Account Data Compromise: The Loss You Cannot Dispute
A card data breach has no dispute right and no compliance case. Visa decides qualification, cost and liability under a guide it doesn't publish.
By Jeffrey Anderson

- An Account Data Compromise Event has no dispute right and no compliance route. Compliance filing conditions exclude violations related to one in their first bullet (ID# 0030225).
- A PCI DSS or PIN management failure that could expose magnetic-stripe data is explicitly not resolved through the Compliance process. It goes to the Global Compromised Account Recovery program instead (ID# 0030230).
- Issuer recovery is scoped to chip card credentials in pairs: account number plus expiration date in a card-absent environment, account number plus card verification value in a card-present one (ID# 0026564).
- Visa alone determines event qualification, Operating Expense Recovery amounts, issuer eligibility and acquirer liability, under a GCAR Guide that is incorporated by reference in Appendix A but not published in the Core Rules.
- Operating Expense Recovery reimburses issuer costs such as reissuing cards. It is cost recovery, not a penalty, and it is separate from fraud losses on the compromised accounts.
- Because there is nothing to argue afterward, the money belongs at the front end: tokenize so the data isn't there, and read your acquirer's pass-through clause before you need it.
An account data compromise is the one category of loss where the dispute machinery doesn't apply to you. There's no dispute right, no representment, no arbitration, and no compliance case. Visa decides what happened, what it costs, and who pays, under a guide it doesn't publish.
That's not a complaint about fairness. It's a planning fact, and it changes what preparing for a breach actually means. If your plan is "we'll argue it later," there is no later.
What counts as an Account Data Compromise Event
The recovery program is narrower than most summaries suggest. An issuer may recover a portion of its operating expenses from an Account Data Compromise Event involving a compromise of either a chip card's account number and expiration date in a card-absent environment, or a chip card's account number and card verification value in a card-present environment (ID# 0026564).
Read that twice, because two qualifiers are doing real work.
First, both limbs say chip card. The rule scopes issuer recovery to compromised chip card credentials, not to any card data of any kind.
Second, the required data pairs differ by environment. Card-absent needs the account number plus the expiration date. Card-present needs the account number plus the card verification value. Losing an account number on its own is not what this rule is written around.
Why you can't file a compliance case
Compliance is the route a member normally uses when a rule was broken, there's no dispute right, and real money was lost. The filing conditions are a checklist, and the very first item rules this out. A member may file for compliance if a violation of the Visa Rules occurred "that is not related to an Account Data Compromise Event" (ID# 0030225).
The other conditions confirm the shape of it. The member must have no dispute, dispute response, or pre-arbitration right. It must have incurred or be about to incur a financial loss as a direct result. It must show the loss wouldn't have happened but for the violation. And it must have made a pre-compliance attempt with full documentation and the specific rule cited.
None of that is available to you here, because the first condition already excluded the whole category.
There's a second rule saying the same thing from the other direction. A violation involving failure to comply with the PIN Management Requirements Documents or PCI DSS that could allow a compromise of magnetic-stripe data "is not resolved through the Compliance process." Those violations are resolved through the Global Compromised Account Recovery program instead (ID# 0030230).
So a PCI DSS failure that exposes card data doesn't become a case you can defend on the merits. It becomes a recovery number handed to your acquirer.
What GCAR actually recovers
Operating Expense Recovery is defined in the glossary as "the recovery amount provided to Issuers through the Global Compromised Account Recovery (GCAR) program associated with an Account Data Compromise Event" (ID# 0026064).
That's issuer operating expenses. Think reissuing cards, customer contact, and the administrative cost of cleaning up an exposed portfolio. It's a cost-recovery mechanism aimed at the banks that had to reissue, not a penalty and not a fraud-loss transfer.
Fraud losses on the compromised accounts are a separate matter that moves through the ordinary liability rules.
The guide Visa doesn't publish
Here's the part worth being blunt about. The Core Rules give Visa "the authority and discretion to determine Account Data Compromise Event qualification, Operating Expense Recovery amounts, Issuer eligibility, and Acquirer liability" under the GCAR program, in accordance with the Visa Global Compromised Account Recovery Guide and the information available about each event (ID# 0026564).
Four determinations, all Visa's, all governed by a document that isn't in the Core Rules. The GCAR Guide appears in Appendix A as a title applicable in all regions, alongside the Visa Acceptance Risk Standards and the Visa Integrity Risk Program Guide. It's incorporated by reference and published separately, which in practice means it reaches acquirers rather than merchants.
I'm not going to quote recovery amounts or qualification thresholds, because they're in that guide and I can't verify them from a public source. Anyone quoting you a specific GCAR figure should be asked where they got it.
What you can verify is the structure: a determination you don't participate in, under a document you can't read, with liability assigned to your acquirer and passed to you by your merchant agreement.
What this changes about how you prepare
The practical consequence is that spend moves from the back end to the front end. There's no arbitration to prepare evidence for, so evidence budget is wasted here. What isn't wasted:
- Don't hold the data. Tokenization removes the account numbers that a compromise event is defined around. You can't lose what you never stored.
- Know your acquirer's pass-through terms. GCAR assigns liability to the acquirer. Whether it lands on you, and how much of it, is your merchant agreement, not the Visa Rules. Read that clause before you need it.
- Keep validation current. Visa runs its Account Information Security program to push cardholder data protection through the system (Visa). Lapsed validation is the thing that turns a bad week into a bad year.
- Expect it to compound. A compromise plus an account termination is how merchants end up needing MATCH list recovery, and that's a much longer road than the breach itself.
None of this is exotic. It's just that the usual instinct, which is to document everything and fight it afterward, has nothing to attach to.
Source: Visa Core Rules and Visa Product and Service Rules, 18 April 2026.
Frequently asked questions
Can I dispute a GCAR assessment?
Not through the dispute or compliance process. Compliance filing explicitly excludes violations related to an Account Data Compromise Event, and the PCI DSS route is directed to GCAR instead. Any challenge runs through your acquirer, on your merchant agreement's terms.
How much does GCAR cost a merchant?
The Core Rules don't say. Recovery amounts are determined by Visa under the GCAR Guide, which isn't published in the rules. Treat any specific figure you're quoted as unsourced until whoever quoted it shows you the document.
Does GCAR apply if only account numbers leaked?
The rule is written around pairs. Card-absent recovery names the account number and expiration date, card-present names the account number and card verification value, and both limbs specify a chip card. Whether a given event qualifies is Visa's determination, not a self-assessment.
Is this the same as a PCI fine?
No. Operating Expense Recovery reimburses issuers for costs like reissuing cards. It's cost recovery, not a penalty, and it sits alongside whatever your acquirer or the card brands do about screening and validation afterward.
Jeffrey Anderson, Merchant Placement Specialist
Merchant placement specialist at Gray Merchants. Jeffrey works directly with acquiring-bank underwriting teams across the firm’s 70+ banking relationships to place high-risk and hard-to-place businesses, structure multi-MID accounts, and keep flagged merchants processing. His writing draws on the placement files he works every week: what underwriters ask for, why accounts get declined, and what keeps an approved account open.