All articles

Hardware & POS

The EMV liability shift, in plain terms

The EMV liability shift is a rule change made by the card networks: for counterfeit card fraud at a physical counter, the loss falls on whichever party — the issuing bank or the merchant — had the less secure technology in the transaction. If the store read the chip, the issuer generally absorbs counterfeit losses. If the store swiped a card that had a chip, the store generally does.

It is not a law, it is not a fine, and it is not something anyone enforces against you. It is a default rule about who pays when something goes wrong.

What does "counterfeit fraud" actually cover?

Cards that were cloned — typically by copying magnetic stripe data and putting it on a new piece of plastic. That was the dominant physical-counter fraud before chips, because stripe data is static and copyable while chip data is not.

The shift does not cover lost-and-stolen fraud, where the real card is used by someone who should not have it, and it does not cover card-not-present fraud, which has its own rules and has always sat largely with the merchant. Confusing these three is the most common mistake owners make when they read a chargeback notice.

What does the store have to do to be on the right side of it?

Read the chip. That is the whole obligation in practice: have a terminal that reads chips and contactless, and use it. The protection is not a certificate you earn once; it is a property of each individual transaction.

Which is why fallback transactions matter, and why a broken reader is a financial problem rather than an inconvenience. A store with perfectly good equipment that swipes because the reader is dirty has forfeited the protection it paid for.

Does the shift mean a store never loses a dispute?

No, and anyone who implies otherwise is overselling. Chip acceptance addresses one category of loss. A customer who genuinely did not authorize a purchase, a service dispute, a duplicate charge, a delivery that never arrived — none of those are counterfeit fraud, and the chip does nothing for them.

The honest summary is that the shift removed a specific, formerly common, formerly expensive category from the merchant's plate. It did not remove disputes.

What about gas pumps and unattended terminals?

Unattended environments ran on different timelines from the counter and have their own requirements, because retrofitting a fuel dispenser is a different proposition from swapping a countertop terminal. If you operate pumps, treat that as a separate question from your in-store acceptance and confirm the specifics with your provider rather than assuming the counter answer applies.

How does this show up in real life?

Mostly as an absence. Stores that moved to chip acceptance saw counterfeit chargebacks fall off their statements and, quite reasonably, stopped thinking about it. The risk returns quietly through fallback transactions, through a reader nobody maintains, and through terminals kept in service past the point where they are supported.

That is the practical maintenance lesson. The protection is real, it is worth having, and it depends on a piece of hardware continuing to work.

What should an owner actually check?

Three things, once a year. That the terminal still reads chips reliably, which a cleaning card and a test transaction settle in two minutes. That contactless is enabled, because a tap is the fastest path back to a chip-read transaction when contacts fail. And that the terminal is still a model your provider supports, since an unsupported device eventually stops receiving the updates its certification depends on.

None of that is difficult. It is simply the kind of maintenance that has no symptom until the day it has an expensive one.

Frequently asked questions

Did the liability shift make chip terminals legally required?

No. Nothing obliges a merchant to accept chip cards by chip. The networks simply made swiping expensive by attaching the counterfeit loss to it, which turned out to be more persuasive than a mandate.

Does contactless get the same protection as inserting the chip?

Yes. Contactless transactions perform the same cryptographic authentication over a different interface, so for liability purposes a tap and a dip are both chip transactions.

What about a card with no chip at all?

If the card itself has no chip, the merchant is not the party with the less secure technology, and the shift generally does not move the loss to you for swiping it. Cards without chips have become rare in the United States, but they still turn up.

Does the shift apply to debit as well as credit?

Yes, though the specifics vary by network and by how the debit transaction was routed and authenticated. PIN-authenticated debit is a strong position regardless, which is one of the quieter arguments for a PIN pad.

Do I need to keep receipts to benefit from it?

Keeping clean records never hurts, but the protection attaches to how the transaction was read rather than to your paperwork. The transaction data itself carries the evidence that the chip was used.

Is there a version of this for online sales?

Not in the same form. Card-not-present fraud is governed by different rules, and the tools there are authentication programs, address and security-code checks, and your own order-screening discipline rather than a hardware upgrade.