Digital Payment Security: A Report by Future Finance Poland and New Liability Rules
On 25 June 2026 in Warsaw, Future Finance Poland (FFP), together with its strategic partner Mastercard, presented the report “Security of Digital Payments”. The legal chapter – on countering fraudulent transactions (pp. 111–141) – was prepared by the PayTech practice of Dudkowiak & Putyra Business Lawyers: Piotr Glapiński, Kinga Argalska, Jakub Mazur, Jacek Szczytko and Mateusz Bałuta.
During the presentation, market participants concluded that the firm’s recommendations should be translated into systemic change, and the group announced further work to that end.
A New Model of Liability for Payment Fraud: From SCA to Real-Time Transaction Monitoring
At the core of the recommendations is a shift in how liability for unauthorised and fraudulent payment transactions is assessed: from a formal test (was strong customer authentication, SCA, applied?) to a functional test – did the provider’s security system actually prevent the abuse?

The forthcoming PSD3/PSR package (the new Payment Services Directive and Regulation; compromise texts of April 2026, expected to apply around 2028) makes transaction monitoring the centre of the security system.
- Correct SCA alone no longer excludes liability – technical authentication is not informed authorisation (CJEU, UOKiK, the Polish Supreme Court).
- Authorised fraud (impersonation fraud): where a customer is manipulated by someone impersonating their provider, the bank should as a rule refund the full amount, and the burden of proving gross negligence rests with the provider (15 business days to refund or justify a refusal).
- Confirmation of payee (IBAN/name check) becomes a risk-allocation mechanism – a failure on the bank’s side triggers an obligation to refund.
- Liability extends beyond banks – PSR brings in hosting providers, electronic-communications operators and very large platforms and search engines (a “Know Your Financial Advertiser” standard), with a right of recourse.
On data and AI, the recommendations point to Article 6(1)(f) GDPR and caution around behavioural biometrics; the narrow carve-out of anti-fraud systems from the AI Act “high-risk” regime and the applicable DORA obligations require separate analysis.
New Requirements for Banks, Fintech Companies, and Payment Service Providers
Banks, national and small payment institutions, electronic money institutions, fintechs and anti-fraud technology providers – in practice, security, compliance, risk, complaints-handling and legal teams, as well as cloud providers and platforms advertising financial services.
How can anti-fraud processes be prepared for the new requirements of PSD3, PSR, DORA, and the AI Act?
- Map and classify your anti-fraud signals against GDPR (Articles 6, 9, 22) and separate processing purposes.
- Make transaction monitoring your core control: move from static rules to dynamic, behaviour-aware analysis and real-time intervention, with a specific warning shown to the customer before they confirm a payment.
- Prepare for confirmation of payee (IBAN/name check) and for the “refund or justify the refusal within 15 business days” workflow in impersonation-fraud cases.
- Keep Data Protection Impact Assessments (DPIAs) and legitimate-interest assessments (LIAs) “alive”, maintain a model-change audit trail, and ensure genuine human oversight with a real power to overturn decisions.
- Classify your anti-fraud engine under DORA and fix vendor contracts (specific country of data processing, model-audit rights, TLPT, exit strategy); assess your AI tools against the AI Act.
Non-compliance risks: refunds, UOKiK/UODO fines and DORA incidents
A defence based solely on “procedural compliance” (for example, the mere fact that SCA was applied) will fail. Consequences include refunds to customers, exposure to disputes and UOKiK (consumer-protection authority) decisions, penalties and proceedings before the UODO (data-protection authority), and damages where confirmation of payee was performed incorrectly.

A failure of the anti-fraud engine may meet the threshold of a major ICT incident under DORA (initial notification within 24 hours).
A call for Systemic Changes in Digital Payment Security
Banks, payment institutions, and fintech companies should assess now whether their processes for authorization, transaction monitoring, dispute resolution, and fraud prevention align with the changes resulting from PSD3/PSR, DORA, the AI Act, and the GDPR.
The PayTech practice at Dudkowiak & Putyra assists financial institutions in reviewing their procedures, assessing risks, and preparing for new digital payment security standards. Contact us or check out our guide to FinTech in Poland.