Federal Credit Card Processing Laws and Requirements

Credit card processing in the United States is governed by a stack of federal statutes rather than any single law. The Truth in Lending Act and Regulation Z set disclosure rules and cap cardholder liability. The Credit CARD Act of 2009 restricts rate hikes and penalty fees. The Fair Credit Billing Act creates the dispute process. The Electronic Fund Transfer Act and Regulation E govern debit cards. The Gramm-Leach-Bliley Act and the Fair and Accurate Credit Transactions Act cover data privacy, security, and disposal. The Bank Secrecy Act and its FinCEN rules impose anti-money-laundering duties. And the Dodd-Frank Durbin Amendment regulates debit interchange fees. Together, these are the federal credit card processing laws that issuers, merchants, and payment processors must follow.

Disclosure Rules Under TILA and Regulation Z

The Truth in Lending Act, implemented through Regulation Z, requires card issuers to disclose the true cost of credit before you commit. Every offer and account opening must include the annual percentage rate, any periodic fees, late payment charges, and the method used to calculate the balance for finance charge purposes. 1Consumer Financial Protection Bureau. 12 CFR Part 1026 – Truth in Lending (Regulation Z)

The obligation continues after account opening. Monthly statements must show the balance, the minimum payment due, applicable interest rates, and fees charged during the cycle. If the issuer changes account terms, Regulation Z generally requires 45 days’ advance written notice, giving you time to pay off the balance or close the account before the change takes effect.

CARD Act Limits on Rates and Fees

The Credit Card Accountability Responsibility and Disclosure Act of 2009 sits on top of TILA and controls how issuers can reprice accounts, charge penalties, and structure statements.

Rate Increase Restrictions

Issuers generally cannot raise the interest rate on an existing balance. The narrow exceptions: a promotional rate expiring on schedule, a variable rate moving with its index, a cardholder falling more than 60 days behind on a minimum payment, or a hardship arrangement ending. 2Office of the Law Revision Counsel. 15 US Code 1666i-1 – Limits on Interest Rate, Fee, and Finance Charge Increases Applicable to Outstanding Balances Even in the delinquency scenario, the issuer must reverse the increase after six consecutive on-time minimum payments. For new transactions, rates can rise going forward, but only with at least 45 days’ written notice explaining the reason and the cardholder’s right to cancel.

Penalty Fee Caps

Late fees and other penalty fees must be “reasonable and proportional” to the violation. 3Office of the Law Revision Counsel. 15 US Code 1665d – Reasonable Penalty Fees on Open End Consumer Credit Plans The CFPB publishes safe harbor amounts that adjust annually. The operative figures are $32 for a first late payment and $43 for a repeat violation of the same type within the next six billing cycles. 4Federal Register. Credit Card Penalty Fees (Regulation Z)

Statement Warnings

Every billing statement must carry a minimum payment warning showing how long payoff would take at the minimum payment and what monthly amount would clear the balance within three years. 5Consumer Financial Protection Bureau. Minimum Payment Warning Explained

Cardholder Liability for Unauthorized Charges

Federal law treats credit card fraud and debit card fraud very differently, and processors have to build both frameworks into their systems.

Credit Cards

Under TILA, liability for unauthorized credit card charges is capped at $50, provided the issuer has given the cardholder a way to report loss or theft. 6Office of the Law Revision Counsel. 15 US Code 1643 – Liability of Holder of Credit Card If the issuer tries to hold the cardholder responsible for more, the burden is on the issuer to prove the charges were authorized. 7Consumer Financial Protection Bureau. 12 CFR 1026.12 – Special Credit Card Provisions Card network zero-liability policies go further than the statute, but $50 is the federal floor.

Debit Cards

Debit card fraud falls under the Electronic Fund Transfer Act and Regulation E. Liability depends on how quickly the loss is reported:

  • Within 2 business days: capped at $50 or the actual unauthorized amount, whichever is less.
  • Between 2 and 60 days from the statement date: up to $500.
  • After 60 days: unlimited liability for transactions occurring after the 60-day window.

Reporting speed is the whole game for debit fraud. 8eCFR. 12 CFR 1005.6 – Liability of Consumer for Unauthorized Transfers

Billing Dispute Process Under the Fair Credit Billing Act

The Fair Credit Billing Act, implemented through Regulation Z, requires issuers to run a structured dispute process for billing errors. The cardholder must send written notice within 60 days after the statement containing the error was mailed, identifying the account, the error, and the suspected amount. 9eCFR. 12 CFR Part 1026 – Truth in Lending (Regulation Z)

The creditor has 30 days to acknowledge receipt in writing, then two full billing cycles (and no more than 90 days total) to correct the error or explain in writing why the charge is accurate. During the investigation, the disputed amount cannot be reported as delinquent or collected. A creditor that fails to follow the procedure forfeits the right to collect the first $50 of the disputed amount, whether or not the charge was valid.

Ability-to-Pay Before Opening or Increasing an Account

Before opening a new credit card account or raising a credit limit, the issuer must evaluate whether the applicant can afford at least the minimum periodic payments. Permissible inputs include current or expected salary, wages, investment income, retirement benefits, credit reports, scoring models, and the issuer’s records from other accounts the customer holds. 10Consumer Financial Protection Bureau. 12 CFR 1026.51 – Ability to Pay

Issuers cannot rely solely on household income. If an application reports only household income, the issuer must gather additional information about the applicant’s individual income or assets before approving the account.

Rules That Apply to Merchants

Cash Discounts

TILA blocks card issuers from prohibiting merchants who offer a discount for cash, check, or debit instead of credit. The discount must be available to all buyers and clearly posted, and a discount structured this way is not a finance charge, so it does not trigger extra disclosure obligations. 11Office of the Law Revision Counsel. 15 US Code 1666f – Inducements to Cardholders by Sellers of Cash Discounts for Payments by Cash, Check, or Similar Means

Surcharges

Surcharges — an add-on fee for credit card payment — are not directly regulated by any federal statute. Surcharge limits come from a patchwork of state laws and the operating rules of Visa and Mastercard. Some states prohibit or restrict surcharging outright, and where surcharges are allowed, network rules generally cap the amount and require point-of-sale disclosure. A merchant considering a surcharge should check both state law and the merchant agreement first.

Debit Interchange Fee Caps

The Durbin Amendment to Dodd-Frank regulates the interchange fees large banks charge merchants for debit transactions. It applies only to issuers with $10 billion or more in assets; smaller issuers are exempt. 12Board of Governors of the Federal Reserve System. Regulation II – Debit Card Interchange Fees and Routing For covered issuers, the cap is 21 cents per transaction plus 5 basis points (0.05%) of the transaction value, with an additional 1 cent allowed for issuers meeting specified fraud prevention standards. In August 2025, a federal court vacated Regulation II but immediately stayed its own order pending appeal, leaving the existing fee caps in place. 13Cooley LLP. District Court Vacates Regulation IIs Debit Card Interchange Fee Standard The cap does not apply to credit cards, where interchange rates are set by the networks.

Regulation II also requires debit card issuers to enable at least two unaffiliated payment networks for routing each transaction, giving merchants a choice of networks.

Data Security and Privacy Under Gramm-Leach-Bliley

The Gramm-Leach-Bliley Act governs how financial institutions collect, use, and protect personal financial information. It reaches farther than most people expect, covering not only banks and card issuers but many payment processors and other businesses engaged in financial activities. 14Federal Trade Commission. How To Comply with the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act

Financial Privacy Rule

Before sharing nonpublic personal information with an unaffiliated third party, a covered institution must provide a clear privacy notice explaining what it collects, how it shares that information, and the customer’s right to opt out of certain sharing. The customer must get a reasonable opportunity to opt out — typically at least 30 days — before sharing begins. 15eCFR. 16 CFR Part 313 – Privacy of Consumer Financial Information

Safeguards Rule

The Safeguards Rule requires a written information security program with administrative, technical, and physical protections. The program must designate a qualified individual to oversee security, include regular risk assessments, implement access controls and encryption, and monitor safeguards over time. The obligation extends to third-party service providers: a processor sharing data with a vendor must ensure the vendor meets the same standards.

Disposal Rule

The Fair and Accurate Credit Transactions Act adds a separate disposal obligation. Any entity that possesses consumer information derived from a credit report must properly destroy it when no longer needed. The rule covers records in any format — paper or electronic — and treats disposal broadly, including discarding, abandoning, or transferring equipment that holds the data. 16eCFR. 16 CFR Part 682 – Disposal of Consumer Report Information and Records

Identity Theft Prevention: The Red Flags Rule

Financial institutions and creditors that maintain “covered accounts” must develop a written identity theft prevention program. A covered account includes any account designed for multiple payments or transactions, such as a credit card account, and any account with a foreseeable risk of identity theft. 17eCFR. 16 CFR Part 681 – Identity Theft Rules

The program must identify warning signs relevant to the institution’s accounts, detect them during account opening and ongoing activity, respond appropriately when a red flag appears, and update as risks change. The board of directors or senior management must approve the initial program and stay involved in oversight.

Anti-Money Laundering Under the Bank Secrecy Act

The Bank Secrecy Act requires financial institutions involved in payment processing to build compliance programs designed to detect and prevent money laundering, terrorism financing, and other financial crimes. 18FinCEN.gov. The Bank Secrecy Act A compliant program includes internal controls, a designated compliance officer, independent testing, and ongoing employee training. The USA PATRIOT Act expanded these duties significantly after 2001.

Suspicious Activity Reports

Banks must file a Suspicious Activity Report with FinCEN for any transaction or pattern involving $5,000 or more where the institution suspects the funds are tied to illegal activity, the transaction is structured to evade reporting requirements, or the transaction has no apparent business purpose. 19eCFR. 31 CFR 1020.320 – Reports by Banks of Suspicious Transactions This is separate from the $10,000 Currency Transaction Report threshold, which applies to any cash transaction over that amount, suspicious or not.

Customer Identification Program

Every bank must maintain a Customer Identification Program that collects, at minimum, the customer’s name, date of birth (for individuals), address, and an identification number such as a Social Security number or passport number. The bank must verify the information within a reasonable time after account opening, using documents like a government-issued photo ID, non-documentary methods, or a combination. 20eCFR. 31 CFR 1020.220 – Customer Identification Programs for Banks

Travel Rule

For electronic fund transfers of $3,000 or more, financial institutions must pass along specified information about the sender and recipient to the next institution in the chain, so identifying details follow the money through the system. 21Financial Crimes Enforcement Network. Funds Travel Regulations: Questions and Answers

Money Services Business Registration

Some payment processors qualify as money services businesses under federal law, which triggers a separate registration duty with the Treasury Department. A business is an MSB if it provides services like money transmission, check cashing, currency exchange, or the sale of money orders or traveler’s checks. With limited exceptions, every MSB must register with FinCEN within 180 days of starting operations, renew every two years, and keep a copy of the registration and supporting documents at a U.S. location for five years. 22FinCEN.gov. Money Services Business (MSB) Registration

An entity acting solely as an agent of a registered MSB does not need to register separately. But if it also conducts its own MSB activities, it must file. Failing to register is a federal crime, so any business involved in payment processing should evaluate whether its activities cross the MSB threshold early.