Mastercard SPME §10 · Sep 2024 → May 2025

Not use, or allow the use of, any type of technology or other organization measures that

substantive

The entire previous content regarding notification timelines and investigation procedures was replaced with detailed new standards about handling, processing, transferring, and securing Personal Information under CCPA and EU Data Protection laws within the MATCH Pro system, including roles, responsibilities, security measures, and breach notification protocols.

Sources Mastercard SPME · Sep 2024 · page 11 PDF Mastercard SPME · May 2025 · page 12 PDF BRAM Response current Chargeback Handling current Content Moderation current Refund Policy current
Why these edits? The updated Section 10 contains expanded data privacy and security obligations related to handling Personal Information under CCPA and EU Data Protection laws in the MATCH Pro system, which directly impacts the BRAM Investigation Response policy that cites Section 10.2.; Chargeback Handling references Sections 10.1 and 10.3, which are adjacent to and contextually connected with Section 10; the new detailed processing, security, and breach notification requirements under privacy laws could affect chargeback investigation and remediation steps.; Content Moderation cites Section 10.5, falling under the same Chapter 10 framework which now includes rigorous personal data processing mandates and breach notification protocols as per the updated Section 10, thus affecting the policy.; Refund Policy cites Section 10.4 within Chapter 10, which now has detailed privacy and personal information handling standards impacting refund processing and related data controls.
Mastercard SPME §10
This section was substantively restructured between versions (0% text overlap). Compare the texts directly below.
Before · Sep 2024 · page 11

Customer must notify Mastercard within 24 hours of the engagement of the PFI. Failure to notify Mastercard within the 24-hour time frame may result in a noncompliance assessment as described in Section 10.7. Alternatively, and provided the responsible Customer determines that Criterion C is satisfied, the responsible Customer itself may elect to investigate the Event in lieu of causing a PFI to conduct an examination of the Merchant or other Agent. Card-present (CP) Alternative Acquirer Investigations (AAIs) For CP AAIs, if the responsible Customer itself elects to conduct the investigation, not later than thirty (30) business days following the date of the notice by Mastercard described above, the responsible Customer must provide to Mastercard that all of the following are true:

  1. The responsible Customer elected to investigate the ADC Event or Potential ADC Event in lieu of causing a PFI to investigate the ADC Event or Potential ADC Event; and Account Data Compromise Events
After · May 2025 · page 12

allows the reidentification of redacted Personal Information (such as a Merchant's Social Security Number or other equivalent government registration identifiers appropriate to the Merchant's country of operation and driver's license information) in the MATCH Pro system. With respect to Corporation's Processing of California consumer Personal Information for the MATCH Pro system on behalf of an Acquirer where the Acquirer is a "Business" under CCPA, the Corporation as a Service Provider must:

  1. Use, retain, disclose, or otherwise Process Personal Information only on behalf of Acquirers and for the specific business purpose of providing and operating the MATCH Pro system and in accordance with Customer's instructions, including as described in the Agreement. The Corporation will not "sell" or "share" (as each is defined under CCPA) Personal Information and will not use, retain, disclose, or otherwise Process Personal Information outside of its direct business relationship with Acquirers or for any other business or commercial purpose except as permitted or required by the Mastercard Rules, any Standards or by applicable law. The Corporation will inform Acquirers if the Corporation determines that it is no longer able to meet its obligations under CCPA. Acquirers reserve the right to take reasonable and appropriate steps to (a) help ensure that the Corporation uses California consumer Personal Information in a manner consistent with the Acquirers' obligations under CCPA and (b) discontinue and remediate unauthorized use of Personal Information.
  2. Not combine Personal Information which it Processes on Acquirers' behalf, with Personal Information which it receives from or on behalf of another person or persons, or collects from its own interaction with individuals, provided that Corporation may combine Personal Information to perform any business purpose permitted or required under the MATCH Pro terms to perform and operate the MATCH Pro system services.
  3. Comply with all applicable sections of CCPA, including with respect to the Personal Information that it collects pursuant to the terms, providing the same level of privacy protections as required of Acquirers by the CCPA (including the applicable regulations).
  4. Provide Acquirers with reasonable assistance to enable Acquirer to comply with California consumer requests made pursuant to CCPA. Privacy and Data Protection Standards for MATCH Pro F.5 The Corporation and Customer Obligations Security Rules and Procedures—Merchant Edition • 11 February 2025
  5. Process Personal Information for the following CCPA business purposes:
    1. Helping to ensure security and integrity to the extent the use of the California consumer's Personal Information is reasonably necessary and proportionate for these purposes;
    2. Debugging to identify and repair errors that impair existing intended functionality;
    3. Performing services on behalf of the Acquirers;
    4. Undertaking internal research for technological development and demonstration;
    5. Undertaking activities to verify or maintain the quality or safety of the MATCH Pro service and to improve, upgrade, or enhance the MATCH Pro service;
    6. To retain and employ another service provider or contractor as a subcontractor where the subcontractor meets the requirements for a service provider or contractor under CCPA;
    7. To build or improve the quality of the MATCH Pro services provided that the Corporation does not use the Personal Information to perform services on behalf of another person; or
    8. To prevent, detect, or investigate data security incidents or protect against malicious, deceptive, fraudulent, or illegal activity. F.6 Data Transfers With respect to Personal Information governed by EU Data Protection Law, a Customer may transfer such Personal Information Processed in connection with MATCH Pro outside of the EEA, the UK, and Switzerland in accordance with EU Data Protection Law, including based on the EEA SCCs or the UK Addendum as appropriate. The Corporation may transfer such Personal Information Processed in connection with MATCH Pro outside of the EEA, the UK, and Switzerland in accordance with the Mastercard BCRs or with any other lawful data transfer mechanism that provides an adequate level of protection under EU Data Protection Law. The Corporation will abide by the Mastercard BCRs when Processing Personal Information in the context of MATCH Pro. A Customer must ensure that any transfers (including any cross-border transfers) of Personal Information Processed in connection with the MATCH Pro (i) comply with Applicable Data Protection Law; (ii) be in accordance with any lawful data transfer mechanism; and (iii) ensure that the Personal Information will be protected with the same level of protection as provided in context of MATCH Pro. F.7 Data Disclosures The Corporation and its Customers must ensure that they will only disclose Personal Information Processed in the context of MATCH Pro in accordance with Applicable Data Protection Law, and in particular that they will require the data recipients to protect the data with at least the same level of protection as described in this appendix. Privacy and Data Protection Standards for MATCH Pro F.6 Data Transfers Security Rules and Procedures—Merchant Edition • 11 February 2025 The Corporation represents and warrants that it will only disclose Personal Information subject to EU Data Protection Law in accordance with the Mastercard BCRs, EEA SCCs or UK Addendum, as applicable. Where the Corporation transfers Personal Information subject to the GDPR or the Swiss Data Protection Act to a Customer in a country that is not part of the EEA or subject to a European Commission adequacy decision, the Parties agree that the transfer are governed by the EEA SCCs, which are hereby incorporated into this appendix by reference. The EEA SCCs are completed as follows: the Parties conclude Module One (controller-to-controller) of the EEA SCCs. The "data exporter" is Corporation; the "data importer" is Customer; the optional docking clause in Clause 7 is implemented; the optional paragraph in Clause 11(a) is struck; the competent supervisory authority in Clause 13(a) is the supervisory authority of Belgium; the governing law in Clause 17 is the law of the Belgium and the courts in Clause 18(b) are the courts of the Belgium; Annex 1 and 2 to the EEA SCCs are Annex 1 and 2 to this appendix. The Parties conclude the UK Addendum for transfers of Personal Information subject to the UK Data Protection Act from Corporation to Customer in a country that is not subject to a UK adequacy decision. The UK Addendum is hereby incorporated into this appendix by reference. Part 1 of the UK Addendum is completed as follows: (i) in Table 1, the "Exporter" is Corporation and the "Importer" is Customer (as set out in the paragraph above), their details are set forth in the Acquirer license agreement and their signatures are included in the signature page of the Acquirer license agreement; (ii) in Table 2, the first option is selected and the "Approved EU SCCs" are those incorporated into this appendix as per the paragraph above; (iii) in Table 3, Annexes 1 and 2 to the Approved EU SCCs are Annexes 1 and 2 to this appendix respectively; and (iv) in Table 4, both the "Importer" and the "Exporter" can terminate the UK Addendum. If either Party's compliance with EU Data Protection Law applicable to transfers of Personal Information is affected by circumstances outside of either Party's control, including if a legal instrument for transfers is invalidated, amended, or replaced, then the Parties will work together in good faith to reasonably resolve such noncompliance. F.8 Security Measures The Corporation and its Customers must implement and maintain a comprehensive written information security program with appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which includes, at a minimum, as appropriate: (1) the pseudonymization and encryption of Personal Information; (2) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; (3) the ability to restore the availability and access to Personal Information in a timely manner in the event of a physical or technical incident; and (4) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing. In assessing the appropriate level of security, the Corporation and its Customers must take into account the state of the art; the costs of implementation; and the nature, scope, context, and purposes of Processing of Personal Information; as well as the risk of varying likelihood and Privacy and Data Protection Standards for MATCH Pro F.8 Security Measures Security Rules and Procedures—Merchant Edition • 11 February 2025 severity for the rights and freedoms of Individuals and the risks that are presented by the Processing of Personal Information, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Information transmitted, stored, or otherwise Processed. F.9 Confidentiality of Personal Information The Corporation and its Customers must take steps to ensure that any person acting under their authority who has access to Personal Information is subject to a duly enforceable contractual or statutory confidentiality obligation, and if applicable, Process Personal Information in accordance with the disclosing party's instructions. F.10 Personal Information Breach Notification Requirements The Parties will assist each other in complying with their Personal Information Breach notification obligations. Where required under Applicable Data Protection Law, the Party which became aware of a Personal Information Breach will notify, without undue delay and, where feasible, not later than 72 hours after having become aware of it, the competent supervisory authority. When the Personal Information Breach is likely to result in a high risk to the rights and freedoms of Individuals or upon the competent supervisory authority’s request to do so, or where such notification is required by Applicable Data Protection Law, such Party must communicate the Personal Information Breach to the Individual without undue delay. F.11 Personal Information Breach Cooperation and Documentation Requirements Each Party must notify the other Party of a Personal Information Breach that relates to Personal Information Processed in the context of MATCH Pro and for which the other Party is a Controller, Business, or Service Provider, without undue delay, and not later than forty-eight (48) hours after having become aware of a Personal Information Breach. Each Party must document all Personal Information Breaches, including the facts relating to the Personal Information Breach, its effects, and the remedial action taken. F.12 Data Protection and Security Audit The Corporation and each Customer must conduct audits on a regular basis to control compliance with Applicable Data Protection Law, including the security measures provided in Section F.8, and the Corporation must comply with the Mastercard BCRs. Privacy and Data Protection Standards for MATCH Pro F.9 Confidentiality of Personal Information Security Rules and Procedures—Merchant Edition • 11 February 2025 Upon prior written request, the Corporation and each Customer agrees to cooperate and, within reasonable time, provide the requesting Party with: (1) a summary of the audit reports demonstrating its compliance with Applicable Data Protection Law obligations and the Standards in this appendix, and as applicable Mastercard BCRs, after redacting any confidential and commercially sensitive information; and (2) confirmation that the audit has not revealed any material vulnerability, or to the extent that any vulnerability was detected, that such vulnerability has been fully remedied. F.13 Liability Subject to the liability clauses in the Standards, the Corporation and each Customer agrees that it will be liable towards Individuals for the entire damage resulting from a violation of Applicable Data Protection Law with regard to Processing of Personal Information for which it is a Controller. Where the Parties are involved in the same Processing and where they are responsible for any damage caused by the Processing of Personal Information, both the Corporation and each responsible Customer may be held liable for the entire damage in order to ensure effective compensation of the Individual. If the Corporation paid full compensation for the damage suffered, the Corporation is entitled to claim back from the Customer(s) that part of the compensation corresponding to each Customer's part of responsibility for the damage. F.14 Termination of MATCH Pro The Corporation and its Customers agree that, apart from the data retention obligation in Section F.5, Paragraph 9, the Standards in this appendix are no longer applicable to a Customer upon the termination of such Customer's use of MATCH Pro. F.15 Invalidity and Severability If any Standard in this appendix is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such Standard does not affect any other Standard in this appendix, and all Standards not affected by such invalidity or unenforceability will remain in full force and effect. Privacy and Data Protection Standards for MATCH Pro F.13 Liability Security Rules and Procedures—Merchant Edition • 11 February 2025 Annex 1 to Appendix F: Processing of Personal Data A. List of Parties
  6. Data exporter: The Corporation – Name and address of the Corporation as well as the name, position, and contact details for the Corporation's contact person: as stipulated in the Acquirer License agreement. – Activities relevant to the data transferred: Providing MATCH Pro – Signature and date: as stipulated in the Acquirer License agreement – Role: controller for the purposes listed in Section F.4 of Appendix F
  7. Data importer: The Customer – Name and address of the Customer as well as the name, position, and contact details for Customer's contact person: as stipulated in the Acquirer License agreement – Activities relevant to the data transferred: participating in, or benefiting from MATCH Pro – Signature and date: as stipulated in the Acquirer License agreement – Role: controller for the purposes listed in Section F.4 of Appendix F B. Description of the Transfer Data Subjects Data Subjects as defined in Appendix E. Categories of data Personal Data relating to a Merchant's principal owners or sole proprietors. Frequency of the transfer Upon Customer's requests, such as on a per query basis or via batch file transfer. Nature of the Processing Collection, storage, analysis, disclosure by transfer or otherwise making available. Purposes of the transfer(s) The transfer is made for the purposes set forth in Section F.4 of Appendix F. Period for which the Personal Data will be retained Personal Data will be retained only for as long as necessary to achieve the relevant purposes of MATCH Pro. C. Competent Supervisory Authority The competent supervisory authority in accordance with Clause 13 of the EEA SCCs is the Belgian Data Protection Authority. Privacy and Data Protection Standards for MATCH Pro Annex 1 to Appendix F: Processing of Personal Data Security Rules and Procedures—Merchant Edition • 11 February 2025 Annex 2 to Appendix F: Technical and Organizational Measures Ensure the Security of the Data The Parties will, as a minimum, implement the following types of security measures:
  8. Physical access control Technical and organizational measures to prevent unauthorized persons from gaining access to the data processing systems available in premises and facilities (including databases, application servers and related hardware), where Personal Data are processed, include: – Establishing security areas, restriction of access paths; – Establishing access authorizations for employees and third parties; – Access control system (ID reader, magnetic card, chip card); – Key management, card-keys procedures; – Door locking (electric door openers, etc.); – Security staff, janitors; – Surveillance facilities, video/CCTV monitor, alarm system; and – Securing decentralized data processing equipment and personal computers.
  9. Virtual access control Technical and organizational measures to prevent data processing systems from being used by unauthorized persons include: – User identification and authentication procedures; – ID/password security procedures (special characters, minimum length, change of password); – Automatic blocking (e.g., password or timeout); – Monitoring of break-in-attempts and automatic turn-off of the user ID upon several erroneous passwords attempts; and – Creation of one master record per user, user master data procedures, per data processing environment.
  10. Data access control Technical and organizational measures to ensure that persons entitled to use a data processing system gain access only to such Personal Data in accordance with their access rights, and that Personal Data cannot be read, copied, modified or deleted without authorization, include: – Internal policies and procedures; – Control authorization schemes; – Differentiated access rights (profiles, roles, transactions and objects); – Monitoring and logging of accesses; – Disciplinary action against employees who access Personal Data without authorization; – Reports of access; – Access procedure; Privacy and Data Protection Standards for MATCH Pro Annex 2 to Appendix F: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 11 February 2025 – Change procedure; and – Deletion procedure.
  11. Disclosure control Technical and organizational measures to ensure that Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic), and that it can be verified to which companies or other legal entities Personal Data are disclosed, include: – Tunneling; – Logging; and – Transport security.
  12. Entry control Technical and organizational measures to monitor whether data have been entered, changed or removed (deleted), and by whom, from data processing systems, include: – Logging and reporting systems; and – Audit trails and documentation.
  13. Control of instructions Technical and organizational measures to ensure that Personal Data are processed solely in accordance with the Instructions of the Controller include: – Unambiguous wording of the contract; – Formal commissioning (request form); and – Criteria for selecting the Processor.
  14. Availability control Technical and organizational measures to ensure that Personal Data are protected against accidental destruction or loss (physical/logical) include: – Backup procedures; – Mirroring of hard disks (e.g., RAID technology); – Uninterruptible power supply (UPS); – Remote storage; – Anti-virus/firewall systems; and – Disaster recovery plan.
  15. Separation control Technical and organizational measures to ensure that Personal Data collected for different purposes can be processed separately include: – Separation of databases; – "Internal client" concept/limitation of use; – Segregation of functions (production/testing); and – Procedures for storage, amendment, deletion, transmission of data for different purposes. Privacy and Data Protection Standards for MATCH Pro Annex 2 to Appendix F: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 11 February 2025 Notices Following are policies pertaining to proprietary rights, trademarks, translations, and details about the availability of additional information online. Proprietary Rights The information contained in this document is proprietary and confidential to Mastercard International Incorporated, one or more of its affiliated entities (collectively “Mastercard”), or both. This material may not be duplicated, published, or disclosed, in whole or in part, without the prior written permission of Mastercard. Trademarks Trademark notices and symbols used in this document reflect the registration status of Mastercard trademarks in the United States. Consult with the Global Customer Service team or the Mastercard Law Department for the registration status of particular product, program, or service names outside the United States. All third-party product and service names are trademarks or registered trademarks of their respective owners. EMV® is a registered trademark of EMVCo LLC in the United States and other countries. For more information, see http://www.emvco.com. Disclaimer Mastercard makes no representations or warranties of any kind, express or implied, with respect to the contents of this document. Without limitation, Mastercard specifically disclaims all representations and warranties with respect to this document and any intellectual property rights subsisting therein or any part thereof, including but not limited to any and all implied warranties of title, non-infringement, or suitability for any purpose (whether or not Mastercard has been advised, has reason to know, or is otherwise in fact aware of any information) or achievement of any particular result. Translation A translation of any Mastercard manual, bulletin, release, or other Mastercard document into a language other than English is intended solely as a convenience to Mastercard customers. Mastercard provides any translated document to its customers “AS IS” and makes no representations or warranties of any kind with respect to the translated document, including, but not limited to, its accuracy or reliability. In no event shall Mastercard be liable for any damages resulting from reliance on any translated document. The English version of any Mastercard document will take precedence over any translated version in any legal proceeding. Notices Security Rules and Procedures—Merchant Edition • 11 February 2025 Information Available Online Mastercard provides details about the standards used for this document, including times expressed, language use, and contact information, on the Technical Resource Center (TRC). Go to the Rules collection of the References section for centralized information. Notices Security Rules and Procedures—Merchant Edition • 11 February 2025
Halyard Pay · 7 files
program: BRAM
authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12
response_window_days: 180
required_evidence:
- transaction_monitoring_records
- corrective_action_plan
- police_report # Mandatory inclusion per updated SPME 8.6.2
halt_actions:
- halt_new_merchant_onboarding
internal_notification_hours: 24
agent_owner: bram_response_agent
 
- # Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
- # Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
- # Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
- # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
+ # Updated policy clarifies the incorporation of enhanced privacy and data protection requirements from Mastercard SPME §10.2, including obligations under CCPA and EU data protection laws related to the MATCH Pro system.
+ # These requirements affect evidence handling and procedural safeguards during BRAM investigations involving Personal Information.
+ # Retains existing processes for police report submission and investigation timeframes with allowance for Mastercard granted extensions.
+ # Emphasizes compliance with applicable privacy, security, and data handling laws as mandated by Mastercard standards.

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.

## Data Privacy and Security Considerations

Given the updates to Mastercard SPME Section 10, acquirers must ensure compliance with enhanced data confidentiality and handling obligations, especially regarding Personal Information processed in systems such as MATCH Pro. This includes adherence to applicable data protection laws like CCPA and EU Data Protection Law, ensuring Personal Information is used solely for authorized purposes, with proper security measures, and that any disclosures or transfers meet legal and Mastercard policy requirements. The acquirer must collaborate with relevant parties to maintain these standards throughout the BRAM investigation process.

Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.

Source authority: Mastercard SPME �8.6.2, �10.2, §§3.9, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.and 12.0.

program: Chargeback Handling
- authority: Mastercard SPME §10.1, §10.3, §10.4, §10.7, and §11.5
+ authority: Mastercard SPME 710.1, 710.3, 710.4, 710.7, 711.5
acknowledgement_business_days: 1
lifecycle_states:
- first_presentment
- chargeback
- second_presentment
- pre_arbitration
- arbitration
evidence_requirements:
first_presentment:
- transaction_receipt
- authorization_record
chargeback:
- merchant_rebuttal_letter
- delivery_confirmation
- customer_communication
- fraud_and_chargeback_data_analysis
second_presentment:
- compelling_evidence
- signed_cardholder_agreement
pre_arbitration:
- full_dispute_record
- prior_correspondence
arbitration:
- full_dispute_record
- arbitration_filing
agent_owner: chargeback_agent
 
- # Incorporated new appeal process details for Account Data Compromise events from Mastercard SPME §10.7,
- # emphasizing the 30-day appeal window, documentation requirements, non-refundable fee, and finality of appeal decisions.
- # This update aligns chargeback handling procedures with recent clarifications regarding financial responsibility appeals,
- # supplementing existing rules per Mastercard SPME §§10.1, 10.3, 10.4, and 11.5.
+ # Updated to incorporate privacy and data protection directives described in Mastercard SPME 710 affecting processing
+ # and handling of chargeback-related information, including obligations for data security, purpose limitations,
+ # and compliance with applicable privacy laws (such as CCPA and GDPR), ensuring that Personal Information
+ # collected and used during chargeback investigations is managed according to these standards,
+ # aligning chargeback handling with both dispute resolution and privacy obligations within Mastercard's framework.

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved.

Lifecycle overview

Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.

Required actions

  1. Acknowledge incoming chargebacks within one business day.

  2. Gather necessary evidence relevant to the dispute stage.

  3. Submit second presentments when liability is disputable, supported by strong documentation.

  4. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.

  5. Retain comprehensive case documentation for auditing and reporting purposes.

  6. Provide all requested documentation promptly to Mastercard during investigations, appeals, and financial responsibility determinations as governed by sections 10.3, 10.4, and updated appeals procedures related to Account Data Compromise Events in section 10.7 of the Mastercard SPME.

Privacy and Data Protection Considerations

In alignment with the enhanced privacy and data protection mandates introduced in recent Mastercard SPME updates, Halyard Pay ensures the protection of Personal Information involved in chargeback investigations. This includes compliance with applicable data protection laws such as the California Consumer Privacy Act (CCPA) and the EU General Data Protection Regulation (GDPR), particularly when processing sensitive merchant or cardholder information during disputes.

Halyard Pay and its third-party service providers handling chargeback-related Personal Information commit to:

- Using and processing data solely for dispute management purposes as authorized by Mastercard.

- Maintaining confidentiality and prohibiting unauthorized sharing or sales of Personal Information.

- Implementing robust technical and organizational security controls to mitigate risks related to data breaches.

- Assisting affected parties in accordance with legal rights under applicable privacy regulations.

- Ensuring any cross-border data transfers comply with lawful mechanisms that preserve data protection standards.

These obligations complement the chargeback handling steps described above and reinforce Halyard Pay's commitment to responsible and compliant dispute management.

## Monitoring and Risk Factors

Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:

  • Laundering: Merchant presenting invalid transaction records rather than bona fide sales.

  • Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.

  • Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.

These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.

Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.7, 11.5.

program: Content Moderation (BRAM)
- authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1
+ authority: Mastercard SPME §10 (updated data processing and notification requirements), §9.4.1, and §8.9.1
prohibited_categories:
- counterfeit_goods
- illegal_drugs
- adult_content_violations
- intellectual_property_violations
- gambling_in_restricted_jurisdictions
review_cadence: weekly
human_review_trigger_business_days: 1
confirmed_violation_action: suspend_processing
case_documentation_required: true
agent_owner: content_mod_agent
 
- # Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
- # Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
- # Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
- # These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
- # Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.
+ # Updated SPME §10 now includes comprehensive personal data processing and breach notification obligations impacting content moderation under Brand Risk and Anti-Money Laundering (BRAM) considerations.
+ # This policy reflects the requirement that Merchant and Acquirer controls must align with these enhanced data privacy standards, including timely notification of engaging investigative entities and safeguarding of personal information related to content issues.
+ # Strengthened accountability mandates in §10 require procedural updates in Content Moderation to ensure compliance with these data protection and incident response protocols under Mastercard’s framework.

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.

  6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.

Acquirer and MMSP Cooperation Requirements

Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.

## Enhanced Data Processing and Notification Requirements

Recent updates to Mastercard SPME Section 10 introduce strengthened data privacy and security obligations relevant to BRAM investigations, including rigorous personal data processing standards, breach notification protocols, and compliance with applicable data protection laws such as CCPA and GDPR. Halyard Pay integrates these mandates to ensure that any processing of merchant personal information during investigations adheres to these enhanced privacy and security requirements, maintaining confidentiality and data integrity.

Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.

The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.10.5, 10.

Refund Policy

Merchants processing transactions on the Mastercard network must maintain and honor a clearly defined refund policy. Halyard Pay requires merchants to process refunds within 30 days of a valid refund request and notify cardholders when refunds are initiated or declined.

When this policy applies

This policy applies to all transaction types where a cardholder requests a refund directly from the merchant, distinct from chargeback disputes initiated through the card network. Merchants must not require cardholders to return goods before issuing a refund when goods are non-returnable by nature.

Required actions

  1. Accept refund requests within 30 days following the original transaction.

  2. Partial refunds are permissible where a portion of the goods or services is non-defective.

  3. Notify cardholders in writing (email or in-app notification) when refunds are processed or declined.

  4. Retain refund transaction records for a minimum of 18 months. months, ensuring that all personal information involved complies with applicable data privacy requirements.

  5. Submit to Mastercard ongoing When submitting documentation as required during investigations related to refunds or financial responsibility determinations, per investigations, ensure compliance with all mandatory data protection standards, including those concerning the processing and handling of personal information as specified by Mastercard SPME sections 10.3 and 10.4. §10.4.

Merchants must cooperate fully with Mastercard’s investigation process, including the retention and prompt timely provision of all forensic or investigative reports related to disputes or refund incidents upon request. Merchants should be aware that investigations informed by as required. Merchants shall adhere to Mastercard’s privacy and security requirements when handling personal data during these reports may affect financial responsibility determinations. processes.

Appeals must be timely, specify the basis for contention, and adhere to Mastercard’s standards; a non-refundable USD 500 fee applies to review appeals.

Source authority: Mastercard SPME §10.4 and §10.7.

policies/bram_response/policy.md — after applying change

BRAM Investigation Response

When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation

notice for one of our merchants, the acquirer must halt new merchant onboarding

immediately and submit an evidence package within one hundred eighty (180) days

of receipt of the notice.

Required actions

  1. Halt new merchant onboarding for the merchant under investigation.

  2. Compile and submit an evidence package containing:

  • Transaction monitoring records covering the prior 180 days.

  • A written corrective action plan.

  • Documentation of any police reports related to alleged coercion claims if applicable.

  1. Notify the Halyard Pay Compliance lead within 24 hours of receipt.

Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.

Additional Considerations for Coercion Claims

When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day

investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.

## Data Privacy and Security Considerations

Given the updates to Mastercard SPME Section 10, acquirers must ensure compliance with enhanced data confidentiality and handling obligations, especially regarding Personal Information processed in systems such as MATCH Pro. This includes adherence to applicable data protection laws like CCPA and EU Data Protection Law, ensuring Personal Information is used solely for authorized purposes, with proper security measures, and that any disclosures or transfers meet legal and Mastercard policy requirements. The acquirer must collaborate with relevant parties to maintain these standards throughout the BRAM investigation process.

Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations

Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.

Source authority: Mastercard SPME �8.6.2, �10.2, §§3.9, 8.6.2, 10.2, 10.7, 12.0, and section 3.9.and 12.0.

policies/chargeback_handling/policy.md — after applying change

Chargeback Handling

Chargebacks are cardholder-initiated disputes against a transaction. Halyard Pay, acting as the acquirer, manages disputes from initial presentment through potential arbitration, adhering to Mastercard's requirements to protect all parties involved.

Lifecycle overview

Disputes progress through defined phases: first presentment, chargeback, second presentment (re-presentment), pre-arbitration, and arbitration. Compliance with evidence standards and timelines at each step is essential to prevent adverse rulings.

Required actions

  1. Acknowledge incoming chargebacks within one business day.

  2. Gather necessary evidence relevant to the dispute stage.

  3. Submit second presentments when liability is disputable, supported by strong documentation.

  4. Escalate to pre-arbitration and arbitration only after issuer rejection of second presentment.

  5. Retain comprehensive case documentation for auditing and reporting purposes.

  6. Provide all requested documentation promptly to Mastercard during investigations, appeals, and financial responsibility determinations as governed by sections 10.3, 10.4, and updated appeals procedures related to Account Data Compromise Events in section 10.7 of the Mastercard SPME.

Privacy and Data Protection Considerations

In alignment with the enhanced privacy and data protection mandates introduced in recent Mastercard SPME updates, Halyard Pay ensures the protection of Personal Information involved in chargeback investigations. This includes compliance with applicable data protection laws such as the California Consumer Privacy Act (CCPA) and the EU General Data Protection Regulation (GDPR), particularly when processing sensitive merchant or cardholder information during disputes.

Halyard Pay and its third-party service providers handling chargeback-related Personal Information commit to:

- Using and processing data solely for dispute management purposes as authorized by Mastercard.

- Maintaining confidentiality and prohibiting unauthorized sharing or sales of Personal Information.

- Implementing robust technical and organizational security controls to mitigate risks related to data breaches.

- Assisting affected parties in accordance with legal rights under applicable privacy regulations.

- Ensuring any cross-border data transfers comply with lawful mechanisms that preserve data protection standards.

These obligations complement the chargeback handling steps described above and reinforce Halyard Pay's commitment to responsible and compliant dispute management.

## Monitoring and Risk Factors

Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:

  • Laundering: Merchant presenting invalid transaction records rather than bona fide sales.

  • Excessive Chargebacks: Monthly Mastercard chargebacks exceed 1% of sales transactions with total chargebacks ≥ USD 5,000.

  • Excessive Fraud: Fraud-to-sales ratio of 8% or more, with at least 10 fraudulent transactions totaling USD 5,000+ in a calendar month.

These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.

Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.7, 11.5.

policies/content_moderation/policy.md — after applying change

Content Moderation (BRAM Brand Integrity)

Mastercard's Business Risk Assessment and Mitigation (BRAM) program prohibits acquirers from processing transactions for merchants engaged in activities violating Mastercard's acceptable use standards. Halyard Pay monitors merchant storefront content and transaction data to identify and remediate prohibited content such as adult content and content violating applicable laws or Mastercard standards.

Prohibited categories

Merchants facilitating counterfeit goods, illegal drugs, unlawful adult content, intellectual property infringement, or gambling services in restricted jurisdictions face immediate review and possible suspension.

Required actions

  1. Review merchant storefront content weekly via automated and manual methods.

  2. Flag merchants with content in prohibited categories for human review within one business day.

  3. Suspend processing if prohibited content is confirmed.

  4. Document findings and remediation steps.

  5. Ensure merchants comply with requirements to manage flagged adult content, including timely removal upon verified complaints, monthly reporting to Acquirers on flagged content and actions taken, and appeals processes as per Mastercard SPME §9.4.1.

  6. Support Acquirers in obtaining temporary access to restricted merchant content if needed.

Acquirer and MMSP Cooperation Requirements

Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.

## Enhanced Data Processing and Notification Requirements

Recent updates to Mastercard SPME Section 10 introduce strengthened data privacy and security obligations relevant to BRAM investigations, including rigorous personal data processing standards, breach notification protocols, and compliance with applicable data protection laws such as CCPA and GDPR. Halyard Pay integrates these mandates to ensure that any processing of merchant personal information during investigations adheres to these enhanced privacy and security requirements, maintaining confidentiality and data integrity.

Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.

The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.

Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.10.5, 10.

policies/refund_policy/policy.md — after applying change

Refund Policy

Merchants processing transactions on the Mastercard network must maintain and honor a clearly defined refund policy. Halyard Pay requires merchants to process refunds within 30 days of a valid refund request and notify cardholders when refunds are initiated or declined.

When this policy applies

This policy applies to all transaction types where a cardholder requests a refund directly from the merchant, distinct from chargeback disputes initiated through the card network. Merchants must not require cardholders to return goods before issuing a refund when goods are non-returnable by nature.

Required actions

  1. Accept refund requests within 30 days following the original transaction.

  2. Partial refunds are permissible where a portion of the goods or services is non-defective.

  3. Notify cardholders in writing (email or in-app notification) when refunds are processed or declined.

  4. Retain refund transaction records for a minimum of 18 months. months, ensuring that all personal information involved complies with applicable data privacy requirements.

  5. Submit to Mastercard ongoing When submitting documentation as required during investigations related to refunds or financial responsibility determinations, per investigations, ensure compliance with all mandatory data protection standards, including those concerning the processing and handling of personal information as specified by Mastercard SPME sections 10.3 and 10.4. §10.4.

Merchants must cooperate fully with Mastercard’s investigation process, including the retention and prompt timely provision of all forensic or investigative reports related to disputes or refund incidents upon request. Merchants should be aware that investigations informed by as required. Merchants shall adhere to Mastercard’s privacy and security requirements when handling personal data during these reports may affect financial responsibility determinations. processes.

Appeals must be timely, specify the basis for contention, and adhere to Mastercard’s standards; a non-refundable USD 500 fee applies to review appeals.

Source authority: Mastercard SPME §10.4 and §10.7.

Source authority: Mastercard SPME §10.

--- a/policies/bram_response/rules.yaml
+++ b/policies/bram_response/rules.yaml
@@ -10,7 +10,7 @@
 internal_notification_hours: 24
 agent_owner: bram_response_agent
 
-# Updated to incorporate Mastercard's new appeal process and fee for contesting financial responsibility for ADC Events as detailed in SPME §10.7.
-# Clarifies that appeals must be timely, substantiated with particularized basis, and accompanied by a non-refundable fee, impacting procedural guidance for BRAM responses.
-# Maintains existing police report requirement and escalation procedures for noncompliance per SPME 8.6.2 and 12.
-# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.
+# Updated policy clarifies the incorporation of enhanced privacy and data protection requirements from Mastercard SPME §10.2, including obligations under CCPA and EU data protection laws related to the MATCH Pro system.
+# These requirements affect evidence handling and procedural safeguards during BRAM investigations involving Personal Information.
+# Retains existing processes for police report submission and investigation timeframes with allowance for Mastercard granted extensions.
+# Emphasizes compliance with applicable privacy, security, and data handling laws as mandated by Mastercard standards.

--- a/policies/bram_response/policy.md
+++ b/policies/bram_response/policy.md
@@ -19,13 +19,14 @@
 ## Additional Considerations for Coercion Claims
 
 When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
-investigation period at its discretion. At least one claim must include a police report from the Cardholder.
-Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
-though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
-merchant within the investigation period to prompt claim submissions.
+investigation period at its discretion. At least one claim must include a police report from the Cardholder. Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation, though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the merchant within the investigation period to prompt claim submissions.
+
+## Data Privacy and Security Considerations
+
+Given the updates to Mastercard SPME Section 10, acquirers must ensure compliance with enhanced data confidentiality and handling obligations, especially regarding Personal Information processed in systems such as MATCH Pro. This includes adherence to applicable data protection laws like CCPA and EU Data Protection Law, ensuring Personal Information is used solely for authorized purposes, with proper security measures, and that any disclosures or transfers meet legal and Mastercard policy requirements. The acquirer must collaborate with relevant parties to maintain these standards throughout the BRAM investigation process.
 
 ## Mastercard's Authority and Customer Appeal Rights on ADC Financial Responsibility Determinations
 
 Mastercard retains exclusive authority to determine the occurrence, scope, and financial responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including whether to consolidate related incidents. Once Mastercard notifies a responsible Customer of the financial responsibility amount, the Customer has thirty (30) calendar days to submit a written appeal with supporting documentation, specifically contending that Mastercard's determination was not according to the Standards. Mastercard charges a non-refundable USD 5,000 fee to review such appeals. Appeals that are untimely or do not meet criteria will not be considered, and Mastercard's decisions on appeals are final without further internal review. Customers remain obligated to provide ongoing information throughout the investigation and failure to submit required documentation in a timely manner may result in such documents being excluded from the appeal consideration. This process safeguards the integrity and finality of Mastercards’ ADC financial responsibility determinations.
 
-Source authority: Mastercard SPME 8.6.2, 10.2, 10.7, 12.0, and section 3.9.+Source authority: Mastercard SPME §§3.9, 8.6.2, 10.2, 10.7, and 12.0.
--- a/policies/chargeback_handling/rules.yaml
+++ b/policies/chargeback_handling/rules.yaml
@@ -1,5 +1,5 @@
 program: Chargeback Handling
-authority: Mastercard SPME §10.1, §10.3, §10.4, §10.7, and §11.5
+authority: Mastercard SPME 710.1, 710.3, 710.4, 710.7, 711.5
 acknowledgement_business_days: 1
 lifecycle_states:
   - first_presentment
@@ -27,7 +27,8 @@
     - arbitration_filing
 agent_owner: chargeback_agent
 
-# Incorporated new appeal process details for Account Data Compromise events from Mastercard SPME §10.7,
-# emphasizing the 30-day appeal window, documentation requirements, non-refundable fee, and finality of appeal decisions.
-# This update aligns chargeback handling procedures with recent clarifications regarding financial responsibility appeals,
-# supplementing existing rules per Mastercard SPME §§10.1, 10.3, 10.4, and 11.5.
+# Updated to incorporate privacy and data protection directives described in Mastercard SPME 710 affecting processing
+# and handling of chargeback-related information, including obligations for data security, purpose limitations,
+# and compliance with applicable privacy laws (such as CCPA and GDPR), ensuring that Personal Information
+# collected and used during chargeback investigations is managed according to these standards,
+# aligning chargeback handling with both dispute resolution and privacy obligations within Mastercard's framework.

--- a/policies/chargeback_handling/policy.md
+++ b/policies/chargeback_handling/policy.md
@@ -15,6 +15,20 @@
 5. Retain comprehensive case documentation for auditing and reporting purposes.
 6. Provide all requested documentation promptly to Mastercard during investigations, appeals, and financial responsibility determinations as governed by sections 10.3, 10.4, and updated appeals procedures related to Account Data Compromise Events in section 10.7 of the Mastercard SPME.
 
+## Privacy and Data Protection Considerations
+
+In alignment with the enhanced privacy and data protection mandates introduced in recent Mastercard SPME updates, Halyard Pay ensures the protection of Personal Information involved in chargeback investigations. This includes compliance with applicable data protection laws such as the California Consumer Privacy Act (CCPA) and the EU General Data Protection Regulation (GDPR), particularly when processing sensitive merchant or cardholder information during disputes.
+
+Halyard Pay and its third-party service providers handling chargeback-related Personal Information commit to:
+
+- Using and processing data solely for dispute management purposes as authorized by Mastercard.
+- Maintaining confidentiality and prohibiting unauthorized sharing or sales of Personal Information.
+- Implementing robust technical and organizational security controls to mitigate risks related to data breaches.
+- Assisting affected parties in accordance with legal rights under applicable privacy regulations.
+- Ensuring any cross-border data transfers comply with lawful mechanisms that preserve data protection standards.
+
+These obligations complement the chargeback handling steps described above and reinforce Halyard Pay's commitment to responsible and compliant dispute management.
+
 ## Monitoring and Risk Factors
 
 Halyard Pay evaluates merchant risk using updated Mastercard MATCH Listing Reason Codes, including new, specific definitions for elevated chargeback and fraud concerns:
@@ -25,4 +39,4 @@
 
 These clarified definitions, part of Mastercard's updated SPME MATCH Listing Reason Codes (see section 11.5), guide Halyard Pay’s risk assessments and chargeback management protocols to align with Mastercard’s evolving standards.
 
-Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.7, 11.5.
+Source authority: Mastercard SPME §§10.1, 10.3, 10.4, 10.7, 11.5.
--- a/policies/content_moderation/rules.yaml
+++ b/policies/content_moderation/rules.yaml
@@ -1,5 +1,5 @@
 program: Content Moderation (BRAM)
-authority: Mastercard SPME §10.5, §9.4.1, and §8.9.1
+authority: Mastercard SPME §10 (updated data processing and notification requirements), §9.4.1, and §8.9.1
 prohibited_categories:
   - counterfeit_goods
   - illegal_drugs
@@ -12,8 +12,6 @@
 case_documentation_required: true
 agent_owner: content_mod_agent
 
-# Updated to reflect Mastercard SPME §9.4.1 enhancements requiring Merchants to manage flagged adult content with timely removals, provide monthly reports to Acquirers (and Mastercard on request), and maintain appeal processes.
-# Added Mastercard SPME §8.9.1 obligations for Acquirers to register MMSP as service providers and provide detailed Merchant data for continuous monitoring focused on BRAM content violations.
-# Removed detailed remediation action plan and repeated ADC event penalty provisions from Mastercard SPME §10.5 to align with the revised, streamlined responsibilities. Content Moderation policy reflects this narrowing of procedural requirements, focusing on ongoing monitoring and enforcement rather than imposed remediation timelines or penalties.
-# These updates increase Merchant and Acquirer accountability and strengthen monitoring of Brand Integrity risks associated with BRAM content.
-# Removed previously outdated Merchant registration and MCC/TCC-based identification specifics no longer mandated.
+# Updated SPME §10 now includes comprehensive personal data processing and breach notification obligations impacting content moderation under Brand Risk and Anti-Money Laundering (BRAM) considerations.
+# This policy reflects the requirement that Merchant and Acquirer controls must align with these enhanced data privacy standards, including timely notification of engaging investigative entities and safeguarding of personal information related to content issues.
+# Strengthened accountability mandates in §10 require procedural updates in Content Moderation to ensure compliance with these data protection and incident response protocols under Mastercard’s framework.
--- a/policies/content_moderation/policy.md
+++ b/policies/content_moderation/policy.md
@@ -19,8 +19,12 @@
 
 Per Mastercard SPME §8.9.1, Halyard Pay as the Merchant Monitoring Service Provider (MMSP) requires Acquirers to register the MMSP per Mastercard Rules 7.10, provide comprehensive merchant information (including legal and trade names, addresses, and URLs) needed for monitoring, and ensure persistent monitoring of each merchant's activity to detect potential violations related to BRAM content, products and services, and merchant transaction laundering.
 
+## Enhanced Data Processing and Notification Requirements
+
+Recent updates to Mastercard SPME Section 10 introduce strengthened data privacy and security obligations relevant to BRAM investigations, including rigorous personal data processing standards, breach notification protocols, and compliance with applicable data protection laws such as CCPA and GDPR. Halyard Pay integrates these mandates to ensure that any processing of merchant personal information during investigations adheres to these enhanced privacy and security requirements, maintaining confidentiality and data integrity.
+
 Note: Mastercard SPME removed prior MCC and Transaction Category Code requirements and registration mandates for non-face-to-face adult content transactions but added detailed content management and reporting obligations under §9.4.1, which Halyard Pay integrates with emphasis on lawful, consented adult content and proactive merchant reporting.
 
 The prior detailed remediation action plan requirements and penalties related to repeated Account Data Compromise (ADC) events under Mastercard SPME §10.5 have been removed, reducing procedural burdens and penalty assessments for Brand Integrity investigations.
 
-Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5.+Source authority: Mastercard SPME §§8.9.1, 9.4.1, 10.5, 10.
--- a/policies/refund_policy/policy.md
+++ b/policies/refund_policy/policy.md
@@ -11,9 +11,11 @@
 1. Accept refund requests within 30 days following the original transaction.
 2. Partial refunds are permissible where a portion of the goods or services is non-defective.
 3. Notify cardholders in writing (email or in-app notification) when refunds are processed or declined.
-4. Retain refund transaction records for a minimum of 18 months.
-5. Submit to Mastercard ongoing documentation as required during investigations related to refunds or financial responsibility determinations, per Mastercard SPME sections 10.3 and 10.4.
+4. Retain refund transaction records for a minimum of 18 months, ensuring that all personal information involved complies with applicable data privacy requirements.
+5. When submitting documentation related to refunds or financial responsibility investigations, ensure compliance with all mandatory data protection standards, including those concerning the processing and handling of personal information as specified by Mastercard SPME §10.4.
 
-Merchants must cooperate fully with Mastercard’s investigation process, including the retention and prompt provision of all forensic or investigative reports related to disputes or incidents upon request. Merchants should be aware that investigations informed by these reports may affect financial responsibility determinations. Appeals must be timely, specify the basis for contention, and adhere to Mastercard’s standards; a non-refundable USD 500 fee applies to review appeals.
+Merchants must cooperate fully with Mastercard’s investigation process, including retention and timely provision of forensic or investigative reports related to disputes or refund incidents as required. Merchants shall adhere to Mastercard’s privacy and security requirements when handling personal data during these processes.
+
+Appeals must be timely, specify the basis for contention, and adhere to Mastercard’s standards; a non-refundable USD 500 fee applies to review appeals.
 
 Source authority: Mastercard SPME §10.4 and §10.7.