Mastercard SPME §1.5 · Sep 2023 → Feb 2024
Data Protection
The compliance requirements for processing personal data have been expanded to explicitly include several specific programs: the MATCH system, the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program, collectively called "Covered Programs."
program: ECP- authority: Mastercard SPME §11.4, §11.5, §13.1.2+ authority: Mastercard SPME 1.5, 1.4, 1.5, 3.1.2chargeback_to_transaction_ratio_threshold: 0.015min_chargeback_count: 100program_tiers:- standard- excessivetier_thresholds:standard: 0.015excessive: 0.030merchant_notification_business_days: 5monitoring_cadence: monthlyagent_owner: ecp_ops_agent- # Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards.- # This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices.- # No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions.+ # Authority updated to include Mastercard SPME 1.5 reflecting the expanded data protection compliance requirements for the Excessive Chargeback Program and other Covered Programs.+ # No threshold or procedural changes were made; this is a compliance citation enhancement to align with updated privacy obligations in Mastercard's rules.
Excessive Chargeback Program (ECP) Thresholds
Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.
Program tiers
There are two escalation tiers:
-
Standard: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.
-
Excessive: chargeback ratio of 3.0% (0.03) or greater for the month.
MATCH Listing criteria
Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a month exceeds 1% of Mastercard sales transactions and chargebacks total at least USD 5,000. Note that American Express acquirers use distinct MATCH reporting thresholds.
Required actions
-
Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.
-
Assign the merchant to the appropriate tier based on ratio thresholds.
-
Evaluate MATCH reporting criteria to identify additional risk.
-
Open an ECP case and notify the merchant within five business days.
-
Continuously monitor merchants' monthly performance until they exit the program.
-
Escalate to chargeback agents for automated case handling.
Data Protection and Privacy Considerations
In line accordance with Mastercard's updated data protection framework under EU policies, Halyard Pay and its customers must comply with Applicable Data Protection Law, Laws and Mastercard’s Appendix D (Covered Programs Privacy and Data Protection Standards) when processing personal data related to the Excessive Chargeback Program and other covered programs such as MATCH and the Merchant Registration Program. Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to limited access, compliance with data transfer restrictions, and facilitating timely notification and cooperation in case breach notifications to maintain the privacy and security of personal data breaches. data. Both Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. in this context, maintaining full accountability.
Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.13.1.2, 1.5.
Excessive Chargeback Program (ECP) Thresholds
Mastercard's Excessive Chargeback Program (ECP) monitors merchants whose chargeback activity exceeds established thresholds relative to monthly transaction volume and chargeback amounts. Halyard Pay tracks these metrics monthly and escalates merchants meeting or surpassing program criteria into risk management processes.
Program tiers
There are two escalation tiers:
-
Standard: chargeback-to-transaction ratio of 1.5% (0.015) or higher and at least 100 chargebacks in a month.
-
Excessive: chargeback ratio of 3.0% (0.03) or greater for the month.
MATCH Listing criteria
Merchants may also be reported to the MATCH system if the number of Mastercard chargebacks in a month exceeds 1% of Mastercard sales transactions and chargebacks total at least USD 5,000. Note that American Express acquirers use distinct MATCH reporting thresholds.
Required actions
-
Calculate each merchant's chargeback-to-transaction ratio and total chargeback amount at month-end.
-
Assign the merchant to the appropriate tier based on ratio thresholds.
-
Evaluate MATCH reporting criteria to identify additional risk.
-
Open an ECP case and notify the merchant within five business days.
-
Continuously monitor merchants' monthly performance until they exit the program.
-
Escalate to chargeback agents for automated case handling.
Data Protection and Privacy Considerations
In line accordance with Mastercard's updated data protection framework under EU policies, Halyard Pay and its customers must comply with Applicable Data Protection Law, Laws and Mastercard’s Appendix D (Covered Programs Privacy and Data Protection Standards) when processing personal data related to the Excessive Chargeback Program and other covered programs such as MATCH and the Merchant Registration Program. Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to limited access, compliance with data transfer restrictions, and facilitating timely notification and cooperation in case breach notifications to maintain the privacy and security of personal data breaches. data. Both Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. in this context, maintaining full accountability.
Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.13.1.2, 1.5.
Source authority: Mastercard SPME §1.5.
--- a/policies/ecp_thresholds/rules.yaml +++ b/policies/ecp_thresholds/rules.yaml @@ -1,5 +1,5 @@ program: ECP -authority: Mastercard SPME §11.4, §11.5, §13.1.2 +authority: Mastercard SPME 1.5, 1.4, 1.5, 3.1.2 chargeback_to_transaction_ratio_threshold: 0.015 min_chargeback_count: 100 program_tiers: @@ -12,6 +12,5 @@ monitoring_cadence: monthly agent_owner: ecp_ops_agent -# Updated authority citation to include Mastercard SPME §13.1.2, reflecting the revised Covered Programs Privacy and Data Protection Standards. -# This update acknowledges enhanced requirements related to Processing of Personal Data under EU Data Protection Law impacting the Excessive Chargeback Program's monitoring and notification practices. -# No changes to thresholds or other parameters were necessary at this time, as the program continues to adhere to existing ECP chargeback criteria while incorporating heightened privacy provisions. +# Authority updated to include Mastercard SPME 1.5 reflecting the expanded data protection compliance requirements for the Excessive Chargeback Program and other Covered Programs. +# No threshold or procedural changes were made; this is a compliance citation enhancement to align with updated privacy obligations in Mastercard's rules. --- a/policies/ecp_thresholds/policy.md +++ b/policies/ecp_thresholds/policy.md @@ -23,6 +23,6 @@ ## Data Protection and Privacy Considerations -In line with Mastercard's updated data protection framework under EU Data Protection Law, Halyard Pay ensures that all processing of personal data involved in the ECP complies with enhanced privacy and security requirements. This includes limiting data access, applying robust safeguards, adhering to data transfer restrictions, and facilitating timely notification and cooperation in case of personal data breaches. Halyard Pay and its customers act as independent controllers of personal data related to the ECP and maintain transparent accountability mechanisms to meet these obligations. +In accordance with Mastercard's updated policies, Halyard Pay and its customers must comply with Applicable Data Protection Laws and Mastercard’s Appendix D (Covered Programs Privacy and Data Protection Standards) when processing personal data related to the Excessive Chargeback Program and other covered programs such as MATCH and the Merchant Registration Program. Halyard Pay ensures robust safeguards, limited access, compliance with data transfer restrictions, and timely breach notifications to maintain the privacy and security of personal data. Both Halyard Pay and its customers act as independent controllers of data in this context, maintaining full accountability. -Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2.+Source authority: Mastercard SPME §§11.4, 11.5, 13.1.2, 1.5.