Mastercard SPME §1.5 · May 2023 → Sep 2023
Data Protection
The section was updated to specify that Mastercard and each Customer must comply with applicable data protection laws and Appendix D privacy standards when processing personal data specifically related to account data compromise events and high-risk customer obligations, highlighting legal compliance requirements.
Security Rules and Procedures—Merchant Edition • 7 February 2023
Chapter 2 Cybersecurity Standards and Programs This chapter is relevant to all Customers, Merchants, Service Providers, and any other Customer agents that store, process, or transmit Account, Card, Cardholder, or Transaction data.
In addition to Rule 3.13 of the Mastercard Rules, the Corporation and each Customer must comply with (1) Applicable Data Protection Law and (2) Appendix D (Covered Programs Privacy and Data Protection Standards), in each case when Processing Personal Data in the context of Activity related to Account Data Compromise events, Mastercard Alert to Control High-risk Customer Obligations
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §11.1.1+ authority: Mastercard SPME §3.7, §11.1.1, §1.5fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.# Acquirers may add and search for information on up to five principal owners per Merchant.# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.# Retroactive alert processing is supported for data up to 360 days old.# Acquirers control receipt and detail of inquiry match information.# Real-time access via MATCH Online and API, and batch operations remain available.# Merchant URL information may be added and searched.# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.+ # Additionally, in line with updated Mastercard SPME §1.5, the fraud monitoring program must comply with applicable data protection laws and Mastercard's Covered Programs Privacy and Data Protection Standards (Appendix D) when processing personal data related to Account Data Compromise events, ensuring enhanced data privacy and security measures in all monitoring activities.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform. Our fraud monitoring procedures integrate strict compliance with applicable data protection laws and Mastercard's privacy standards as outlined in SPME §1.5 and Appendix D, especially during events involving Account Data Compromise.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-
Ensure that all processing of personal data under this policy, particularly during Account Data Compromise events, complies with applicable data protection laws and Mastercard's Appendix D privacy requirements to safeguard data privacy and security.
6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §1.5, §3.7, and §11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform. Our fraud monitoring procedures integrate strict compliance with applicable data protection laws and Mastercard's privacy standards as outlined in SPME §1.5 and Appendix D, especially during events involving Account Data Compromise.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-
Ensure that all processing of personal data under this policy, particularly during Account Data Compromise events, complies with applicable data protection laws and Mastercard's Appendix D privacy requirements to safeguard data privacy and security.
6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §1.5, §3.7, and §11.1.1.
Source authority: Mastercard SPME §1.5.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §11.1.1 +authority: Mastercard SPME §3.7, §11.1.1, §1.5 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -18,3 +18,4 @@ # Real-time access via MATCH Online and API, and batch operations remain available. # Merchant URL information may be added and searched. # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. +# Additionally, in line with updated Mastercard SPME §1.5, the fraud monitoring program must comply with applicable data protection laws and Mastercard's Covered Programs Privacy and Data Protection Standards (Appendix D) when processing personal data related to Account Data Compromise events, ensuring enhanced data privacy and security measures in all monitoring activities. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -1,6 +1,6 @@ # Fraud Monitoring -Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform. +Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform. Our fraud monitoring procedures integrate strict compliance with applicable data protection laws and Mastercard's privacy standards as outlined in SPME §1.5 and Appendix D, especially during events involving Account Data Compromise. ## When this policy applies @@ -12,7 +12,8 @@ 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. 4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -5. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -6. Track case progress until the account returns to threshold compliance or is terminated. +5. Ensure that all processing of personal data under this policy, particularly during Account Data Compromise events, complies with applicable data protection laws and Mastercard's Appendix D privacy requirements to safeguard data privacy and security. +6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +7. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7 and §11.1.1. +Source authority: Mastercard SPME §1.5, §3.7, and §11.1.1.