Brazilian Court Puts Merchants on Notice: One Wrong Move and You Own the Chargeback

Table of Contents
You Snooze, You Lose: The New Chargeback Liability Rule
Imagine this: a customer uses a stolen credit card to buy a high-end smartphone from your online store. You ship it, they get it, and then the real cardholder issues a chargeback. Who eats the loss? In Brazil, the answer just got a lot more nuanced. The Superior Court of Justice (STJ) recently decided that a merchant can be held solely responsible for the chargeback if its own conduct was a decisive factor in the fraud's success. This isn't just legal jargon – it's a wake-up call for every e-commerce business.
Featured Snippet Bait: What makes a merchant solely liable for a chargeback in Brazil? If the merchant's negligence – like failing to verify CVV, address, or using outdated fraud checks – directly enabled the fraudulent transaction, the STJ says they bear full financial responsibility, not the bank or the cardholder.
The Case That Broke the Camel's Back
The STJ case involved a small online retailer that processed a transaction without basic security measures. The fraudster used stolen card details, and the merchant didn't verify the CVV or perform an address check. When the chargeback hit, the merchant argued it was the bank's fault for issuing the card. The court disagreed. It ruled that because the merchant's lax controls were the proximate cause of the fraud, the merchant was solely liable for the chargeback amount – including fees and penalties.
Why This Ruling Is a Bigger Deal Than You Think
This decision flips the traditional chargeback liability framework. Normally, chargebacks are a shared pain – merchants, acquirers, and card networks all have skin in the game. But the STJ's new precedent means that if your online store cuts corners on security, you could be on the hook for 100% of the loss. Think of it like leaving your front door wide open in a sketchy neighborhood – you can't blame the burglar's tools. Your sloppy security made the crime too easy.
Let's be real: reading your merchant agreement is about as fun as cleaning grout with a toothbrush. But this ruling means you need to pay attention to the fine print. The STJ's summary of precedents now includes this principle, and it's a game-changer.
What Exactly Counts as “Decisive Conduct”?
The court didn't give an exhaustive list, but based on the ruling and similar cases, here are red flags:
- Not requiring CVV or CVC codes for card-not-present transactions.
- Ignoring address verification service (AVS) mismatches.
- Shipping to unverified or high-risk addresses without additional checks.
- Using outdated or non-existent fraud detection tools.
- Failing to implement 3D Secure or other authentication protocols.
In other words, if your fraud prevention is as flimsy as a paper umbrella in a hurricane, you're playing with fire. The STJ expects merchants to take reasonable steps to prevent fraud. If you don't, you become the fraudster's accomplice in the eyes of the law.
But Wait, There's a Silver Lining (Sort Of)
This ruling also clarifies that if the merchant has adequate security measures in place and the fraud still happens – say, a sophisticated data breach that leaks card info – the merchant may not be solely liable. The bank and card network might share the blame. So it's not about being perfect; it's about not being negligent.
What Should Merchants Do Now?
First, take a deep breath. Then audit your checkout flow. Are you asking for CVV? Are you using address verification? Even simple steps can shift the liability back to the bank. Consider these actions:
- Implement 3D Secure 2.0 – it's not perfect but it helps.
- Use real-time fraud scoring tools that flag suspicious transactions.
- Delay shipping for high-risk orders until you verify the customer.
- Keep detailed logs of all security checks performed – if a chargeback dispute arises, you'll have proof you did your part.
And yes, update your terms of service to reflect that you take fraud prevention seriously. It won't save you in court, but it sets expectations.
FAQ
Does this ruling apply to all e-commerce merchants in Brazil?
Yes, the STJ's decision is a precedent that lower courts must follow in similar cases. It applies to any merchant that processes card-not-present transactions, including online stores, subscription services, and digital goods sellers.
What if the fraudster used a fake identity but the merchant did all checks?
If the merchant performed standard security checks (CVV, AVS, 3D Secure) and the transaction was still approved, the merchant is likely not solely liable. The burden shifts to the issuing bank to prove the merchant's conduct was decisive. However, each case is fact-specific.
Can this ruling be reversed or appealed?
The STJ is the highest court for non-constitutional matters in Brazil. Reversals are rare, and this decision was from a panel of judges. It could be challenged if there is a conflicting decision from another panel, but for now, it's the law.
Self-Audit Checklist: Are You Liable?

NakedPact Editorial Committee
Article created by the NakedPact editorial team. Our mission is to analyze, simplify, and expose unfair terms and hidden risks in everyday contracts to protect citizens and consumers.
Sources and Legal References

Do you own a website?
Want to communicate your data processing transparency to your users? Dynamically use our badge and showcase your platform's compliance.
Recommended Readings
🛡️ Protect your rights with one click
Don't risk signing abusive clauses. Install the free NakedPact extension for Chrome or Firefox and instantly analyze any contract on the web.
Don't trust, verify.
Now that you know the risks, don't sign blindly. Upload your contract to NakedPact and let AI find the hidden clauses for you. It's 100% free.
Analyze Your Contract Now
