Forced retention of payment methods
⚠️ Article status notice: This article has been marked as incomplete
This article needs additional work for its sourcing and verifiability to meet the wiki's Content Guidelines and be in line with our Mission Statement for comprehensive coverage of consumer protection issues. In particular:
- Not a reference in sight.
This notice will be removed once the issue/s highlighted above have been addressed and sufficient documentation has been added to establish the systemic nature of these issues. Once you believe the article is ready to have its notice removed, please visit the Moderator's noticeboard, or the discord and post to the #appeals
channel.
Learn more ▼
Forced retention of payment methods is when online platforms and payment processors store user payment credentials, often without a clear or easily accessible way to revoke them. In many cases, cards or payment authorizations remain attached to an account unless a new method is added or until the account itself is deleted. This design restricts users’ control over their financial data and could potentially result in unwanted recurring charges.
The issue disproportionately affects individuals with limited financial resources, as well as non-profit or low-budget users, who may lack the legal or technical knowledge required to challenge such systems.
How it works
In most cases, forced retention of payment methods is implemented through user interfaces that do not allow stored payment data to be removed unless a replacement method is added. Some platforms go further, requiring the deletion of the entire account in order to erase billing credentials.
Another variant involves payment intermediaries (like PayPal), where billing agreements are created automatically during a one-time purchase without an explicit consent process[citation needed]. These agreements remain active unless manually revoked, which is often hidden behind asynchronous interfaces or inaccessible menus.
Overall, these systems are designed in a way that favors continued billing and makes revocation difficult, non-obvious, or impossible without contacting support.
Why it is a problem
Forced retention of payment methods causes long-term risks for consumers by removing their ability to control how and when they are billed. When a person cannot revoke stored card data or stop an ongoing billing authorization, unwanted charges become more likely. This risk increases when services use automatic renewals or hide cancellation options.
Many users are not offered a simple way to delete a card or cancel a billing agreement. This situation puts the burden on the user while disadvantaging those with limited time, resources, or legal knowledge. Some may even feel compelled to delete their account or give up access to services just to stop the billing.
These obstacles are often made worse by unclear interfaces, delayed menus, or wording that makes it difficult to understand how to stop payments.
Examples
Amazon
A class-action lawsuit is currently pending against Amazon for enrolling customers into Audible and charging them the $14.95 monthly subscription fee without notice or consent. Grace Sherk, the plaintiff, claims this act by Amazon was only possible due to the company holding customers' payment and billing information by default[1]. When combined with Audible's failure to enact click-to-cancel, customers' were locked into monthly payments until they could resolve the issue with customer service.
Legal framework
Article 6 and 17 of the General Data Protection Regulation (GDPR)
In the UK and EU, these articles define the lawfulness of processing and the right to erasure. If a user requests the removal of stored financial data and the platform refuses unless a new payment method is provided, this may violate both articles.
Article 12 of the GDPR
This article requires that any interface related to data control be concise, transparent, intelligible and easily accessible. In one case, PayPal delayed the display of the “automatic payments” menu using asynchronous loading scripts. This made the cancellation option harder to find and act upon.
Article L133-8 of the French Monetary and Financial Code
This provision states that any pre-authorized payment must remain revocable at any time before execution. In the case involving PayPal and Cdiscount, the user could not cancel the agreement even though no ongoing service or debt existed.
Article L121-1 of the French Consumer Code
This article prohibits misleading commercial practices. Automatically creating a billing agreement without explicit consent or visible contract may fall under this category.
Directive 2011/83/EU on consumer rights
This directive requires that any information related to billing, subscriptions or renewals be provided in a clear and accessible way. In all examples cited, such information was absent or concealed.
References
- ↑ "Amazon Audible faces class action over unauthorized subscriptions". Top Class Actions. 2025-04-23.