Skip to main content
Category: Regulations and Standards

Fair Credit Billing Act

Also known as:
Simply put

The Fair Credit Billing Act (FCBA) is a United States federal law, enacted in 1974, that protects consumers from unfair credit card billing practices and limits their liability for unauthorized purchases. It gives consumers a process to dispute billing errors and prevents creditors from harming a consumer's credit standing while a dispute is being investigated.

Formal definition

The FCBA is a U.S. federal statute enacted on October 28, 1974 that amends the Truth in Lending Act (TILA) to address unfair credit billing practices on open-end (revolving) consumer credit accounts. It establishes procedures for disputing billing errors, limits consumer liability for unauthorized purchases, and prohibits creditors from taking actions that adversely affect a consumer's credit standing until an investigation of a disputed item is completed. Note that the FCBA is a consumer-protection law governing creditor billing obligations and is distinct from card brand and network chargeback rules, which separately govern dispute processing between merchants, acquirers, and issuers; the FCBA does not itself impose payment data security controls such as those in PCI DSS.

Why it matters

The FCBA establishes the statutory foundation for consumer credit card billing dispute rights in the United States. By limiting a consumer's liability for unauthorized purchases and requiring creditors to follow a defined investigation process, it shapes how issuers must respond when a cardholder reports a billing error or an unauthorized charge. For compliance officers and issuer operations teams, the Act's obligations are not optional customer-service practices but legal requirements tied to the Truth in Lending Act, which the FCBA amends.

One frequently misunderstood point is that the FCBA and card brand chargeback rules are distinct mechanisms. The FCBA governs the legal relationship and billing obligations between the creditor and the consumer, while chargeback rules published by the card networks separately govern how disputes are processed between merchants, acquirers, and issuers. A single disputed transaction may implicate both frameworks, but they impose different obligations, timelines, and remedies. Teams that conflate the two risk mishandling either the statutory consumer-protection requirements or the network dispute workflow.

It is also important to be clear about scope: the FCBA is a consumer-protection statute addressing billing practices and does not impose payment data security controls. Requirements for protecting cardholder data and sensitive authentication data fall under PCI DSS and related standards, not the FCBA. Merchant risk and fraud teams should treat the FCBA as governing dispute and liability rights rather than as a data-security mandate.

Who it's relevant to

Issuers and Creditor Operations Teams
Issuers must implement billing dispute and investigation procedures consistent with the FCBA, including limiting consumer liability for unauthorized purchases and refraining from adverse credit-standing actions on disputed items until an investigation is completed. These obligations are legal requirements under the statute, distinct from network chargeback timelines.
Compliance and Regulatory Officers
The FCBA amends the Truth in Lending Act and sits within the U.S. consumer-protection framework. Compliance teams need to distinguish its statutory obligations from card brand chargeback rules and from data-security standards such as PCI DSS, since the FCBA governs billing practices rather than payment data protection.
Fraud Analysts and Merchant Risk Teams
The FCBA's limits on consumer liability for unauthorized purchases influence how disputes and fraud claims flow through to merchants and acquirers. Understanding that the FCBA governs the consumer-creditor relationship, while network rules govern merchant-acquirer-issuer dispute processing, helps teams correctly attribute liability and dispute handling to the applicable framework.
Consumers and Cardholders
The Act gives consumers a defined process to dispute billing errors and unauthorized charges and protects their credit standing during an investigation. Consumers relying on these protections should confirm current procedural requirements against authoritative sources such as the FTC.

Inside FCBA

Scope of Covered Transactions
The FCBA is a U.S. federal law that amends the Truth in Lending Act and applies to 'open-end' consumer credit accounts, such as credit cards. It is generally distinct from protections for debit cards or other payment types, which may be governed by separate laws or network rules.
Billing Error Dispute Rights
The law establishes a consumer's right to dispute certain billing errors, such as unauthorized charges, charges for goods or services not accepted or not delivered as agreed, arithmetic errors, and charges for which the consumer requests additional clarification or documentation.
Written Notice Requirement
Consumers generally must notify the creditor in writing of a claimed billing error within a defined period after the statement containing the error was sent. Practitioners should confirm current timeframes and procedural details against the statute and its implementing regulation rather than assuming fixed values.
Creditor Investigation Obligations
Upon receiving a proper dispute notice, the creditor is obligated to acknowledge the dispute and investigate or correct the account within statutory timeframes. During the investigation, the disputed amount and related charges are subject to limits on collection and reporting activity.
Relationship to Chargebacks
The FCBA is a consumer statutory right that is separate from the chargeback mechanisms defined by card brand and network rules. A consumer billing-error claim under the FCBA and a network chargeback may address overlapping situations but operate under different frameworks, timelines, and parties.

Common questions

Answers to the questions practitioners most commonly ask about FCBA.

Is the Fair Credit Billing Act the same as the chargeback rules my acquirer enforces?
No. The FCBA is a U.S. federal consumer-protection statute that gives cardholders certain rights to dispute billing errors on open-end credit accounts. Chargeback rules are separate operating rules established by the card brands and payment networks, which change over time and vary by region. While a cardholder's FCBA dispute rights and a network chargeback may relate to the same underlying transaction, they are governed by different frameworks with different procedures, timelines, and obligations. Do not treat statutory dispute rights and network chargeback rights as interchangeable.
Does the FCBA cover every type of payment card and transaction dispute?
Not necessarily. The FCBA is directed at open-end consumer credit accounts and specific categories of billing disputes as defined by the statute and its implementing regulation. It does not automatically govern every payment type, every card product, or every kind of fraud or dispute. The applicability of the FCBA to a particular scenario depends on the account type and the nature of the dispute as defined in the law. For any specific case, confirm coverage against the current statutory and regulatory text rather than assuming it applies to all card disputes.
How does an FCBA billing-error dispute interact with a network chargeback in practice?
They operate as parallel but distinct processes. A cardholder may assert statutory rights under the FCBA with the card issuer, while the issuer may separately initiate a chargeback under the applicable network operating rules. Merchants and processors typically experience the operational impact through the network chargeback and representment workflow, which is governed by brand-specific rules that vary by region and change over time. Teams should map how their issuer-side and network-side processes align, and consult qualified legal counsel for how statutory obligations apply to their situation.
What should merchant risk teams retain to respond to disputes that may involve FCBA rights?
Retention practices should focus on transaction records and evidence needed to respond to disputes under the applicable network rules, while remaining consistent with data-protection obligations. Note that PCI DSS requires that sensitive authentication data, such as full track data, card verification codes, and PIN blocks, not be stored after authorization even when encrypted. Cardholder data such as PAN may be stored only under defined controls and should be masked or truncated where full values are not needed. Design dispute-evidence retention so it does not create prohibited storage of sensitive authentication data, and confirm requirements against the current published PCI DSS.
Does FCBA compliance reduce our PCI DSS scope or fraud exposure?
No. The FCBA addresses consumer billing-dispute rights and does not by itself alter PCI DSS scope, which is determined by how you store, process, or transmit cardholder data and by the controls you validate. It also does not function as a fraud-prevention control; it is a dispute and remediation framework, not a detection mechanism. Reducing fraud and PCI DSS scope depends on separate technical and operational measures, such as tokenization, encryption, truncation, and authentication controls, evaluated on their implementation rather than on any statutory compliance status.
Who owns FCBA-related responsibilities across our payment stakeholders?
Statutory dispute-handling obligations under the FCBA generally fall on the credit issuer that maintains the consumer account, not on the merchant or processor. Merchants, acquirers, and processors more commonly engage with the operational consequences through network chargeback and representment processes governed by brand rules. Because roles and legal obligations differ by party, region, and account type, organizations should define responsibilities in their agreements and confirm specific legal duties with qualified counsel rather than assuming a single party handles all aspects.

Common misconceptions

The FCBA is a payment security or data protection standard comparable to PCI DSS.
The FCBA is a U.S. consumer-protection statute governing billing-error disputes on open-end credit accounts. It is not a data security standard and does not define technical controls for protecting cardholder data or sensitive authentication data; those are addressed by PCI DSS and related standards.
The FCBA and network chargeback rules are the same thing.
They are distinct. The FCBA provides statutory dispute rights against creditors, while chargebacks are governed by card brand and network operating rules, which vary by region and change over time. A cardholder may have rights under both, but each follows its own process and timeframe.
The FCBA covers all payment methods, including debit cards.
The FCBA generally applies to open-end consumer credit, such as credit cards. Protections for debit cards and other payment types may fall under different laws or rules. Practitioners should not assume FCBA coverage extends uniformly across all payment instruments.

Best practices

Confirm current FCBA dispute timeframes, notice requirements, and creditor obligations against the statute and its implementing regulation rather than relying on remembered fixed values, as procedural details should be verified against the authoritative source.
Maintain clear internal workflows that distinguish FCBA statutory billing-error disputes from network chargebacks, since they operate under different frameworks, parties, and timelines.
Ensure written consumer dispute notices are acknowledged and investigated within applicable statutory periods, and document all correspondence and investigation steps to demonstrate compliance.
Coordinate between compliance, dispute-handling, and fraud teams so that a single customer complaint is routed correctly whether it involves a billing-error claim, a chargeback, or a fraud investigation.
Avoid treating FCBA compliance as a substitute for payment security controls; keep it separate from PCI DSS and related data-protection obligations, which address different risks.
Verify which payment instruments a given dispute involves before applying FCBA procedures, recognizing that non-credit payment types may be governed by different laws or network rules.