This post is also available in:
In an earlier article we described the case of two elderly phishing victims and a 2019 decision of the Antwerp courts. That decision has now been confirmed by the Antwerp Court of Appeal, in November 2020.
Phishing is on the rise
Phishing is a fraud by email, SMS, WhatsApp or other online means by which hackers seek to obtain personal data for fraudulent use, posing as well-known companies in messages that now look more genuine than ever. Banks and their clients are a prime target. Despite repeated warnings, some clients still fall into the trap. In 2019, Ombudsfin recorded 647 payment-services complaints (against 261 in 2015), of which 221 concerned internet fraud.
To what extent must the bank bear the loss?
In banking law, the principles applicable to phishing are the same as those for the loss or theft of a payment instrument. In short: the client bears limited liability of EUR 50 for transactions before notifying the bank; all subsequent phishing-related transactions are the bank’s responsibility; but by exception, if the client is grossly negligent, he bears full liability for the disputed transactions.
The client’s gross negligence: a notion assessed objectively
Gross negligence in phishing is left to the court’s assessment and is not limited to the statutory examples (such as writing security data on a card or failing to warn the bank in time). Banking law expects the holder of a payment instrument to use it in accordance with its terms of issue, to take all reasonable steps to keep it and its data secure, and to notify the bank (or Card Stop) immediately of any loss, theft or unlawful or unauthorised use.
Age and perception do not matter
Crucially, gross negligence is assessed independently of the victim’s personal characteristics. The client’s age is irrelevant to the court’s assessment of the conduct expected by banking law. His perception of the events, or his capacity to perceive them (which age may diminish), cannot be used to exclude gross negligence and shift liability to the bank. This is the view of the leading authors and of the Antwerp Court of Appeal in its November 2020 judgment. The court’s analysis must take the circumstances into account, but only objectively, against the abstract conduct any prudent person would adopt in an identical situation. In short, on unauthorised payment transactions, the court, like the first-instance court before it, applies an assessment in abstracto, not in concreto.
It should be recalled, however, that the bank’s role remains strictly framed when acting as a payment service provider. As the Court of Cassation recently confirmed, the bank owes no duty to advise or to warn when it executes a transfer for an investment.
This article is a translation. Only the French version is authoritative. It is provided for information purposes and does not constitute legal advice.
On the same topic
- The Bank Is Not an Automatic Insurer Against Phishing
- Phishing and Fraudulent Use of Payment Instruments
- Phishing: Where Recent Belgian Case Law Now Stands
- Banking Phishing: Is the Bank the Temporary Financier of Uncertainty?
- Phishing and Liability: Ignoring Public Warnings Amounts to Gross Negligence
Leave a Reply