Skip to content

Returns, Fraud and Abuse: What the Law Actually Lets You Do (UK and EU, 2026)

You can refuse a serial returner. You cannot refuse a statutory right, and you cannot let a model decide alone. The three walls around returns-abuse enforcement, what the US litigation actually held, and why your returns-fraud model is probably not high-risk under the EU AI Act.

The Sellarix team · 23 Jul 2026 · 20 min read

Every merchant with a returns problem eventually asks the same question, usually in a slightly guilty tone: can I just ban them?

The answer is yes, more often than most retailers believe. But there are three walls, they are made of different material, and almost every article on return fraud describes only the first one.

This guide covers all three, for UK and EU merchants, with the statutory text quoted rather than paraphrased. It also corrects a mistake that has spread quickly this year: the widespread claim that returns-abuse scoring is "high-risk" under the EU AI Act. On the published text, it almost certainly is not, and the reason why matters.

This is not legal advice. It is a sourced map of where the boundaries sit, written so you can have a sharper conversation with someone who is qualified to give it.

The three walls

WallWhat it limitsWhere it comes from
Consumer law floorRights you cannot refuse, however abusive the customerCRA 2015, CCR 2013
Data protection ceilingLetting a model decide on its ownUK GDPR / GDPR Article 22
Privacy and fairnessWhat you share, and who gets caughtPrivacy law, Equality Act

Between those walls there is a great deal of room. Most retailers are operating well inside it and think they are on the edge.

First, be precise about what you are stopping

Most returns programmes fail before they reach a legal question, because "return abuse" is used to describe six different behaviours with different economics, different legality and different correct responses. Lumping them together produces a policy that punishes your best customers and misses your worst.

Bracketing, which is not abuse at all

A customer orders the same item in three sizes intending to keep one. It is expensive for you and entirely legitimate, and it is usually a symptom of your own product data rather than the customer's behaviour. If your size guide is vague or your fit is inconsistent between lines, bracketing is the rational response and the customer is subsidising your ambiguity with their time.

Enforcement is the wrong tool here. Better sizing information, fit feedback from previous purchasers, and honest photography reduce it. Blocking it just moves the order to a competitor who explains their sizing better.

Wardrobing

Buying, using once, returning as unworn. Genuinely costly, genuinely deliberate, and the case where inspection on receipt earns its keep. Note that it is a factual dispute about the condition of goods, not a legal question about entitlement: if the item comes back used, you are not refusing a return so much as disputing that the goods are as described by the customer.

Serial returning

High return rates across many orders, with no individual return being illegitimate. This is the category where retailers most often overreach, because every single transaction is lawful and the pattern is what bothers them. The lawful response is to withdraw discretionary generosity, not to refuse rights.

Receipt and price manipulation

Returning items bought elsewhere, exploiting price-match or price-drop windows, or returning an item bought on discount for a full-price refund. Largely a process problem: it is solved by requiring proof of purchase and by refunding what was paid rather than current price.

Empty-box and switch fraud

The returned parcel contains a brick, or an older broken unit of the same model. This is straightforwardly criminal, and it is the one category where a police report is proportionate. It is also the strongest argument for photographing returns at the point of inspection.

Refund claims without return

"It never arrived" or "the box was empty on delivery", at a rate that cannot be explained by carrier error. Deals with the carrier and delivery evidence more than with returns policy.

Why the taxonomy matters legally

Because the three walls apply differently to each. Disputing whether returned goods are in the condition claimed is a factual argument you are entitled to have. Refusing a lawful cancellation because someone cancels a lot is a different act with a different answer. A policy that does not distinguish them will get the second one wrong while believing it is doing the first.

Wall one: the floor you cannot go below

Two statutory rights matter, and they are frequently confused with each other and with your own returns policy.

The 14-day cancellation right (distance selling)

Under the Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013, for goods bought at distance "the cancellation period ends at the end of 14 days after the day on which the goods come into the physical possession of" the consumer.[1]

No reason is required. The customer does not have to like the product, justify themselves, or be pleasant about it. Where an order arrives in multiple deliveries, the period runs from the last item.[1]

The 30-day right to reject (faulty goods)

Separately, the Consumer Rights Act 2015 gives a short-term right to reject goods that are faulty, running to "the end of 30 days beginning with the first day after these have all happened", meaning ownership transfer, delivery, and any required installation.[2] Perishable goods have a shorter window.[2]

Why this wall is the one people hit

Here is the trap. A returns-abuse system flags a customer, your policy blocks them from returning, and the very next return they attempt is a faulty item inside 30 days or a cancellation inside 14. You have now refused a statutory right, and their return history is irrelevant to whether that right exists.

The person who returns forty percent of what they buy still gets the 14 days on order forty-one. Abuse does not forfeit statutory rights. There is no serial-returner exception, because Parliament did not write one.

What you can do is remove everything you granted voluntarily, and for most retailers that is the larger part of the policy. Extended windows, free return postage, no-quibble refunds beyond the statutory minimum, instant refunds before goods arrive back, and free exchanges are all gifts. Gifts can be withdrawn.

If you sell into the EU, the equivalent withdrawal right and its interaction with your advertised window is covered in more detail in our article on the EU right of withdrawal.

Wall two: the model cannot decide alone

This is the wall almost nobody writes about, and it is the one that turns a sensible fraud programme into a regulatory problem.

Article 22 of the UK GDPR and GDPR is short enough to quote in full:

"The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her."[3]

Two tests, and both must be met before Article 22 bites: the decision is solely automated, and it has a legal or similarly significant effect.

Is refusing a return "similarly significant"?

Honestly: it depends, and anyone who tells you otherwise is guessing. A single declined return on a low-value item is unlikely to qualify. Permanently blacklisting an account, refusing all future service, or cutting off access to a payment method starts to look materially different, particularly if the customer relies on that retailer.

The ICO's guidance is that Article 22 engages where profiling has no meaningful human involvement and significantly impacts individuals.[4] The prudent reading is that account-level bans are in scope and individual return refusals may not be, and that the safest design does not depend on winning that argument.

The three exceptions

If Article 22 does apply, the decision is prohibited unless it:

"(a) is necessary for entering into, or performance of, a contract between the data subject and a data controller; (b) is authorised by Union or Member State law...; or (c) is based on the data subject's explicit consent."[3]

Note what is missing. Legitimate interests is not on that list. The lawful basis that carries most fraud prevention work elsewhere in the GDPR does not open this door, which surprises a lot of teams who assumed their fraud programme was already covered.

The safeguards, if you rely on (a) or (c)

"the data controller shall implement suitable measures to safeguard the data subject's rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision."[3]

Three concrete obligations: a human they can reach, a channel to put their side, and a route to challenge the outcome. The ICO adds that you must inform people about the processing, provide simple ways to request intervention or challenge, and carry out regular checks that the system works as intended.[4]

The cheapest compliance route is also the best operations

The whole of Article 22 hangs on the word solely. Put a human in the loop and the article does not engage in the first place.

But it has to be a real human doing real work. A member of staff who clicks "confirm" on whatever the model says, with no authority to disagree and no information beyond the score, is not meaningful involvement. It is a rubber stamp with a payroll number, and it will be recognised as one.

Meaningful review means the reviewer sees the underlying reasons rather than only a score, has genuine authority to overturn, and demonstrably does overturn sometimes. If your override rate is zero, that is evidence against you, not a sign the model is excellent.

A DPIA is not optional here

A Data Protection Impact Assessment is required for systematic and extensive automated evaluation of personal data used for decisions with legal or similarly significant effects.[4] A returns-abuse scoring programme is close to the textbook description. If you have deployed one without a DPIA, that is the first gap to close, and it is a document, not a project.

Wall three: what the American experience actually shows

The US is roughly a decade ahead on retail returns scoring, and its litigation history is instructive precisely because it did not go the way people assume.

The Retail Equation

The Retail Equation scores return activity for major retailers. The CFPB lists it among consumer reporting companies, describing it as a company that "monitors and reports to merchants retail product return and suspected exchange fraud and abuse", and notes that it "will provide one free report if you request it".[5]

That listing is the fact everyone quotes. The litigation is the fact worth knowing.

The FCRA theory failed

In Hayden v. The Retail Equation, Inc., No. 8:20-cv-01203 (C.D. Cal.), the court dismissed the Fair Credit Reporting Act claim, holding that "the customer risk score does not bear on plaintiffs' eligibility for credit" and that retailers were not extending credit by deferring payment or debt.[6] The CCPA, unfair competition and unjust enrichment claims went the same way.[6]

One claim survived: California invasion of privacy.[6]

Read the lesson correctly

The exposure was not "you scored someone". It was what was shared with whom, and whether the customer knew. Credit-law framing failed; privacy framing survived.

That maps almost perfectly onto UK and EU exposure, where the risk was never consumer-credit law to begin with. It is transparency, data sharing and automated decision-making. If you take one strategic point from the American experience, take this: the dangerous part is the data flow to a third party, not the existence of a score.

Which leads to a practical question worth asking your vendor: when you send return histories to a shared scoring service, whose customers are those, what does the vendor do with them, and did you tell anyone? If the honest answer is "I do not know", that is the finding.

The EU AI Act point almost everyone is getting wrong

A claim has spread this year that returns-fraud scoring is high-risk under the EU AI Act. It is worth taking apart, because the reasoning behind it is backwards.

Annex III point 5(b) covers:

"AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud"[7]

People see "with the exception of financial fraud", conclude the drafters were thinking about fraud systems, and reason from there to returns fraud being in scope.

Read it again. The category is creditworthiness and credit scoring. The fraud clause is a carve-out narrowing that category, not a separate heading. A returns-abuse model does not evaluate creditworthiness at all. It never enters the category, so the exception never needs to rescue it.

On the published text, a returns-abuse model is very unlikely to be high-risk under 5(b), and the fraud exception is irrelevant to it.

Two cautions before anyone relaxes

First, purpose governs, not naming. If your model does drift into assessing whether someone can be trusted to pay, for example gating buy-now-pay-later eligibility, you may have walked into 5(b) whatever the internal name for it is.

Second, and more importantly: not high-risk is not the same as unregulated. Article 22 still applies. Consumer law still applies. Transparency obligations still apply. The AI Act is one instrument among several, and it happens to be the one least likely to be your problem here.

If your store also runs a customer-facing chatbot, the transparency obligations that took effect on 2 August 2026 are a separate matter, covered in our Article 50 write-up.

What you can actually do

Having spent four sections on limits, here is the part that matters commercially. The permitted space is wide.

Withdraw discretionary generosity

  • Reduce a flagged customer to the statutory minimum window instead of your advertised longer one
  • Charge for return postage where you normally absorb it
  • Refund on receipt and inspection rather than on dispatch of the return
  • Remove free exchanges, advance replacements and instant credit
  • Require the original packaging and proof of purchase, consistently applied

None of this touches a statutory right. All of it materially changes the economics for someone gaming the policy.

Change the friction, not the entitlement

  • Require returns to a named address with tracking
  • Inspect before refunding, and document the inspection
  • Cap the number of concurrent open returns per account

Act at the point of order, not the point of return

This is the underused one. Declining to accept an order is a far cleaner position than accepting the money and then restricting the rights that come with it. Refusing to contract is generally simpler ground than curtailing a contract you have already formed.

Enforce the policy you actually published

Most disputes turn on the retailer failing to follow its own written terms, not on the terms themselves. Publish the rules plainly, apply them consistently, and keep the record.

The economics, which decide whether any of this is worth doing

A legal ceiling tells you what you may do. It does not tell you what you should. The commercial case for returns enforcement is narrower than vendors suggest, and it turns on one number most retailers have never calculated.

The cost of a false positive is not the cost of the return

When you wrongly restrict a good customer, you do not lose the margin on one order. You lose their future orders, and in the cases that hurt most, you lose them loudly and in public.

Work it out for your own store. Take a customer with a normal repeat rate and a normal basket, project their remaining lifetime value, and compare it with the cost of the return you are trying to avoid. For most retailers with any repeat business, one wrongly-flagged good customer wipes out the savings from a substantial number of correctly-blocked bad ones.

This is why the threshold question matters more than the model. A model tuned to catch nearly all abuse will inevitably catch good customers too, and at typical retail lifetime values, that trade is usually negative. The correct operating point for most stores is a conservative one that catches the obvious cases and lets the marginal ones through.

The base rate problem

Genuine return fraud is a small share of returns, and returns are a minority of orders. Anything you build is therefore hunting a rare event, and rare-event detection produces mostly false positives unless it is very precise.

The practical implication: if your flagged population is large, your model is almost certainly wrong rather than your customers being unusually dishonest. A flag rate that looks alarming is a reason to check the model before acting on it.

Where the money actually is

For most merchants, the recoverable value sits in three places, and none of them require scoring anyone:

  • Reducing returns at source. Better sizing, better photography, accurate delivery expectations and honest descriptions prevent returns that enforcement can only process more cheaply
  • Withdrawing subsidies. Free return postage is often the single largest controllable cost, and reducing it for high-return accounts requires no model at all, only a rule
  • Faster resale. The margin lost to returns is mostly in the time between goods coming back and being sellable again. Inspection and restocking speed usually beats prevention on return

Enforcement is the fourth priority, not the first, and it is the only one with legal risk attached. That ordering is the most commercially useful thing in this guide.

A tiered policy beats a binary one

Rather than a block list, most retailers get better results from tiers applied consistently:

TierTriggerTreatment
StandardDefaultFull advertised policy, free returns, refund on dispatch
WatchElevated return rateFull policy retained, refund on receipt and inspection
RestrictedSustained pattern after reviewStatutory minimum only, customer pays return postage, no advance replacement
DeclinedEvidenced fraudFuture orders not accepted

Every tier above "Declined" leaves statutory rights intact, which is what keeps the programme lawful. The escalation to "Declined" acts at the point of order rather than the point of return, which is the cleaner ground described earlier. And the "Watch" tier, which costs the customer nothing they would notice, is where most of the savings actually come from.

What to write down

If a regulator or a court ever asks, these documents are the difference between a defensible programme and an improvised one.

  1. A DPIA covering the scoring, its purpose, the data, the risks and the mitigations
  2. Your Article 22 position, in writing: either why the decision is not solely automated, or which exception you rely on and which safeguards you provide
  3. Privacy notice wording that actually mentions returns profiling. If a customer would be surprised to learn it happens, your notice is not doing its job
  4. The human review process: who reviews, what they see, what authority they have, and the override rate
  5. A retention period for return histories, with something that enforces it
  6. Vendor due diligence if you use a third-party service, covering what leaves your systems and what the vendor does with it
  7. Bias checks, because a model trained on historic decisions can concentrate refusals on a protected group without anyone intending it

Two questions to put to a vendor

If you are buying a returns-abuse or fraud product rather than building one, the sales conversation rarely covers the things that decide your exposure. Two questions cut through it.

"Does data about my customers leave my systems, and what happens to it?"

Shared scoring networks work by pooling behaviour across retailers, which is exactly what makes them effective and exactly what created the surviving claim in the American litigation.[6]

You need to know whether your customers' return histories are used to score other retailers' customers, whether the vendor is a processor acting on your instructions or a controller in its own right, and what your privacy notice says about any of it. If the vendor is a controller and your notice does not mention the arrangement, that gap is yours, not theirs.

"Can you show me the reasons, not just the score?"

A vendor who supplies only a number cannot support meaningful human review, because your reviewer has nothing to review. That makes it structurally impossible to rely on the human-in-the-loop route out of Article 22, and pushes you onto one of the three exceptions instead.

Ask to see what the reviewer's screen actually looks like before you sign. If it is a score and a traffic light, you are buying a rubber stamp.

A note on retention

Return histories are useful for as long as the pattern is live and a liability indefinitely thereafter. Pick a period, write it down, and make something enforce it. An unbounded behavioural history about customers is the kind of thing that is entirely defensible in year one and very hard to explain in year five.

The ten-minute self-assessment

  1. Can a customer be blocked from returning by an automated rule with no human involved? If yes, Article 22 is live
  2. Does your policy allow refusing a return of faulty goods inside 30 days? If yes, that is unlawful
  3. Does it allow refusing a distance cancellation inside 14 days? Same answer
  4. Does your privacy notice mention returns profiling by name?
  5. Is there a DPIA?
  6. Can a flagged customer reach a human and contest the decision?
  7. What is your override rate, and do you know it?
  8. Does return data leave your systems, and to whom?
  9. How long do you keep return histories, and what enforces that?
  10. Has anyone checked whether refusals concentrate on any protected group?

Anything you cannot answer is not necessarily a breach. It is an undocumented position, which is the thing that becomes a breach under scrutiny.

The honest summary

You have more freedom than you think and less automation than you want.

You can be strict, selective and commercially hard-nosed about returns. You can withdraw every discretionary benefit from customers who abuse them, and for most retailers that is where the money is. What you cannot do is refuse a statutory right, and what you should not do is let a model make consequential decisions about people with nobody accountable in the loop.

The American litigation is the clearest signal available: the claim that survived was about privacy and data sharing, not about scoring itself.[6] Build accordingly: score if it helps, keep a human accountable, tell people it happens, and be careful what you send to third parties.

Then go and take away the free return postage, which is legal, effective, and does not require anyone's permission.

Where to start on Monday

If this guide has left you with a list and no obvious first move, the order below reflects how much each step reduces exposure against how long it takes.

  1. Read your own returns policy as a customer would. A surprising number of policies already promise less than the retailer thinks, or more. Either way you are being judged against the published text
  2. Find out whether anything is currently automated end to end. If no human can override a returns block, that is the single highest-priority change and it is usually a configuration setting
  3. Check the privacy notice mentions returns profiling. One paragraph, and its absence is the most common finding
  4. Write the DPIA. A day's work, and it forces the other questions into the open
  5. Measure the override rate. If nobody knows it, nobody is reviewing anything
  6. Then, and only then, tune the model. Model quality is the last thing to worry about and the first thing everyone starts with

None of this requires a legal budget to begin. It requires an afternoon and a willingness to write down what you are already doing, which is usually where the uncomfortable discoveries are.

One closing observation from having watched retailers work through this. The stores that end up with a defensible programme are rarely the ones that bought the best model. They are the ones that decided early what they were willing to do to a customer who turns out to be innocent, wrote that down, and built backwards from it. The legal analysis then mostly takes care of itself, because a policy that treats a wrongly-flagged customer decently is very hard to attack from any direction.

Sources

  1. 1.Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013, regulation 30
  2. 2.Consumer Rights Act 2015, section 22 (short-term right to reject)
  3. 3.GDPR Article 22, automated individual decision-making, including profiling
  4. 4.ICO, Automated decision-making and profiling
  5. 5.CFPB, consumer reporting companies list: The Retail Equation
  6. 6.Inside Class Actions, Hayden v. The Retail Equation, partial dismissal, 16 May 2022
  7. 7.EU AI Act, Annex III: high-risk AI systems referred to in Article 6(2)
  8. 8.EU AI Act, Article 6: classification rules for high-risk AI systems
  9. 9.EU AI Act, Article 50: transparency obligations
  10. 10.ICO, What else do we need to consider if Article 22 applies?
  11. 11.ICO, What if Article 22 does not apply to our processing?
  12. 12.ICO, The impact of Article 22 of the UK GDPR on fairness
  13. 13.ICO, Rights related to automated decision making including profiling
  14. 14.ICO, Data protection impact assessments
  15. 15.GDPR Article 35, data protection impact assessment
  16. 16.GDPR Article 6, lawfulness of processing
  17. 17.GDPR Article 13, information to be provided where data are collected from the data subject
  18. 18.GDPR Article 15, right of access by the data subject
  19. 19.GDPR Recital 71, profiling
  20. 20.Data Protection Act 2018
  21. 21.Consumer Rights Act 2015, section 20 (right to reject)
  22. 22.Equality Act 2010
  23. 23.Directive 2011/83/EU on consumer rights
  24. 24.Hannum et al v. The Retail Equation, Inc. et al, complaint
  25. 25.Hunton, multiple retailers sued under CCPA over return-fraud data sharing
  26. 26.Lexology, court grants in part dismissal of privacy claims against The Retail Equation
  27. 27.CFPB, list of consumer reporting companies

Frequently asked