Alior Bank, mBank, BNP Paribas and Bank Millennium will change the way they handle reports of unauthorised payment transactions. The banks have also committed to reassessing some complaints that were previously rejected. Four binding decisions by the president of Poland's Office of Competition and Consumer Protection, UOKiK, conclude proceedings that lasted almost four years.
The dispute focused primarily on what a bank should do after a customer reports a payment transaction that they say they neither made nor authorised. UOKiK argued that in some cases banks failed to return funds within the statutory deadline or refunded money only conditionally for the duration of their internal complaint procedure. Banks will change procedures and revisit some old cases
The decisions concern Alior Bank, mBank, BNP Paribas and Bank Millennium. Each institution proposed remedies that, according to UOKiK, eliminate both the questioned practices and their effects. In practice, this means changing procedures for the future and reassessing some claims from customers who were previously refused reimbursement.
UOKiK president Tomasz Chróstny has emphasised that a commitment decision is not a compromise with the bank. It can be issued when a company proposes measures that fully remove an infringement and its consequences.
One of the most important issues in the proceedings was the distinction between authenticating a customer and authorising a specific transaction.
Authentication confirms a user's identity or the correct use of a payment instrument. Authorisation, by contrast, means the customer consciously consented to a particular payment. The fact that a card, password, code or banking-app confirmation was technically used does not automatically prove that the customer knowingly approved the actual transaction.
This distinction is especially important in cases involving social-engineering fraud, account takeover or criminals impersonating bank employees. A technically correct authentication process may occur even when the victim does not understand what transaction is really being approved. When should the bank return the money?
As a general rule, a bank should refund a reported unauthorised transaction immediately and no later than the end of the next business day after detecting it or receiving the customer's notification.
There are exceptions. A bank may withhold reimbursement when it has reasonable and properly documented grounds to suspect fraud by the payer and reports the matter to law-enforcement authorities.
An initial refund also does not necessarily settle liability permanently. If the bank subsequently proves that the customer acted intentionally or with gross negligence, it may seek repayment of the reimbursed amount. Security measures are also changing
The UOKiK proceedings have run alongside broader changes in fraud prevention across Poland's financial sector. Banks have introduced systems using artificial intelligence and behavioural biometrics to detect unusual activity, delays for selected transactions and tools allowing customers to block transactions immediately after suspicious activity is detected.
UOKiK says some of these changes followed recommendations for payment-service providers issued in 2024. The aim is to prevent the theft of funds before a dispute over responsibility arises. Ten similar proceedings remain open
The four decisions close the cases involving these banks, but UOKiK's work in the area is not finished. Ten similar proceedings concerning other banks remain under way.
For customers, the most practical consequence is that some people whose complaints about unauthorised transactions were rejected may now receive a fresh assessment. The scope and procedure will depend on the individual commitment decisions issued to each institution.
Source: ManagerPlus; Office of Competition and Consumer Protection (UOKiK), 7 September 2026.
(0)Comments