Mastercard SPME §1.5 · Sep 2023 → Feb 2024

Data Protection

substantive

The compliance requirements for processing personal data have been expanded to explicitly include several specific programs: the MATCH system, the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program, collectively called "Covered Programs."

Sources Mastercard SPME · Sep 2023 · page 12 PDF Mastercard SPME · Feb 2024 · page 12 PDF ECP Thresholds current
Also in §1.x this release substantive §1.5.1 Compliance with Privacy, Data Protection and Information Security Requirements
Why these edits? The expansion of data protection requirements now explicitly includes the Excessive Chargeback Program, requiring updates to ensure compliance with data processing standards for this program.
Mastercard SPME §1.5
In addition to Rule 3.13 of the Mastercard Rules, the Corporation and each Customer must comply with (1) Applicable Data Protection Law and (2) Appendix D (Covered Programs Privacy and Data Protection Standards), in each case when Processing Personal Data in the context of Activity related to Account Data Compromise events, Mastercard Alert to Control High-risk Customer Obligations(Merchants) (MATCH™) system, the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program (collectively a “Covered Program”).
Halyard Pay · 2 files
program: ECP
- authority: Mastercard SPME §11.4, §11.5, §13.1.2
+ authority: Mastercard SPME 1.5, 1.4, 1.5, 3.1.2
chargeback_to_transaction_ratio_threshold: 0.015
min_chargeback_count: 100
program_tiers:
- standard
- excessive
tier_thresholds:
standard: 0.015
excessive: 0.030
merchant_notification_business_days: 5
monitoring_cadence: monthly
agent_owner: ecp_ops_agent
 
- # Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards.
- # This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices.
- # No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions.
+ # Authority updated to include Mastercard SPME 1.5 reflecting the expanded data protection compliance requirements for the Excessive Chargeback Program and other Covered Programs.
+ # No threshold or procedural changes were made; this is a compliance citation enhancement to align with updated privacy obligations in Mastercard's rules.

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers:

  • Standard: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.

  • Excessive: chargeback ratio of 3.0% (0.03) or greater for the month.

MATCH Listing criteria

Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a month exceeds 1% of Mastercard sales transactions and chargebacks total at least USD 5,000. Note that American Express acquirers use distinct MATCH reporting thresholds.

Required actions

  1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.

  2. Assign the merchant to the appropriate tier based on ratio thresholds.

  3. Evaluate MATCH reporting criteria to identify additional risk.

  4. Open an ECP case and notify the merchant within five business days.

  5. Continuously monitor merchants' monthly performance until they exit the program.

  6. Escalate to chargeback agents for automated case handling.

Data Protection and Privacy Considerations

In line accordance with Mastercard's updated data protection framework under EU policies, Halyard Pay and its customers must comply with Applicable Data Protection Law, Laws and Mastercard’s Appendix D (Covered Programs Privacy and Data Protection Standards) when processing personal data related to the Excessive Chargeback Program and other covered programs such as MATCH and the Merchant Registration Program. Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to limited access, compliance with data transfer restrictions, and facilitating timely notification and cooperation in case breach notifications to maintain the privacy and security of personal data breaches. data. Both Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. in this context, maintaining full accountability.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.13.1.2, 1.5.

policies/ecp_thresholds/policy.md — after applying change

Excessive Chargeback Program (ECP) Thresholds

Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.

Program tiers

There are two escalation tiers:

  • Standard: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.

  • Excessive: chargeback ratio of 3.0% (0.03) or greater for the month.

MATCH Listing criteria

Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a month exceeds 1% of Mastercard sales transactions and chargebacks total at least USD 5,000. Note that American Express acquirers use distinct MATCH reporting thresholds.

Required actions

  1. Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.

  2. Assign the merchant to the appropriate tier based on ratio thresholds.

  3. Evaluate MATCH reporting criteria to identify additional risk.

  4. Open an ECP case and notify the merchant within five business days.

  5. Continuously monitor merchants' monthly performance until they exit the program.

  6. Escalate to chargeback agents for automated case handling.

Data Protection and Privacy Considerations

In line accordance with Mastercard's updated data protection framework under EU policies, Halyard Pay and its customers must comply with Applicable Data Protection Law, Laws and Mastercard’s Appendix D (Covered Programs Privacy and Data Protection Standards) when processing personal data related to the Excessive Chargeback Program and other covered programs such as MATCH and the Merchant Registration Program. Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to limited access, compliance with data transfer restrictions, and facilitating timely notification and cooperation in case breach notifications to maintain the privacy and security of personal data breaches. data. Both Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. in this context, maintaining full accountability.

Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.13.1.2, 1.5.

Source authority: Mastercard SPME §1.5.

--- a/policies/ecp_thresholds/rules.yaml
+++ b/policies/ecp_thresholds/rules.yaml
@@ -1,5 +1,5 @@
 program: ECP
-authority: Mastercard SPME §11.4, §11.5, §13.1.2
+authority: Mastercard SPME 1.5, 1.4, 1.5, 3.1.2
 chargeback_to_transaction_ratio_threshold: 0.015
 min_chargeback_count: 100
 program_tiers:
@@ -12,6 +12,5 @@
 monitoring_cadence: monthly
 agent_owner: ecp_ops_agent
 
-# Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards.
-# This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices.
-# No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions.
+# Authority updated to include Mastercard SPME 1.5 reflecting the expanded data protection compliance requirements for the Excessive Chargeback Program and other Covered Programs.
+# No threshold or procedural changes were made; this is a compliance citation enhancement to align with updated privacy obligations in Mastercard's rules.
--- a/policies/ecp_thresholds/policy.md
+++ b/policies/ecp_thresholds/policy.md
@@ -23,6 +23,6 @@
 
 ## Data Protection and Privacy Considerations
 
-In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations.
+In accordance with Mastercard's updated policies, Halyard Pay and its customers must comply with Applicable Data Protection Laws and Mastercard’s Appendix D (Covered Programs Privacy and Data Protection Standards) when processing personal data related to the Excessive Chargeback Program and other covered programs such as MATCH and the Merchant Registration Program. Halyard Pay ensures robust safeguards, limited access, compliance with data transfer restrictions, and timely breach notifications to maintain the privacy and security of personal data. Both Halyard Pay and its customers act as independent controllers of data in this context, maintaining full accountability.
 
-Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.+Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 1.5.