Gross negligence
A serious failure of care by a payer that can shift losses from unauthorised payments onto them.
In EU and UK payment law, a payer who fails, intentionally or with gross negligence, to keep personalised security credentials safe or to meet other obligations for their payment instruments can bear the losses from unauthorised transactions. The law does not define the term precisely, and it is generally read as a significant degree of carelessness, well beyond ordinary negligence. Whether handing credentials to an agent could count is unsettled, which is one reason agent designs avoid credential sharing in favour of delegated tokens.
Agent Minute explains this term on 22 December 2026.
Related terms
Unauthorised payment transactionA payment the payer did not consent to; in the EU and UK the payer's provider must generally refund it promptly.Consumer standard of cautionThe UK APP reimbursement exception for consumers who, with gross negligence, ignore specific expectations.Agent tokenA payment credential issued for use by a specific agent, which can be limited and revoked without replacing the card.Access tokenA credential a client presents to access protected resources, representing a specific, limited authorisation.