What This Covers
This page addresses fraud carried out through electronic banking channels — internet banking, mobile banking, UPI, debit/credit cards, and similar payment systems — where the account holder did not authorise the transaction. It does not cover disputes over a bank's ordinary service quality (see the general banking complaint pages) or fraud committed by a person known to the account holder who was voluntarily given access to credentials.
Applicable Law — RBI's Customer Liability Framework
The RBI's 2017 circular on "Customer Protection – Limiting Liability of Customers in Unauthorised Electronic Banking Transactions" (as consolidated in RBI's current master directions) remains the operative framework for transactions taking place now. It sets out three scenarios:
- Zero liability: Where the unauthorised transaction results from a contributory fraud/negligence/deficiency on the bank's part (regardless of whether the customer notifies the bank), or results from a third-party breach where the deficiency lies neither with the bank nor the customer, and the customer notifies the bank within 3 working days of receiving communication about the transaction.
- Limited liability: Where the loss arises from third-party fraud and the customer notifies the bank between 4 and 7 working days — the customer's liability is capped (for example, ₹5,000 for basic savings accounts, ₹10,000 for other savings accounts/prepaid instruments, ₹25,000 for most credit cards, subject to the account type and the bank's board-approved policy).
- Beyond 7 working days: Customer liability is determined as per the bank's board-approved policy, and can be higher.
Delay by the bank in resolving a reported unauthorised transaction dispute — RBI requires resolution within 90 days of the complaint being received — is itself a further, separate deficiency.
Separately, under the Consumer Protection Act, 2019, a bank extending electronic banking facilities for consideration is a "service" provider under Section 2(42), the account holder is a "consumer" under Section 2(7), and the bank's failure to apply the correct liability framework, or its delay beyond the RBI-mandated resolution timeline, is "deficiency" under Section 2(11) that can independently be taken to the Consumer Commission.
Jurisdiction & Forum
| Forum | Pecuniary jurisdiction | Location |
|---|---|---|
| DCDRC Puducherry | Value of goods/services paid as consideration up to ₹50 Lakh | Lawspet, Puducherry |
| SCDRC Puducherry | ₹50 Lakh to ₹2 Crore; also first appeals from DCDRC orders | Lawspet, Puducherry |
| NCDRC | Above ₹2 Crore; also first appeals from SCDRC orders | New Delhi |
(Section 34(1)/47(1)(a)(i)/58(1)(a)(i) of the Act itself set these thresholds at ₹1 Crore / ₹10 Crore / above ₹10 Crore; each carries a proviso letting the Central Government prescribe a different value. Exercising that power, the Consumer Protection (Jurisdiction of the District Commission, the State Commission and the National Commission) Rules, 2021 currently set the values shown in the table above.) A Puducherry account holder may generally file at DCDRC Puducherry under Section 34(2).
Limitation Period
Under Section 69, CPA 2019, a complaint must ordinarily be filed within two years from the date the cause of action arose — typically the date the bank wrongly refused to reverse the transaction, or the date the 90-day resolution window lapsed without resolution. This is separate from, and in addition to, the police/cybercrime reporting timeline, which should be done immediately regardless of this limitation period.
Documents Typically Needed
- Bank statement/passbook showing the unauthorised transaction(s)
- SMS/email alerts received for the transaction, and the date/time they were received
- Written complaint to the bank (date and time are critical, since they start the 3/7-working-day clock) and its acknowledgment
- FIR or complaint copy filed with the police/National Cyber Crime Reporting Portal (cybercrime.gov.in) or Helpline 1930
- Bank's written response/resolution letter, if any, and proof of when the 90-day resolution window lapsed (if it did)
- Any card-blocking or account-freezing confirmation
General Process Outline
- Step 1 — Report immediately: Notify the bank in writing (and by phone/app, keeping a reference number) the moment an unauthorised transaction is noticed — the reporting date determines the applicable liability tier.
- Step 2 — Report to cybercrime authorities: File a complaint on the National Cyber Crime Reporting Portal (cybercrime.gov.in) or call 1930, and lodge a police complaint/FIR where appropriate.
- Step 3 — Await bank resolution: The bank is expected to resolve the dispute and credit the disputed amount (for eligible zero/limited-liability cases) typically within 10 working days pending final resolution, and complete resolution within 90 days.
- Step 4 — Regulatory escalation: If unresolved or wrongly decided, a complaint may be filed with the RBI Integrated Ombudsman (cms.rbi.org.in), free of cost.
- Step 5 — Legal notice and complaint: A written notice to the bank, followed by a complaint under Section 35 at DCDRC Puducherry with supporting documents and affidavit, online via e-jagriti.gov.in or in person.
- Step 6 — Admission, hearing, order: Per Section 36 (admission, ordinarily within 21 days of filing), Section 38 (notice to the opposite party within 21 days of admission, response within 30 days extendable by 15 days), and Section 39, hearing and an order granting relief the Commission considers appropriate on the facts proved.
- Step 7 — Appeal: An order of DCDRC may be appealed to SCDRC Puducherry under Section 41 within 45 days of the order (condonable for sufficient cause); an appellant required to pay any amount under the order must first deposit 50% of that amount.