Mastercard SPME §13.1.2 · May 2023 → Sep 2023

Service Provider Risk Management Program

substantive

The update extensively revises the Covered Programs Privacy and Data Protection Standards appendix, adding detailed obligations for Customers and the Corporation regarding EU Data Protection Law compliance, data transfer mechanisms, security measures, breach notifications, audits, liabilities, and termination. It clarifies roles, legal bases for processing, data accuracy, and introduces detailed annexes with terms and technical security controls.

Sources Mastercard SPME · May 2023 · page 153 PDF Mastercard SPME · Sep 2023 · page 141 PDF ECP Thresholds current
Why these edits? The updated SPME section 13.1.2 extensively revises compliance requirements under EU Data Protection Law for Covered Programs including the Excessive Chargeback Program (ECP). This directly affects the 'ecp_thresholds' policy, which cites section 11.4 relating to the Excessive Chargeback Program, requiring updates to reflect enhanced data protection and privacy obligations for processing personal data involved in chargeback monitoring.
Mastercard SPME §13.1.2
This section was substantively restructured between versions (9% text overlap). Compare the texts directly below.
Before · May 2023 · page 153

Security Rules and Procedures—Merchant Edition • 7 February 2023

Appendix A Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 7 February 2023

Appendix B Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 7 February 2023

Appendix C Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 7 February 2023

Appendix D Covered Programs Privacy and Data Protection Standards This appendix describes the privacy and data protection Standards for Covered Programs as they relate to European Union (EU) Data Protection Law. D.1 Purpose......................................................................................................................................................... 159 D.2 Scope.............................................................................................................................................................159 D.3 Definitions.....................................................................................................................................................159 D.4 Acknowledgment of Roles......................................................................................................................... 160 D.5 The Corporation and Customer Obligations..........................................................................................161 D.6 Data Transfers.............................................................................................................................................162 D.7 Data Disclosures..........................................................................................................................................162 D.8 Security Measures.......................................................................................................................................163 D.9 Confidentiality of Personal Data..............................................................................................................164 D.10 Personal Data Breach Notification Requirements..............................................................................164 D.11 Personal Data Breach Cooperation and Documentation Requirements........................................164 D.12 Data Protection and Security Audit......................................................................................................164 D.13 Liability........................................................................................................................................................165 D.14 Termination of the Covered Programs Use..........................................................................................165 D.15 Invalidity and Severability........................................................................................................................165 Annex 1 to Appendix D: Processing of Personal Data .................................................................................166 Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data.... 167 Covered Programs Privacy and Data Protection Standards Security Rules and Procedures—Merchant Edition • 7 February 2023

D.1 Purpose This appendix provides Standards regarding the Processing of Personal Data of Data Subjects subject to EU Data Protection Law by the Corporation and its Customers (collectively referred to in this appendix as the “Parties”) in the context of the Covered Programs: Account Data Compromise events, Mastercard Alert to Control High-risk (Merchants) (MATCH™) system, the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program. D.2 Scope The Standards in this appendix supplement the privacy and data protection Standards contained in Section 1.5 of this manual and Rule 3.13 of the Mastercard Rules to the extent that the requirements pertain to the Processing of Personal Data subject to EU Data Protection Law in the context of the Covered Programs. In the event of a conflict, the Standards in this appendix take precedence. D.3 Definitions As used solely for the purposes of this appendix, the following terms have the meanings set forth below. Capitalized terms not otherwise defined herein have the meaning provided in Appendix E of this manual. Controller The entity which alone or jointly with others determines the purposes and the means of the Processing of Personal Data. Criminal Data Any Personal Data relating to criminal convictions, offenses, or related security measures. EEA Standard Contractual Clauses (EEA SCCs) The clauses annexed to the EU Commission Decision 2021/914 of June 4, 2021, on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended from time to time. Covered Programs Privacy and Data Protection Standards D.1 Purpose Security Rules and Procedures—Merchant Edition • 7 February 2023

EU Data Protection Law The EU General Data Protection Regulation 2016/679 GDPR (as amended and replaced from time to time) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC, and as amended and replaced from time to time) and their national implementing legislations; the Swiss Federal Data Protection Act (as amended and replaced from time to time); the Monaco Data Protection Act 2018 (as amended and replaced from time to time); the UK Data Protection Act (as amended and replaced from time to time); and the Data Protection Acts of the EEA countries (as amended and replaced from time to time). Mastercard Binding Corporate Rules (Mastercard BCRs) The Mastercard Binding Corporate Rules as approved by the EEA and UK data protection authorities and available on the Corporation’s public facing website. Personal Data Breach A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to or other unauthorized Processing of Personal Data transmitted, stored, or otherwise Processed. Processor The entity which Processes Personal Data on behalf of a Controller. Sensitive Data Any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation, as well as any other type of data that will be considered to be sensitive according to any future revision of EU Data Protection Law. UK Addendum The addendum to the EEA Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022). D.4 Acknowledgment of Roles The Corporation and its Customers acknowledge and confirm that: (1) neither Party acts as a Processor on behalf of the other Party; (2) each Party is an independent Controller; and (3) this appendix does not create a joint- Controllership or a Controller-Processor relationship between the Parties. The Covered Programs Privacy and Data Protection Standards D.4 Acknowledgment of Roles Security Rules and Procedures—Merchant Edition • 7 February 2023

Corporation and its Customers acknowledge and agree that the scope of each Party’s role as an independent Controller is as follows:

  • A Customer is a Controller for any Processing, including disclosing Personal Data to the Corporation, for the purpose of developing enhanced or incremental risk information to aid the Customer in its own determination of risk in its Merchant acquiring business.
  • The Corporation is a Controller for any Processing for the purpose of operating the Covered Programs, including product development, support and maintenance, and making the Covered Programs available to its Customers (e.g., as set out in Chapter 11) and for internal research, fraud, security, and risk management as listed in Rule 3.10 "Confidential Information of Customers" of the Mastercard Rules. D.5 The Corporation and Customer Obligations The Corporation and each Customer independently is responsible for compliance with EU Data Protection Law in relation to the Processing of Personal Data for which it is a Controller as described in section D.4. Notwithstanding the above, with regard to any Processing of Personal Data of Data Subjects that a Customer adds to the Covered Programs, including the Processing for which the Corporation is the Controller, a Customer must:
After · Sep 2023 · page 141

Security Rules and Procedures—Merchant Edition • 1 August 2023

Appendix A Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 1 August 2023

Appendix B Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 1 August 2023

Appendix C Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 1 August 2023

Appendix D Covered Programs Privacy and Data Protection Standards This appendix describes the privacy and data protection Standards for Covered Programs as they relate to European Union (EU) Data Protection Law. D.1 Purpose......................................................................................................................................................... 147 D.2 Scope.............................................................................................................................................................147 D.3 Definitions.....................................................................................................................................................147 D.4 Acknowledgment of Roles......................................................................................................................... 148 D.5 The Corporation and Customer Obligations..........................................................................................149 D.6 Data Transfers.............................................................................................................................................150 D.7 Data Disclosures..........................................................................................................................................150 D.8 Security Measures.......................................................................................................................................151 D.9 Confidentiality of Personal Data..............................................................................................................151 D.10 Personal Data Breach Notification Requirements..............................................................................151 D.11 Personal Data Breach Cooperation and Documentation Requirements........................................152 D.12 Data Protection and Security Audit......................................................................................................152 D.13 Liability........................................................................................................................................................152 D.14 Termination of the Covered Programs Use..........................................................................................153 D.15 Invalidity and Severability........................................................................................................................153 Annex 1 to Appendix D: Processing of Personal Data .................................................................................153 Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data.... 154 Covered Programs Privacy and Data Protection Standards Security Rules and Procedures—Merchant Edition • 1 August 2023

D.1 Purpose This appendix provides Standards regarding the Processing of Personal Data of Data Subjects subject to EU Data Protection Law by the Corporation and its Customers (collectively referred to in this appendix as the “Parties”) in the context of the Covered Programs: Account Data Compromise events, Mastercard Alert to Control High-risk (Merchants) (MATCH™) system, the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program. D.2 Scope The Standards in this appendix supplement the privacy and data protection Standards contained in Section 1.5 of this manual and Rule 3.13 of the Mastercard Rules to the extent that the requirements pertain to the Processing of Personal Data subject to EU Data Protection Law in the context of the Covered Programs. In the event of a conflict, the Standards in this appendix take precedence. D.3 Definitions As used solely for the purposes of this appendix, the following terms have the meanings set forth below. Capitalized terms not otherwise defined herein have the meaning provided in Appendix E of this manual. Controller The entity which alone or jointly with others determines the purposes and the means of the Processing of Personal Data. Criminal Data Any Personal Data relating to criminal convictions, offenses, or related security measures. EEA Standard Contractual Clauses (EEA SCCs) The clauses annexed to the EU Commission Decision 2021/914 of June 4, 2021, on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended from time to time. EU Data Protection Law The EU General Data Protection Regulation 2016/679 GDPR (as amended and replaced from time to time) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC, and as amended and replaced from time to time) and their national implementing legislations; the Swiss Federal Data Protection Act (as amended and replaced from time to time); the Monaco Data Protection Act 2018 (as amended and replaced from time to time); the UK Data Covered Programs Privacy and Data Protection Standards D.1 Purpose Security Rules and Procedures—Merchant Edition • 1 August 2023

Protection Act (as amended and replaced from time to time); and the Data Protection Acts of the EEA countries (as amended and replaced from time to time). Mastercard Binding Corporate Rules (Mastercard BCRs) The Mastercard Binding Corporate Rules as approved by the EEA and UK data protection authorities and available on the Corporation’s public facing website. Personal Data Breach A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to or other unauthorized Processing of Personal Data transmitted, stored, or otherwise Processed. Processor The entity which Processes Personal Data on behalf of a Controller. Sensitive Data Any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation, as well as any other type of data that will be considered to be sensitive according to any future revision of EU Data Protection Law. UK Addendum The addendum to the EEA Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022). D.4 Acknowledgment of Roles The Corporation and its Customers acknowledge and confirm that: (1) neither Party acts as a Processor on behalf of the other Party; (2) each Party is an independent Controller; and (3) this appendix does not create a joint-Controllership or a Controller-Processor relationship between the Parties. The Corporation and its Customers acknowledge and agree that the scope of each Party’s role as an independent Controller is as follows:

  • A Customer is a Controller for any Processing, including disclosing Personal Data to the Corporation, for the purpose of developing enhanced or incremental risk information to aid the Customer in its own determination of risk in its Merchant acquiring business.
  • The Corporation is a Controller for any Processing for the purpose of operating the Covered Programs, including product development, support and maintenance, and making the Covered Programs available to its Customers (e.g., as set out in Chapter 11) and for internal research, fraud, security, and risk management as listed in Rule 3.10 "Confidential Information of Customers" of the Mastercard Rules. Covered Programs Privacy and Data Protection Standards D.4 Acknowledgment of Roles Security Rules and Procedures—Merchant Edition • 1 August 2023 D.5 The Corporation and Customer Obligations The Corporation and each Customer independently is responsible for compliance with EU Data Protection Law in relation to the Processing of Personal Data for which it is a Controller as described in section D.4. Notwithstanding the above, with regard to any Processing of Personal Data of Data Subjects that a Customer adds to the Covered Programs, including the Processing for which the Corporation is the Controller, a Customer must:
  1. Rely on a valid legal ground under EU Data Protection Law for each of the Processing purposes, including obtaining Data Subjects’ consent if required or appropriate under EU Data Protection Law.
  2. Provide appropriate notice to the Data Subjects regarding (i) the their Processing of Personal Data, in a timely manner (e.g., informing Merchants about the possible use of MATCH upon termination of the Merchant Agreement) and at the minimum with the elements required under EU Data Protection Law, and (ii), as appropriate, the existence of Mastercard BCRs. Each Customer must also provide a link to the Corporation’s privacy notice for the Processing in relation to MATCH (available at https://www.mastercard.com/ global/en/vision/corp-responsibility/commitment-to-privacy/match-privacy.html ), where applicable.
  3. Take reasonable steps to ensure that Personal Data are accurate, complete, and current; adequate, relevant, and limited to what is necessary in relation to the purposes for which they are Processed.
  4. Respond to Data Subjects’ requests to exercise their rights under EU Data Protection Law, including the right of (i) access, (ii) rectification, (iii) erasure, (iv) data portability, (v) restriction of Processing, and (vi) objection to the Processing, if and as required under EU Data Protection Law. The Corporation agrees to cooperate with the Customer in responding to such requests where appropriate.
  5. Limit its Processing of Personal Data to the Processing that is necessary for the purpose of developing enhanced or incremental risk information to aid in its own determination of risk in its Merchant acquiring business.
  6. Not engage in or otherwise perform any automated decision-making or profiling based on Personal Data that are Processed in the context of the Covered Programs.
  7. Will add any Sensitive Data, Criminal Data, or government identification information of Data Subjects to the Covered Programs.
  8. Only Process Personal Data in connection with the Covered Programs for as long as necessary to achieve the purposes for which they are Processed. Any Personal Data Processed in relation to MATCH must be deleted or destroyed after a maximum of five (5) years. Covered Programs Privacy and Data Protection Standards D.5 The Corporation and Customer Obligations Security Rules and Procedures—Merchant Edition • 1 August 2023 D.6 Data Transfers A Customer may transfer the Personal Data Processed in connection with the Covered Programs outside of the EEA, the UK, and Switzerland in accordance with EU Data Protection Law, including based on the EEA SCCs or the UK Addendum as appropriate. The Corporation may transfer the Personal Data Processed in connection with the Covered Programs outside of the EEA, the UK, and Switzerland in accordance with the Mastercard BCRs or with any other lawful data transfer mechanism that provides an adequate level of protection under EU Data Protection Law. The Corporation will abide by the Mastercard BCRs when Processing Personal Data in the context of the Covered Programs. D.7 Data Disclosures The Corporation and its Customers must ensure that they will only disclose Personal Data Processed in the context of the Covered Programs in accordance with EU Data Protection Law, and in particular that they will require the data recipients to protect the data with at least the same level of protection as described in this appendix. The Corporation represents and warrants that it will only disclose Personal Data in accordance with the Mastercard BCRs. Where the Corporation transfers Personal Data subject to the GDPR or the Swiss Data Protection Act to a Customer in a country that is not part of the EEA or subject to a European Commission adequacy decision, the Parties agree that the transfer shall be governed by the EEA SCCs, which are hereby incorporated into this appendix by reference. The SCCs are completed as follows: the Parties conclude Module One (controller-to-controller) of the EEA SCCs. The “data exporter” is Corporation; the “data importer” is Customer; the optional docking clause in Clause 7 is implemented; the optional paragraph in Clause 11(a) is struck; the competent supervisory authority in Clause 13(a) shall be the supervisory authority of Belgium; the governing law in Clause 17 is the law of the Belgium and the courts in Clause 18(b) are the courts of the Belgium; Annex 1 and 2 to the EEA SCCs are Annex 1 and 2 to this appendix. The Parties conclude the UK Addendum for transfers of Personal Data subject to the UK Data Protection Act from Corporation to Customer in a country that is not subject to a UK adequacy decision. The UK Addendum is hereby incorporated into this appendix by reference. Part 1 of the UK Addendum is completed as follows: (i) in Table 1, the "Exporter" is Corporation and the "Importer" is Customer (as set out in the paragraph above), their details are set forth in the Acquirer license agreement and their signatures are included in the signature page of the Acquirer license agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are those incorporated into this appendix as per the paragraph above; (iii) in Table 3, Annexes 1 and 2 to the Approved EU SCCs are Annexes 1 and 2 to this appendix respectively; and (iv) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum. If either Party’s compliance with EU Data Protection Law applicable to transfers of Personal Data is affected by circumstances outside of either Party’s control, including if a legal Covered Programs Privacy and Data Protection Standards D.6 Data Transfers Security Rules and Procedures—Merchant Edition • 1 August 2023 instrument for transfers is invalidated, amended, or replaced, then the Parties will work together in good faith to reasonably resolve such non-compliance. D.8 Security Measures The Corporation and its Customers must implement and maintain a comprehensive written information security program with appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which includes, at a minimum, as appropriate: (1) the pseudonymization and encryption of Personal Data; (2) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; (3) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (4) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing. In assessing the appropriate level of security, the Corporation and its Customers must take into account the state of the art; the costs of implementation; and the nature, scope, context, and purposes of Processing of Personal Data; as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects and the risks that are presented by the Processing of Personal Data, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed. D.9 Confidentiality of Personal Data The Corporation and its Customers must take steps to ensure that any person acting under their authority who has access to Personal Data is subject to a duly enforceable contractual or statutory confidentiality obligation, and if applicable, Process Personal Data in accordance with the Controller’s instructions. D.10 Personal Data Breach Notification Requirements The Parties will assist each other in complying with their Personal Data Breach notification obligations. Where required under EU Data Protection Law, the Party which became aware of a Personal Data Breach will notify, without undue delay and, where feasible, not later than 72 hours after having become aware of it, the competent supervisory authority. When the Personal Data Breach is likely to result in a high risk to the rights and freedoms of Data Subjects or upon the competent supervisory authority’s request to do so, such Party must communicate the Personal Data Breach to the Data Subject without undue delay, where required under EU Data Protection Law. Covered Programs Privacy and Data Protection Standards D.8 Security Measures Security Rules and Procedures—Merchant Edition • 1 August 2023 D.11 Personal Data Breach Cooperation and Documentation Requirements Each Party must notify the other Party of a Personal Data Breach that relates to Personal Data Processed in the context of the Covered Programs and for which the other Party is a Controller, without undue delay, and not later than forty-eight (48) hours after having become aware of a Personal Data Breach. Each Party must document all Personal Data Breaches, including the facts relating to the Personal Data Breach, its effects, and the remedial action taken. D.12 Data Protection and Security Audit The Corporation and each Customer must conduct audits on a regular basis to control compliance with EU Data Protection Law, including the security measures provided in section D.8, and the Corporation must comply with the Mastercard BCRs. Upon prior written request, the Corporation and each Customer agrees to cooperate and, within reasonable time, provide the requesting Party with: (1) a summary of the audit reports demonstrating its compliance with EU Data Protection Law obligations and the Standards in this appendix, and as applicable Mastercard BCRs, after redacting any confidential and commercially sensitive information; and (2) confirmation that the audit has not revealed any material vulnerability, or to the extent that any such vulnerability was detected, that such vulnerability has been fully remedied. D.13 Liability Subject to the liability clauses in the Standards, the Corporation and each Customer agrees that it will be liable towards Data Subjects for the entire damage resulting from a violation of EU Data Protection Law with regard to Processing of Personal Data for which it is a Controller. Where the Parties are involved in the same Processing and where they are responsible for any damage caused by the Processing of Personal Data, both the Corporation and each responsible Customer may be held liable for the entire damage in order to ensure effective compensation of the Data Subject. If the Corporation paid full compensation for the damage suffered, the Corporation is entitled to claim back from the Customer(s) that part of the compensation corresponding to each Customer’s part of responsibility for the damage. Covered Programs Privacy and Data Protection Standards D.11 Personal Data Breach Cooperation and Documentation Requirements Security Rules and Procedures—Merchant Edition • 1 August 2023 D.14 Termination of the Covered Programs Use Mastercard and its Customers agree that, apart from the data retention obligation in section D.5, paragraph 8, the Standards in this appendix are no longer applicable to a Customer upon the termination of such Customer’s use of the Covered Programs. D.15 Invalidity and Severability If any Standard in this appendix is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such Standard shall not affect any other Standard in this appendix, and all Standards not affected by such invalidity or unenforceability will remain in full force and effect. Annex 1 to Appendix D: Processing of Personal Data A. List of Parties
  9. Data exporter: Corporation – Name and address of the Corporation as well as the name, position, and contact details for the Corporation’s contact person: as stipulated in the Acquirer License agreement. – Activities relevant to the data transferred: Providing the Covered Programs – Signature and date: as stipulated in the Acquirer License agreement – Role: controller for the purposes listed in Section D.4 of appendix D.
  10. Data importer: Customer – Name and address of the Customer as well as the name, position, and contact details for Customer’s contact person: as stipulated in the Acquirer License agreement – Activities relevant to the data transferred: participating in, or benefiting from, the Covered Programs – Signature and date: as stipulated in the Acquirer License agreement – Role: controller for the purposes listed in Section D.4 of appendix D B. Description of the Transfer Data Subjects Data Subjects as defined in Appendix E. Categories of data Personal Data relating to a Merchant’s principal owners or sole proprietors. Sensitive Data transferred The Parties do not Process any Sensitive Data in the context of the Covered Programs. Covered Programs Privacy and Data Protection Standards D.14 Termination of the Covered Programs Use Security Rules and Procedures—Merchant Edition • 1 August 2023 Frequency of the transfer Upon Customer’s requests, such as on a per query basis or via batch file transfer. Nature of the Processing Collection, storage, analysis, disclosure by transfer or otherwise making available. Purposes of the transfer(s) The transfer is made for the purposes set forth in Section D.4 of appendix D. Period for which the Personal Data will be retained Personal Data will be retained only for as long as necessary to achieve the relevant purposes for each of the Covered Programs. C. Competent Supervisory Authority The competent supervisory authority in accordance with Clause 13 of the EEA SCCs is the Belgian Data Protection Authority. Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data The Parties will, as a minimum, implement the following types of security measures:
  11. Physical access control Technical and organizational measures to prevent unauthorized persons from gaining access to the data processing systems available in premises and facilities (including databases, application servers and related hardware), where Personal Data are processed, include: – Establishing security areas, restriction of access paths; – Establishing access authorizations for employees and third parties; – Access control system (ID reader, magnetic card, chip card); – Key management, card-keys procedures; – Door locking (electric door openers, etc.); – Security staff, janitors; – Surveillance facilities, video/CCTV monitor, alarm system; – Securing decentralized data processing equipment and personal computers.
  12. Virtual access control Technical and organizational measures to prevent data processing systems from being used by unauthorized persons include: – User identification and authentication procedures; – ID/password security procedures (special characters, minimum length, change of password); – Automatic blocking (e.g., password or timeout); Covered Programs Privacy and Data Protection Standards Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 1 August 2023 – Monitoring of break-in-attempts and automatic turn-off of the user ID upon several erroneous passwords attempts; – Creation of one master record per user, user master data procedures, per data processing environment.
  13. Data access control Technical and organizational measures to ensure that persons entitled to use a data processing system gain access only to such Personal Data in accordance with their access rights, and that Personal Data cannot be read, copied, modified or deleted without authorization, include: – Internal policies and procedures; – Control authorization schemes; – Differentiated access rights (profiles, roles, transactions and objects); – Monitoring and logging of accesses; – Disciplinary action against employees who access Personal Data without authorization; – Reports of access; – Access procedure; – Change procedure; – Deletion procedure.
  14. Disclosure control Technical and organizational measures to ensure that Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic), and that it can be verified to which companies or other legal entities Personal Data are disclosed, include: – Tunneling – Logging – Transport security
  15. Entry control Technical and organizational measures to monitor whether data have been entered, changed or removed (deleted), and by whom, from data processing systems, include: – Logging and reporting systems; – Audit trails and documentation.
  16. Control of instructions Technical and organizational measures to ensure that Personal Data are processed solely in accordance with the Instructions of the Controller include: – Unambiguous wording of the contract; – Formal commissioning (request form); – Criteria for selecting the Processor
  17. Availability control Technical and organizational measures to ensure that Personal Data are protected against accidental destruction or loss (physical/logical) include: – Backup procedures; Covered Programs Privacy and Data Protection Standards Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 1 August 2023 – Mirroring of hard disks (e.g., RAID technology); – Uninterruptible power supply (UPS); – Remote storage; – Anti-virus/firewall systems; – Disaster recovery plan.
  18. Separation control Technical and organizational measures to ensure that Personal Data collected for different purposes can be processed separately include: – Separation of databases; – "Internal client" concept / limitation of use; – Segregation of functions (production/testing); – Procedures for storage, amendment, deletion, transmission of data for different purposes. Covered Programs Privacy and Data Protection Standards Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 1 August 2023 Appendix E Definitions The following terms as used in this manual have the meanings set forth below. Acceptance Mark................................................................................................................................................163 Acceptor...............................................................................................................................................................163 Access Device......................................................................................................................................................163 Account.................................................................................................................................................................163 Account Enablement System...........................................................................................................................164 Account Holder....................................................................................................................................................164 Account PAN........................................................................................................................................................164 Account PAN Range........................................................................................................................................... 164 Acquirer................................................................................................................................................................164 Activity(ies)..........................................................................................................................................................164 Affiliate Customer, Affiliate..............................................................................................................................164 Applicable Data Protection Law......................................................................................................................164 Area of Use..........................................................................................................................................................165 Association Customer, Association..................................................................................................................165 ATM Access Fee...................................................................................................................................................165 ATM Owner Agreement.....................................................................................................................................165 ATM Terminal.......................................................................................................................................................165 ATM Transaction.................................................................................................................................................166 Authenticating Entity........................................................................................................................................ 166 Automated Teller Machine (ATM)....................................................................................................................166 Bank Branch Terminal........................................................................................................................................166 BIN.........................................................................................................................................................................166 Brand Fee.............................................................................................................................................................166 Brand Mark..........................................................................................................................................................167 Card.......................................................................................................................................................................167 Cardholder...........................................................................................................................................................167 Cardholder Communication............................................................................................................................. 167 Cardholder Verification Method (CVM)..........................................................................................................167 Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC)........................................................... 168 Chip-only MPOS Terminal.................................................................................................................................168 Chip Transaction.................................................................................................................................................168 Cirrus Acceptance Mark.................................................................................................................................... 168 Cirrus Access Device...........................................................................................................................................168 Cirrus Account.....................................................................................................................................................168 Definitions Security Rules and Procedures—Merchant Edition • 1 August 2023 Cirrus Brand Mark...............................................................................................................................................169 Cirrus Card...........................................................................................................................................................169 Cirrus Customer..................................................................................................................................................169 Cirrus Payment Application..............................................................................................................................169 Cirrus Word Mark................................................................................................................................................169 Competing ATM Network..................................................................................................................................169 Competing EFT POS Network......................................................................................................................... 169 Competing International ATM Network.........................................................................................................170 Competing North American ATM Network....................................................................................................170 Consumer Device Cardholder Verification Method, Consumer Device CVM, CDCVM...........................170 Contact Chip Transaction.................................................................................................................................171 Contactless Payment Device............................................................................................................................171 Contactless Transaction....................................................................................................................................171 Control, Controlled.............................................................................................................................................171 Corporation..........................................................................................................................................................171 Corporation System...........................................................................................................................................172 Credentials Management System...................................................................................................................172 Cross-border Transaction..................................................................................................................................172 Customer.............................................................................................................................................................172 Customer Report................................................................................................................................................172 Data Storage Entity (DSE)...............................................................................................................................172 Data Subject.......................................................................................................................................................172 Device Binding.....................................................................................................................................................173 Digital Activity(ies).............................................................................................................................................173 Digital Activity Agreement................................................................................................................................173 Digital Activity Customer..................................................................................................................................173 Digital Activity Service Provider (DASP)........................................................................................................ 173 Digital Activity Sponsoring Customer.............................................................................................................173 Digital Goods.......................................................................................................................................................174 Digital Wallet.......................................................................................................................................................174 Digital Wallet Operator (DWO).......................................................................................................................174 Digital Wallet Operator Mark, DWO Mark.................................................................................................... 174 Digital Wallet Operator (DWO) Security Incident, DWO Security Incident............................................ 174 Digitization, Digitize...........................................................................................................................................174 Domestic Transaction........................................................................................................................................175 Dual Interface......................................................................................................................................................175 Electronic Money.................................................................................................................................................175 Electronic Money Institution.............................................................................................................................175 Electronic Money Issuer.....................................................................................................................................175 Definitions Security Rules and Procedures—Merchant Edition • 1 August 2023 EMV Mode Contactless Transaction...............................................................................................................175 End User...............................................................................................................................................................176 Gateway Customer............................................................................................................................................176 Gateway Processing...........................................................................................................................................176 Gateway Transaction.........................................................................................................................................176 Global Collection Only (GCO) Data Collection Program.............................................................................176 Host Card Emulation (HCE).............................................................................................................................176 Hybrid Terminal...................................................................................................................................................176 ICA.........................................................................................................................................................................177 Independent Sales Organization (ISO)...........................................................................................................177 Installment Lending Agreement...................................................................................................................... 177 Interchange System...........................................................................................................................................177 Identification & Verification (ID&V).................................................................................................................177 Inter-European Transaction..............................................................................................................................177 Interregional Transaction..................................................................................................................................178 Intracountry Transaction...................................................................................................................................178 Intra–European Transaction.............................................................................................................................178 Intra–Non–SEPA Transaction...........................................................................................................................178 Intraregional Transaction..................................................................................................................................178 Issuer.....................................................................................................................................................................179 License, Licensed.................................................................................................................................................179 Licensee................................................................................................................................................................179 Maestro................................................................................................................................................................179 Maestro Acceptance Mark................................................................................................................................179 Maestro Access Device......................................................................................................................................179 Maestro Account.................................................................................................................................................179 Maestro Brand Mark..........................................................................................................................................180 Maestro Card...................................................................................................................................................... 180 Maestro Customer.............................................................................................................................................180 Maestro Payment Application..........................................................................................................................180 Maestro Word Mark...........................................................................................................................................180 Magnetic Stripe Mode Contactless Transaction...........................................................................................180 Manual Cash Disbursement Transaction........................................................................................................181 Marks....................................................................................................................................................................181 Mastercard...........................................................................................................................................................181 Mastercard Acceptance Mark.......................................................................................................................... 181 Mastercard Access Device.................................................................................................................................181 Mastercard Account...........................................................................................................................................181 Mastercard Biometric Card..............................................................................................................................181 Definitions Security Rules and Procedures—Merchant Edition • 1 August 2023 Mastercard-branded Application Identifier (AID).........................................................................................182 Mastercard Brand Mark.....................................................................................................................................182 Mastercard Card.................................................................................................................................................182 Mastercard Cloud-Based Payments............................................................................................................... 182 Mastercard Consumer-Presented QR Transaction.......................................................................................182 Mastercard Customer........................................................................................................................................182 Mastercard Digital Enablement Service.........................................................................................................183 Mastercard Europe.............................................................................................................................................183 Mastercard Incorporated..................................................................................................................................183 Mastercard Payment Application....................................................................................................................183 Mastercard Safety Net......................................................................................................................................183 Mastercard Symbol............................................................................................................................................183 Mastercard Token...............................................................................................................................................183 Mastercard Token Account Range...................................................................................................................184 Mastercard Token Vault.....................................................................................................................................184 Mastercard Word Mark..................................................................................................................................... 184 Member, Membership........................................................................................................................................184 Merchandise Transaction.................................................................................................................................. 184 Merchant..............................................................................................................................................................185 Merchant Agreement.........................................................................................................................................185 Merchant Token Requestor...............................................................................................................................185 Mobile Payment Device.....................................................................................................................................185 Mobile POS (MPOS) Terminal..........................................................................................................................185 MoneySend Payment Transaction...................................................................................................................185 Multi-Account Chip Card...................................................................................................................................186 Multi-Factor Authentication Method, MFA Method.....................................................................................186 Non-Mastercard Funding Source.....................................................................................................................186 Non-Mastercard Receiving Account................................................................................................................186 Non-Mastercard Systems and Networks Standards...................................................................................186 On-behalf Token Requestor..............................................................................................................................186 On-Device Cardholder Verification..................................................................................................................186 Originating Account Holder..............................................................................................................................186 Originating Institution (OI)...............................................................................................................................187 Ownership, Owned.............................................................................................................................................187 Participation........................................................................................................................................................187 Pass-through Digital Wallet............................................................................................................................. 187 Pass-through Digital Wallet Operator (DWO)..............................................................................................187 Payment Account Reference (PAR).................................................................................................................187 Payment Application..........................................................................................................................................188 Definitions Security Rules and Procedures—Merchant Edition • 1 August 2023 Payment Facilitator...........................................................................................................................................188 Payment Transaction.........................................................................................................................................188 Payment Transfer Activity(ies) (PTA)..............................................................................................................188 Personal Data......................................................................................................................................................188 Point of Interaction (POI)..................................................................................................................................188 Point-of-Sale (POS) Terminal...........................................................................................................................189 Point–of–Sale (POS) Transaction....................................................................................................................189 Portfolio................................................................................................................................................................189 Principal Customer, Principal............................................................................................................................189 Processed PTA Transaction...............................................................................................................................189 Processed Transaction.......................................................................................................................................190 Processing of Personal Data.............................................................................................................................190 Program................................................................................................................................................................190 Program Service..................................................................................................................................................190 PTA Account.........................................................................................................................................................190 PTA Account Number.........................................................................................................................................190 PTA Account Portfolio........................................................................................................................................191 PTA Agreement...................................................................................................................................................191 PTA Customer.....................................................................................................................................................191 PTA Originating Account...................................................................................................................................191 PTA Program.......................................................................................................................................................191 PTA Receiving Account.......................................................................................................................................191 PTA Settlement Guarantee Covered Program..............................................................................................191 PTA Settlement Obligation ..............................................................................................................................192 PTA Transaction..................................................................................................................................................192 Quick Response (QR) Code ..............................................................................................................................192 Receiving Account Holder..................................................................................................................................192 Receiving Agent...................................................................................................................................................192 Receiving Customer............................................................................................................................................192 Receiving Institution (RI)....................................................................................................................................192 Region...................................................................................................................................................................192 Remote Electronic Transaction ....................................................................................................................... 193 Service Provider.................................................................................................................................................. 193 Settlement Obligation.......................................................................................................................................193 Shared Deposit Transaction.............................................................................................................................193 Solicitation, Solicit..............................................................................................................................................193 Special Issuer Program......................................................................................................................................193 Sponsor, Sponsorship.........................................................................................................................................194 Sponsored Digital Activity Entity.....................................................................................................................194 Definitions Security Rules and Procedures—Merchant Edition • 1 August 2023 Sponsored Merchant..........................................................................................................................................194 Sponsored Merchant Agreement.....................................................................................................................194 Staged Digital Wallet........................................................................................................................................195 Staged Digital Wallet Operator (DWO).........................................................................................................195 Standards............................................................................................................................................................195 Stand-In Parameters.........................................................................................................................................195 Stand-In Processing Service.............................................................................................................................195 Strong Customer Authentication (SCA)........................................................................................................196 Sub-licensee.........................................................................................................................................................196 Terminal................................................................................................................................................................196 Third Party Processor (TPP)..............................................................................................................................196 Token.....................................................................................................................................................................196 Tokenization, Tokenize........................................................................................................................................196 Token Requestor..................................................................................................................................................196 Token Vault...........................................................................................................................................................197 Transaction..........................................................................................................................................................197 Transaction Data................................................................................................................................................197 Transaction Management System..................................................................................................................197 Trusted Service Manager...................................................................................................................................197 Virtual Account....................................................................................................................................................197 Volume..................................................................................................................................................................198 Wallet Token Requestor.....................................................................................................................................198 Word Mark...........................................................................................................................................................198 Definitions Security Rules and Procedures—Merchant Edition • 1 August 2023 Additional and/or revised terms may also be used for purposes of the Rules in a particular chapter or section of this manual. Acceptance Mark Any one of the Corporation’s Marks displayed at a Point of Interaction (POI) to indicate brand acceptance. See Cirrus Acceptance Mark, Maestro Acceptance Mark, Mastercard Acceptance Mark. Acceptor The Merchant, Sponsored Merchant, ATM owner, or other entity that accepts a Card pursuant to a Merchant Agreement, Sponsored Merchant Agreement, or ATM Owner Agreement for purposes of conducting a Transaction. Access Device A device other than a Card that has successfully completed all applicable Mastercard certification and testing requirements, if any, and:
  • Uses at least one Payment Application provisioned to the device by or with the approval of a Customer to provide access to an Account;
  • Supports the transmission or exchange of data using one or both of the following: – Magnetic stripe or chip data containing a dynamic cryptogram to or with a Terminal, as applicable, by implementing the EMV Contactless Specifications (Book D) to effect Transactions at the Terminal without requiring direct contact of the device to the Terminal – Chip data containing a dynamic cryptogram to or with a Terminal, as applicable, by implementing the Mastercard Cloud-Based Payments (MCBP) documentation to effect Transactions at the Terminal by capture of a QR Code containing the Transaction Data
  • May also support the transmission of magnetic stripe data containing a dynamic cryptogram to a Terminal to effect Transactions identified by the Acquirer in Transaction messages as magnetic stripe Transactions. A Cirrus Access Device, Maestro Access Device, and Mastercard Access Device is each an Access Device. Also see Mobile Payment Device. Account An account maintained by or on behalf of a Cardholder by an Issuer for the processing of Transactions, and which is identified with a bank identification number (BIN) or Issuer identification number (IIN) designated by the Corporation in its routing tables for routing to the Interchange System. Also see Cirrus Account, Maestro Account, Mastercard Account. Definitions Acceptance Mark Security Rules and Procedures—Merchant Edition • 1 August 2023 Account Enablement System Performs Account enablement services for Mastercard Cloud-Based Payments, which may include Account and Access Device eligibility checks, Identification & Verification (ID&V), Digitization, and subsequent lifecycle management. Account Holder A user who holds a PTA Account and has agreed to participate in a PTA Transaction. Account PAN The primary account number (PAN) allocated to an Account by an Issuer. Account PAN Range The range of Account PANs designated by an Issuer for Digitization. Acquirer A Customer in its capacity as an acquirer of a Transaction. Activity(ies) The undertaking of any lawful act that can be undertaken only pursuant to a License granted by the Corporation. Payment Transfer Activity is a type of Activity. Also see Digital Activity(ies). Affiliate Customer, Affiliate A Customer that participates indirectly in Activity through the Sponsorship of a Principal or, solely with respect to Mastercard Activity, through the Sponsorship of an Association. An Affiliate may not Sponsor any other Customer. Applicable Data Protection Law All applicable law, statute, declaration, decree, legislation, enactment, order, ordinance, regulation or rule (each as amended and replaced from time to time) which relates to the Definitions Account Enablement System Security Rules and Procedures—Merchant Edition • 1 August 2023 protection of individuals with regards to the Processing of Personal Data to which the Parties are subject, including but not limited to the EU General Data Protection Regulation 2016/679; the e-Privacy Directive 2002/58/EC and their national implementing legislations the California Consumer Privacy Act; the U.S. Gramm-Leach-Bliley Act; the Brazil General Data Protection Act; the South Africa Protection of Personal Information Act; laws regulating unsolicited email, telephone, and text message communications; security breach notification laws; laws imposing minimum security requirements; laws requiring the secure disposal of records containing certain Personal Data; laws governing the portability and/or cross-border transfer of Personal Data; and all other similar international, federal, state, provincial, and local requirements; each as applicable. Area of Use The country or countries in which a Customer is Licensed to use the Marks and conduct Activity or in which a PTA Customer is permitted to Participate in a PTA Program, and, as a rule, set forth in the License or PTA Agreement or in an exhibit to the License or PTA Agreement. Association Customer, Association A Mastercard Customer that participates directly in Mastercard Activity using its assigned BINs and which may Sponsor one or more Mastercard Affiliates but may not directly issue Mastercard Cards or acquire Mastercard Transactions, or in the case of a PTA Association, may not directly hold PTA Accounts, without the express prior written consent of the Corporation. ATM Access Fee A fee charged by an Acquirer in connection with a cash withdrawal or Shared Deposit Transaction initiated at the Acquirer’s ATM Terminal with a Card, and added to the total Transaction amount transmitted to the Issuer. ATM Owner Agreement An agreement between an ATM owner and a Customer that sets forth the terms pursuant to which the ATM accepts Cards. ATM Terminal An ATM that enables a Cardholder to effect an ATM Transaction with a Card (and if contactless-enabled, an Access Device) in accordance with the Standards. Definitions Area of Use Security Rules and Procedures—Merchant Edition • 1 August 2023 ATM Transaction A cash withdrawal effected at an ATM Terminal with a Card and processed through the Mastercard ATM Network. An ATM Transaction is identified with MCC 6011 (Automated Cash Disbursements—Customer Financial Institution). Authenticating Entity An Authenticating Entity is a Merchant, Service Provider, or Digital Wallet Operator that uses an MFA Method to authenticate a Cardholder when a Token is used to conduct a Card-not-present Transaction of any type (excluding mail order and telephone order [MO/TO] Transactions). Automated Teller Machine (ATM) An unattended self-service device that performs basic banking functions such as accepting deposits, cash withdrawals, ordering transfers among accounts, loan payments and account balance inquiries. Bank Branch Terminal An attended device, located on the premises of a Customer or other financial institution designated as its authorized agent by the Corporation, that facilitates a Manual Cash Disbursement Transaction by a Cardholder. BIN A bank identification number (BIN, sometimes referred to as an Issuer identification number, or IIN) is a unique number assigned by Mastercard for use by a Customer in accordance with the Standards. Brand Fee A fee charged for certain Transactions not routed to the Interchange System. Definitions ATM Transaction Security Rules and Procedures—Merchant Edition • 1 August 2023 Brand Mark A Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles device. The Mastercard Brand Mark, Maestro Brand Mark, and Cirrus Brand Mark is each a Brand Mark. The Mastercard Symbol is also a Brand Mark. Card A card issued by a Customer pursuant to License and in accordance with the Standards and that provides access to an Account. Unless otherwise stated herein, Standards applicable to the use and acceptance of a Card are also applicable to an Access Device and, in a Card-not-present environment, an Account. A Cirrus Card, Maestro Card, and Mastercard Card is each a Card. Cardholder The authorized user of a Card or Access Device issued by a Customer. Cardholder Communication Any communication by or on behalf of an Issuer to a Cardholder or prospective Cardholder. A Solicitation is one kind of Cardholder Communication. Cardholder Verification Method (CVM) A process used to confirm that the person presenting the Card is an authorized Cardholder. The Corporation deems the following to be valid CVMs when used in accordance with the Standards:
  • The comparison, by the Merchant or Acquirer accepting the Card, of the signature on the Card’s signature panel with the signature provided on the Transaction receipt by the person presenting the Card;
  • The comparison, by the Card Issuer or the EMV chip on the Card, of the value entered on a Terminal’s PIN pad with the personal identification number (PIN) given to or selected by the Cardholder upon Card issuance; and
  • The use of a Consumer Device CVM (CDCVM) that Mastercard approved as a valid CVM for Transactions upon the successful completion of the certification and testing procedures set forth in section 3.11 of the Security Rules and Procedures. In certain Card-present environments, a Merchant may complete the Transaction without a CVM (“no CVM” as the CVM), such as in Quick Payment Service (QPS) Transactions, Contactless Transactions less than or equal to the CVM limit, and Transactions at an unattended Point-of- Sale (POS) Terminal identified as Cardholder-activated Terminal (CAT) Level 2 or Level 3. Definitions Brand Mark Security Rules and Procedures—Merchant Edition • 1 August 2023 Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC) A Card with an embedded EMV-compliant chip containing memory and interactive capabilities used to identify and store additional data about a Cardholder, an Account, or both. Chip-only MPOS Terminal An MPOS Terminal that has a contact chip reader and no magnetic stripe-reading capability and that must:
  1. Operate as an online-only POS Terminal for authorization purposes;
  2. Support either signature or No CVM Required as a Cardholder Verification Method, and may also support PIN verification if conducted by means of a PIN entry device (PED) that is in compliance with the Payment Card Industry (PCI) POS PED Security Requirements and Evaluation Program; and
  3. Otherwise comply with the Corporation’s requirements for Hybrid POS Terminals. Chip Transaction A Contact Chip Transaction or a Contactless Transaction. Cirrus Acceptance Mark A Mark consisting of the Cirrus Brand Mark placed on the dark blue acceptance rectangle, available at www.mastercardbrandcenter.com. Cirrus Access Device An Access Device that uses at least one Cirrus Payment Application to provide access to a Cirrus Account when used at an ATM Terminal or Bank Branch Terminal. Cirrus Account An account eligible to be a Cirrus Account and identified with a BIN/IIN associated with a Portfolio designated by the Corporation as a Cirrus Portfolio in its routing tables. Definitions Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC) Security Rules and Procedures—Merchant Edition • 1 August 2023 Cirrus Brand Mark A Mark consisting of the Cirrus Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles device. The Corporation is the exclusive owner of the Cirrus Brand Mark. Cirrus Card A Card that provides access to a Cirrus Account. Cirrus Customer A Customer that has been granted a Cirrus License in accordance with the Standards. Cirrus Payment Application A Payment Application that stores Cirrus Account data. Cirrus Word Mark A Mark consisting of the word “Cirrus” followed by a registered trademark ® or ™ symbol (depending on its trademark status in a particular country) or the local law equivalent. “Cirrus” must appear in English and be spelled correctly, with the letter “C” capitalized. “Cirrus” must not be abbreviated, hyphenated, used in the plural or possessive, translated from English into another language, or appear in another alphabet except for specific authorized versions in Chinese (translation), Arabic (transliteration), Georgian (transliteration), and Korean (transliteration). The Corporation is the exclusive owner of the Cirrus Word Mark. Competing ATM Network A Competing International ATM Network or a Competing North American ATM Network, as the case may be. Competing EFT POS Network A network, other than any network owned and operated by the Corporation, which provides access to Maestro Accounts at POS Terminals by use of payment cards and has the following characteristics: Definitions Cirrus Brand Mark Security Rules and Procedures—Merchant Edition • 1 August 2023
  4. It provides a common service mark or marks to identify the POS Terminal and payment cards, which provide Maestro Account access;
  5. It is not an affiliate of the Corporation; and
  6. It operates in at least one country in which the Corporation has granted a License or Licenses. The following networks are designated without limitation to be Competing EFT POS Networks: Interlink; Electron; and V-Pay. Competing International ATM Network A network of ATMs and payment cards, other than the Corporation, identified by a common brand mark that is used exclusively or primarily for ATM interchange that:
  7. Operates in at least three countries;
  8. Uses a common service mark or marks to identify the ATMs and payment cards which provide account access through it; and
  9. Provides account access to at least 40,000,000 debit cards and by means of at least 25,000 ATMs. Competing North American ATM Network A network of ATMs and access cards, other than the Corporation, identified by a common brand mark that is used exclusively or primarily for ATM interchange and that possesses each of the following characteristics:
  10. It operates in at least 40 of the states or provinces of the states and provinces of the United States and Canada;
  11. It uses a common service mark or common service marks to identify the terminals and cards which provide account access through it;
  12. There are at least 40,000,000 debit cards that provide account access through it; and
  13. There are at least 12,000 ATMs that provide account access through it. Consumer Device Cardholder Verification Method, Consumer Device CVM, CDCVM A CVM that occurs when personal credentials established by the Cardholder to access an Account by means of a particular Access Device are entered on the Access Device and verified, either within the Access Device or by the Issuer during online authorization. A CDCVM is valid if the Issuer has approved the use of the CVM for the authentication of the Cardholder. Definitions Competing International ATM Network Security Rules and Procedures—Merchant Edition • 1 August 2023 Contact Chip Transaction A Transaction in which data is exchanged between the Chip Card and the Terminal through the reading of the chip using the contact interface, in conformance with EMV specifications. Contactless Payment Device A means other than a Card by which a Cardholder may access an Account at a Terminal in accordance with the Standards. A Contactless Payment Device is a type of Access Device that exchanges data with the Terminal by means of radio frequency communications. Also see Mobile Payment Device. Contactless Transaction A Transaction in which data is exchanged between the Chip Card or Access Device and the Terminal through the reading of the chip using the contactless interface, by means of radio frequency communications. Also see EMV Mode Contactless Transaction, Magnetic Stripe Mode Contactless Transaction. Control, Controlled As used herein, Control has such meaning as the Corporation deems appropriate in its sole discretion given the context of the usage of the term and all facts and circumstances the Corporation deems appropriate to consider. As a general guideline, Control often means to have, alone or together with another entity or entities, direct, indirect, legal, or beneficial possession (by contract or otherwise) of the power to direct the management and policies of another entity. Corporation Mastercard International Incorporated, Maestro International Inc., and their subsidiaries and affiliates. As used herein, Corporation also means the President and Chief Executive Officer of Mastercard International Incorporated, or his or her designee, or such officers or other employees responsible for the administration and/or management of a program, service, product, system or other function. Unless otherwise set forth in the Standards, and subject to any restriction imposed by law or regulation, or by the Board of Directors of Mastercard International Incorporated, or by the Mastercard International Incorporated Certificate of Incorporation or the Mastercard Incorporated Certificate of Incorporation (as each such Certificate of Incorporation may be amended from time to time), each such person is authorized to act on behalf of the Corporation and to so act in his or her sole discretion. Definitions Contact Chip Transaction Security Rules and Procedures—Merchant Edition • 1 August 2023 Corporation System The Interchange System as defined in this manual. Credentials Management System Facilitates credential preparation and/or remote mobile Payment Application management for Mastercard Cloud-Based Payments. Cross-border Transaction A Transaction that occurs at a Card acceptance location in a different country from the country in which the Card was issued. Customer A financial institution or other entity that has been approved for Participation. A Customer may be a Principal, Association, Affiliate, Digital Activity Customer, Sponsored Digital Activity Entity, or PTA Customer. Also see Cirrus Customer, Maestro Customer, Mastercard Customer, Member. Customer Report Any report that a Customer is required to provide to the Corporation, whether on a one-time or repeated basis, pertaining to its License, Activities, Digital Activity Agreement, Digital Activities, PTA Agreement, Payment Transfer Activities, use of any Mark, or any such matters. By way of example and not limitation, the Quarterly Mastercard Report (QMR) is a Customer Report. Data Storage Entity (DSE) A Service Provider that performs DSE Program Service. Data Subject A Cardholder, a Merchant, or other natural person or entity whose Personal Data are Processed by or on behalf of the Corporation, a Customer, or a Merchant. Definitions Corporation System Security Rules and Procedures—Merchant Edition • 1 August 2023 Device Binding The process by which a Wallet Token Requestor binds a Mastercard Token corresponding to a Cardholder’s Account to that Cardholder’s Mobile Payment Device, which may consist of:
  • The provisioning of the Token and its associated encryption keys into the secure element within the Mobile Payment Device;
  • The loading of an application for a remotely-managed secure server into the Mobile Payment Device and the successful communication of the device with the application; or
  • Other methodology acceptable to the Corporation. Digital Activity(ies) The undertaking of any lawful act pursuant to approval by the Corporation as set forth in a Digital Activity Agreement or other written documentation. Participation in the Mastercard Digital Enablement Service as a Wallet Token Requestor is a Digital Activity. Digital Activity Agreement The contract between the Corporation and a Digital Activity Customer granting the Digital Activity Customer the right to participate in Digital Activity and a limited License to use one or more of the Marks in connection with such Digital Activity, in accordance with the Standards. Digital Activity Customer A Customer that participates in Digital Activity pursuant to a Digital Activity Agreement and which may not issue Cards, acquire Transactions, or Sponsor any other Customer into the Corporation. Digital Activity Service Provider (DASP) A Service Provider that performs DASP Program Service. Digital Activity Sponsoring Customer A Principal Customer or Digital Activity Customer that sponsors a Sponsored Digital Activity Entity to participate in Digital Activity. Definitions Device Binding Security Rules and Procedures—Merchant Edition • 1 August 2023 Digital Goods Any goods that are stored, delivered, and used in electronic format, such as, by way of example but not limitation, books, newspapers, magazines, music, games, game pieces, and software (excluding gift cards). The delivery of a purchase of Digital Goods may occur on a one-time or subscription basis. Digital Wallet A Pass-through Digital Wallet or a Staged Digital Wallet. Digital Wallet Operator (DWO) A Service Provider that operates a Staged Digital Wallet or a Customer that operates a Pass- through Digital Wallet. A Merchant that stores Mastercard or Maestro Account data solely on its own behalf to effect Transactions initiated by the consumer is not deemed to be a DWO. Digital Wallet Operator Mark, DWO Mark A Mark identifying a particular Pass-through Digital Wallet and/or Staged Digital Wallet, and which may be displayed at the POI to denote that a retailer, or any other person, firm, or corporation, accepts payments effected by means of that Pass-through Digital Wallet and/or Staged Digital Wallet. A “Staged DWO Mark” and a “Pass-through DWO Mark” are both types of DWO Marks. Digital Wallet Operator (DWO) Security Incident, DWO Security Incident Any incident pertaining to the unintended or unlawful disclosure of Personal Data in connection with such Personal Data being processed through a DWO. Digitization, Digitize Data preparation performed by, or on behalf of, an Issuer prior to the provisioning of Account credentials or a PTA Customer prior to the provisioning of PTA Account credentials, in the form of a Mastercard Token, onto a Payment Device or into a server. Digitization includes Tokenization. Definitions Digital Goods Security Rules and Procedures—Merchant Edition • 1 August 2023 Domestic Transaction See Intracountry Transaction. Dual Interface The description of a Terminal or Card that is capable of processing Contactless Transactions by means of its contactless interface and Contact Chip Transactions by means of its contact interface. Electronic Money Electronically (including magnetically) accessed monetary value as represented by a claim on the Electronic Money Issuer which:
  1. Is issued on receipt of funds for the purpose of making transactions with payment cards; and
  2. Is accepted by the Electronic Money Issuer or a person other than the Electronic Money Issuer. Electronic Money Institution An entity authorized by applicable regulatory authority or other government entity as an “electronic money institution”, “e-money institution”, “small electronic money institution”, or any other applicable qualification under which an entity is authorized to issue or acquire Electronic Money transactions under applicable law or regulation. Electronic Money Issuer An Electronic Money Institution with respect only to its issuing activities. EMV Mode Contactless Transaction A Contactless Transaction in which the Terminal and the chip exchange data, enabling the chip to approve the Transaction offline on the Issuer’s behalf or to request online authorization from the Issuer, in compliance with the Standards. Definitions Domestic Transaction Security Rules and Procedures—Merchant Edition • 1 August 2023 End User Recipients of any lending services from the Installment Service Provider in accordance with an Installment Lending Agreement. An End User can be a natural person or an entity. Gateway Customer A Customer that uses the Gateway Processing service. Gateway Processing A service that enables a Customer to forward a Gateway Transaction to and/or receive a Gateway Transaction from the Mastercard® ATM Network. Gateway Transaction An ATM transaction effected with a payment card or other access device not bearing a Mark that is processed through or using the Mastercard® ATM Network. Global Collection Only (GCO) Data Collection Program A program of the Corporation pursuant to which a Customer must provide collection-only reporting of non-Processed Transactions effected with a Card, Access Device, or Account issued under a Mastercard-assigned BIN via the Corporation’s Global Clearing Management System (GCMS), in accordance with the requirements set forth in the Mastercard Global Collection Only manual. Host Card Emulation (HCE) The presentation on a Mobile Payment Device of a virtual and exact representation of a Chip Card using only software on the Mobile Payment Device and occurring by means of its communication with a secure remote server. Hybrid Terminal A Terminal, including any POS or MPOS Terminal (“Hybrid POS Terminal”, “Hybrid MPOS Terminal”), ATM Terminal (“Hybrid ATM Terminal”), or Bank Branch Terminal (“Hybrid Bank Branch Terminal”), that: Definitions End User Security Rules and Procedures—Merchant Edition • 1 August 2023
  3. Is capable of processing both Contact Chip Transactions and magnetic stripe Transactions;
  4. Has the equivalent hardware, software, and configuration as a Terminal with full EMV Level 1 and Level 2 type approval status with regard to the chip technical specifications; and
  5. Has satisfactorily completed the Corporation’s Terminal Integration Process (TIP) in the appropriate environment of use. ICA A unique number assigned by the Corporation to identify a Customer in relation to Activity. Independent Sales Organization (ISO) A Service Provider that performs ISO Program Service. Installment Lending Agreement The agreement between the Installment Service Provider and an End User, which includes terms and conditions governing the relationship between the parties, such as lending amount and repayment terms. Interchange System The computer hardware and software operated by and on behalf of the Corporation for the routing, processing, and settlement of Transactions and PTA Transactions including, without limitation, the Mastercard Network, the Mastercard ATM Network, the Dual Message System, the Single Message System, the Global Clearing Management System (GCMS), and the Settlement Account Management (SAM) system. Identification & Verification (ID&V) The identification and verification of a person as the Cardholder to whom the Issuer allocated the Account PAN to be Tokenized. Inter-European Transaction A Transaction completed using a Card issued in a country or territory listed in Single European Payments Area (SEPA) at a Terminal located in a country or territory listed in Non-Single European Payments Area (Non-SEPA) or Transaction completed using a Card issued in a country Definitions ICA Security Rules and Procedures—Merchant Edition • 1 August 2023 or territory listed in Non-Single European Payments Area (Non–SEPA) at a Terminal located in a country or territory listed in Single European Payments Area (SEPA). Interregional Transaction A Transaction that occurs at a Card acceptance location in a different Region from the Region in which the Card was issued. In the Europe Region, the term “Interregional Transaction” includes any “Inter-European Transaction,” as such term is defined in the “Europe Region” chapter of the Mastercard Rules. Intracountry Transaction A Transaction that occurs at a Card acceptance location in the same country as the country in which the Card was issued. A Transaction conducted with a Card bearing one or more of the Brand Marks, either alone or in combination with the marks of another payment scheme, and processed as a Transaction, as shown by the Card type identification in the Transaction record, via either the Interchange System or a different network, qualifies as an Intracountry Transaction. “Domestic Transaction” is an alternative term for Intracountry Transaction. Intra–European Transaction An Intra-Non-SEPA Transaction or an Intra–SEPA Transaction, but not an Inter–European Transaction. Intra–Non–SEPA Transaction A Transaction completed using a Card issued in a country or territory listed in Non–Single European Payments Area (Non–SEPA) at a Terminal located in a country or territory listed in Non–Single European Payments Area (Non–SEPA). Intraregional Transaction A Transaction that occurs at a Card acceptance location in a different country from the country in which the Card was issued, within the same Region. In the Europe Region, this term is replaced by “Intra-European Transaction,” as such term is defined in the “Europe Region” chapter of the Mastercard Rules. Definitions Interregional Transaction Security Rules and Procedures—Merchant Edition • 1 August 2023 Issuer A Customer in its capacity as an issuer of a Card or Account. License, Licensed The contract between the Corporation and a Customer granting the Customer the right to use one or more of the Marks in accordance with the Standards and in the case of Payment Transfer Activity, includes a PTA Agreement. To be “Licensed” means to have such a right pursuant to a License. Licensee A Customer or other person authorized in writing by the Corporation to use one or more of the Marks. Maestro Maestro International Incorporated, a Delaware U.S.A. corporation or any successor thereto. Maestro Acceptance Mark A Mark consisting of the Maestro Brand Mark placed on the dark blue acceptance rectangle, as available at www.mastercardbrandcenter.com. Maestro Access Device An Access Device that uses at least one Maestro Payment Application to provide access to a Maestro Account when used at a Terminal. Maestro Account An account eligible to be a Maestro Account and identified with a BIN/IIN associated with a Portfolio designated by the Corporation as a Maestro Portfolio in its routing tables. Definitions Issuer Security Rules and Procedures—Merchant Edition • 1 August 2023 Maestro Brand Mark A Mark consisting of the Maestro Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles device. The Corporation is the exclusive owner of the Maestro Brand Mark. Maestro Card A Card that provides access to a Maestro Account. Maestro Customer A Customer that has been granted a Maestro License in accordance with the Standards. Maestro Payment Application A Payment Application that stores Maestro Account data. Maestro Word Mark A Mark consisting of the word “Maestro” followed by a registered trademark ® or ™ symbol (depending on its trademark status in a particular country) or the local law equivalent. “Maestro” must appear in English and be spelled correctly, with the letter “M” capitalized. “Maestro” must not be abbreviated, hyphenated, used in the plural or possessive, translated from English into another language, or appear in another alphabet except for specific authorized versions in Chinese (translation), Arabic (transliteration), Georgian (transliteration), and Korean (transliteration). Maestro is the exclusive owner of the Maestro Word Mark. Magnetic Stripe Mode Contactless Transaction A Contactless Transaction in which the Terminal receives static and dynamic data from the chip and constructs messages that can be transported in a standard magnetic stripe message format, in compliance with the Standards. Definitions Maestro Brand Mark Security Rules and Procedures—Merchant Edition • 1 August 2023 Manual Cash Disbursement Transaction A disbursement of cash performed upon the acceptance of a Card by a Customer financial institution teller. A Manual Cash Disbursement Transaction is identified with MCC 6010 (Manual Cash Disbursements—Customer Financial Institution). Marks The names, logos, trade names, logotypes, trademarks, service marks, trade designations, and other designations, symbols, and marks that the Corporation owns, manages, licenses, or otherwise Controls and makes available for use by Customers and other authorized entities in accordance with a License. A “Mark” means any one of the Marks. Mastercard Mastercard International Incorporated, a Delaware U.S.A. corporation. Mastercard Acceptance Mark A Mark consisting of the Mastercard Brand Mark or Mastercard Symbol placed on the dark blue acceptance rectangle, as available at www.mastercardbrandcenter.com. Mastercard Access Device An Access Device that uses at least one Mastercard Payment Application to provide access to a Mastercard Account when used at a Terminal. Mastercard Account Any type of account (credit, debit, prepaid, commercial, etc.) identified as a Mastercard Account with a primary account number (PAN) that begins with a BIN in the range of 222100 to 272099 or 510000 to 559999. Mastercard Biometric Card A Mastercard or Maestro Chip Card containing a fingerprint sensor and compliant with the Corporation’s biometric Standards. Definitions Manual Cash Disbursement Transaction Security Rules and Procedures—Merchant Edition • 1 August 2023 Mastercard-branded Application Identifier (AID) Any of the Corporation’s EMV chip application identifiers for Mastercard, Maestro, and Cirrus Payment Applications as defined in the M/Chip Requirements manual. Mastercard Brand Mark A Mark consisting of the Mastercard Word Mark as a custom lettering legend placed within the Mastercard Interlocking Circles Device. The Corporation is the exclusive owner of the Mastercard Brand Mark. The Mastercard Symbol is also a Mastercard Brand Mark. Mastercard Card A Card that provides access to a Mastercard Account. Mastercard Cloud-Based Payments A specification that facilitates the provisioning of Digitized Account data into a Host Card Emulation (HCE) server and the use of the remotely stored Digitized Account data, along with single-use payment credentials, in Transactions effected by a Cardholder using a Mobile Payment Device. The Mastercard Digital Enablement Service offers Mastercard Cloud-Based Payments as an on-behalf service. Mastercard Consumer-Presented QR Transaction A Mastercard Consumer-Presented QR Transaction is an EMV Chip Transaction effected through the presentment of a QR Code by the Cardholder, using a Mobile Payment Device, and the capture of the QR Code by the Merchant containing the Transaction Data required to initiate a Transaction. Each Mastercard Consumer-Presented QR Transaction must comply with all requirements set forth in the Standards applicable to a Mastercard Consumer-Presented QR Transaction, including but not limited to those herein, in the technical specifications for authorization messages, in the M/Chip Requirements for Contact and Contactless manual, and in the Mastercard Cloud-Based Payments (MCBP) documentation. Mastercard Customer A Customer that has been granted a Mastercard License in accordance with the Standards. Also see Member. Definitions Mastercard-branded Application Identifier (AID) Security Rules and Procedures—Merchant Edition • 1 August 2023 Mastercard Digital Enablement Service Any of the services offered by the Corporation exclusively to Customers for the digital enablement of Account and/or PTA Account data, including but not limited to ID&V Service, Tokenization Service, Digitization Service, Token Mapping Service, Mastercard Cloud-Based Payments, Digital Card Image Database, CVC 3 pre-validation and other on-behalf cryptographic validation services, and Service Requests. Mastercard Europe Mastercard Europe SA, a Belgian private limited liability (company). Mastercard Incorporated Mastercard Incorporated, a Delaware U.S.A. corporation. Mastercard Payment Application A Payment Application that stores Mastercard Account data. Mastercard Safety Net A service offered by the Corporation that performs fraud monitoring at the network level for all Transactions processed on the Mastercard Network. The service invokes targeted measures to provide protective controls on behalf of a participating Issuer to assist in minimizing losses in the event of a catastrophic fraud attack. Mastercard Symbol A Mark consisting of the Mastercard interlocking circles device. The Corporation is the exclusive owner of the Mastercard Symbol. The Mastercard Symbol is also a Mastercard Brand Mark. Mastercard Token A Token allocated from a Mastercard Token Account Range that the Corporation has designated to an Issuer or PTA Customer and that corresponds to an Account PAN or a PTA Account Number. The Corporation exclusively owns all right, title, and interest in any Mastercard Token. Definitions Mastercard Digital Enablement Service Security Rules and Procedures—Merchant Edition • 1 August 2023 Mastercard Token Account Range A bank identification number (BIN) or portion of a BIN (“BIN range”) designated by the Corporation to an Issuer or PTA Customer for the allocation of Mastercard Tokens in a particular Token implementation. A Mastercard Token Account Range must be designated from a BIN reserved for the Corporation by the ISO Registration Authority and for which the Corporation is therefore the “BIN Controller,” as such term is defined in the EMV Payment Tokenization Specification Technical Framework (also see the term “Token BIN Range” in that document). A Mastercard Token Account Range is identified in the Corporation’s routing tables as having the same attributes as the corresponding Account PAN Range or the range of PTA Account Numbers. Mastercard Token Vault The Token Vault owned and operated by Mastercard and enabled by means of the Mastercard Digital Enablement Service. Mastercard Word Mark A Mark consisting of the word “Mastercard” followed by a registered trademark ® symbol or the local law equivalent. “Mastercard” must appear in English and be spelled correctly, with the letter “M” capitalized. “Mastercard” must not be abbreviated, hyphenated, used in the plural or possessive, translated from English into another language, or appear in another alphabet except for specific authorized versions in Chinese (translation), Arabic (transliteration), Georgian (transliteration), and Korean (transliteration). The Corporation is the exclusive owner of the Mastercard Word Mark. Member, Membership A financial institution or other entity that is approved to be a Mastercard Customer in accordance with the Standards and which, as a Mastercard Customer, has been granted membership (“Membership”) in and has become a member (“Member”) of the Corporation. “Membership” also means “Participation”. Merchandise Transaction The purchase by a Cardholder of merchandise or a service, but not currency, in an approved category at an ATM Terminal and dispensed or otherwise provided by such ATM Terminal. A Merchandise Transaction is identified with MCC 6012 (Merchandise and Services—Customer Financial Institution), unless otherwise specified. Definitions Mastercard Token Account Range Security Rules and Procedures—Merchant Edition • 1 August 2023 Merchant A retailer, or any other person, firm or corporation that, pursuant to a Merchant Agreement, agrees to accept Cards when properly presented. Merchant Agreement An agreement between a Merchant and a Customer that sets forth the terms pursuant to which the Merchant is authorized to accept Cards. Merchant Token Requestor A Merchant Token Requestor is a Merchant that connects directly to the Mastercard Digital Enablement Service (MDES) for the purpose of Tokenizing a Mastercard or Maestro Account primary account number (PAN) provided by a Cardholder for use in a future Transaction with the Merchant. A Merchant Token Requestor is a type of Token Requestor. Mobile Payment Device A Cardholder-controlled mobile device containing a Payment Application compliant with the Standards, and which uses an integrated keyboard and screen to access an Account. A Mobile Payment Device may also be a Contactless Payment Device or a Mastercard Consumer- Presented QR payment device. Mobile POS (MPOS) Terminal An MPOS Terminal enables a mobile device to be used as a POS Terminal. Card “reading” and software functionality that meets the Corporation’s requirements may reside within the mobile device, on a server accessed by the mobile device, or in a separate accessory connected (such as via Bluetooth or a USB port) to the mobile device. The mobile device may be any multi-purpose mobile computing platform, including, by way of example and not limitation, a feature phone, smart phone, tablet, or personal digital assistant (PDA). MoneySend Payment Transaction A type of Payment Transaction that is effected pursuant to, and subject to, the MoneySend Standards. Definitions Merchant Security Rules and Procedures—Merchant Edition • 1 August 2023 Multi-Account Chip Card A Chip Card with more than one Account encoded in the chip. Multi-Factor Authentication Method, MFA Method A Multi-Factor Authentication (MFA) Method is an authentication solution that includes two or more factors from the following categories: possession, knowledge, or inherence, with no more than one factor in any single category. Non-Mastercard Funding Source Any funding source used to fund a PTA Transaction other than an Account. Non-Mastercard Receiving Account Any receiving account used to receive a PTA Transaction other than an Account. Non-Mastercard Systems and Networks Standards The applicable rules, regulations, by-laws, standards, procedures, and any other obligations or requirements of an applicable payment network or system that is not owned, operated, or controlled by the Corporation. On-behalf Token Requestor A Digital Activity Customer or other Customer, approved by the Corporation to conduct Digital Activity and authorized to Tokenize a Mastercard or Maestro primary account number (PAN) using the Mastercard Digital Enablement Service (MDES) on behalf of a DWO or Merchant. On-Device Cardholder Verification The use of a CDCVM as the CVM for a Transaction. Originating Account Holder The Account Holder originating the PTA Transaction. Definitions Multi-Account Chip Card Security Rules and Procedures—Merchant Edition • 1 August 2023 Originating Institution (OI) A PTA Customer that Participates in a Payment Transfer Activity as an originator of PTA Transactions. Ownership, Owned As used herein, ownership has such meaning as the Corporation deems appropriate in its sole discretion given the context of the usage of the term in all facts and circumstances the Corporation deems appropriate to consider. As a general guideline, ownership often means to own indirectly, legally, or beneficially more than fifty percent (50 percent) of an entity. Participation The right to participate in Activity, Digital Activity, and/or Payment Transfer Activity granted to a Customer by the Corporation. For a Mastercard Customer, Participation is an alternative term for Membership. Pass-through Digital Wallet Functionality which can be used at more than one Merchant, and by which the Pass-through Digital Wallet Operator stores Mastercard or Maestro Account data provided by the Cardholder to the DWO for purposes of effecting a payment initiated by the Cardholder to a Merchant or Sponsored Merchant, and upon the performance of a Transaction, transfers the Account data to the Merchant or Sponsored Merchant or to its Acquirer or the Acquirer’s Service Provider. Pass-through Digital Wallet Operator (DWO) A Digital Activity Customer or other Customer, approved by the Corporation to engage in Digital Activity, that operates a Pass-through Digital Wallet. Payment Account Reference (PAR) A unique non-financial alphanumeric value assigned to an Account PAN or PTA Account Number that is used to link the Account PAN or PTA Account Number to all of its corresponding Tokens. Definitions Originating Institution (OI) Security Rules and Procedures—Merchant Edition • 1 August 2023 Payment Application A package of code and data stored in a Card, an Access Device, a server, or a combination of Access Device and server, that when exercised outputs a set of data that may be used to effect a Transaction, in accordance with the Standards. A Mastercard Payment Application, Maestro Payment Application, and Cirrus Payment Application is each a Payment Application. Payment Facilitator A Service Provider registered by an Acquirer to facilitate the acquiring of Transactions by the Acquirer from Sponsored Merchant, and which in doing so, performs PF Program Service. Payment Transaction A PTA Transaction that transfers funds to an Account. A Payment Transaction is not a credit that reverses a previous purchase. Includes MoneySend Payment Transaction and Gaming Payment Transaction. Payment Transfer Activity(ies) (PTA) The undertaking of any lawful act that can be undertaken only pursuant to a PTA Agreement or pursuant to a License granted by the Corporation. Participation in a PTA Program is Payment Transfer Activity. Personal Data Any information relating to an identified or identifiable individual, including contact information, demographic information, passport number, Social Security number or other national identification number, bank account information, Primary Account Number and authentication information (e.g. identification codes, passwords). Point of Interaction (POI) The location at which a Transaction occurs or a PTA Transaction originates, as determined by the Corporation. Definitions Payment Application Security Rules and Procedures—Merchant Edition • 1 August 2023 Point-of-Sale (POS) Terminal One of the following:
  • An attended or unattended device, including any commercial off-the-shelf (COTS) or other device enabled with mobile point-of-sale (MPOS) functionality, that is in the physical possession of a Merchant and is deployed in or at the Merchant’s premises, and which enables a Cardholder to use a Card or Access Device to effect a Transaction for the purchase of products or services sold by such Merchant; or
  • A Bank Branch Terminal. A POS Terminal must comply with the POS Terminal security and other applicable Standards. Point–of–Sale (POS) Transaction The sale of products or services by a Merchant to a Cardholder pursuant to acceptance of a Card by the Merchant or Manual Cash Disbursement Transaction. A POS Transaction may be a Card-present Transaction taking place in a face-to-face environment or at an unattended POS Terminal, or a Card-not-present Transaction taking place in a non-face-to-face environment (for example, an e-commerce, mail order, phone order, or recurring payment Transaction). Portfolio All Cards issued bearing the same major industry identifier, BIN/IIN, and any additional digits that uniquely identify Cards for routing purposes. Principal Customer, Principal A Customer that participates directly in Activity using its assigned BINs/IINs and which may Sponsor one or more Affiliates. Processed PTA Transaction A PTA Transaction which is:
  1. Initiated by or on behalf of the Originating Institution via the Corporation System in accordance with the Standards; and
  2. Cleared, meaning the Originating Institution transferred the PTA Transaction data within the applicable time frame to the Corporation via the Corporation System, for the purpose of a transfer of funds via the Corporation System, and such PTA Transaction data is subsequently transferred by the Corporation to the Receiving Customer for such purpose. Definitions Point-of-Sale (POS) Terminal Security Rules and Procedures—Merchant Edition • 1 August 2023 Processed Transaction A Transaction which is:
  3. Authorized by the Issuer via the Interchange System, unless a properly processed offline Chip Transaction approval is obtained or no authorization is required, in accordance with the Standards; and
  4. Cleared, meaning the Acquirer transferred the Transaction Data within the applicable presentment time frame to the Corporation via the Interchange System, for the purpose of a transfer of funds via the Interchange System, and such Transaction Data is subsequently transferred by the Corporation to the Issuer for such purpose. Processing of Personal Data Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of such data. Program A Customer’s Card issuing program, Merchant acquiring program, ATM Terminal acquiring program, Digital Activity program, and/or a PTA Program in which a Customer is Participating. Program Service Any service described in the Standards that directly or indirectly supports a Program and regardless of whether the entity providing the service is registered as a Service Provider of one or more Customers. The Corporation has the sole right to determine whether a service is a Program Service. PTA Account A PTA Originating Account and/or a PTA Receiving Account. PTA Account Number The account number allocated to a PTA Account by a PTA Customer. Definitions Processed Transaction Security Rules and Procedures—Merchant Edition • 1 August 2023 PTA Account Portfolio All PTA Accounts issued by a PTA Customer. PTA Agreement The agreement between the Corporation and a PTA Customer granting the PTA Customer the right to Participate in a PTA Program, in accordance with the Standards. PTA Customer A Customer that Participates in a PTA Program pursuant to a PTA Agreement. PTA Originating Account The funding source of the Originating Account Holder, from where funds are acquired by the Originating Institution to initiate a PTA Transaction. PTA Program A type of Payment Transfer Activity that is identified in the applicable Standards as being a PTA Program, including the MoneySend Program, the Mastercard Merchant Presented QR Program, the Mastercard Send Cross-Border Service, and the Mastercard Gaming and Gambling Payments Program. PTA Receiving Account The Account or, if applicable for a particular PTA Program (as set forth in the Standards for such PTA Program), the Non-Mastercard Receiving Account, held by a Receiving Account Holder and to which the Receiving Customer must ensure receipt of a PTA Transaction. PTA Settlement Guarantee Covered Program A PTA Settlement Obligation arising from a PTA Transaction conducted pursuant to a PTA Program that is identified in the applicable Standards as being a PTA Settlement Guarantee Covered Program. Definitions PTA Account Portfolio Security Rules and Procedures—Merchant Edition • 1 August 2023 PTA Settlement Obligation A financial obligation of a Principal or Association PTA Customer to another Principal or Association PTA Customer arising from a PTA Transaction. PTA Transaction A financial transaction in which funds are transferred from an Originating Institution to a Receiving Customer on behalf of Account Holders pursuant to a PTA Program. Quick Response (QR) Code An ISO 18004-compliant encoding and visualization of data. Receiving Account Holder The Account Holder receiving the PTA Transaction. Receiving Agent A PTA Customer that Participates in Payment Transfer Activity as an agent for the purpose of receiving a PTA Transaction. Receiving Customer A Receiving Agent or a Receiving Institution. Receiving Institution (RI) A PTA Customer that Participates in Payment Transfer Activity as a receiver of PTA Transactions on behalf of a Receiving Account Holder. Region A geographic region as defined by the Corporation from time to time. See Appendix A of the Mastercard Rules manual. Definitions PTA Settlement Obligation Security Rules and Procedures—Merchant Edition • 1 August 2023 Remote Electronic Transaction In the Europe Region, all types of Card-not-present Transaction (e-commerce Transactions, recurring payments, installments, Card-on-file Transactions, in-app Transactions, and Transactions completed through a Digital Wallet, including MasterPass™). Mail order and telephone order (MO/TO) Transactions and Transactions completed with anonymous prepaid Cards are excluded from this definition. Service Provider A person that performs Program Service. The Corporation has the sole right to determine whether a person is or may be a Service Provider and if so, the category of Service Provider. A Service Provider is an agent of the Customer that receives or otherwise benefits from Program Service, whether directly or indirectly, performed by such Service Provider. Settlement Obligation A financial obligation of a Principal or Association Customer to another Principal or Association Customer arising from a Transaction. Shared Deposit Transaction A deposit to a savings Account or checking Account conducted at an ATM Terminal located in the U.S. Region, initiated with a Card issued by a U.S. Region Customer other than the Acquirer, and processed through the Mastercard ATM Network. Solicitation, Solicit An application, advertisement, promotion, marketing communication, or the like distributed as printed materials, in electronic format (including but not limited to an email, website, mobile application, or social media platform), or both intended to solicit the enrollment of a person or entity as a Cardholder or Account Holder or as a Merchant. To “Solicit” means to use a Solicitation. Special Issuer Program Issuer Activity that the Corporation deems may be undertaken only with the express prior consent of the Corporation. As of the date of the publication of these Rules, Special Issuer Programs include Affinity Card Programs, Co-Brand Card Programs, and Prepaid Card Definitions Remote Electronic Transaction Security Rules and Procedures—Merchant Edition • 1 August 2023 Programs, and with respect to Mastercard Activity only, Brand Value Transaction and proprietary account, Remote Transaction Mastercard Account, and secured Mastercard Card Programs. Sponsor, Sponsorship The relationship described in the Standards between:
  • a Principal or Association and an Affiliate that engages in Activity indirectly through the Principal or Association, in which case, the Principal or Association is the Sponsor of the Affiliate and the Affiliate is Sponsored by the Principal or Association;
  • a Payment Facilitator and a Sponsored Merchant, in which case the Payment Facilitator is the Sponsor of the Sponsored Merchant and the Sponsored Merchant is Sponsored by the Payment Facilitator; or
  • a Digital Activity Sponsoring Customer and a Sponsored Digital Activity Entity, in which case the Digital Activity Sponsoring Customer is the Sponsor of the Sponsored Digital Activity Entity. “Sponsorship” means the Sponsoring of a Customer, a Sponsored Merchant, or a Sponsored Digital Activity Entity. Sponsored Digital Activity Entity A wholly-owned subsidiary (or other affiliated entity as approved by the Corporation) of a Digital Activity Sponsoring Customer. The Sponsored Digital Activity Entity may be approved at the sole discretion of the Corporation to participate in Digital Activity pursuant to a Digital Activity Agreement or other agreement with the Corporation. Sponsored Merchant A merchant that, pursuant to an agreement with a Payment Facilitator, is authorized to accept Cards when properly presented. A Sponsored Merchant is also referred to as a Submerchant. Sponsored Merchant Agreement An agreement between a Sponsored Merchant and a Payment Facilitator that sets forth the terms pursuant to which the Sponsored Merchant is authorized to accept Cards. A Sponsored Merchant Agreement is also referred to as a Submerchant Agreement. Definitions Sponsor, Sponsorship Security Rules and Procedures—Merchant Edition • 1 August 2023 Staged Digital Wallet Functionality that can be used at more than one retailer, and by which the Staged Digital Wallet Operator effects a two-stage payment to a retailer to complete a purchase initiated by a Cardholder. The following may occur in either order:
  • Payment stage—In the payment stage, the Staged DWO pays the retailer by means of: – A proprietary non-Mastercard method (and not with a Mastercard Card); or – A funds transfer to an account held by the Staged DWO for or on behalf of the retailer.
  • Funding stage—In the funding stage, the Staged DWO uses a Mastercard or Maestro Account provided to the Staged DWO by the Cardholder (herein, the “funding account”) to perform a transaction that funds or reimburses the Staged Digital Wallet. The retailer does not receive Mastercard or Maestro Account data or other information identifying the network brand and payment card issuer for the funding account. Staged Digital Wallet Operator (DWO) A registered Service Provider that operates a Staged Digital Wallet. Standards The organizational documents, operating rules, regulations, policies, and procedures of the Corporation, including but not limited to any manuals, guides, announcements or bulletins, as may be amended from time to time. Stand-In Parameters A set of authorization requirements established by the Corporation or the Issuer that are accessed by the Interchange System using the Stand-In Processing Service to determine the appropriate responses to authorization requests. Stand-In Processing Service A service offered by the Corporation in which the Interchange System authorizes or declines Transactions on behalf of and uses Stand-In Parameters provided by the Issuer (or in some cases, by the Corporation). The Stand-In Processing Service responds only when the Issuer is unavailable, the Transaction cannot be delivered to the Issuer, or the Issuer exceeds the response time parameters set by the Corporation. Definitions Staged Digital Wallet Security Rules and Procedures—Merchant Edition • 1 August 2023 Strong Customer Authentication (SCA) Authentication as required by the 2nd Payment Services Directive (Directive [EU] 2015/2366 of 25 November 2015) Regulatory Technical Standards on Strong Customer Authentication (as amended and replaced from time to time). Sub-licensee A person authorized in writing to use a Mark either by a Licensee in accordance with the Standards or by the Corporation. Terminal Any attended or unattended device capable of the electronic capture and exchange of Account data that meets the Corporation requirements for Terminal eligibility, functionality, and security, and permits a Cardholder to effect a Transaction in accordance with the Standards. An ATM Terminal, Bank Branch Terminal, and POS Terminal is each a type of Terminal. Third Party Processor (TPP) A Service Provider that performs TPP Program Service. Token A numeric value that (i) is a surrogate for the primary account number (PAN) used by a payment card issuer to identify a payment card account or is a surrogate for the PTA Account Number used by a PTA Customer to identify a PTA Account; (ii) is issued in compliance with the EMV Payment Tokenization Specification Technical Framework; and (iii) passes the basic validation rules for a PAN, including the Luhn Formula for Computing Modulus 10 Check Digit. Also see Mastercard Token. Tokenization, Tokenize The process by which a Mastercard Token replaces an Account PAN or a PTA Account Number. Token Requestor An entity that requests the replacement of Account PANs with Mastercard Tokens. Definitions Strong Customer Authentication (SCA) Security Rules and Procedures—Merchant Edition • 1 August 2023 Token Vault A repository of tokens that are implemented by a tokenization system, which may also perform primary account number (PAN) mapping and cryptography validation. Transaction A financial transaction arising from the proper acceptance of a Card or Account bearing or identified with one or more of the Brand Marks, either alone or in combination with the marks of another payment scheme, at a Card acceptance location and identified in messages with a Card Program identifier. Transaction Data Any data and/or data element or subelement that the Standards and/or the Corporation’s interface specifications require to be used to initiate, authorize, clear, and/or settle a Transaction or PTA Transaction (whether authorized, cleared, and/or settled via the Interchange System or otherwise) or that the Corporation requires to be provided. Transaction Management System Performs Transaction management services for Mastercard Cloud-Based Payments, which may include credential authentication, application cryptogram mapping and validation, ensuring synchronization with the Credentials Management System, and forwarding of Transactions to the Issuer for authorization. Trusted Service Manager Provisions an Access Device with the Payment Application, personalization data, or post- issuance application management commands by means of an over-the-air (OTA) communication channel. Virtual Account A Mastercard Account issued without a physical Card or Access Device. A Virtual Account cannot be electronically read. Definitions Token Vault Security Rules and Procedures—Merchant Edition • 1 August 2023 Volume The aggregate financial value of a group of Transactions. “Volume” does not mean the number of Transactions. Wallet Token Requestor A Wallet Token Requestor is a Pass-through DWO that connects directly to the Mastercard Digital Enablement Service (MDES) for the purpose of Tokenizing a Mastercard or Maestro Account primary account number (PAN) provided by a Cardholder for use in a future Transaction. Word Mark A Mark consisting of the name of one of the Corporation’s brands followed by a registered trademark ® or ™ symbol (depending on its trademark status in a particular country) or the local law equivalent. See Cirrus Word Mark, Maestro Word Mark, Mastercard Word Mark. Definitions Volume Security Rules and Procedures—Merchant Edition • 1 August 2023 Notices Following are policies pertaining to proprietary rights, trademarks, translations, and details about the availability of additional information online. Proprietary Rights The information contained in this document is proprietary and confidential to Mastercard International Incorporated, one or more of its affiliated entities (collectively “Mastercard”), or both. This material may not be duplicated, published, or disclosed, in whole or in part, without the prior written permission of Mastercard. Trademarks Trademark notices and symbols used in this document reflect the registration status of Mastercard trademarks in the United States. Consult with the Global Customer Service team or the Mastercard Law Department for the registration status of particular product, program, or service names outside the United States. All third-party product and service names are trademarks or registered trademarks of their respective owners. EMV® is a registered trademark of EMVCo LLC in the United States and other countries. For more information, see http://www.emvco.com. Disclaimer Mastercard makes no representations or warranties of any kind, express or implied, with respect to the contents of this document. Without limitation, Mastercard specifically disclaims all representations and warranties with respect to this document and any intellectual property rights subsisting therein or any part thereof, including but not limited to any and all implied warranties of title, non-infringement, or suitability for any purpose (whether or not Mastercard has been advised, has reason to know, or is otherwise in fact aware of any information) or achievement of any particular result. Translation A translation of any Mastercard manual, bulletin, release, or other Mastercard document into a language other than English is intended solely as a convenience to Mastercard customers. Mastercard provides any translated document to its customers “AS IS” and makes no representations or warranties of any kind with respect to the translated document, including, but not limited to, its accuracy or reliability. In no event shall Mastercard be liable for any damages resulting from reliance on any translated document. The English version of any Mastercard document will take precedence over any translated version in any legal proceeding. Notices Security Rules and Procedures—Merchant Edition • 1 August 2023 Information Available Online Mastercard provides details about the standards used for this document, including times expressed, language use, and contact information, on the Technical Resource Center (TRC). Go to the Rules collection of the References section for centralized information. Notices Security Rules and Procedures—Merchant Edition • 1 August 2023
Halyard Pay · 2 files
program: ECP
- authority: Mastercard SPME §11.4, §11.5
+ authority: Mastercard SPME §11.4, §11.5, §13.1.2
chargeback_to_transaction_ratio_threshold: 0.015
min_chargeback_count: 100
program_tiers:
- standard
- excessive
tier_thresholds:
standard: 0.015
excessive: 0.030
merchant_notification_business_days: 5
monitoring_cadence: monthly
agent_owner: ecp_ops_agent
 
- # Added citation to Mastercard SPME §11.5 due to updated MATCH Listing Reason Codes.
- # Although thresholds for chargebacks remain, the updated MATCH section clarifies American Express-specific thresholds and criteria for excessive chargebacks and fraud,
- # which are relevant to this program's monitoring and notification practices. No parameter changes needed at this time.
+ # Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards.
+ # This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices.
+ # No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions.

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) identifies monitors merchants whose chargeback activity exceeds defined established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay monitors merchant chargeback-to-transaction ratios and related chargeback dollar thresholds on a tracks these metrics monthly basis and escalates merchants who meet meeting or exceed surpassing program criteria to the appropriate remediation track. into risk management processes.

Program tiers

Two tiers define the There are two escalation ladder: tiers:

  • Standard: chargeback-to-transaction ratio of 1.5% (0.015) or greater higher and at least 100 chargebacks in the a month.

  • Excessive: chargeback ratio of 3.0% (0.03) or greater in the same measurement period. for the month.

MATCH Listing criteria

In addition to ratio thresholds, merchants Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a single month exceeds 1% of Mastercard sales transactions for that month and chargebacks total at least USD 5,000 or more. 5,000. Note that American Express acquirers use their own thresholds for chargeback distinct MATCH reporting to MATCH. thresholds.

Required actions

  1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month close. month-end.

  2. Assign the merchant to the applicable appropriate tier if based on ratio thresholds are met. thresholds.

  3. Consider Evaluate MATCH reporting criteria around chargeback volume and amounts for to identify additional risk flagging. risk.

  4. Open an ECP case and notify the merchant within five business days.

  5. Track the merchant's progress on a Continuously monitor merchants' monthly basis performance until they exit the program.

  6. Escalate to chargeback agent agents for automated case management. handling.

## Data Protection and Privacy Considerations

In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.

Source authority: Mastercard SPME §§11.4, 11.5.11.5, 13.1.2.

policies/ecp_thresholds/policy.md — after applying change

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) identifies monitors merchants whose chargeback activity exceeds defined established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay monitors merchant chargeback-to-transaction ratios and related chargeback dollar thresholds on a tracks these metrics monthly basis and escalates merchants who meet meeting or exceed surpassing program criteria to the appropriate remediation track. into risk management processes.

Program tiers

Two tiers define the There are two escalation ladder: tiers:

  • Standard: chargeback-to-transaction ratio of 1.5% (0.015) or greater higher and at least 100 chargebacks in the a month.

  • Excessive: chargeback ratio of 3.0% (0.03) or greater in the same measurement period. for the month.

MATCH Listing criteria

In addition to ratio thresholds, merchants Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a single month exceeds 1% of Mastercard sales transactions for that month and chargebacks total at least USD 5,000 or more. 5,000. Note that American Express acquirers use their own thresholds for chargeback distinct MATCH reporting to MATCH. thresholds.

Required actions

  1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month close. month-end.

  2. Assign the merchant to the applicable appropriate tier if based on ratio thresholds are met. thresholds.

  3. Consider Evaluate MATCH reporting criteria around chargeback volume and amounts for to identify additional risk flagging. risk.

  4. Open an ECP case and notify the merchant within five business days.

  5. Track the merchant's progress on a Continuously monitor merchants' monthly basis performance until they exit the program.

  6. Escalate to chargeback agent agents for automated case management. handling.

## Data Protection and Privacy Considerations

In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.

Source authority: Mastercard SPME §§11.4, 11.5.11.5, 13.1.2.

Source authority: Mastercard SPME §13.1.2.

--- a/policies/ecp_thresholds/rules.yaml
+++ b/policies/ecp_thresholds/rules.yaml
@@ -1,5 +1,5 @@
 program: ECP
-authority: Mastercard SPME §11.4, §11.5
+authority: Mastercard SPME §11.4, §11.5, §13.1.2
 chargeback_to_transaction_ratio_threshold: 0.015
 min_chargeback_count: 100
 program_tiers:
@@ -12,6 +12,6 @@
 monitoring_cadence: monthly
 agent_owner: ecp_ops_agent
 
-# Added citation to Mastercard SPME §11.5 due to updated MATCH Listing Reason Codes.
-# Although thresholds for chargebacks remain, the updated MATCH section clarifies American Express-specific thresholds and criteria for excessive chargebacks and fraud,
-# which are relevant to this program's monitoring and notification practices. No parameter changes needed at this time.+# Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards.
+# This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices.
+# No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions.

--- a/policies/ecp_thresholds/policy.md
+++ b/policies/ecp_thresholds/policy.md
@@ -1,26 +1,28 @@
 # Excessive Chargeback Program (ECP) Thresholds
 
-Mastercard's Excessive Chargeback Program (ECP) identifies merchants whose chargeback
-activity exceeds defined thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay monitors merchant chargeback-to-transaction ratios and related chargeback dollar thresholds on a monthly basis and escalates merchants who meet or exceed program criteria to the appropriate remediation track.
+Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.
 
 ## Program tiers
 
-Two tiers define the escalation ladder:
-- **Standard**: chargeback-to-transaction ratio of 1.5% (0.015) or greater and at
-  least 100 chargebacks in the month.
-- **Excessive**: ratio of 3.0% (0.03) or greater in the same measurement period.
+There are two escalation tiers:
+- **Standard**: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.
+- **Excessive**: chargeback ratio of 3.0% (0.03) or greater for the month.
 
 ## MATCH Listing criteria
 
-In addition to ratio thresholds, merchants may be reported to MATCH if the number of Mastercard chargebacks in a single month exceeds 1% of Mastercard sales transactions for that month and chargebacks total at least USD 5,000 or more. American Express acquirers use their own thresholds for chargeback reporting to MATCH.
+Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a month exceeds 1% of Mastercard sales transactions and chargebacks total at least USD 5,000. Note that American Express acquirers use distinct MATCH reporting thresholds.
 
 ## Required actions
 
-1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month close.
-2. Assign the merchant to the applicable tier if ratio thresholds are met.
-3. Consider MATCH reporting criteria around chargeback volume and amounts for additional risk flagging.
+1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.
+2. Assign the merchant to the appropriate tier based on ratio thresholds.
+3. Evaluate MATCH reporting criteria to identify additional risk.
 4. Open an ECP case and notify the merchant within five business days.
-5. Track the merchant's progress on a monthly basis until they exit the program.
-6. Escalate to chargeback agent for automated case management.
+5. Continuously monitor merchants' monthly performance until they exit the program.
+6. Escalate to chargeback agents for automated case handling.
 
-Source authority: Mastercard SPME §§11.4, 11.5.+## Data Protection and Privacy Considerations
+
+In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.
+
+Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.