Mastercard SPME §1.5.1 · May 2023 → Sep 2023

Compliance with Privacy, Data Protection and Information Security Requirements

substantive

The section was replaced with new introductory text for Chapter 2 on Cybersecurity Standards and Programs, expanding scope to include all Customers, Merchants, Service Providers, and agents handling payment data, removing prior specific obligations regarding compliance with data protection laws.

Sources Mastercard SPME · May 2023 · page 2 PDF Mastercard SPME · Sep 2023 · page 2 PDF KYB Acquirer current
Also in §1.x this release substantive §1.4 Connecting to Mastercard—Physical and Logical Security substantive §1.4.1 Minimum Security Requirements substantive §1.5 Data Protection
Why these edits? The scope of compliance obligations has expanded beyond specific data protection laws to include all Customers, Merchants, Service Providers, and agents handling payment data, increasing the breadth of cybersecurity compliance requirements relevant to Acquirer KYB obligations.
Mastercard SPME §1.5.1
This section was substantively restructured between versions (4% text overlap). Compare the texts directly below.
Before · May 2023 · page 2

Requirements The Corporation and each Customer must comply with Applicable Data Protection Law when Processing Personal Data in the context of Activity related to a Covered Program. Customer Obligations

After · Sep 2023 · page 2

Security Rules and Procedures—Merchant Edition • 1 August 2023

Chapter 2 Cybersecurity Standards and Programs This chapter is relevant to all Customers, Merchants, Service Providers, and any other Customer agents that store, process, or transmit Account, Card, Cardholder, or Transaction data.

Halyard Pay · 2 files
program: Acquirer KYB
- authority: Mastercard SPME 2.1, 11.2.6
+ authority: Mastercard SPME 2.1, 11.2.6, 2
required_documents:
- incorporation
- beneficial_ownership
- aml_screen
- license_verification
min_review_cycle_days: 365
suspension_trigger: document_collection_failure
record_retention_years: 7
aml_watchlist_sources:
- ofac_sdn
- eu_consolidated
agent_owner: kyb_agent
# The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+ #
+ # Per Mastercard SPME §2, compliance obligations now explicitly include all Customers, Merchants, Service Providers, and agents who store, process, or transmit Account, Card, Cardholder, or Transaction data.
+ # This broadened scope requires the Acquirer KYB program to address cybersecurity standards in addition to prior data protection mandates.

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

## Cybersecurity Compliance Scope

Halyard Pay must also ensure compliance with expanded cybersecurity standards applicable to all Customers, Merchants, Service Providers, and related agents that handle Mastercard Account, Card, Cardholder, or Transaction data as outlined in Mastercard SPME Chapter 2. This broadens the scope of protection beyond specific data protection laws and reinforces safeguarding of sensitive payment data throughout the KYB and onboarding processes.

Source authority: Mastercard SPME ��������2.1, §§1.5.1, 2.1, 11.2.6.

policies/kyb_acquirer/policy.md — after applying change

Acquirer KYB (Know Your Business) Obligations

Acquirers processing transactions on the Mastercard network are required to perform

Know Your Business (KYB) due diligence on merchants before onboarding and on a

recurring basis thereafter. Halyard Pay, as an acquirer, must collect and verify a

minimum set of documents for each merchant to establish business legitimacy, confirm

beneficial ownership, and satisfy anti-money laundering screening requirements.

When this policy applies

This policy applies to all new merchant onboarding and to all periodic re-verification

reviews. Merchants that fail to supply required documentation within the stipulated

period must be suspended from processing until compliance is restored.

Required actions

  1. Collect all required KYB documents at onboarding prior to approval.

  2. Conduct AML screening against applicable watchlists before approval.

  3. Verify business licenses for regulated merchant categories.

  4. Schedule a full re-verification review at least once every 365 days.

  5. Document all verification outcomes and retain records for audit purposes.

  6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.

## Cybersecurity Compliance Scope

Halyard Pay must also ensure compliance with expanded cybersecurity standards applicable to all Customers, Merchants, Service Providers, and related agents that handle Mastercard Account, Card, Cardholder, or Transaction data as outlined in Mastercard SPME Chapter 2. This broadens the scope of protection beyond specific data protection laws and reinforces safeguarding of sensitive payment data throughout the KYB and onboarding processes.

Source authority: Mastercard SPME ��������2.1, §§1.5.1, 2.1, 11.2.6.

Source authority: Mastercard SPME §1.5.1.

--- a/policies/kyb_acquirer/rules.yaml
+++ b/policies/kyb_acquirer/rules.yaml
@@ -1,5 +1,5 @@
 program: Acquirer KYB
-authority: Mastercard SPME 2.1, 11.2.6
+authority: Mastercard SPME 2.1, 11.2.6, 2
 required_documents:
   - incorporation
   - beneficial_ownership
@@ -13,4 +13,7 @@
   - eu_consolidated
 agent_owner: kyb_agent
 # The Acquirer must specifically retain all MATCH records concerning any Merchant, Sponsored Merchant, or ATM owner for at least two years following the termination or expiration of the related agreement, per Mastercard SPME 11.2.6.
-# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.+# This retention requirement updates prior guidance by imposing a defined minimum retention period beyond the MATCH system's internal data purging schedule.
+#
+# Per Mastercard SPME §2, compliance obligations now explicitly include all Customers, Merchants, Service Providers, and agents who store, process, or transmit Account, Card, Cardholder, or Transaction data.
+# This broadened scope requires the Acquirer KYB program to address cybersecurity standards in addition to prior data protection mandates.
--- a/policies/kyb_acquirer/policy.md
+++ b/policies/kyb_acquirer/policy.md
@@ -21,4 +21,8 @@
 5. Document all verification outcomes and retain records for audit purposes.
 6. Retain all MATCH system records related to Merchants, Sponsored Merchants, or ATM owners for a minimum of two years after termination or expiration of the applicable agreement, to comply with Mastercard's explicit record retention requirements.
 
-Source authority: Mastercard SPME 2.1, 11.2.6.+## Cybersecurity Compliance Scope
+
+Halyard Pay must also ensure compliance with expanded cybersecurity standards applicable to all Customers, Merchants, Service Providers, and related agents that handle Mastercard Account, Card, Cardholder, or Transaction data as outlined in Mastercard SPME Chapter 2. This broadens the scope of protection beyond specific data protection laws and reinforces safeguarding of sensitive payment data throughout the KYB and onboarding processes.
+
+Source authority: Mastercard SPME §§1.5.1, 2.1, 11.2.6.