Cross-Border Payments: FX, Chargebacks, and Risk Controls
December. A mid-size marketplace in Berlin runs a promo into LATAM. Sales jump. So do problems. FX costs come in higher than forecast. The team sees a 60 bps drop in margin from spread…
Money moving across borders, data that must not leak, and the rules that decide what an operator is allowed to keep.
Two subjects sit on this desk because in practice they are one: money cannot move without data about the person moving it, and almost every rule that constrains the second exists because of the first. The desk covers settlement and chargebacks, the practical difference between a method a customer trusts and one they merely recognise, retention periods, lawful bases, breach notification, and the gap between what a privacy policy says and what the network calls on the page actually do.
A legal claim here is sourced to the instrument that contains it, by article or section number, never to a summary or to another publication’s reading of it. Where a requirement has a currency ceiling and a percentage ceiling, both are printed together with which applies. Compliance marketing — a badge, a certification logo, a claim of being “fully compliant” — is treated as a claim to be checked against a register, not as evidence.
December. A mid-size marketplace in Berlin runs a promo into LATAM. Sales jump. So do problems. FX costs come in higher than forecast. The team sees a 60 bps drop in margin from spread…
Saturday night. You win a small prize. You tap “Withdraw.” One app shows “pending… please wait 24–48 hours.” Another sends a push, “Funds…
Når du leder efter et online kasino, fokuserer du typisk på tre vigtige aspekter: velkomstbonusser, spiludvalg og betalingsmetoder i online kasinoer . Et godt udbetalingssystem,…
Negli ultimi anni, i metodi di pagamento digitali sono diventati sempre più importanti per chi ama scommettere online. Tra questi, ecoPayz è emerso come una delle soluzioni…
Disclaimer: This article is for information only. It is not legal advice.
Finding the safest and most secure platforms is where we use stringent standards that have proven effective in distinguishing leading operators from others that are subpar. Our rigorous…
The issuing bank decides whether your exemption request lives or dies. That single fact shapes every calculation a merchant makes about strong customer authentication under PSD2: ask for frictionless processing, and you may get it, or you may get a soft decline that kills the transaction twice.
A SOC 2 report is an independent CPA firm's examination of a service organization's controls relevant to the AICPA Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy.
Your merchant account is not monitored against one chargeback ratio. Visa, Mastercard, and your payment processor each run separate programmes with distinct numerators, denominators, and minimum-count floors.
The Payment Card Industry Security Standards Council sets no minimum or maximum for how long cardholder data may sit in your systems. What it demands instead is a retention and disposal policy that limits storage to what is necessary for legal, regulatory, or business purposes—and once that necessity expires, the data must be securely deleted or rendered unrecoverable.
A customer taps their card at your terminal. The screen flashes "Approved." Yet your bank account sits empty. That gap between authorization and spendable cash is not a single delay but a chain of distinct steps, each running on its own clock, and understanding where your money lives during those days can mean the difference between managing cash flow and merely hoping for it.
Dates an engineering plan has to respect
| Date | What changes | Status | Where it is written |
|---|---|---|---|
| 17 Oct 2024 | NIS2 transposition deadline for Member States | In force | Directive (EU) 2022/2555, Article 41 |
| 17 Jan 2025 | DORA applies to financial entities and their critical ICT providers | In force | Regulation (EU) 2022/2554, Article 64 |
| 12 Sep 2025 | The Data Act becomes applicable, including the switching provisions for cloud services | In force | Regulation (EU) 2023/2854, Article 50 |
| 2 Aug 2027 | AI Act obligations for high-risk systems listed in Annex I start to apply | Ahead | Regulation (EU) 2024/1689, Article 113(c) |
Only instruments with a date in the text of the act itself are listed. Proposals still in trilogue are not.
Independent trade desk. We take no commission on anything we describe and run no affiliate programme of our own. Every figure on this page names the standard, filing or organisation it comes from; where a number could not be verified the page says so. How we work and how we correct. Reviewed:
Cookies, and what this site stores. The Dispatch sets no advertising or analytics cookies and loads no third-party tracker. Closing this notice writes one key — icd-notice — into your browser’s local storage, so that the notice does not return. Nothing else is kept. The one thing a page here sends onward is what a reader types into the form on the contact page, and that is described before the form is used. What the policy says.