Phishing, Internet Fraud and Bank Liability: Do the Client’s Age and Perception Matter?

This post is also available in: Français (French) Nederlands (Dutch)

In an earlier article we described the case of two elderly phishing victims and a 2019 decision of the Antwerp courts. That decision has now been confirmed by the Antwerp Court of Appeal, in November 2020.

Phishing is on the rise

Phishing is a fraud by email, SMS, WhatsApp or other online means by which hackers seek to obtain personal data for fraudulent use, posing as well-known companies in messages that now look more genuine than ever. Banks and their clients are a prime target. Despite repeated warnings, some clients still fall into the trap. In 2019, Ombudsfin recorded 647 payment-services complaints (against 261 in 2015), of which 221 concerned internet fraud.

To what extent must the bank bear the loss?

In banking law, the principles applicable to phishing are the same as those for the loss or theft of a payment instrument. In short: the client bears limited liability of EUR 50 for transactions before notifying the bank; all subsequent phishing-related transactions are the bank’s responsibility; but by exception, if the client is grossly negligent, he bears full liability for the disputed transactions.

The client’s gross negligence: a notion assessed objectively

Gross negligence in phishing is left to the court’s assessment and is not limited to the statutory examples (such as writing security data on a card or failing to warn the bank in time). Banking law expects the holder of a payment instrument to use it in accordance with its terms of issue, to take all reasonable steps to keep it and its data secure, and to notify the bank (or Card Stop) immediately of any loss, theft or unlawful or unauthorised use.

Age and perception do not matter

Crucially, gross negligence is assessed independently of the victim’s personal characteristics. The client’s age is irrelevant to the court’s assessment of the conduct expected by banking law. His perception of the events, or his capacity to perceive them (which age may diminish), cannot be used to exclude gross negligence and shift liability to the bank. This is the view of the leading authors and of the Antwerp Court of Appeal in its November 2020 judgment. The court’s analysis must take the circumstances into account, but only objectively, against the abstract conduct any prudent person would adopt in an identical situation. In short, on unauthorised payment transactions, the court, like the first-instance court before it, applies an assessment in abstracto, not in concreto.

It should be recalled, however, that the bank’s role remains strictly framed when acting as a payment service provider. As the Court of Cassation recently confirmed, the bank owes no duty to advise or to warn when it executes a transfer for an investment.

This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.

Leave a Reply

Up ↑

Discover more from Banking and Finance law in Belgium

Subscribe now to keep reading and get access to the full archive.

Continue reading