


Contact us:

Szymon Bolimowski

Szymon Bolimowski

Advocate / Senior Associate / Disputes of Financial Institutions

+48 888 461 965

s.bolimowski@kochanski.pl