Unauthorised payment: reporting without delay is required

French law firm dedicated to business disputes

Last updated on
29/8/2026

Reporting an unauthorised payment transaction within thirteen months of the debit is not enough to obtain a refund. The duty to report without delay arises as soon as the transaction becomes known. A payer who delays deliberately or through gross negligence loses the right to correction. But the court must first date that knowledge and establish the seriousness of the negligence (Com., 14 January 2026, No. 22-14.822).

Key points

  • The user of a payment instrument must report an unauthorised transaction without delay, from the moment they became aware of it.
  • The report must be made at the latest within thirteen months of the debit date, under Article L. 133-24 of the French Monetary and Financial Code, in the version resulting from Ordinance No. 2009-866 of 15 July 2009.
  • Complying with that thirteen-month period does not protect the user: a late report, whether deliberate or grossly negligent, deprives them of the right to have the transaction corrected.
  • A refusal to refund based on lateness presupposes that the date on which the first contested transaction became known is established.
  • A clause making the cardholder solely responsible for use of the card does not, in itself, establish gross negligence.

Reporting an unauthorised payment transaction

The commercial chamber quashes the court of appeal's decision: the judges could not find that reporting was late without dating the knowledge of the first contested transaction. A private individual had opened a gold deposit account with a payment service provider. On 24 March 2017, the provider sent a new withdrawal and payment card to their address. The holder claimed neither to have requested nor received that card, and to have suffered daily unauthorised withdrawals from 30 March to 17 May 2017. They submitted a challenge form on 23 May 2017, then brought proceedings against the provider seeking reimbursement and damages.

The decision under appeal (CA Paris, 3 January 2022, No. 20/07303) had dismissed those claims, finding that the report was late and that the holder had been imprudent and negligent. The decision is quashed in all its provisions, with remittal to the Paris court of appeal, differently constituted. The commercial chamber first rejects, however, the argument raised in the appeal to the Cour de cassation (France's highest civil court) that the user is free to take thirteen months: that ground of appeal is unfounded.

The commercial chamber, having referred to the Court of Justice of the European Union a question on the interpretation of Directive 2007/64 EC of 13 November 2007 and received its answer (CJUE, 1 August 2025, C-665/23), sets out the rule applicable to unauthorised transactions:

the obligation on the payment service user to report an unauthorised transaction to their payment service provider without delay arises from the moment they became aware of it and that, having failed to report it, deliberately or through gross negligence, they are deprived of the right to obtain correction of that transaction, regardless of whether the report was made within thirteen months of the debit date.

The second quashing concerns gross negligence. The lower court judges had found that the holder was contractually solely responsible for use of the card, and had failed both to prevent a third party from accessing their letterbox and to keep their user ID and secret key confidential. The commercial chamber holds this reasoning "insufficient to establish the gross negligence allegedly committed by [the holder], in particular for failing to specify the circumstances in which the third party had obtained access to their user ID and secret key".

What late reporting changes for the provider

The payment service provider may refuse to correct a transaction reported late, but only if the delay is intentional or results from gross negligence, established in concrete terms. Two distinct bases must be handled separately. The first is late reporting under Article L. 133-24 of the French Monetary and Financial Code. The second is the allocation of losses under Article L. 133-19, IV, of the same code, which requires fraudulent conduct by the payer, or an intentional or grossly negligent breach of the obligations in Articles L. 133-16 and L. 133-17 of that code.

The practical starting point shifts. The date of the first contested debit is no longer enough to characterise a delay: it is the date of knowledge of the transaction that governs the assessment. A refusal file that merely counts the weeks elapsed since the debit remains incomplete. It must specify when the holder knew, how they knew, and why their silence reflects an intention or an established breach of a duty of diligence.

The reasons given for a refusal are also tightened as regards data security. Relying on a contractual clause placing sole liability on the cardholder, or on general imprudence, does not meet the requirement of gross negligence. The commercial chamber expects a description of the circumstances in which the third party obtained the user ID and the secret key. Failing that, Article L. 133-18 of the French Monetary and Financial Code, in the version resulting from Law No. 2010-737 of 1 July 2010, leads to immediate refund of the unauthorised transaction.

What the decision confirms and what remains open

The decision confirms that the thirteen-month period is no safe harbour for the user, while at the same time tightening the reasoning requirements imposed on a refusal to correct. What the decision changes: establishing the date of knowledge becomes a mandatory preliminary step whenever a report is challenged as late. What it confirms: loss of the right to correction remains subject to qualified conduct by the payer, intentional or grossly negligent, apart from fraudulent conduct.

The opinion of the advocate general référendaire sheds light on that requirement. It distinguishes imprudence from negligence, two different notions, and notes that the decision under appeal did not establish the seriousness of the negligence, which justified the quashing. It also recalls that, according to the answer given by the Court of Justice of the European Union, a late report that is intentional or grossly negligent deprives the payer of a refund of all unauthorised transactions, and not only of those that could have been avoided.

Part of the dispute remains open. The court of appeal to which the case is remitted will have to establish the date of knowledge of the first transaction and, where appropriate, establish gross negligence. As the case law stood on 14 January 2026, the solution is given on texts in their version prior to Ordinance No. 2017-1252 of 9 August 2017, which invites a check of the version applicable to each dispute.

What steps should be taken when handling a challenge?

Handling a challenge to an unauthorised transaction turns on two items of evidence: the date on which the customer became aware, and the exact circumstances in which the security data were compromised. The chronology must be reconstructed from objective evidence: statements made available, alerts sent, intermediate complaints. Characterising the delay as deliberate or grossly negligent requires showing that the customer knew and did not act.

The second step concerns personalised security features. Under Article L. 133-19, III, of the French Monetary and Financial Code, save where the payer has acted fraudulently, the payer bears no financial consequence where the provider fails to supply appropriate means enabling the notification for blocking purposes provided for in Article L. 133-17 of the same code. The availability and traceability of the blocking channel are therefore a separate point of vigilance, independent of the customer's conduct.

Points to document as soon as a challenge is received

  • The date on which the customer states they became aware of the first contested transaction, and the documents corroborating it.
  • The circumstances of the compromise: access to mail, disclosure of the user ID and the secret key, authentication method used.
  • The maximum reporting period of thirteen months from the debit date, bearing in mind that compliance with it does not prevent loss of the right to correction.
  • The customer's status, since Article L. 133-24 of the French Monetary and Financial Code reserves contractual derogation to cases where the user is not a natural person acting for non-professional purposes.

Frequently Asked Questions

Can a customer obtain a refund for a fraudulent payment reported eleven months after the debit?

Not necessarily. Under a commercial chamber decision of 14 January 2026, the duty to report an unauthorised payment transaction without delay arises as soon as the user becomes aware of it. Reporting within thirteen months of the debit therefore offers no shelter: a customer who delays deliberately or through gross negligence after learning of the transaction loses the right to have it corrected.

How can the date on which the account holder discovered an unauthorised withdrawal be proved?

The commercial chamber does not allocate the burden of that proof in its decision of 14 January 2026, but it requires the court to establish the date whenever a report is said to be late. In practice, the debate turns on objective evidence: account statements made available, alerts sent to the customer, log-ins, and exchanges predating the formal challenge.

Is a clause making the cardholder solely responsible for use of the card enough to refuse a refund?

No. In its decision of 14 January 2026, the commercial chamber held to be insufficient reasoning that the holder was contractually solely responsible for use of the card and had failed to keep the user ID and secret key confidential. A refusal requires gross negligence to be established, in particular by specifying the circumstances in which the third party obtained those security data.

Can the thirteen-month reporting period be set aside by the payment services contract?

Yes, but not in every case. Article L. 133-24 of the French Monetary and Financial Code, in the version resulting from Ordinance No. 2009-866 of 15 July 2009, allows the parties to depart from its provisions, except where the user is a natural person acting for non-professional purposes. The status of the customer therefore determines whether a contractual adjustment of the reporting duty is valid.

What is the risk for a provider that offers no means of blocking a compromised card?

It may have to bear the entire loss. Under Article L. 133-19, III, of the French Monetary and Financial Code, in the version resulting from Ordinance No. 2009-866 of 15 July 2009, the payer bears no financial consequence, save where the payer has acted fraudulently, if the provider fails to supply appropriate means enabling the notification for the purpose of blocking the payment instrument provided for in Article L. 133-17 of the same code.