Fair Credit Billing Act
The Fair Credit Billing Act (FCBA) is a United States federal law, enacted in 1974, that protects consumers from unfair credit card billing practices and limits their liability for unauthorized purchases. It gives consumers a process to dispute billing errors and prevents creditors from harming a consumer's credit standing while a dispute is being investigated.
The FCBA is a U.S. federal statute enacted on October 28, 1974 that amends the Truth in Lending Act (TILA) to address unfair credit billing practices on open-end (revolving) consumer credit accounts. It establishes procedures for disputing billing errors, limits consumer liability for unauthorized purchases, and prohibits creditors from taking actions that adversely affect a consumer's credit standing until an investigation of a disputed item is completed. Note that the FCBA is a consumer-protection law governing creditor billing obligations and is distinct from card brand and network chargeback rules, which separately govern dispute processing between merchants, acquirers, and issuers; the FCBA does not itself impose payment data security controls such as those in PCI DSS.
Why it matters
The FCBA establishes the statutory foundation for consumer credit card billing dispute rights in the United States. By limiting a consumer's liability for unauthorized purchases and requiring creditors to follow a defined investigation process, it shapes how issuers must respond when a cardholder reports a billing error or an unauthorized charge. For compliance officers and issuer operations teams, the Act's obligations are not optional customer-service practices but legal requirements tied to the Truth in Lending Act, which the FCBA amends.
One frequently misunderstood point is that the FCBA and card brand chargeback rules are distinct mechanisms. The FCBA governs the legal relationship and billing obligations between the creditor and the consumer, while chargeback rules published by the card networks separately govern how disputes are processed between merchants, acquirers, and issuers. A single disputed transaction may implicate both frameworks, but they impose different obligations, timelines, and remedies. Teams that conflate the two risk mishandling either the statutory consumer-protection requirements or the network dispute workflow.
It is also important to be clear about scope: the FCBA is a consumer-protection statute addressing billing practices and does not impose payment data security controls. Requirements for protecting cardholder data and sensitive authentication data fall under PCI DSS and related standards, not the FCBA. Merchant risk and fraud teams should treat the FCBA as governing dispute and liability rights rather than as a data-security mandate.
Who it's relevant to
Inside FCBA
Common questions
Answers to the questions practitioners most commonly ask about FCBA.