Passers-by walk in front of the Polski Bank on July 22, 2022 in the center of Warsaw. - The PKO Bank Polski Group is one of the largest institutions in Poland, and it is also one of the leading financial groups in Central and Eastern Europe.
MIGUEL MEDINA/AFP via Getty Images
Poland's consumer protection authority
The Office of Competition and Consumer Protection (UOKiK) issued what Polish law calls "commitment decisions" against Alior Bank, mBank, BNP Paribas Bank Polska, and Bank Millennium, closing nearly four years of enforcement proceedings. The four banks are required to change their complaints procedures and, critically, to reopen past rejections and reconsider them on the correct legal standard. Ten separate proceedings against other Polish banks remain active.
Banks Treated Entered Codes as Proof of Consent — the Law Says Otherwise
The legal distinction that drove every refund denial in this saga is a technical one, but it is not complicated once stated plainly: authentication and authorization are not the same thing under EU payment services law.
Authentication is the technical process of verifying who is operating a payment instrument — checking that the correct PIN was entered, that the registered app was unlocked, or that a one-time SMS code was used. It confirms identity. Authorization, by contrast, is something larger: the payer's conscious, informed consent to a specific transaction. Authentication can occur without authorization whenever a criminal manipulates a victim into entering a valid code for a transaction the victim does not understand.
Phishing attacks and social engineering schemes — where fraudsters impersonate banks, marketplace platforms, or even police officers — exploit this gap. The victim authenticates, because the correct code is entered. But the victim never authorized the payment, because they had no idea they were approving a transfer to a criminal. Banks across Poland treated authentication as conclusive proof of authorization, denied the refund, and often told customers in writing that the "transaction was authorized" and that the customer was responsible.
UOKiK President Tomasz Chróstny put it plainly in the formal proceedings statement: "Authorization and authentication are not the same thing. Correct use of a card, entry of a code, or confirmation of an operation in an app does not in itself establish that the consumer consciously agreed to a given transaction."
A Four-Year Enforcement Campaign
The road to Monday's decisions began in July 2021, when UOKiK opened explanatory proceedings against 18 Polish banks over their handling of unauthorized payment complaints. The regulator had been receiving a growing wave of consumer complaints: money vanished from accounts through phishing and credential theft, victims reported it, and banks said no.
Formal charges followed in July 2022 against five institutions — Bank Millennium, BNP Paribas Bank Polska, Credit Agricole Bank Polska, mBank, and Santander Bank Polska — for unlawfully refusing to return funds from unauthorized transactions and for misleading consumers in their complaint responses. A second wave of charges hit four more banks in late 2022, and
Monday's decisions close four of those cases. UOKiK President Chróstny described the outcome as proof that even lengthy regulatory dialogue can produce concrete legal results: "The conclusion of proceedings against Alior Bank, BNP Paribas, Bank Millennium, and mBank shows that even in difficult cases, dialogue can be constructive and lead to specific solutions required by law and protecting consumer interests."
What the D+1 Rule Actually Requires
The law these banks violated has been on the books since Poland transposed the EU's Payment Services Directive (PSD2) into national law. Article 46 of the Act on Payment Services requires a straightforward sequence when a customer reports an unauthorized transaction: the bank must return the disputed funds by the end of the next business day after receiving the report.
Only two situations permit the bank to withhold that refund. First, if the customer's complaint arrives more than 13 months after the unauthorized transaction — the statute of limitations. Second, if the bank has well-founded, documented grounds to suspect that the customer themselves committed fraud, and the bank has formally notified law enforcement of that suspicion.
Banks have no legal right to withhold the initial refund while conducting their own internal investigation. Banks have no legal right to withhold the refund because they believe the customer was negligent. Banks have no legal right to withhold the refund because the transaction passed strong customer authentication. The refund is owed first. If the bank later establishes through evidence — and ultimately through a court — that the customer's intentional conduct or gross negligence caused the loss, the bank may then pursue recovery. That is the legally correct sequence. What the four named banks were doing was the reverse: investigating first, refusing second, and effectively forcing customers to sue in order to recover funds the law required to be returned within a day.
The 72-Year-Old Retiree Who Lost Her Life Savings
UOKiK has described the human cost of these practices through documented cases. Among the most striking: a 72-year-old woman who spent 30 years building her savings. A fraudster obtained her banking credentials and
The bank's failures were multiple and documented: it processed a currency conversion without question; it wired funds abroad without triggering alerts; it issued a large loan to a customer with a low pension and no borrowing history; it did not flag the moment a fraudster, posing as the woman, changed her marital status from married to widowed — solely to avoid requiring her husband's signature on the loan.
When she filed a complaint, the bank denied it. Its position, according to UOKiK: the transaction was authorized.
What Commitment Decisions Mean — and Why Past Victims Should Pay Attention
A commitment decision under Polish competition and consumer law is not a settlement or a compromise. UOKiK can only issue one when the proposed remedies completely eliminate both the unlawful practice and its effects. That is why the re-examination requirement matters: it is not enough for the banks to behave correctly in the future. The decisions require them to go back through past rejections and apply the correct legal standard.
Consumers who previously had unauthorized-payment complaints rejected by Alior Bank, mBank, BNP Paribas Bank Polska, or Bank Millennium should be aware that their cases may now be eligible for re-examination. The banks are obligated to conduct that review process under the terms of their commitment decisions.
The financial exposure from these re-examinations is real. Where a bank finds that a past rejection was incorrect — that authentication was treated as authorization, or that a refund was not made within D+1 — the consumer should receive the money owed, potentially including amounts stolen years ago.
AI and Behavioral Biometrics: How Banks Are Changing Their Prevention
Beyond the refund rules, UOKiK's years of dialogue have also produced voluntary industry-wide changes in how banks try to stop fraud before it happens. Since the regulator published
These are meaningful improvements. They address fraud prevention — stopping the attack before the consumer loses money. But they are separate from the refund rights that Monday's decisions reinforce. Even when a bank's fraud-detection systems fail, the D+1 rule still applies.
Is Your Bank Next? The Rest of the Cases
Monday's decisions close four of the proceedings launched since 2021. Ten others remain active against other Polish banks that were part of the same enforcement campaign. The regulator has not publicly named all of the institutions still under investigation in this tranche, though the original 2021 sweep covered 18 banks and subsequent waves added more.
The decisions reached with the four named banks do not bind institutions still in proceedings — but they set a clear precedent for the standard UOKiK will require.
Are You Protected Even If Your Bank Is in France or Germany?
Poland is not acting alone. The same PSD2 Directive that UOKiK enforced against these four banks governs payment services across all 27 EU member states. The authentication/authorization distinction is not a Polish legal peculiarity — it is embedded in the directive's text and applies to every bank in the EU.
That principle got sharper legal backing in March 2026, when Advocate General Athanasios Rantos of the Court of Justice of the EU (CJEU) issued a
Tukowiecka
(C-70/25). The case arose from a Polish woman who was tricked through a phishing attack into entering her banking credentials on a fake website — a fraudster took 3,000 PLN (approximately $808) from her account, PKO Bank Polski refused to refund her, and she sued. The Polish district court referred the question to the CJEU.
Rantos concluded that EU law requires banks to refund unauthorized payments immediately upon notification — even when the bank suspects the customer acted with gross negligence. The bank's remedy comes afterward: if the bank can prove the customer was grossly negligent, it may pursue recovery through a separate legal process. But gross negligence is not, under Rantos's reading, a valid ground to refuse the initial refund. The CJEU typically follows its advocates general, though it is not required to do so. The final ruling, when issued, could entrench "refund first" as the EU-wide mandatory standard for every bank from Lisbon to Tallinn.
Know Your Rights: What Polish Law Requires Right Now
Under current Polish law (and EU law across the bloc), bank customers have concrete protections when unauthorized transactions occur:
Contact your bank immediately through its official customer service channel once you discover money has disappeared from your account.
The bank must return the disputed funds by the end of the next business day — not after completing an investigation, not after concluding you were at fault, but by the following business day.
You have 13 months from the transaction date to file a complaint. Consumers who discover old unauthorized transactions should check whether they fall within that window.
A correctly entered PIN, SMS code, or app confirmation does not mean you authorized the transaction. The bank must show that you consciously consented to that specific payment — not merely that a valid credential was used.
If the bank returns the money and later seeks to reclaim it by asserting you were grossly negligent or acted with intent, the burden of proof is on the bank. And even then, that claim must go through proper legal channels — not a unilateral account debit.
If you believe a previous complaint was wrongly rejected at Alior Bank, mBank, BNP Paribas Bank Polska, or Bank Millennium, Monday's commitment decisions mean those banks are now obligated to reconsider.
About UOKiK
The Office of Competition and Consumer Protection (
Urząd Ochrony Konkurencji i Konsumentów
) is
Frequently Asked Questions
My bank rejected my fraud refund claim years ago, saying I "authorized" the transaction because I entered a code. Can I resubmit that claim?
If your bank is Alior Bank, mBank, BNP Paribas Bank Polska, or Bank Millennium, then yes — Monday's commitment decisions require those banks to re-examine past rejections. For other Polish banks, the underlying law (the D+1 rule under the Act on Payment Services) applied to your claim too; UOKiK's ongoing proceedings against other institutions may produce similar outcomes. If the rejection was within the last 13 months, you can file a new complaint citing the legal distinction between authentication and authorization. If it was older, whether the bank's re-examination obligation covers it will depend on the terms of its specific commitment decision.
What does "authentication" versus "authorization" actually mean in practice, and why does it matter for my claim?
Authentication is the technical step of confirming who is using a payment instrument — entering a PIN, using a fingerprint, typing in an SMS code. Authorization is the separate, legally required step of your conscious, informed agreement to a specific transaction. Under PSD2 and Polish law, authentication alone does not create authorization. A criminal who tricks you into entering a valid code has achieved authentication — but you never authorized a transfer to that criminal. Banks that treated the correct entry of a code as the end of the inquiry were misapplying the law. That misapplication is exactly what the four commitment decisions address, and it is also the question that the CJEU's pending ruling in C-70/25 will answer definitively for all 27 EU member states.
Does this ruling only protect Polish consumers, or does it affect bank customers across the EU?
The D+1 rule and the authentication/authorization distinction both derive from EU-wide law — the Payment Services Directive (PSD2) applies across all 27 member states. The pending CJEU ruling in C-70/25 Tukowiecka, following Advocate General Rantos's March 2026 opinion, could make "refund immediately, pursue recovery later" a mandatory standard for every EU bank. Polish enforcement by UOKiK reflects the law as it stands in Poland today; the CJEU ruling, when issued, will determine whether the same protection is enforceable in every other EU country.
What should I do right now if I think my bank is holding onto money it should have already returned?
Contact the bank directly through its official channel — not through a link received via email or text message. Report the unauthorized transaction if you have not already done so, and request that the bank process your complaint under Article 46 of the Act on Payment Services (the D+1 rule). If the bank denies your claim or does not respond within the legally required period, file a complaint with UOKiK (uokik.gov.pl) or call the free consumer helpline at 801 440 220. You can also seek assistance from the Financial Ombudsman (
Rzecznik Finansowy
) or from the dlakonsumentow.pl consumer advice service.
(0)Comments