Mastercard SPME §13.1.2 · Sep 2024 → May 2025

Service Provider Risk Management Program

substantive

The appendix D privacy and data protection standards for Covered Programs have been updated to exclude MATCH and introduce a new Appendix F covering privacy/data protections specifically for MATCH Pro, with obligations realigned under applicable laws. This includes updated roles, obligations, and definitions for processing personal data and information.

Sources Mastercard SPME · Sep 2024 · page 144 PDF Mastercard SPME · May 2025 · page 152 PDF ATO Detection current
Why these edits? The Mastercard SPME update introduces Appendix F, which replaces former privacy and data protection standards for MATCH with updated obligations specifically tailored for MATCH Pro, affecting Account-Takeover Detection policies that cite section 6.2 relating to MATCH data handling.
Mastercard SPME §13.1.2
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Appendix A Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Appendix B Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Appendix C Omitted This appendix has been omitted. Omitted Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Appendix D Covered Programs Privacy and Data Protection Standards This appendix describes the privacy and data protection Standards for Covered Programs as they relate to European Union (EU) Data Protection Law. D.1 Purpose......................................................................................................................................................... 150 158 D.2 Scope.............................................................................................................................................................150 Scope.............................................................................................................................................................158 D.3 Definitions.....................................................................................................................................................150 Definitions.....................................................................................................................................................158 D.4 Acknowledgment of Roles......................................................................................................................... 151 159 D.5 The Corporation and Customer Obligations..........................................................................................152 Obligations..........................................................................................160 D.6 Data Transfers.............................................................................................................................................153 Transfers.............................................................................................................................................161 D.7 Data Disclosures..........................................................................................................................................153 Disclosures..........................................................................................................................................161 D.8 Security Measures.......................................................................................................................................154 Measures.......................................................................................................................................162 D.9 Confidentiality of Personal Data..............................................................................................................154 Data..............................................................................................................162 D.10 Personal Data Breach Notification Requirements..............................................................................154 Requirements..............................................................................162 D.11 Personal Data Breach Cooperation and Documentation Requirements........................................155 Requirements........................................163 D.12 Data Protection and Security Audit......................................................................................................155 Audit......................................................................................................163 D.13 Liability........................................................................................................................................................155 Liability........................................................................................................................................................163 D.14 Termination of the Covered Programs Use..........................................................................................156 Use..........................................................................................164 D.15 Invalidity and Severability........................................................................................................................156 Severability........................................................................................................................164 Annex 1 to Appendix D: Processing of Personal Data .................................................................................156 .................................................................................164 Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data.... 157 165 Covered Programs Privacy and Data Protection Standards Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 D.1 Purpose This appendix provides Standards regarding the Processing of Personal Data of Data Subjects subject to EU Data Protection Law by the Corporation and its Customers (collectively referred to in this appendix as the “Parties”"Parties") in the context of the Covered Programs: following covered programs: Account Data ¶ Data Compromise events, Mastercard Alert to Control High-risk (Merchants) (MATCH™) system, the ¶ the Excessive Chargeback Program, the Merchant Registration Program, and the Franchise Management Program. Program (collectively, the "Covered Programs"). For privacy and data protection Standards applicable to Mastercard Alert to Control High-risk (Merchants) (MATCH™ Pro system), refer to Appendix F of this manual. D.2 Scope The Standards in this appendix supplement the privacy and data protection Standards contained in Section 1.5 of this manual and Rule 3.13 of the Mastercard Rules to the extent that the requirements pertain to the Processing of Personal Data subject to EU Data Protection Law in the context of the Covered Programs. In the event of a conflict, the Standards in this appendix take precedence. D.3 Definitions As used solely for the purposes of this appendix, the following terms have the meanings set forth below. Capitalized terms not otherwise defined herein have the meaning provided in Appendix E of this manual. Controller The entity which alone or jointly with others determines the purposes and the means of the Processing of Personal Data. Criminal Data Any Personal Data relating to criminal convictions, offenses, or related security measures. EEA Standard Contractual Clauses (EEA SCCs) The clauses annexed to the EU Commission Decision 2021/914 of June 4, 2021, on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended from time to time. EU Data Protection Law The EU General Data Protection Regulation 2016/679 GDPR (as amended and replaced from time to time) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC, and as amended and replaced from time to time) and their national implementing legislations; the Swiss Federal Data Protection Act (as amended and replaced from time to time); the Covered Programs Privacy and Data Protection Standards D.1 Purpose Security Rules and Procedures—Merchant Edition • 11 February 2025 Monaco Data Protection Act 2018 (as amended and replaced from time to time); the UK Data ¶ Covered Programs Privacy and Data Protection Standards ¶ D.1 Purpose ¶ Security Rules and Procedures—Merchant Edition • 6 August 2024 Protection Act (as amended and replaced from time to time); and the Data Protection Acts of the EEA countries (as amended and replaced from time to time). Mastercard Binding Corporate Rules (Mastercard BCRs) The Mastercard® Binding Corporate Rules as approved by the EEA and UK data protection authorities and available on the Corporation’s public facing website. Personal Data Breach A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to or other unauthorized Processing of Personal Data transmitted, stored, or otherwise Processed. Processor The entity which Processes Personal Data on behalf of a Controller. Sensitive Data Any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation, as well as any other type of data that will be considered to be sensitive according to any future revision of EU Data Protection Law. UK Addendum The addendum to the EEA Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022). D.4 Acknowledgment of Roles The Corporation and its Customers acknowledge and confirm that: (1) neither Party acts as a Processor on behalf of the other Party; (2) each Party is an independent Controller; and (3) this appendix does not create a joint-Controllership or a Controller-Processor relationship between the Parties. The Corporation and its Customers acknowledge and agree that the scope of each Party’s role as an independent Controller is as follows: • A Customer is a Controller for any Processing, including disclosing Personal Data to the Corporation, for the purpose of developing enhanced or incremental risk information to aid the Customer in its own determination of risk in its Merchant acquiring business. • The Corporation is a Controller for any Processing for the purpose of operating the Covered Programs, including product development, support and maintenance, and making the Covered Programs available to its Customers (e.g., as set out in Chapter 11) and for internal Covered Programs Privacy and Data Protection Standards D.4 Acknowledgment of Roles Security Rules and Procedures—Merchant Edition • 11 February 2025 research, fraud, security, and risk management as listed in Rule 3.10 "Confidential Information of Customers" of the Mastercard Rules. ¶ Covered Programs Privacy and Data Protection Standards ¶ D.4 Acknowledgment of Roles ¶ Security Rules and Procedures—Merchant Edition • 6 August 2024 D.5 The Corporation and Customer Obligations The Corporation and each Customer independently is responsible for compliance with EU Data Protection Law in relation to the Processing of Personal Data for which it is a Controller as described in section D.4. Notwithstanding the above, with regard to any Processing of Personal Data of Data Subjects that a Customer adds to the Covered Programs, including the Processing for which the Corporation is the Controller, a Customer must: 1. Rely on a valid legal ground under EU Data Protection Law for each of the Processing purposes, including obtaining Data Subjects’ consent if required or appropriate under EU Data Protection Law. 2. Provide appropriate notice to the Data Subjects regarding (i) the their Processing of Personal Data, in a timely manner (e.g., informing Merchants about the possible use of MATCH upon termination of the Merchant Agreement) and at the minimum with the elements required under EU Data Protection Law, and (ii), as appropriate, the existence of Mastercard BCRs. Each Customer must also provide a link to the Corporation’s privacy notice for the Processing in relation to MATCH (available at https://www.mastercard.com/ global/en/vision/corp-responsibility/commitment-to-privacy/match-privacy.html ), where applicable. 3. Take reasonable steps to ensure that Personal Data are accurate, complete, and current; adequate, relevant, and limited to what is necessary in relation to the purposes for which they are Processed. 4. Respond to Data Subjects’ requests to exercise their rights under EU Data Protection Law, including the right of (i) access, (ii) rectification, (iii) erasure, (iv) data portability, (v) restriction of Processing, and (vi) objection to the Processing, if and as required under EU Data Protection Law. The Corporation agrees to cooperate with the Customer in responding to such requests where appropriate. 5. Limit its Processing of Personal Data to the Processing that is necessary for the purpose of developing enhanced or incremental risk information to aid in its own determination of risk in its Merchant acquiring business. 6. Not engage in or otherwise perform any automated decision-making or profiling based on Personal Data that are Processed in the context of the Covered Programs. 7. Will add any Sensitive Data, Criminal Data, or government identification information of Data Subjects to the Covered Programs. 8. Only Process Personal Data in connection with the Covered Programs for as long as necessary to achieve the purposes for which they are Processed. Any Personal Data Processed in relation to MATCH must be deleted or destroyed after a maximum of five (5) years. Covered Programs Privacy and Data Protection Standards D.5 The Corporation and Customer Obligations Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 D.6 Data Transfers A Customer may transfer the Personal Data Processed in connection with the Covered Programs outside of the EEA, the UK, and Switzerland in accordance with EU Data Protection Law, including based on the EEA SCCs or the UK Addendum as appropriate. The Corporation may transfer the Personal Data Processed in connection with the Covered Programs outside of the EEA, the UK, and Switzerland in accordance with the Mastercard BCRs or with any other lawful data transfer mechanism that provides an adequate level of protection under EU Data Protection Law. The Corporation will abide by the Mastercard BCRs when Processing Personal Data in the context of the Covered Programs. D.7 Data Disclosures The Corporation and its Customers must ensure that they will only disclose Personal Data Processed in the context of the Covered Programs in accordance with EU Data Protection Law, and in particular that they will require the data recipients to protect the data with at least the same level of protection as described in this appendix. The Corporation represents and warrants that it will only disclose Personal Data in accordance with the Mastercard BCRs. Where the Corporation transfers Personal Data subject to the GDPR or the Swiss Data Protection Act to a Customer in a country that is not part of the EEA or subject to a European Commission adequacy decision, the Parties agree that the transfer shall be governed by the EEA SCCs, which are hereby incorporated into this appendix by reference. The SCCs are completed as follows: the Parties conclude Module One (controller-to-controller) of the EEA SCCs. The “data exporter” is Corporation; the “data importer” is Customer; the optional docking clause in Clause 7 is implemented; the optional paragraph in Clause 11(a) is struck; the competent supervisory authority in Clause 13(a) shall be the supervisory authority of Belgium; the governing law in Clause 17 is the law of the Belgium and the courts in Clause 18(b) are the courts of the Belgium; Annex 1 and 2 to the EEA SCCs are Annex 1 and 2 to this appendix. The Parties conclude the UK Addendum for transfers of Personal Data subject to the UK Data Protection Act from Corporation to Customer in a country that is not subject to a UK adequacy decision. The UK Addendum is hereby incorporated into this appendix by reference. Part 1 of the UK Addendum is completed as follows: (i) in Table 1, the "Exporter" is Corporation and the "Importer" is Customer (as set out in the paragraph above), their details are set forth in the Acquirer license agreement and their signatures are included in the signature page of the Acquirer license agreement; (ii) in Table 2, the first option is selected and the “Approved EU SCCs” are those incorporated into this appendix as per the paragraph above; (iii) in Table 3, Annexes 1 and 2 to the Approved EU SCCs are Annexes 1 and 2 to this appendix respectively; and (iv) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum. If either Party’s compliance with EU Data Protection Law applicable to transfers of Personal Data is affected by circumstances outside of either Party’s control, including if a legal Covered Programs Privacy and Data Protection Standards D.6 Data Transfers Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 instrument for transfers is invalidated, amended, or replaced, then the Parties will work together in good faith to reasonably resolve such non-compliance. D.8 Security Measures The Corporation and its Customers must implement and maintain a comprehensive written information security program with appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which includes, at a minimum, as appropriate: (1) the pseudonymization and encryption of Personal Data; (2) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services; (3) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (4) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the Processing. In assessing the appropriate level of security, the Corporation and its Customers must take into account the state of the art; the costs of implementation; and the nature, scope, context, and purposes of Processing of Personal Data; as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects and the risks that are presented by the Processing of Personal Data, in particular from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed. D.9 Confidentiality of Personal Data The Corporation and its Customers must take steps to ensure that any person acting under their authority who has access to Personal Data is subject to a duly enforceable contractual or statutory confidentiality obligation, and if applicable, Process Personal Data in accordance with the Controller’s instructions. D.10 Personal Data Breach Notification Requirements The Parties will assist each other in complying with their Personal Data Breach notification obligations. Where required under EU Data Protection Law, the Party which became aware of a Personal Data Breach will notify, without undue delay and, where feasible, not later than 72 hours after having become aware of it, the competent supervisory authority. When the Personal Data Breach is likely to result in a high risk to the rights and freedoms of Data Subjects or upon the competent supervisory authority’s request to do so, such Party must communicate the Personal Data Breach to the Data Subject without undue delay, where required under EU Data Protection Law. Covered Programs Privacy and Data Protection Standards D.8 Security Measures Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 D.11 Personal Data Breach Cooperation and Documentation Requirements Each Party must notify the other Party of a Personal Data Breach that relates to Personal Data Processed in the context of the Covered Programs and for which the other Party is a Controller, without undue delay, and not later than forty-eight (48) hours after having become aware of a Personal Data Breach. Each Party must document all Personal Data Breaches, including the facts relating to the Personal Data Breach, its effects, and the remedial action taken. D.12 Data Protection and Security Audit The Corporation and each Customer must conduct audits on a regular basis to control compliance with EU Data Protection Law, including the security measures provided in section D.8, and the Corporation must comply with the Mastercard BCRs. Upon prior written request, the Corporation and each Customer agrees to cooperate and, within reasonable time, provide the requesting Party with: (1) a summary of the audit reports demonstrating its compliance with EU Data Protection Law obligations and the Standards in this appendix, and as applicable Mastercard BCRs, after redacting any confidential and commercially sensitive information; and (2) confirmation that the audit has not revealed any material vulnerability, or to the extent that any such vulnerability was detected, that such vulnerability has been fully remedied. D.13 Liability Subject to the liability clauses in the Standards, the Corporation and each Customer agrees that it will be liable towards Data Subjects for the entire damage resulting from a violation of EU Data Protection Law with regard to Processing of Personal Data for which it is a Controller. Where the Parties are involved in the same Processing and where they are responsible for any damage caused by the Processing of Personal Data, both the Corporation and each responsible Customer may be held liable for the entire damage in order to ensure effective compensation of the Data Subject. If the Corporation paid full compensation for the damage suffered, the Corporation is entitled to claim back from the Customer(s) that part of the compensation corresponding to each Customer’s part of responsibility for the damage. Covered Programs Privacy and Data Protection Standards D.11 Personal Data Breach Cooperation and Documentation Requirements Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 D.14 Termination of the Covered Programs Use Mastercard and its Customers agree that, apart from the data retention obligation in section D.5, paragraph 8, the Standards in this appendix are no longer applicable to a Customer upon the termination of such Customer’s use of the Covered Programs. D.15 Invalidity and Severability If any Standard in this appendix is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such Standard shall not affect any other Standard in this appendix, and all Standards not affected by such invalidity or unenforceability will remain in full force and effect. Annex 1 to Appendix D: Processing of Personal Data A. List of Parties 1. Data exporter: Corporation – Name and address of the Corporation as well as the name, position, and contact details for the Corporation’s contact person: as stipulated in the Acquirer License agreement. – Activities relevant to the data transferred: Providing the Covered Programs – Signature and date: as stipulated in the Acquirer License agreement – Role: controller for the purposes listed in Section D.4 of appendix D. 2. Data importer: Customer – Name and address of the Customer as well as the name, position, and contact details for Customer’s contact person: as stipulated in the Acquirer License agreement – Activities relevant to the data transferred: participating in, or benefiting from, the Covered Programs – Signature and date: as stipulated in the Acquirer License agreement – Role: controller for the purposes listed in Section D.4 of appendix D B. Description of the Transfer Data Subjects Data Subjects as defined in Appendix E. Categories of data Personal Data relating to a Merchant’s principal owners or sole proprietors. Sensitive Data transferred The Parties do not Process any Sensitive Data in the context of the Covered Programs. Covered Programs Privacy and Data Protection Standards D.14 Termination of the Covered Programs Use Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Frequency of the transfer Upon Customer’s requests, such as on a per query basis or via batch file transfer. Nature of the Processing Collection, storage, analysis, disclosure by transfer or otherwise making available. Purposes of the transfer(s) The transfer is made for the purposes set forth in Section D.4 of appendix D. Period for which the Personal Data will be retained Personal Data will be retained only for as long as necessary to achieve the relevant purposes for each of the Covered Programs. C. Competent Supervisory Authority The competent supervisory authority in accordance with Clause 13 of the EEA SCCs is the Belgian Data Protection Authority. Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data The Parties will, as a minimum, implement the following types of security measures: 1. Physical access control Technical and organizational measures to prevent unauthorized persons from gaining access to the data processing systems available in premises and facilities (including databases, application servers and related hardware), where Personal Data are processed, include: – Establishing security areas, restriction of access paths; – Establishing access authorizations for employees and third parties; – Access control system (ID reader, magnetic card, chip card); – Key management, card-keys procedures; – Door locking (electric door openers, etc.); – Security staff, janitors; – Surveillance facilities, video/CCTV monitor, alarm system; – Securing decentralized data processing equipment and personal computers. 2. Virtual access control Technical and organizational measures to prevent data processing systems from being used by unauthorized persons include: – User identification and authentication procedures; – ID/password security procedures (special characters, minimum length, change of password); – Automatic blocking (e.g., password or timeout); Covered Programs Privacy and Data Protection Standards Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 – Monitoring of break-in-attempts and automatic turn-off of the user ID upon several erroneous passwords attempts; – Creation of one master record per user, user master data procedures, per data processing environment. 3. Data access control Technical and organizational measures to ensure that persons entitled to use a data processing system gain access only to such Personal Data in accordance with their access rights, and that Personal Data cannot be read, copied, modified or deleted without authorization, include: – Internal policies and procedures; – Control authorization schemes; – Differentiated access rights (profiles, roles, transactions and objects); – Monitoring and logging of accesses; – Disciplinary action against employees who access Personal Data without authorization; – Reports of access; – Access procedure; – Change procedure; – Deletion procedure. 4. Disclosure control Technical and organizational measures to ensure that Personal Data cannot be read, copied, modified or deleted without authorization during electronic transmission, transport or storage on storage media (manual or electronic), and that it can be verified to which companies or other legal entities Personal Data are disclosed, include: – Tunneling – Logging – Transport security 5. Entry control Technical and organizational measures to monitor whether data have been entered, changed or removed (deleted), and by whom, from data processing systems, include: – Logging and reporting systems; – Audit trails and documentation. 6. Control of instructions Technical and organizational measures to ensure that Personal Data are processed solely in accordance with the Instructions of the Controller include: – Unambiguous wording of the contract; – Formal commissioning (request form); – Criteria for selecting the Processor 7. Availability control Technical and organizational measures to ensure that Personal Data are protected against accidental destruction or loss (physical/logical) include: – Backup procedures; Covered Programs Privacy and Data Protection Standards Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 – Mirroring of hard disks (e.g., RAID technology); – Uninterruptible power supply (UPS); – Remote storage; – Anti-virus/firewall systems; – Disaster recovery plan. 8. Separation control Technical and organizational measures to ensure that Personal Data collected for different purposes can be processed separately include: – Separation of databases; – "Internal client" concept / limitation of use; – Segregation of functions (production/testing); – Procedures for storage, amendment, deletion, transmission of data for different purposes. Covered Programs Privacy and Data Protection Standards Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Appendix E Definitions The following terms as used in this manual have the meanings set forth below. Acceptance Mark................................................................................................................................................166 ¶ Acceptor...............................................................................................................................................................166 Mark................................................................................................................................................174 Acceptor...............................................................................................................................................................174 Access Device......................................................................................................................................................166 ¶ Account.................................................................................................................................................................166 Device......................................................................................................................................................174 Account.................................................................................................................................................................174 Account Enablement System...........................................................................................................................167 System...........................................................................................................................175 Account Holder....................................................................................................................................................167 Holder....................................................................................................................................................175 Account PAN........................................................................................................................................................167 PAN........................................................................................................................................................175 Account PAN Range........................................................................................................................................... 167 ¶ Acquirer................................................................................................................................................................167 175 Acquirer................................................................................................................................................................175 Activity(ies)..........................................................................................................................................................167 ..........................................................................................................................................................175 Affiliate Customer, Affiliate..............................................................................................................................167 Affiliate..............................................................................................................................175 Applicable Data Protection Law......................................................................................................................167 Law......................................................................................................................175 Area of Use..........................................................................................................................................................168 Use..........................................................................................................................................................176 Association Customer, Association..................................................................................................................168 Association..................................................................................................................176 ATM Access Fee...................................................................................................................................................168 Fee...................................................................................................................................................176 ATM Owner Agreement.....................................................................................................................................168 Agreement.....................................................................................................................................176 ATM Terminal.......................................................................................................................................................168 Terminal.......................................................................................................................................................176 ATM Transaction.................................................................................................................................................169 Transaction.................................................................................................................................................177 Authenticating Entity........................................................................................................................................ 169 177 Automated Teller Machine (ATM)....................................................................................................................169 ....................................................................................................................177 Bank Branch Terminal........................................................................................................................................169 ¶ BIN.........................................................................................................................................................................169 Terminal........................................................................................................................................177 BIN.........................................................................................................................................................................177 Brand Fee.............................................................................................................................................................169 Fee.............................................................................................................................................................177 Brand Mark..........................................................................................................................................................170 ¶ Card.......................................................................................................................................................................170 ¶ Cardholder...........................................................................................................................................................170 Mark..........................................................................................................................................................178 Card.......................................................................................................................................................................178 Cardholder...........................................................................................................................................................178 Cardholder Communication............................................................................................................................. 170 178 Cardholder Verification Method (CVM)..........................................................................................................170 ..........................................................................................................178 Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC)........................................................... 171 179 Chip-only MPOS Terminal.................................................................................................................................171 Terminal.................................................................................................................................179 Chip Transaction.................................................................................................................................................171 Transaction.................................................................................................................................................179 Cirrus Acceptance Mark.................................................................................................................................... 171 179 Cirrus Access Device...........................................................................................................................................171 Device...........................................................................................................................................179 Cirrus Account.....................................................................................................................................................171 Account.....................................................................................................................................................179 Definitions Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Cirrus Brand Mark...............................................................................................................................................172 Mark...............................................................................................................................................180 Cirrus Card...........................................................................................................................................................172 Card...........................................................................................................................................................180 Cirrus Customer..................................................................................................................................................172 Customer..................................................................................................................................................180 Cirrus Payment Application..............................................................................................................................172 Application..............................................................................................................................180 Cirrus Word Mark................................................................................................................................................172 Mark................................................................................................................................................180 Competing ATM Network..................................................................................................................................172 Network..................................................................................................................................180 Competing EFT POS Network......................................................................................................................... 172 180 Competing International ATM Network.........................................................................................................173 Network.........................................................................................................181 Competing North American ATM Network....................................................................................................173 Network....................................................................................................181 Consumer Device Cardholder Verification Method, Consumer Device CVM, CDCVM...........................173 CDCVM...........................181 Contact Chip Transaction.................................................................................................................................174 Transaction.................................................................................................................................182 Contactless Payment Device............................................................................................................................174 Device............................................................................................................................182 Contactless Transaction....................................................................................................................................174 Transaction....................................................................................................................................182 Control, Controlled.............................................................................................................................................174 ¶ Corporation..........................................................................................................................................................174 Controlled.............................................................................................................................................182 Corporation..........................................................................................................................................................182 Corporation System...........................................................................................................................................175 System...........................................................................................................................................183 Credentials Management System...................................................................................................................175 System...................................................................................................................183 Cross-border Transaction..................................................................................................................................175 Transaction..................................................................................................................................183 Cryptocurrency, Crypto.....................................................................................................................................175 Crypto.....................................................................................................................................183 Cryptocurrency Merchant, Crypto Merchant................................................................................................175 Merchant................................................................................................183 Cryptocurrency Transaction, Crypto Transaction.........................................................................................175 ¶ Customer.............................................................................................................................................................176 Transaction.........................................................................................183 Customer.............................................................................................................................................................184 Customer Report................................................................................................................................................176 Report................................................................................................................................................184 Data Storage Entity (DSE)...............................................................................................................................176 ¶ Data Subject.......................................................................................................................................................176 ...............................................................................................................................184 Data Subject.......................................................................................................................................................184 Device Binding.....................................................................................................................................................176 Binding.....................................................................................................................................................184 Digital Activity(ies).............................................................................................................................................176 .............................................................................................................................................184 Digital Activity Agreement................................................................................................................................177 Agreement................................................................................................................................185 Digital Activity Customer..................................................................................................................................177 Customer..................................................................................................................................185 Digital Activity Service Provider (DASP)........................................................................................................ 177 185 Digital Activity Sponsoring Customer.............................................................................................................177 Customer.............................................................................................................185 Digital Goods.......................................................................................................................................................177 Goods.......................................................................................................................................................185 Digital Wallet.......................................................................................................................................................177 Wallet.......................................................................................................................................................185 Digital Wallet Operator (DWO).......................................................................................................................177 .......................................................................................................................185 Digital Wallet Operator Mark, DWO Mark.................................................................................................... 178 186 Digital Wallet Operator (DWO) Security Incident, DWO Security Incident............................................ 178 186 Digitization, Digitize...........................................................................................................................................178 Digitize...........................................................................................................................................186 Domestic Transaction........................................................................................................................................178 Transaction........................................................................................................................................186 Dual Interface......................................................................................................................................................178 Interface......................................................................................................................................................186 Definitions Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Electronic Money.................................................................................................................................................178 Money.................................................................................................................................................186 Electronic Money Institution.............................................................................................................................179 Institution.............................................................................................................................187 Electronic Money Issuer.....................................................................................................................................179 Issuer.....................................................................................................................................187 EMV Mode Contactless Transaction...............................................................................................................179 Transaction...............................................................................................................187 End User...............................................................................................................................................................179 User...............................................................................................................................................................187 Gateway Customer............................................................................................................................................179 Customer............................................................................................................................................187 Gateway Processing...........................................................................................................................................179 Processing...........................................................................................................................................187 Gateway Transaction.........................................................................................................................................179 Transaction.........................................................................................................................................187 Global Collection Only (GCO) Data Collection Program.............................................................................180 Program.............................................................................188 Host Card Emulation (HCE).............................................................................................................................180 .............................................................................................................................188 Hybrid Terminal...................................................................................................................................................180 ¶ ICA.........................................................................................................................................................................180 Terminal...................................................................................................................................................188 ICA.........................................................................................................................................................................188 Identification & Verification (ID&V).................................................................................................................180 .................................................................................................................188 Independent Sales Organization (ISO)...........................................................................................................180 ...........................................................................................................188 Installment Lending Agreement...................................................................................................................... 181 189 Interchange System...........................................................................................................................................181 System...........................................................................................................................................189 Inter-European Transaction..............................................................................................................................181 Transaction..............................................................................................................................189 Interregional Transaction..................................................................................................................................181 Transaction..................................................................................................................................189 Intracountry Transaction...................................................................................................................................181 Transaction...................................................................................................................................189 Intra–European Transaction.............................................................................................................................182 Transaction.............................................................................................................................190 Intra–Non–SEPA Transaction...........................................................................................................................182 Transaction...........................................................................................................................190 Intraregional Transaction..................................................................................................................................182 ¶ Issuer.....................................................................................................................................................................182 Transaction..................................................................................................................................190 Issuer.....................................................................................................................................................................190 License, Licensed.................................................................................................................................................182 ¶ Licensee................................................................................................................................................................182 ¶ Maestro................................................................................................................................................................182 Licensed.................................................................................................................................................190 Licensee................................................................................................................................................................190 Maestro................................................................................................................................................................190 Maestro Acceptance Mark................................................................................................................................183 Mark................................................................................................................................191 Maestro Access Device......................................................................................................................................183 Device......................................................................................................................................191 Maestro Account.................................................................................................................................................183 Account.................................................................................................................................................191 Maestro Brand Mark..........................................................................................................................................183 Mark..........................................................................................................................................191 Maestro Card...................................................................................................................................................... 183 191 Maestro Customer.............................................................................................................................................183 Customer.............................................................................................................................................191 Maestro Payment Application..........................................................................................................................183 Application..........................................................................................................................191 Maestro Word Mark...........................................................................................................................................183 Mark...........................................................................................................................................191 Magnetic Stripe Mode Contactless Transaction...........................................................................................184 Transaction...........................................................................................192 Manual Cash Disbursement Transaction........................................................................................................184 ¶ Marks....................................................................................................................................................................184 ¶ Mastercard...........................................................................................................................................................184 Transaction........................................................................................................192 Marks....................................................................................................................................................................192 Mastercard...........................................................................................................................................................192 Mastercard Acceptance Mark.......................................................................................................................... 184 192 Definitions Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Mastercard Access Device.................................................................................................................................184 Device.................................................................................................................................192 Mastercard Account...........................................................................................................................................185 Account...........................................................................................................................................193 Mastercard Biometric Card..............................................................................................................................185 Card..............................................................................................................................193 Mastercard-branded Application Identifier (AID).........................................................................................185 .........................................................................................193 Mastercard Brand Mark.....................................................................................................................................185 Mark.....................................................................................................................................193 Mastercard Card.................................................................................................................................................185 Card.................................................................................................................................................193 Mastercard Cloud-Based Payments............................................................................................................... 185 193 Mastercard Consumer-Presented QR Transaction.......................................................................................185 Transaction.......................................................................................193 Mastercard Customer........................................................................................................................................186 Customer........................................................................................................................................194 Mastercard Digital Enablement Service.........................................................................................................186 Service.........................................................................................................194 Mastercard Europe.............................................................................................................................................186 Europe.............................................................................................................................................194 Mastercard Incorporated..................................................................................................................................186 Incorporated..................................................................................................................................194 Mastercard Payment Application....................................................................................................................186 Application....................................................................................................................194 Mastercard Safety Net......................................................................................................................................186 Net......................................................................................................................................194 Mastercard Symbol............................................................................................................................................187 Symbol............................................................................................................................................195 Mastercard Token...............................................................................................................................................187 Token...............................................................................................................................................195 Mastercard Token Account Range...................................................................................................................187 Range...................................................................................................................195 Mastercard Token Vault.....................................................................................................................................187 Vault.....................................................................................................................................195 Mastercard Word Mark..................................................................................................................................... 187 195 Member, Membership........................................................................................................................................188 Membership........................................................................................................................................196 Merchandise Transaction.................................................................................................................................. 188 ¶ Merchant..............................................................................................................................................................188 196 Merchant..............................................................................................................................................................196 Merchant Agreement.........................................................................................................................................188 Agreement.........................................................................................................................................196 Merchant Token Requestor...............................................................................................................................188 Requestor...............................................................................................................................196 Mobile Payment Device.....................................................................................................................................188 Device.....................................................................................................................................196 Mobile POS (MPOS) Terminal..........................................................................................................................189 Terminal..........................................................................................................................197 MoneySend Payment Transaction...................................................................................................................189 Transaction...................................................................................................................197 Multi-Account Chip Card...................................................................................................................................189 Card...................................................................................................................................197 Multi-Factor Authentication Method, MFA Method.....................................................................................189 Method.....................................................................................197 Non-Mastercard Funding Source.....................................................................................................................189 Source.....................................................................................................................197 Non-Mastercard Receiving Account................................................................................................................189 Account................................................................................................................197 Non-Mastercard Systems and Networks Standards...................................................................................189 Standards...................................................................................197 On-behalf Token Requestor..............................................................................................................................190 Requestor..............................................................................................................................198 On-Device Cardholder Verification..................................................................................................................190 Verification..................................................................................................................198 Originating Account Holder..............................................................................................................................190 Holder..............................................................................................................................198 Originating Institution (OI)...............................................................................................................................190 ...............................................................................................................................198 Ownership, Owned.............................................................................................................................................190 ¶ Participation........................................................................................................................................................190 Owned.............................................................................................................................................198 Participation........................................................................................................................................................198 Pass-through Digital Wallet............................................................................................................................. 190 198 Definitions Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Pass-through Digital Wallet Operator (DWO)..............................................................................................191 ..............................................................................................199 Payment Account Reference (PAR).................................................................................................................191 .................................................................................................................199 Payment Application..........................................................................................................................................191 Application..........................................................................................................................................199 Payment Facilitator...........................................................................................................................................191 Facilitator...........................................................................................................................................199 Payment Transaction.........................................................................................................................................191 Transaction.........................................................................................................................................199 Payment Transfer Activity(ies) (PTA)..............................................................................................................191 ..............................................................................................................199 Personal Data......................................................................................................................................................192 Data......................................................................................................................................................200 Point of Interaction (POI)..................................................................................................................................192 ..................................................................................................................................200 Point-of-Sale (POS) Terminal...........................................................................................................................192 Terminal...........................................................................................................................200 Point–of–Sale (POS) Transaction....................................................................................................................192 ¶ Portfolio................................................................................................................................................................192 Transaction....................................................................................................................200 Portfolio................................................................................................................................................................200 Principal Customer, Principal............................................................................................................................193 Principal............................................................................................................................201 Processed PTA Transaction...............................................................................................................................193 Transaction...............................................................................................................................201 Processed Transaction.......................................................................................................................................193 Transaction.......................................................................................................................................201 Processing of Personal Data.............................................................................................................................193 ¶ Program................................................................................................................................................................193 Data.............................................................................................................................201 Program................................................................................................................................................................201 Program Service..................................................................................................................................................194 Service..................................................................................................................................................202 PTA Account.........................................................................................................................................................194 Account.........................................................................................................................................................202 PTA Account Number.........................................................................................................................................194 Number.........................................................................................................................................202 PTA Account Portfolio........................................................................................................................................194 Portfolio........................................................................................................................................202 PTA Agreement...................................................................................................................................................194 Agreement...................................................................................................................................................202 PTA Customer.....................................................................................................................................................194 Customer.....................................................................................................................................................202 PTA Originating Account...................................................................................................................................194 Account...................................................................................................................................202 PTA Program.......................................................................................................................................................194 Program.......................................................................................................................................................202 PTA Receiving Account.......................................................................................................................................195 Account.......................................................................................................................................203 PTA Settlement Guarantee Covered Program..............................................................................................195 Program..............................................................................................203 PTA Settlement Obligation ..............................................................................................................................195 ..............................................................................................................................203 PTA Transaction..................................................................................................................................................195 Transaction..................................................................................................................................................203 Quick Response (QR) Code ..............................................................................................................................195 ..............................................................................................................................203 Receiving Account Holder..................................................................................................................................195 Holder..................................................................................................................................203 Receiving Agent...................................................................................................................................................195 Agent...................................................................................................................................................203 Receiving Customer............................................................................................................................................196 Customer............................................................................................................................................204 Receiving Institution (RI)....................................................................................................................................196 ¶ Region...................................................................................................................................................................196 ....................................................................................................................................204 Region...................................................................................................................................................................204 Remote Electronic Transaction ....................................................................................................................... 196 204 Service Provider.................................................................................................................................................. 196 204 Settlement Obligation.......................................................................................................................................196 Obligation.......................................................................................................................................204 Shared Deposit Transaction.............................................................................................................................197 Transaction.............................................................................................................................205 Solicitation, Solicit..............................................................................................................................................197 Solicit..............................................................................................................................................205 Definitions Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Sponsor, Sponsorship.........................................................................................................................................197 Sponsorship.........................................................................................................................................205 Sponsored Digital Activity Entity.....................................................................................................................197 Entity.....................................................................................................................205 Sponsored Merchant..........................................................................................................................................198 Merchant..........................................................................................................................................206 Sponsored Merchant Agreement.....................................................................................................................198 Agreement.....................................................................................................................206 Staged Digital Wallet........................................................................................................................................198 Wallet........................................................................................................................................206 Staged Digital Wallet Operator (DWO).........................................................................................................198 ¶ Standards............................................................................................................................................................198 .........................................................................................................206 Standards............................................................................................................................................................206 Stand-In Parameters.........................................................................................................................................199 Parameters.........................................................................................................................................207 Stand-In Processing Service.............................................................................................................................199 Service.............................................................................................................................207 Strong Customer Authentication (SCA)........................................................................................................199 ¶ Sub-licensee.........................................................................................................................................................199 ¶ Terminal................................................................................................................................................................199 ........................................................................................................207 Sub-licensee.........................................................................................................................................................207 Terminal................................................................................................................................................................207 Third Party Processor (TPP)..............................................................................................................................199 ¶ Token.....................................................................................................................................................................200 ..............................................................................................................................207 Token.....................................................................................................................................................................208 Tokenization, Tokenize........................................................................................................................................200 Tokenize........................................................................................................................................208 Token Requestor..................................................................................................................................................200 Requestor..................................................................................................................................................208 Token Vault...........................................................................................................................................................200 ¶ Transaction..........................................................................................................................................................200 Vault...........................................................................................................................................................208 Transaction..........................................................................................................................................................208 Transaction Data................................................................................................................................................200 Data................................................................................................................................................208 Transaction Management System..................................................................................................................201 System..................................................................................................................209 Trusted Service Manager...................................................................................................................................201 Manager...................................................................................................................................209 Virtual Account....................................................................................................................................................201 ¶ Volume..................................................................................................................................................................201 Account....................................................................................................................................................209 Volume..................................................................................................................................................................209 Wallet Token Requestor.....................................................................................................................................201 Requestor.....................................................................................................................................209 Word Mark...........................................................................................................................................................201 Mark...........................................................................................................................................................209 Definitions Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Additional and/or revised terms may also be used for purposes of the Rules in a particular chapter or section of this manual. Acceptance Mark Any one of the Corporation’s Marks displayed at a Point of Interaction (POI) to indicate brand acceptance. See Cirrus® Acceptance Mark, Maestro® Acceptance Mark, Mastercard® Acceptance Mark. Acceptor The Merchant, Sponsored Merchant, ATM owner, or other entity that accepts a Card pursuant to a Merchant Agreement, Sponsored Merchant Agreement, or ATM Owner Agreement for purposes of conducting a Transaction. Access Device A device other than a Card that has successfully completed all applicable Mastercard certification and testing requirements, if any, and: • Uses at least one Payment Application provisioned to the device by or with the approval of a Customer to provide access to an Account; • Supports the transmission or exchange of data using one or both of the following: – Magnetic stripe or chip data containing a dynamic cryptogram to or with a Terminal, as applicable, by implementing the EMV® Contactless Specifications (Book D) to effect Transactions at the Terminal without requiring direct contact of the device to the Terminal – Chip data containing a dynamic cryptogram to or with a Terminal, as applicable, by implementing the Mastercard Cloud-Based Payments (MCBP) documentation to effect Transactions at the Terminal by capture of a QR Code containing the Transaction Data • May also support the transmission of magnetic stripe data containing a dynamic cryptogram to a Terminal to effect Transactions identified by the Acquirer in Transaction messages as magnetic stripe Transactions. A Cirrus Access Device, Maestro Access Device, and Mastercard Access Device is each an Access Device. See also Mobile Payment Device. Account An account maintained by or on behalf of a Cardholder by an Issuer for the processing of Transactions, and which is identified with a bank identification number (BIN) or Issuer identification number (IIN) designated by the Corporation in its routing tables for routing to the Interchange System. See also Cirrus Account, Maestro Account, Mastercard Account. Definitions Acceptance Mark Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Account Enablement System Performs Account enablement services for Mastercard Cloud-Based Payments, which may include Account and Access Device eligibility checks, Identification & Verification (ID&V), Digitization, and subsequent lifecycle management. Account Holder A user who holds a PTA Account and has agreed to participate in a PTA Transaction. Account PAN The primary account number (PAN) allocated to an Account by an Issuer. Account PAN Range The range of Account PANs designated by an Issuer for Digitization. Acquirer A Customer in its capacity as an acquirer of a Transaction. Activity(ies) The undertaking of any lawful act that can be undertaken only pursuant to a License granted by the Corporation. Payment Transfer Activity is a type of Activity. See also Digital Activity(ies). Affiliate Customer, Affiliate A Customer that participates indirectly in Activity through the Sponsorship of a Principal or, solely with respect to Mastercard Activity, through the Sponsorship of an Association. An Affiliate may not Sponsor any other Customer. Applicable Data Protection Law All applicable law, statute, declaration, decree, legislation, enactment, order, ordinance, regulation or rule (each as amended and replaced from time to time) which relates to the Definitions Account Enablement System Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 protection of individuals with regards to the Processing of Personal Data to which the Parties are subject, including but not limited to the EU General Data Protection Regulation 2016/679; the e-Privacy Directive 2002/58/EC and their national implementing legislations the California Consumer Privacy Act; the U.S. Gramm-Leach-Bliley Act; the Brazil General Data Protection Act; the South Africa Protection of Personal Information Act; laws regulating unsolicited email, telephone, and text message communications; security breach notification laws; laws imposing minimum security requirements; laws requiring the secure disposal of records containing certain Personal Data; laws governing the portability and/or cross-border transfer of Personal Data; and all other similar international, federal, state, provincial, and local requirements; each as applicable. Area of Use The country or countries in which a Customer is Licensed to use the Marks and conduct Activity or in which a PTA Customer is permitted to Participate in a PTA Program, and, as a rule, set forth in the License or PTA Agreement or in an exhibit to the License or PTA Agreement. Association Customer, Association A Mastercard Customer that participates directly in Mastercard Activity using its assigned BINs and which may Sponsor one or more Mastercard Affiliates but may not directly issue Mastercard Cards or acquire Mastercard Transactions, or in the case of a PTA Association, may not directly hold PTA Accounts, without the express prior written consent of the Corporation. ATM Access Fee A fee charged by an Acquirer in connection with a cash withdrawal or Shared Deposit Transaction initiated at the Acquirer’s ATM Terminal with a Card, and added to the total Transaction amount transmitted to the Issuer. ATM Owner Agreement An agreement between an ATM owner and a Customer that sets forth the terms pursuant to which the ATM accepts Cards. ATM Terminal An ATM that enables a Cardholder to effect an ATM Transaction with a Card (and if contactless-enabled, an Access Device) in accordance with the Standards. Definitions Area of Use Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 ATM Transaction A cash withdrawal effected at an ATM Terminal with a Card and processed through the Mastercard ATM Network. An ATM Transaction is identified with MCC 6011 (Automated Cash Disbursements—Customer Financial Institution). Authenticating Entity An Authenticating Entity is a Merchant, Service Provider, or Digital Wallet Operator that uses an MFA Method to authenticate a Cardholder when a Token is used to conduct a Card-not-present Transaction of any type (excluding mail order and telephone order [MO/TO] Transactions). Automated Teller Machine (ATM) An unattended self-service device that performs basic banking functions such as accepting deposits, cash withdrawals, ordering transfers among accounts, loan payments and account balance inquiries. Bank Branch Terminal An attended device, located on the premises of a Customer or other financial institution designated as its authorized agent by the Corporation, that facilitates a Manual Cash Disbursement Transaction by a Cardholder. BIN A bank identification number (BIN, sometimes referred to as an Issuer identification number, or IIN) is a unique number assigned by Mastercard for use by a Customer in accordance with the Standards. Brand Fee A fee charged for certain Transactions not routed to the Interchange System. Definitions ATM Transaction Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Brand Mark A Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles device. The Mastercard Brand Mark, Maestro Brand Mark, and Cirrus Brand Mark is each a Brand Mark. The Mastercard Symbol is also a Brand Mark. Card A card issued by a Customer pursuant to License and in accordance with the Standards and that provides access to an Account. Unless otherwise stated herein, Standards applicable to the use and acceptance of a Card are also applicable to an Access Device and, in a Card-not-present environment, an Account. A Cirrus Card, Maestro Card, and Mastercard Card is each a Card. Cardholder The authorized user of a Card or Access Device issued by a Customer. Cardholder Communication Any communication by or on behalf of an Issuer to a Cardholder or prospective Cardholder. A Solicitation is one kind of Cardholder Communication. Cardholder Verification Method (CVM) A process used to confirm that the person presenting the Card is an authorized Cardholder. The Corporation deems the following to be valid CVMs when used in accordance with the Standards: • The comparison, by the Merchant or Acquirer accepting the Card, of the signature on the Card’s signature panel with the signature provided on the Transaction receipt by the person presenting the Card; • The comparison, by the Card Issuer or the EMV chip on the Card, of the value entered on a Terminal’s PIN pad with the personal identification number (PIN) given to or selected by the Cardholder upon Card issuance; and • The use of a Consumer Device CVM (CDCVM) that Mastercard approved as a valid CVM for Transactions upon the successful completion of the certification and testing procedures set forth in section 3.11 of the Security Rules and Procedures. In certain Card-present environments, a Merchant may complete the Transaction without a CVM (“no CVM” as the CVM), such as in Quick Payment Service (QPS) Transactions, Contactless Transactions less than or equal to the CVM limit, and Transactions at an unattended Point-of- Sale (POS) Terminal identified as Cardholder-activated Terminal (CAT) Level 2 or Level 3. Definitions Brand Mark Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC) A Card with an embedded EMV-compliant chip containing memory and interactive capabilities used to identify and store additional data about a Cardholder, an Account, or both. Chip-only MPOS Terminal An MPOS Terminal that has a contact chip reader and no magnetic stripe-reading capability and that must: 1. Operate as an online-only POS Terminal for authorization purposes; 2. Support either signature or No CVM Required as a Cardholder Verification Method, and may also support PIN verification if conducted by means of a PIN entry device (PED) that is in compliance with the Payment Card Industry (PCI) POS PED Security Requirements and Evaluation Program; and 3. Otherwise comply with the Corporation’s requirements for Hybrid POS Terminals. Chip Transaction A Contact Chip Transaction or a Contactless Transaction. Cirrus Acceptance Mark A Mark consisting of the Cirrus Brand Mark placed on the dark blue acceptance rectangle, available at www.mastercardbrandcenter.com. Cirrus Access Device An Access Device that uses at least one Cirrus Payment Application to provide access to a Cirrus Account when used at an ATM Terminal or Bank Branch Terminal. Cirrus Account An account eligible to be a Cirrus Account and identified with a BIN/IIN associated with a Portfolio designated by the Corporation as a Cirrus Portfolio in its routing tables. Definitions Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC) Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Cirrus Brand Mark A Mark consisting of the Cirrus Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles device. The Corporation is the exclusive owner of the Cirrus Brand Mark. Cirrus Card A Card that provides access to a Cirrus Account. Cirrus Customer A Customer that has been granted a Cirrus License in accordance with the Standards. Cirrus Payment Application A Payment Application that stores Cirrus Account data. Cirrus Word Mark A Mark consisting of the word “Cirrus” followed by a registered trademark ® or ™ symbol (depending on its trademark status in a particular country) or the local law equivalent. “Cirrus” must appear in English and be spelled correctly, with the letter “C” capitalized. “Cirrus” must not be abbreviated, hyphenated, used in the plural or possessive, translated from English into another language, or appear in another alphabet except for specific authorized versions in Chinese (translation), Arabic (transliteration), Georgian (transliteration), and Korean (transliteration). The Corporation is the exclusive owner of the Cirrus Word Mark. Competing ATM Network A Competing International ATM Network or a Competing North American ATM Network, as the case may be. Competing EFT POS Network A network, other than any network owned and operated by the Corporation, which provides access to Maestro Accounts at POS Terminals by use of payment cards and has the following characteristics: Definitions Cirrus Brand Mark Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 1. It provides a common service mark or marks to identify the POS Terminal and payment cards, which provide Maestro Account access; 2. It is not an affiliate of the Corporation; and 3. It operates in at least one country in which the Corporation has granted a License or Licenses. The following networks are designated without limitation to be Competing EFT POS Networks: Interlink; Electron; and V-Pay. Competing International ATM Network A network of ATMs and payment cards, other than the Corporation, identified by a common brand mark that is used exclusively or primarily for ATM interchange that: 1. Operates in at least three countries; 2. Uses a common service mark or marks to identify the ATMs and payment cards which provide account access through it; and 3. Provides account access to at least 40,000,000 debit cards and by means of at least 25,000 ATMs. Competing North American ATM Network A network of ATMs and access cards, other than the Corporation, identified by a common brand mark that is used exclusively or primarily for ATM interchange and that possesses each of the following characteristics: 1. It operates in at least 40 of the states or provinces of the states and provinces of the United States and Canada; 2. It uses a common service mark or common service marks to identify the terminals and cards which provide account access through it; 3. There are at least 40,000,000 debit cards that provide account access through it; and 4. There are at least 12,000 ATMs that provide account access through it. Consumer Device Cardholder Verification Method, Consumer Device CVM, CDCVM A CVM that occurs when personal credentials established by the Cardholder to access an Account by means of a particular Access Device are entered on the Access Device and verified, either within the Access Device or by the Issuer during online authorization. A CDCVM is valid if the Issuer has approved the use of the CVM for the authentication of the Cardholder. Definitions Competing International ATM Network Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Contact Chip Transaction A Transaction in which data is exchanged between the Chip Card and the Terminal through the reading of the chip using the contact interface, in conformance with EMV specifications. Contactless Payment Device A means other than a Card by which a Cardholder may access an Account at a Terminal in accordance with the Standards. A Contactless Payment Device is a type of Access Device that exchanges data with the Terminal by means of radio frequency communications. See also Mobile Payment Device. Contactless Transaction A Transaction in which data is exchanged between the Chip Card or Access Device and the Terminal through the reading of the chip using the contactless interface, by means of radio frequency communications. See also EMV Mode Contactless Transaction, Magnetic Stripe Mode Contactless Transaction. Control, Controlled As used herein, Control has such meaning as the Corporation deems appropriate in its sole discretion given the context of the usage of the term and all facts and circumstances the Corporation deems appropriate to consider. As a general guideline, Control often means to have, alone or together with another entity or entities, direct, indirect, legal, or beneficial possession (by contract or otherwise) of the power to direct the management and policies of another entity. Corporation Mastercard International Incorporated, Maestro International Inc., and their subsidiaries and affiliates. As used herein, Corporation also means the President and Chief Executive Officer of Mastercard International Incorporated, or his or her designee, or such officers or other employees responsible for the administration and/or management of a program, service, product, system or other function. Unless otherwise set forth in the Standards, and subject to any restriction imposed by law or regulation, or by the Board of Directors of Mastercard International Incorporated, or by the Mastercard International Incorporated Certificate of Incorporation or the Mastercard Incorporated Certificate of Incorporation (as each such Certificate of Incorporation may be amended from time to time), each such person is authorized to act on behalf of the Corporation and to so act in his or her sole discretion. Definitions Contact Chip Transaction Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Corporation System The Interchange System as defined in this manual. Credentials Management System Facilitates credential preparation and/or remote mobile Payment Application management for Mastercard Cloud-Based Payments. Cross-border Transaction A Transaction that occurs at a Card acceptance location in a different country from the country in which the Card was issued. Cryptocurrency, Crypto A digital asset recognized as a medium of exchange, unit of account, and store of value that uses cryptography to secure transactions associated with the digital asset, control the generation of additional cryptocurrency units, and verify the transfer of funds. The recognition of a Cryptocurrency as a medium of exchange, unit of account, and store of value occurs only by agreement within the community of users of such Cryptocurrency. For the avoidance of doubt, legal tender or virtual currency issued by a government or centralized banking system is not considered Cryptocurrency. Cryptocurrency Merchant, Crypto Merchant A Merchant that sells or trades in Cryptocurrency. Cryptocurrency Transaction, Crypto Transaction A Card-present or Card-not-present Transaction in which a Cardholder uses an Account to directly purchase Cryptocurrencies, or to purchase, sell, or trade Cryptocurrencies by means of a digital currency, alternative currency, or virtual currency exchange platform. A Cryptocurrency Transaction is identified with MCC 6051 (Quasi Cash: Merchant), TCC U, and a Transaction Type Identifier (TTI) value of P70 (Cryptocurrency). Definitions Corporation System Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Customer A financial institution or other entity that has been approved for Participation. A Customer may be a Principal, Association, Affiliate, Digital Activity Customer, Sponsored Digital Activity Entity, or PTA Customer. See also Cirrus Customer, Maestro Customer, Mastercard Customer, Member. Customer Report Any report that a Customer is required to provide to the Corporation, whether on a one-time or repeated basis, pertaining to its License, Activities, Digital Activity Agreement, Digital Activities, PTA Agreement, Payment Transfer Activities, use of any Mark, or any such matters. By way of example and not limitation, the Quarterly Mastercard Report (QMR) is a Customer Report. Data Storage Entity (DSE) A Service Provider that performs DSE Program Service. Data Subject A Cardholder, a Merchant, or other natural person or entity whose Personal Data are Processed by or on behalf of the Corporation, a Customer, or a Merchant. Device Binding The process by which a Wallet Token Requestor binds a Mastercard Token corresponding to a Cardholder’s Account to that Cardholder’s Mobile Payment Device, which may consist of: • The provisioning of the Token and its associated encryption keys into the secure element within the Mobile Payment Device; • The loading of an application for a remotely-managed secure server into the Mobile Payment Device and the successful communication of the device with the application; or • Other methodology acceptable to the Corporation. Digital Activity(ies) The undertaking of any lawful act pursuant to approval by the Corporation as set forth in a Digital Activity Agreement or other written documentation. Participation in the Mastercard Digital Enablement Service as a Wallet Token Requestor is a Digital Activity. Definitions Customer Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Digital Activity Agreement The contract between the Corporation and a Digital Activity Customer granting the Digital Activity Customer the right to participate in Digital Activity and a limited License to use one or more of the Marks in connection with such Digital Activity, in accordance with the Standards. Digital Activity Customer A Customer that participates in Digital Activity pursuant to a Digital Activity Agreement and which may not issue Cards, acquire Transactions, or Sponsor any other Customer into the Corporation. Digital Activity Service Provider (DASP) A Service Provider that performs DASP Program Service. Digital Activity Sponsoring Customer A Principal Customer or Digital Activity Customer that sponsors a Sponsored Digital Activity Entity to participate in Digital Activity. Digital Goods Any goods that are stored, delivered, and used in electronic format, such as, by way of example but not limitation, books, newspapers, magazines, music, games, game pieces, and software (excluding gift cards). The delivery of a purchase of Digital Goods may occur on a one-time or subscription basis. Digital Wallet A Pass-through Digital Wallet or a Staged Digital Wallet. Digital Wallet Operator (DWO) A Service Provider that operates a Staged Digital Wallet or a Customer that operates a Pass- through Digital Wallet. A Merchant that stores Mastercard or Maestro Account data solely on its own behalf to effect Transactions initiated by the consumer is not deemed to be a DWO. Definitions Digital Activity Agreement Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Digital Wallet Operator Mark, DWO Mark A Mark identifying a particular Pass-through Digital Wallet and/or Staged Digital Wallet, and which may be displayed at the POI to denote that a retailer, or any other person, firm, or corporation, accepts payments effected by means of that Pass-through Digital Wallet and/or Staged Digital Wallet. A “Staged DWO Mark” and a “Pass-through DWO Mark” are both types of DWO Marks. Digital Wallet Operator (DWO) Security Incident, DWO Security Incident Any incident pertaining to the unintended or unlawful disclosure of Personal Data in connection with such Personal Data being processed through a DWO. Digitization, Digitize Data preparation performed by, or on behalf of, an Issuer prior to the provisioning of Account credentials or a PTA Customer prior to the provisioning of PTA Account credentials, in the form of a Mastercard Token, onto a Payment Device or into a server. Digitization includes Tokenization. Domestic Transaction See Intracountry Transaction. Dual Interface The description of a Terminal or Card that is capable of processing Contactless Transactions by means of its contactless interface and Contact Chip Transactions by means of its contact interface. Electronic Money Electronically (including magnetically) accessed monetary value as represented by a claim on the Electronic Money Issuer which: 1. Is issued on receipt of funds for the purpose of making transactions with payment cards; and 2. Is accepted by the Electronic Money Issuer or a person other than the Electronic Money Issuer. Definitions Digital Wallet Operator Mark, DWO Mark Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Electronic Money Institution An entity authorized by applicable regulatory authority or other government entity as an “electronic money institution”, “e-money institution”, “small electronic money institution”, or any other applicable qualification under which an entity is authorized to issue or acquire Electronic Money transactions under applicable law or regulation. Electronic Money Issuer An Electronic Money Institution with respect only to its issuing activities. EMV Mode Contactless Transaction A Contactless Transaction in which the Terminal and the chip exchange data, enabling the chip to approve the Transaction offline on the Issuer’s behalf or to request online authorization from the Issuer, in compliance with the Standards. End User Recipients of any lending services from the Installment Service Provider in accordance with an Installment Lending Agreement. An End User can be a natural person or an entity. Gateway Customer A Customer that uses the Gateway Processing service. Gateway Processing A service that enables a Customer to forward a Gateway Transaction to and/or receive a Gateway Transaction from the Mastercard® ATM Network. Gateway Transaction An ATM transaction effected with a payment card or other access device not bearing a Mark that is processed through or using the Mastercard® ATM Network. Definitions Electronic Money Institution Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Global Collection Only (GCO) Data Collection Program A program of the Corporation pursuant to which a Customer must provide collection-only reporting of non-Processed Transactions effected with a Card, Access Device, or Account issued under a Mastercard-assigned BIN via the Corporation’s Global Clearing Management System (GCMS), in accordance with the requirements set forth in the Mastercard Global Collection Only manual. Host Card Emulation (HCE) The presentation on a Mobile Payment Device of a virtual and exact representation of a Chip Card using only software on the Mobile Payment Device and occurring by means of its communication with a secure remote server. Hybrid Terminal A Terminal, including any POS or MPOS Terminal (“Hybrid POS Terminal”, “Hybrid MPOS Terminal”), ATM Terminal (“Hybrid ATM Terminal”), or Bank Branch Terminal (“Hybrid Bank Branch Terminal”), that: 1. Is capable of processing both Contact Chip Transactions and magnetic stripe Transactions; 2. Has the equivalent hardware, software, and configuration as a Terminal with full EMV Level 1 and Level 2 type approval status with regard to the chip technical specifications; and 3. Has satisfactorily completed the Corporation’s Terminal Integration Process (TIP) in the appropriate environment of use. ICA A unique number assigned by the Corporation to identify a Customer in relation to Activity. Identification & Verification (ID&V) The identification and verification of a person as the Cardholder to whom the Issuer allocated the Account PAN to be Tokenized. Independent Sales Organization (ISO) A Service Provider that performs ISO Program Service. Definitions Global Collection Only (GCO) Data Collection Program Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Installment Lending Agreement The agreement between the Installment Service Provider and an End User, which includes terms and conditions governing the relationship between the parties, such as lending amount and repayment terms. Interchange System The computer hardware and software operated by and on behalf of the Corporation for the routing, processing, and settlement of Transactions and PTA Transactions including, without limitation, the Mastercard Network, the Mastercard ATM Network, the Dual Message System, the Single Message System, the Global Clearing Management System (GCMS), and the Settlement Account Management (SAM) system. Inter-European Transaction A Transaction completed using a Card issued in a country or territory listed in Single European Payments Area (SEPA) at a Terminal located in a country or territory listed in Non-Single European Payments Area (Non-SEPA) or Transaction completed using a Card issued in a country or territory listed in Non-Single European Payments Area (Non–SEPA) at a Terminal located in a country or territory listed in Single European Payments Area (SEPA). Interregional Transaction A Transaction that occurs at a Card acceptance location in a different Region from the Region in which the Card was issued. In the Europe Region, the term “Interregional Transaction” includes any “Inter-European Transaction,” as such term is defined in the “Europe Region” chapter of the Mastercard Rules. Intracountry Transaction A Transaction that occurs at a Card acceptance location in the same country as the country in which the Card was issued. A Transaction conducted with a Card bearing one or more of the Brand Marks, either alone or in combination with the marks of another payment scheme, and processed as a Transaction, as shown by the Card type identification in the Transaction record, via either the Interchange System or a different network, qualifies as an Intracountry Transaction. “Domestic Transaction” is an alternative term for Intracountry Transaction. Definitions Installment Lending Agreement Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Intra–European Transaction An Intra-Non-SEPA Transaction or an Intra–SEPA Transaction, but not an Inter–European Transaction. Intra–Non–SEPA Transaction A Transaction completed using a Card issued in a country or territory listed in Non–Single European Payments Area (Non–SEPA) at a Terminal located in a country or territory listed in Non–Single European Payments Area (Non–SEPA). Intraregional Transaction A Transaction that occurs at a Card acceptance location in a different country from the country in which the Card was issued, within the same Region. In the Europe Region, this term is replaced by “Intra-European Transaction,” as such term is defined in the “Europe Region” chapter of the Mastercard Rules. Issuer A Customer in its capacity as an issuer of a Card or Account. License, Licensed The contract between the Corporation and a Customer granting the Customer the right to use one or more of the Marks in accordance with the Standards and in the case of Payment Transfer Activity, includes a PTA Agreement. To be “Licensed” means to have such a right pursuant to a License. Licensee A Customer or other person authorized in writing by the Corporation to use one or more of the Marks. Maestro Maestro International Incorporated, a Delaware U.S.A. corporation or any successor thereto. Definitions Intra–European Transaction Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Maestro Acceptance Mark A Mark consisting of the Maestro Brand Mark placed on the dark blue acceptance rectangle, as available at www.mastercardbrandcenter.com. Maestro Access Device An Access Device that uses at least one Maestro Payment Application to provide access to a Maestro Account when used at a Terminal. Maestro Account An account eligible to be a Maestro Account and identified with a BIN/IIN associated with a Portfolio designated by the Corporation as a Maestro Portfolio in its routing tables. Maestro Brand Mark A Mark consisting of the Maestro Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles device. The Corporation is the exclusive owner of the Maestro Brand Mark. Maestro Card A Card that provides access to a Maestro Account. Maestro Customer A Customer that has been granted a Maestro License in accordance with the Standards. Maestro Payment Application A Payment Application that stores Maestro Account data. Maestro Word Mark A Mark consisting of the word “Maestro” followed by a registered trademark ® or ™ symbol (depending on its trademark status in a particular country) or the local law equivalent. Definitions Maestro Acceptance Mark Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 “Maestro” must appear in English and be spelled correctly, with the letter “M” capitalized. “Maestro” must not be abbreviated, hyphenated, used in the plural or possessive, translated from English into another language, or appear in another alphabet except for specific authorized versions in Chinese (translation), Arabic (transliteration), Georgian (transliteration), and Korean (transliteration). Maestro is the exclusive owner of the Maestro Word Mark. Magnetic Stripe Mode Contactless Transaction A Contactless Transaction in which the Terminal receives static and dynamic data from the chip and constructs messages that can be transported in a standard magnetic stripe message format, in compliance with the Standards. Manual Cash Disbursement Transaction A disbursement of cash performed upon the acceptance of a Card by a Customer financial institution teller. A Manual Cash Disbursement Transaction is identified with MCC 6010 (Manual Cash Disbursements—Customer Financial Institution). Marks The names, logos, trade names, logotypes, trademarks, service marks, trade designations, and other designations, symbols, and marks that the Corporation owns, manages, licenses, or otherwise Controls and makes available for use by Customers and other authorized entities in accordance with a License. A “Mark” means any one of the Marks. Mastercard Mastercard International Incorporated, a Delaware U.S.A. corporation. Mastercard Acceptance Mark A Mark consisting of the Mastercard Brand Mark or Mastercard Symbol placed on the dark blue acceptance rectangle, as available at www.mastercardbrandcenter.com. Mastercard Access Device An Access Device that uses at least one Mastercard Payment Application to provide access to a Mastercard Account when used at a Terminal. Definitions Magnetic Stripe Mode Contactless Transaction Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Mastercard Account Any type of account (credit, debit, prepaid, commercial, etc.) identified as a Mastercard Account with a primary account number (PAN) that begins with a BIN in the range of 222100 to 272099 or 510000 to 559999. Mastercard Biometric Card A Mastercard or Maestro Chip Card containing a fingerprint sensor and compliant with the Corporation’s biometric Standards. Mastercard-branded Application Identifier (AID) Any of the Corporation’s EMV chip application identifiers for Mastercard, Maestro, and Cirrus Payment Applications as defined in the M/Chip Requirements manual. Mastercard Brand Mark A Mark consisting of the Mastercard Word Mark as a custom lettering legend placed within the Mastercard Interlocking Circles Device. The Corporation is the exclusive owner of the Mastercard Brand Mark. The Mastercard Symbol is also a Mastercard Brand Mark. Mastercard Card A Card that provides access to a Mastercard Account. Mastercard Cloud-Based Payments A specification that facilitates the provisioning of Digitized Account data into a Host Card Emulation (HCE) server and the use of the remotely stored Digitized Account data, along with single-use payment credentials, in Transactions effected by a Cardholder using a Mobile Payment Device. The Mastercard Digital Enablement Service offers Mastercard Cloud-Based Payments as an on-behalf service. Mastercard Consumer-Presented QR Transaction A Mastercard Consumer-Presented QR Transaction is an EMV Chip Transaction effected through the presentment of a QR Code by the Cardholder, using a Mobile Payment Device, and Definitions Mastercard Account Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 the capture of the QR Code by the Merchant containing the Transaction Data required to initiate a Transaction. Each Mastercard Consumer-Presented QR Transaction must comply with all requirements set forth in the Standards applicable to a Mastercard Consumer-Presented QR Transaction, including but not limited to those herein, in the technical specifications for authorization messages, in the M/Chip Requirements for Contact and Contactless manual, and in the Mastercard Cloud-Based Payments (MCBP) documentation. Mastercard Customer A Customer that has been granted a Mastercard License in accordance with the Standards. See also Member. Mastercard Digital Enablement Service Any of the services offered by the Corporation exclusively to Customers for the digital enablement of Account and/or PTA Account data, including but not limited to ID&V Service, Tokenization Service, Digitization Service, Token Mapping Service, Mastercard Cloud-Based Payments, Digital Card Image Database, CVC 3 pre-validation and other on-behalf cryptographic validation services, and Service Requests. Mastercard Europe Mastercard Europe SA, a Belgian private limited liability (company). Mastercard Incorporated Mastercard Incorporated, a Delaware U.S.A. corporation. Mastercard Payment Application A Payment Application that stores Mastercard Account data. Mastercard Safety Net A service offered by the Corporation that performs fraud monitoring at the network level for all Transactions processed on the Mastercard Network. The service invokes targeted measures to provide protective controls on behalf of a participating Issuer to assist in minimizing losses in the event of a catastrophic fraud attack. Definitions Mastercard Customer Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Mastercard Symbol A Mark consisting of the Mastercard interlocking circles device. The Corporation is the exclusive owner of the Mastercard Symbol. The Mastercard Symbol is also a Mastercard Brand Mark. Mastercard Token A Token allocated from a Mastercard Token Account Range that the Corporation has designated to an Issuer or PTA Customer and that corresponds to an Account PAN or a PTA Account Number. The Corporation exclusively owns all right, title, and interest in any Mastercard Token. Mastercard Token Account Range A bank identification number (BIN) or portion of a BIN (“BIN range”) designated by the Corporation to an Issuer or PTA Customer for the allocation of Mastercard Tokens in a particular Token implementation. A Mastercard Token Account Range must be designated from a BIN reserved for the Corporation by the ISO Registration Authority and for which the Corporation is therefore the “BIN Controller,” as such term is defined in the EMV Payment Tokenization Specification Technical Framework (also see the term “Token BIN Range” in that document). A Mastercard Token Account Range is identified in the Corporation’s routing tables as having the same attributes as the corresponding Account PAN Range or the range of PTA Account Numbers. Mastercard Token Vault The Token Vault owned and operated by Mastercard and enabled by means of the Mastercard Digital Enablement Service. Mastercard Word Mark A Mark consisting of the word “Mastercard” followed by a registered trademark ® symbol or the local law equivalent. “Mastercard” must appear in English and be spelled correctly, with the letter “M” capitalized. “Mastercard” must not be abbreviated, hyphenated, used in the plural or possessive, translated from English into another language, or appear in another alphabet except for specific authorized versions in Chinese (translation), Arabic (transliteration), Georgian (transliteration), and Korean (transliteration). The Corporation is the exclusive owner of the Mastercard Word Mark. Definitions Mastercard Symbol Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Member, Membership A financial institution or other entity that is approved to be a Mastercard Customer in accordance with the Standards and which, as a Mastercard Customer, has been granted membership (“Membership”) in and has become a member (“Member”) of the Corporation. “Membership” also means “Participation”. Merchandise Transaction The purchase by a Cardholder of merchandise or a service, but not currency, in an approved category at an ATM Terminal and dispensed or otherwise provided by such ATM Terminal. A Merchandise Transaction is identified with MCC 6012 (Merchandise and Services—Customer Financial Institution), unless otherwise specified. Merchant A retailer, or any other person, firm or corporation that, pursuant to a Merchant Agreement, agrees to accept Cards when properly presented. Merchant Agreement An agreement between a Merchant and a Customer that sets forth the terms pursuant to which the Merchant is authorized to accept Cards. Merchant Token Requestor A Merchant Token Requestor is a Merchant that connects directly to the Mastercard Digital Enablement Service (MDES) for the purpose of Tokenizing a Mastercard or Maestro Account primary account number (PAN) provided by a Cardholder for use in a future Transaction with the Merchant. A Merchant Token Requestor is a type of Token Requestor. Mobile Payment Device A Cardholder-controlled mobile device containing a Payment Application compliant with the Standards, and which uses an integrated keyboard and screen to access an Account. A Mobile Payment Device may also be a Contactless Payment Device or a Mastercard Consumer- Presented QR payment device. Definitions Member, Membership Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Mobile POS (MPOS) Terminal An MPOS Terminal enables a mobile device to be used as a POS Terminal. Card “reading” and software functionality that meets the Corporation’s requirements may reside within the mobile device, on a server accessed by the mobile device, or in a separate accessory connected (such as via Bluetooth or a USB port) to the mobile device. The mobile device may be any multi-purpose mobile computing platform, including, by way of example and not limitation, a feature phone, smart phone, tablet, or personal digital assistant (PDA). MoneySend Payment Transaction A type of Payment Transaction that is effected pursuant to, and subject to, the Mastercard MoneySend and Funding Transactions Program Standards. Multi-Account Chip Card A Chip Card with more than one Account encoded in the chip. Multi-Factor Authentication Method, MFA Method A Multi-Factor Authentication (MFA) Method is an authentication solution that includes two or more factors from the following categories: possession, knowledge, or inherence, with no more than one factor in any single category. Non-Mastercard Funding Source Any funding source used to fund a PTA Transaction other than an Account. Non-Mastercard Receiving Account Any receiving account used to receive a PTA Transaction other than an Account. Non-Mastercard Systems and Networks Standards The applicable rules, regulations, by-laws, standards, procedures, and any other obligations or requirements of an applicable payment network or system that is not owned, operated, or controlled by the Corporation. Definitions Mobile POS (MPOS) Terminal Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 On-behalf Token Requestor A Digital Activity Customer or other Customer, approved by the Corporation to conduct Digital Activity and authorized to Tokenize a Mastercard or Maestro primary account number (PAN) using the Mastercard Digital Enablement Service (MDES) on behalf of a DWO or Merchant. On-Device Cardholder Verification The use of a CDCVM as the CVM for a Transaction. Originating Account Holder The Account Holder originating the PTA Transaction. Originating Institution (OI) A PTA Customer that Participates in a Payment Transfer Activity as an originator of PTA Transactions. Ownership, Owned As used herein, ownership has such meaning as the Corporation deems appropriate in its sole discretion given the context of the usage of the term in all facts and circumstances the Corporation deems appropriate to consider. As a general guideline, ownership often means to own indirectly, legally, or beneficially more than fifty percent (50 percent) of an entity. Participation The right to participate in Activity, Digital Activity, and/or Payment Transfer Activity granted to a Customer by the Corporation. For a Mastercard Customer, Participation is an alternative term for Membership. Pass-through Digital Wallet Functionality which can be used at more than one Merchant, and by which the Pass-through Digital Wallet Operator stores Mastercard or Maestro Account data provided by the Cardholder to the DWO for purposes of effecting a payment initiated by the Cardholder to a Merchant or Definitions On-behalf Token Requestor Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Sponsored Merchant, and upon the performance of a Transaction, transfers the Account data to the Merchant or Sponsored Merchant or to its Acquirer or the Acquirer’s Service Provider. Pass-through Digital Wallet Operator (DWO) A Digital Activity Customer or other Customer, approved by the Corporation to engage in Digital Activity, that operates a Pass-through Digital Wallet. Payment Account Reference (PAR) A unique non-financial alphanumeric value assigned to an Account PAN or PTA Account Number that is used to link the Account PAN or PTA Account Number to all of its corresponding Tokens. Payment Application A package of code and data stored in a Card, an Access Device, a server, or a combination of Access Device and server, that when exercised outputs a set of data that may be used to effect a Transaction, in accordance with the Standards. A Mastercard Payment Application, Maestro Payment Application, and Cirrus Payment Application is each a Payment Application. Payment Facilitator A Service Provider registered by an Acquirer to facilitate the acquiring of Transactions by the Acquirer from Sponsored Merchant, and which in doing so, performs PF Program Service. Payment Transaction A PTA Transaction that transfers funds to an Account. A Payment Transaction is not a credit that reverses a previous purchase. Includes MoneySend Payment Transaction and Gaming Payment Transaction. Payment Transfer Activity(ies) (PTA) The undertaking of any lawful act that can be undertaken only pursuant to a PTA Agreement or pursuant to a License granted by the Corporation. Participation in a PTA Program is Payment Transfer Activity. Definitions Pass-through Digital Wallet Operator (DWO) Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Personal Data Any information relating to an identified or identifiable individual, including contact information, demographic information, passport number, Social Security number or other national identification number, bank account information, Primary Account Number and authentication information (e.g., identification codes, passwords). Point of Interaction (POI) The location at which a Transaction occurs or a PTA Transaction originates, as determined by the Corporation. Point-of-Sale (POS) Terminal One of the following: • An attended or unattended device, including any commercial off-the-shelf (COTS) or other device enabled with mobile point-of-sale (MPOS) functionality, that is in the physical possession of a Merchant and is deployed in or at the Merchant’s premises, and which enables a Cardholder to use a Card or Access Device to effect a Transaction for the purchase of products or services sold by such Merchant; or • A Bank Branch Terminal. A POS Terminal must comply with the POS Terminal security and other applicable Standards. Point–of–Sale (POS) Transaction The sale of products or services by a Merchant to a Cardholder pursuant to acceptance of a Card by the Merchant or Manual Cash Disbursement Transaction. A POS Transaction may be a Card-present Transaction taking place in a face-to-face environment or at an unattended POS Terminal, or a Card-not-present Transaction taking place in a non-face-to-face environment (for example, an e-commerce, mail order, phone order, or recurring payment Transaction). Portfolio All Cards issued bearing the same major industry identifier, BIN/IIN, and any additional digits that uniquely identify Cards for routing purposes. Definitions Personal Data Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Principal Customer, Principal A Customer that participates directly in Activity using its assigned BINs/IINs and which may Sponsor one or more Affiliates. Processed PTA Transaction A PTA Transaction which is: 1. Initiated by or on behalf of the Originating Institution via the Corporation System in accordance with the Standards; and 2. Cleared, meaning the Originating Institution transferred the PTA Transaction data within the applicable time frame to the Corporation via the Corporation System, for the purpose of a transfer of funds via the Corporation System, and such PTA Transaction data is subsequently transferred by the Corporation to the Receiving Customer for such purpose. Processed Transaction A Transaction which is: 1. Authorized by the Issuer via the Interchange System, unless a properly processed offline Chip Transaction approval is obtained or no authorization is required, in accordance with the Standards; and 2. Cleared, meaning the Acquirer transferred the Transaction Data within the applicable presentment time frame to the Corporation via the Interchange System, for the purpose of a transfer of funds via the Interchange System, and such Transaction Data is subsequently transferred by the Corporation to the Issuer for such purpose. Processing of Personal Data Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of such data. Program A Customer’s Card issuing program, Merchant acquiring program, ATM Terminal acquiring program, Digital Activity program, and/or a PTA Program in which a Customer is Participating. Definitions Principal Customer, Principal Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Program Service Any service described in the Standards that directly or indirectly supports a Program and regardless of whether the entity providing the service is registered as a Service Provider of one or more Customers. The Corporation has the sole right to determine whether a service is a Program Service. PTA Account A PTA Originating Account and/or a PTA Receiving Account. PTA Account Number The account number allocated to a PTA Account by a PTA Customer. PTA Account Portfolio All PTA Accounts issued by a PTA Customer. PTA Agreement The agreement between the Corporation and a PTA Customer granting the PTA Customer the right to Participate in a PTA Program, in accordance with the Standards. PTA Customer A Customer that Participates in a PTA Program pursuant to a PTA Agreement. PTA Originating Account The funding source of the Originating Account Holder, from where funds are acquired by the Originating Institution to initiate a PTA Transaction. PTA Program A type of Payment Transfer Activity that is identified in the applicable Standards as being a PTA Program, including the MoneySend Program, the Mastercard Merchant Presented QR Program, Definitions Program Service Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 the Mastercard Send Cross-Border Service, and the Mastercard Gaming and Gambling Payments Program. PTA Receiving Account The Account or, if applicable for a particular PTA Program (as set forth in the Standards for such PTA Program), the Non-Mastercard Receiving Account, held by a Receiving Account Holder and to which the Receiving Customer must ensure receipt of a PTA Transaction. PTA Settlement Guarantee Covered Program A PTA Settlement Obligation arising from a PTA Transaction conducted pursuant to a PTA Program that is identified in the applicable Standards as being a PTA Settlement Guarantee Covered Program. PTA Settlement Obligation A financial obligation of a Principal or Association PTA Customer to another Principal or Association PTA Customer arising from a PTA Transaction. PTA Transaction A financial transaction in which funds are transferred from an Originating Institution to a Receiving Customer on behalf of Account Holders pursuant to a PTA Program. Quick Response (QR) Code An ISO 18004-compliant encoding and visualization of data. Receiving Account Holder The Account Holder receiving the PTA Transaction. Receiving Agent A PTA Customer that Participates in Payment Transfer Activity as an agent for the purpose of receiving a PTA Transaction. Definitions PTA Receiving Account Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Receiving Customer A Receiving Agent or a Receiving Institution. Receiving Institution (RI) A PTA Customer that Participates in Payment Transfer Activity as a receiver of PTA Transactions on behalf of a Receiving Account Holder. Region A geographic region as defined by the Corporation from time to time. See Appendix A of the Mastercard Rules manual. Remote Electronic Transaction In the Europe Region, all types of Card-not-present Transaction (e-commerce Transactions, recurring payments, installments, Card-on-file Transactions, in-app Transactions, and Transactions completed through a Digital Wallet, including MasterPass®). Mail order and telephone order (MO/TO) Transactions and Transactions completed with anonymous prepaid Cards are excluded from this definition. Service Provider A person that performs Program Service. The Corporation has the sole right to determine whether a person is or may be a Service Provider and if so, the category of Service Provider. A Service Provider is an agent of the Customer that receives or otherwise benefits from Program Service, whether directly or indirectly, performed by such Service Provider. Settlement Obligation A financial obligation of a Principal or Association Customer to another Principal or Association Customer arising from a Transaction. Definitions Receiving Customer Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Shared Deposit Transaction A deposit to a savings Account or checking Account conducted at an ATM Terminal located in the U.S. Region, initiated with a Card issued by a U.S. Region Customer other than the Acquirer, and processed through the Mastercard ATM Network. Solicitation, Solicit An application, advertisement, promotion, marketing communication, or the like distributed as printed materials, in electronic format (including but not limited to an email, website, mobile application, or social media platform), or both intended to solicit the enrollment of a person or entity as a Cardholder or Account Holder or as a Merchant. To “Solicit” means to use a Solicitation. Sponsor, Sponsorship The relationship described in the Standards between: • a Principal or Association and an Affiliate that engages in Activity indirectly through the Principal or Association, in which case, the Principal or Association is the Sponsor of the Affiliate and the Affiliate is Sponsored by the Principal or Association; • a Payment Facilitator and a Sponsored Merchant, in which case the Payment Facilitator is the Sponsor of the Sponsored Merchant and the Sponsored Merchant is Sponsored by the Payment Facilitator; or • a Digital Activity Sponsoring Customer and a Sponsored Digital Activity Entity, in which case the Digital Activity Sponsoring Customer is the Sponsor of the Sponsored Digital Activity Entity. “Sponsorship” means the Sponsoring of a Customer, a Sponsored Merchant, or a Sponsored Digital Activity Entity. Sponsored Digital Activity Entity A wholly-owned subsidiary (or other affiliated entity as approved by the Corporation) of a Digital Activity Sponsoring Customer. The Sponsored Digital Activity Entity may be approved at the sole discretion of the Corporation to participate in Digital Activity pursuant to a Digital Activity Agreement or other agreement with the Corporation. Definitions Shared Deposit Transaction Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Sponsored Merchant A merchant that, pursuant to an agreement with a Payment Facilitator, is authorized to accept Cards when properly presented. A Sponsored Merchant is also referred to as a Submerchant. Sponsored Merchant Agreement An agreement between a Sponsored Merchant and a Payment Facilitator that sets forth the terms pursuant to which the Sponsored Merchant is authorized to accept Cards. A Sponsored Merchant Agreement is also referred to as a Submerchant Agreement. Staged Digital Wallet Functionality that can be used at more than one retailer, and by which the Staged Digital Wallet Operator effects a two-stage payment to a retailer to complete a purchase initiated by a Cardholder. The following may occur in either order: • Payment stage—In the payment stage, the Staged DWO pays the retailer by means of: – A proprietary non-Mastercard method (and not with a Mastercard Card); or – A funds transfer to an account held by the Staged DWO for or on behalf of the retailer. • Funding stage—In the funding stage, the Staged DWO uses a Mastercard or Maestro Account provided to the Staged DWO by the Cardholder (herein, the “funding account”) to perform a transaction that funds or reimburses the Staged Digital Wallet. The retailer does not receive Mastercard or Maestro Account data or other information identifying the network brand and payment card issuer for the funding account. Staged Digital Wallet Operator (DWO) A registered Service Provider that operates a Staged Digital Wallet. Standards The organizational documents, operating rules, regulations, policies, and procedures of the Corporation, including but not limited to any manuals, guides, announcements or bulletins, as may be amended from time to time. Definitions Sponsored Merchant Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Stand-In Parameters A set of authorization requirements established by the Corporation or the Issuer that are accessed by the Interchange System using the Stand-In Processing Service to determine the appropriate responses to authorization requests. Stand-In Processing Service A service offered by the Corporation in which the Interchange System authorizes or declines Transactions on behalf of and uses Stand-In Parameters provided by the Issuer (or in some cases, by the Corporation). The Stand-In Processing Service responds only when the Issuer is unavailable, the Transaction cannot be delivered to the Issuer, or the Issuer exceeds the response time parameters set by the Corporation. Strong Customer Authentication (SCA) Authentication as required by the 2nd Payment Services Directive (Directive [EU] 2015/2366 of 25 November 2015) Regulatory Technical Standards on Strong Customer Authentication (as amended and replaced from time to time). Sub-licensee A person authorized in writing to use a Mark either by a Licensee in accordance with the Standards or by the Corporation. Terminal Any attended or unattended device capable of the electronic capture and exchange of Account data that meets the Corporation requirements for Terminal eligibility, functionality, and security, and permits a Cardholder to effect a Transaction in accordance with the Standards. An ATM Terminal, Bank Branch Terminal, and POS Terminal is each a type of Terminal. Third Party Processor (TPP) A Service Provider that performs TPP Program Service. Definitions Stand-In Parameters Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Token A numeric value that (i) is a surrogate for the primary account number (PAN) used by a payment card issuer to identify a payment card account or is a surrogate for the PTA Account Number used by a PTA Customer to identify a PTA Account; (ii) is issued in compliance with the EMV Payment Tokenization Specification Technical Framework; and (iii) passes the basic validation rules for a PAN, including the Luhn Formula for Computing Modulus 10 Check Digit. See also Mastercard Token. Tokenization, Tokenize The process by which a Mastercard Token replaces an Account PAN or a PTA Account Number. Token Requestor An entity that requests the replacement of Account PANs with Mastercard Tokens. Token Vault A repository of tokens that are implemented by a tokenization system, which may also perform primary account number (PAN) mapping and cryptography validation. Transaction A financial transaction arising from the proper acceptance of a Card or Account bearing or identified with one or more of the Brand Marks, either alone or in combination with the marks of another payment scheme, at a Card acceptance location and identified in messages with a Card Program identifier. Transaction Data Any data and/or data element or subelement that the Standards and/or the Corporation’s interface specifications require to be used to initiate, authorize, clear, and/or settle a Transaction or PTA Transaction (whether authorized, cleared, and/or settled via the Interchange System or otherwise) or that the Corporation requires to be provided. Definitions Token Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025 Transaction Management System Performs Transaction management services for Mastercard Cloud-Based Payments, which may include credential authentication, application cryptogram mapping and validation, ensuring synchronization with the Credentials Management System, and forwarding of Transactions to the Issuer for authorization. Trusted Service Manager Provisions an Access Device with the Payment Application, personalization data, or post- issuance application management commands by means of an over-the-air (OTA) communication channel. Virtual Account A Mastercard Account issued without a physical Card or Access Device. A Virtual Account cannot be electronically read. Volume The aggregate financial value of a group of Transactions. “Volume” does not mean the number of Transactions. Wallet Token Requestor A Wallet Token Requestor is a Pass-through DWO that connects directly to the Mastercard Digital Enablement Service (MDES) for the purpose of Tokenizing a Mastercard or Maestro Account primary account number (PAN) provided by a Cardholder for use in a future Transaction. Word Mark A Mark consisting of the name of one of the Corporation’s brands followed by a registered trademark ® or ™ symbol (depending on its trademark status in a particular country) or the local law equivalent. See Cirrus Word Mark, Maestro Word Mark, Mastercard Word Mark. Definitions Transaction Management System Security Rules and Procedures—Merchant Edition • 6 August 2024 ¶ Notices ¶ Following 11 February 2025 Appendix F Privacy and Data Protection Standards for MATCH Pro F.1 Purpose..........................................................................................................................................................211 F.2 Scope..............................................................................................................................................................211 F.3 Definitions.....................................................................................................................................................211 F.4 Acknowledgment of Roles..........................................................................................................................213 F.5 The Corporation and Customer Obligations...........................................................................................214 F.6 Data Transfers .............................................................................................................................................216 F.7 Data Disclosures...........................................................................................................................................216 F.8 Security Measures........................................................................................................................................217 F.9 Confidentiality of Personal Information...................................................................................................218 F.10 Personal Information Breach Notification Requirements...................................................................218 F.11 Personal Information Breach Cooperation and Documentation Requirements.............................218 F.12 Data Protection and Security Audit.......................................................................................................218 F.13 Liability.........................................................................................................................................................219 F.14 Termination of MATCH Pro...................................................................................................................... 219 F.15 Invalidity and Severability.........................................................................................................................219 Annex 1 to Appendix F: Processing of Personal Data.................................................................................. 220 Annex 2 to Appendix F: Technical and Organizational Measures Ensure the Security of the Data.....221 Privacy and Data Protection Standards for MATCH Pro Security Rules and Procedures—Merchant Edition • 11 February 2025 This appendix describes the privacy and data protection for MATCH Pro as they relate to the Applicable Data Protection Law. F.1 Purpose This appendix provides Standards regarding the Processing of Personal Information of Individuals subject to Applicable Data Protection Law by the Corporation and its Customers (collectively referred to in this appendix as the "Parties") in the context of Mastercard Alert to Control High-risk (Merchants) (MATCH Pro) system. F.2 Scope The Standards in this appendix supplement the privacy and data protection Standards contained in Section 1.5 of this manual and Rule 3.13 of the Mastercard Rules to the extent that the requirements pertain to the Processing of Personal Information subject to Applicable Data Protection Law in the context of MATCH Pro. In the event of a conflict, the Standards in this appendix take precedence. F.3 Definitions As used solely for the purposes of this appendix, the following terms have the meanings set forth below. Capitalized terms not otherwise defined herein have the meaning provided in Appendix E of this manual. Applicable Data Protection Law Any Law, statute, declaration, decree, legislation, enactment, order, ordinance, regulation, rule, circular (as amended and replaced from time to time) that relates to the protection of individuals with regards to the Processing of Personal Information to which the Parties are policies pertaining to proprietary rights, trademarks, translations, and details ¶ about the availability of additional information online. ¶ Proprietary Rights ¶ The information contained in this document is proprietary and confidential to Mastercard ¶ International Incorporated, one or more of its affiliated entities (collectively “Mastercard”), or ¶ both. ¶ This material may not be duplicated, published, or disclosed, in whole or in part, without the ¶ prior written permission of Mastercard. ¶ Trademarks ¶ Trademark notices and symbols used in this document reflect the registration status of ¶ Mastercard trademarks in the United States. Consult with the Global Customer Service team or ¶ the Mastercard Law Department for the registration status of particular product, program, or ¶ service names outside the United States. ¶ All third-party product and service names are trademarks or registered trademarks of their ¶ respective owners. ¶ EMV® is a registered trademark of EMVCo LLC in the United States and other countries. For ¶ more information, see http://www.emvco.com. ¶ Disclaimer ¶ Mastercard makes no representations or warranties of any kind, express or implied, with respect ¶ to the contents of this document. Without limitation, Mastercard specifically disclaims all ¶ representations and warranties with respect to this document and any intellectual property ¶ rights subsisting therein or any part thereof, subject, including but not limited to any the EU Data Protection Law; California Consumer Privacy Act of 2018 (California Civil Code §§ 1798.100 to 1798.199) and its implementing regulations ("CCPA"), as amended including by the California Privacy Rights Act ("CPRA"); California's Data Breach Notification statue (California Civ. Code §1798.82 et seq.), the California Commercial Credit Reporting Act (California Civ. Code §1785.41 et seq.); Personal Information Protection and Electronic Documents Act , Quebec's Law 25 (or an Act to modernize legislative provisions as regards the protection of personal information); the Brazil General Data Protection Act; the South Africa Protection of Personal Information Act; the Personal Information Protection Law of the PRC and other PRC Laws relating to privacy and protection of Personal information; Kingdom of Saudi Arabia Personal Data Protection Law (amended 2023) and its Implementing Regulations; Nigeria Data Protection Act 2023 and its subsidiary regulations and guidelines, Turkey Law on the Protection Of Personal Data (DPL) No. 6698 and its regulations and successors; security breach notification Laws; Laws imposing minimum Privacy and Data Protection Standards for MATCH Pro F.1 Purpose Security Rules and Procedures—Merchant Edition • 11 February 2025 security requirements; Laws requiring the secure disposal of records containing certain Personal Information; Laws governing the portability and/or cross-border transfer of Personal Information; and all implied ¶ warranties of title, non-infringement, or suitability other similar international, federal, state, national, provincial, and local requirements; each as applicable, in connection with MATCH Pro. Business The entity which meets the definition of "Business" under CCPA. Controller The entity which alone or jointly with others determines the purposes and the means of the Processing of Personal Information that is subject to Applicable Data Protection Law as appropriated. Criminal Data Any Personal Information relating to criminal convictions, offenses, or related security measures. EEA Standard Contractual Clauses (EEA SCCs) The clauses annexed to the EU Commission Decision 2021/914 of June 4, 2021, on standard contractual clauses for any purpose (the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended from time to time. EU Data Protection Law The EU General Data Protection Regulation 2016/679 GDPR (as amended and replaced from time to time) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC, and as amended and replaced from time to time) and their national implementing legislations; the Swiss Federal Data Protection Act (as amended and replaced from time to time); the Monaco Data Protection Act 2018 (as amended and replaced from time to time); the UK Data Protection Act (as amended and replaced from time to time); and the Data Protection Acts of the EEA countries (as amended and replaced from time to time). Mastercard Binding Corporate Rules (Mastercard BCRs) The Mastercard Binding Corporate Rules as approved by the EEA and UK data protection authorities and available on the Corporation's public facing website. Personal Data or Personal Information Any information relating to an identified or identifiable individual, whether or not Mastercard ¶ has been advised, has reason to know, or is otherwise in fact aware of any information) or ¶ achievement of any particular result. ¶ Translation ¶ A translation of any Mastercard manual, bulletin, release, or other Mastercard document into a ¶ language other than English is intended solely as a convenience to Mastercard customers. ¶ Mastercard provides any translated document to its customers “AS IS” and makes no ¶ representations or warranties of any kind with respect to the translated document, including, ¶ directly or indirectly identifiable, including but not limited to, its accuracy or reliability. In no event shall Mastercard be liable to contact information, demographic information, passport number, Social Security number or other national identification number, bank account information, Primary Account Number and authentication information (e.g., identification codes, passwords) or as defined under the Applicable Privacy and Data Protection Law. Personal Data Breach or Personal Information Breach A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to or other unauthorized Processing of Personal Information transmitted, stored, or otherwise Processed. Privacy and Data Protection Standards for any ¶ damages resulting from reliance on any translated document. The English version of any ¶ Mastercard document will take precedence over any translated version in any legal proceeding. ¶ Notices MATCH Pro F.3 Definitions Security Rules and Procedures—Merchant Edition • 6 August 2024 ¶ 11 February 2025 Processor The entity which Processes Personal Information Available Online ¶ subject to Applicable Data Protection Law on behalf of a Controller. Sensitive Personal Information Any Personal Information subject to the Applicable Data Protection Law revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health or data concerning a natural person's sex life or sexual orientation, as well as any other type of data that will be considered to be sensitive according to any future revision of EU Data Protection Law; or any Personal Information that is defined as "sensitive personal information" under the Applicable Privacy Law. Service Provider The entity which Processes Personal Information subject to CCPA on behalf of a Business as further described in Section F.4. UK Addendum The addendum to the EEA Standard Contractual Clauses issued by the UK Information Commissioner under Section 119A of the UK Data Protection Act 2018 (Version B1.0, in force March 21, 2022). UK Standard Contractual Clauses or UK SCCs The UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued under Section 119A of the Data Protection Act 2018 by the Information Commissioner and laid before Parliament on 2 February 2022 in force 21 March 2022. F.4 Acknowledgment of Roles With respect to Personal Information subject to Applicable Data Protection Law: The Corporation and its Customers acknowledge and confirm that: (1) neither Party acts as a Processor on behalf of the other Party; (2) each Party is an independent Controller; and (3) this appendix does not create a joint-Controllership or a Controller-Processor relationship between the Parties. The Corporation and its Customers acknowledge and agree that the scope of each Party’s role as an independent Controller is as follows: A Customer is a Controller for any Processing, including disclosing Personal Information to the Corporation, for the purpose of developing enhanced or incremental risk information to aid the Customer in its own determination of risk in its Merchant acquiring business. The Corporation is a Controller for any Processing for the purpose of operating MATCH Pro, including product development, support and maintenance, and making the MATCH Pro available to its Customers (e.g., as set out in Chapter 11) and for internal research, fraud, security, and risk management as listed in Rule 3.10 Confidential Information of Customers of the Mastercard provides details about the standards used Rules. Privacy and Data Protection Standards for this document, including times ¶ expressed, language use, and contact information, on the Technical Resource Center (TRC). Go ¶ to the Rules collection of the References section for centralized information. ¶ Notices MATCH Pro F.4 Acknowledgment of Roles Security Rules and Procedures—Merchant Edition • 6 August 202411 February 2025 With respect to Corporation's Processing Personal Information subject to CCPA processed within the MATCH Pro system: Where Acquirer is a Business under CCPA, the Corporation is a Service Provider. F.5 The Corporation and Customer Obligations The Corporation and each Customer independently is responsible for compliance with their obligations under Applicable Data Protection Law in relation to the Processing of Personal Information in accordance with each Party's role as described in Section F.4. Notwithstanding the above, with regard to any Processing of Personal Information of Individuals that a Customer adds to MATCH Pro, the Customer must: 1. Rely on a valid legal ground under Applicable Data Protection Law for each of the Processing purposes, including obtaining Individuals' consent if required or appropriate under Applicable Data Protection Law. 2. Provide appropriate notice to the Individuals regarding (i) the their Processing of Personal Information, in a timely manner (e.g., informing Merchants that Customers are using MATCH Pro to assess Merchants prior to engaging them and about the possible use of MATCH Pro upon termination of the Merchant Agreement) and at the minimum with the elements required under Applicable Data Protection Law, and (ii), as appropriate, the existence of Mastercard BCRs. 3. Provide a link to the Corporation's privacy notice for the Processing in relation to Process of Personal Information in MATCH Pro (available at www.mastercard.com/global/en/vision/ corp-responsibility/commitment-to-privacy/match-privacy.html), subject to Applicable Data Protection Law, where applicable. Where such processing is subject to CCPA, each Customer provide appropriate notice for the MATCH Pro processing activities within Customer's own privacy statement or notice. 4. Take reasonable steps to ensure that Personal Information are accurate, complete, and current; adequate, relevant, and limited to what is necessary in relation to the purposes for which they are Processed. 5. Respond to Individuals' requests to exercise their rights as required under Applicable Data Protection Law: – With respect to the Processing of Personal Information subject to Applicable Data Protection law, such rights may include the right of (i) access, (ii) rectification, (iii) erasure, (iv) data portability, (v) restriction of Processing, and (vi) objection to the Processing, if and as required under Applicable Data Protection Law. – With respect to the Processing of Personal Information subject to CCPA, such rights may include the right to (i) know; (ii) correct inaccurate Personal Information; (iv) request deletion of Personal Information; (iv) opt-out from sale or sharing of Personal Information (where applicable); or (v) request to limit use and disclosure of sensitive personal information (where applicable). The Customer will be responsible for responding to CCPA consumer' requests. Privacy and Data Protection Standards for MATCH Pro F.5 The Corporation and Customer Obligations Security Rules and Procedures—Merchant Edition • 11 February 2025 The Acquirer is responsible for addressing the requests regarding the rectification or correction and erasure or deletion of Personal Information with respect to Acquirer's MATCH Pro listings. The Corporation will provide the Customer with reasonable cooperation in responding to such requests where appropriate. 6. Limit its Processing of Personal Information to the Processing that is necessary for the purpose of developing enhanced or incremental risk information to aid in its own determination of risk in its Merchant acquiring business. 7. Not engage in or otherwise perform any automated decision-making with legal or similar effect or profiling based on Personal Information that are Processed in the context of the MATCH Pro. 8. Add any Sensitive Personal Information, Criminal Data, or government identification information of Individuals to MATCH Pro only as necessary for MATCH Pro. 9. Only Process Personal Information in connection with MATCH Pro for as long as necessary to achieve the purposes for which they are Processed. Any Personal Information processed in relation to MATCH Pro must be deleted or destroyed after a maximum of five (5) years.
Halyard Pay · 2 files
program: ATO Detection
- authority: Mastercard SPME 10.6.2.1, 10.6.4
+ authority: Mastercard SPME 10.6.2.1, 10.6.4, Appendix F
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
 
- # This ATO Detection policy incorporates Mastercard SPME .6.4 updates that affect Account Data Compromise (ADC) event mitigation. It adjusts risk evaluation processes by recognizing that merchants in the U.S. and Canada with high tokenization rates and e-commerce transaction volumes may benefit from reduced or waived reimbursement requirements during such events. This complements detection signal thresholds by informing downstream operational decisions on ADC events, ensuring alignment with Mastercard's revised criteria for operational reimbursement and event assessment.
+ # This ATO Detection policy incorporates updates from Mastercard SPME including Appendix F, which replaces prior privacy and data protection standards related to the Mastercard Alert to Control High-risk (MATCH) system with those specific to MATCH Pro.
+ #
+ # The policy continues to address Account Data Compromise event mitigation by adjusting risk evaluation for transactions, particularly acknowledging requirements for merchants in the U.S. and Canada with high tokenization and e-commerce volumes.
+ #
+ # The inclusion of Appendix F guidance ensures compliance with updated data handling, privacy, and processing standards affecting the use of MATCH Pro data in ATO detection, aligning operational and reimbursement decision processes with Mastercard’s latest criteria.
+ #
+ # For comprehensive privacy and data protection provisions applying to MATCH Pro, reference Mastercard SPME Appendix F.
+

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains involves unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. to perform transactions. Halyard Pay implements employs real-time risk scoring on of authentication events and enforces a combined with mandatory 3DS (3-D Secure) challenge challenges for any session where the computed risk score meets or exceeds the sessions surpassing defined threshold. risk thresholds.

Detection signals

The risk model incorporates multiple uses behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to indicators such as location inconsistencies, device fingerprint, fingerprint changes, transaction velocity breaches, and indicators of credential-stuffing activity. anomalies, and signs of credential-stuffing.

Required actions

  1. Evaluate Analyze each authentication event against using the defined signal list in real time. specified signals instantly.

  2. Compute a normalized Generate a risk score between from 0.0 and to 1.0.

  3. If the risk A score is 0.5 or greater, trigger a mandatory triggers a compulsory 3DS challenge before authorizing the transaction. transaction approval.

  4. Log Document all ATO signals and outcomes in their resolutions within the case management system.

  5. Escalate persistent high-risk accounts to with ongoing high risk for manual assessment by the ATO response team for manual review. team.

  6. In the event On detection of an Account Data Compromise (ADC), ensure that any Terminal Servicer Servicers (TS) involved must promptly initiates a forensic investigation by engage a PCI Forensic Investigator (PFI) to conduct a forensic investigation within 72 hours, and completes hours and complete it expediently.

7. Require Terminal Servicers to revalidate PCI DSS compliance within 90 calendar days of investigation completion and comply with PCI DSS Data Encryption and Software Validation (DESV) Appendix standards within 12 months, as soon as practical. ¶ 7. Confirm that outlined in Mastercard SPME §10.6.2.1.

8. Mandate registration of all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of the forensic investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1. ¶ 8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through with Mastercard Connect within 10 calendar days of awareness, and confirm incident awareness and ensure full cooperation with Mastercard and law enforcement authorities.

  1. Verify timely receipt by Mastercard of unedited Mastercard receives full forensic examination findings. reports without edits.

  2. Ensure Confirm that all required recommended containment actions identified in measures from forensic reports reviews are completed enacted by the Terminal Servicers involved. Servicers.

These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened align with Mastercard's updated protocols for Covered Programs and MATCH Pro privacy standards (Mastercard SPME Appendix F), ensuring robust risk mitigation and compliance in handling ATO and ADC event protocols, supporting minimized risk and financial exposure through compliance and timely remediation. events.

Source authority: Mastercard SPME §6.2, §10.6.2.1.§10.6.2.1, Appendix F.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains involves unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. to perform transactions. Halyard Pay implements employs real-time risk scoring on of authentication events and enforces a combined with mandatory 3DS (3-D Secure) challenge challenges for any session where the computed risk score meets or exceeds the sessions surpassing defined threshold. risk thresholds.

Detection signals

The risk model incorporates multiple uses behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to indicators such as location inconsistencies, device fingerprint, fingerprint changes, transaction velocity breaches, and indicators of credential-stuffing activity. anomalies, and signs of credential-stuffing.

Required actions

  1. Evaluate Analyze each authentication event against using the defined signal list in real time. specified signals instantly.

  2. Compute a normalized Generate a risk score between from 0.0 and to 1.0.

  3. If the risk A score is 0.5 or greater, trigger a mandatory triggers a compulsory 3DS challenge before authorizing the transaction. transaction approval.

  4. Log Document all ATO signals and outcomes in their resolutions within the case management system.

  5. Escalate persistent high-risk accounts to with ongoing high risk for manual assessment by the ATO response team for manual review. team.

  6. In the event On detection of an Account Data Compromise (ADC), ensure that any Terminal Servicer Servicers (TS) involved must promptly initiates a forensic investigation by engage a PCI Forensic Investigator (PFI) to conduct a forensic investigation within 72 hours, and completes hours and complete it expediently.

7. Require Terminal Servicers to revalidate PCI DSS compliance within 90 calendar days of investigation completion and comply with PCI DSS Data Encryption and Software Validation (DESV) Appendix standards within 12 months, as soon as practical. ¶ 7. Confirm that outlined in Mastercard SPME §10.6.2.1.

8. Mandate registration of all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of the forensic investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1. ¶ 8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through with Mastercard Connect within 10 calendar days of awareness, and confirm incident awareness and ensure full cooperation with Mastercard and law enforcement authorities.

  1. Verify timely receipt by Mastercard of unedited Mastercard receives full forensic examination findings. reports without edits.

  2. Ensure Confirm that all required recommended containment actions identified in measures from forensic reports reviews are completed enacted by the Terminal Servicers involved. Servicers.

These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened align with Mastercard's updated protocols for Covered Programs and MATCH Pro privacy standards (Mastercard SPME Appendix F), ensuring robust risk mitigation and compliance in handling ATO and ADC event protocols, supporting minimized risk and financial exposure through compliance and timely remediation. events.

Source authority: Mastercard SPME §6.2, §10.6.2.1.§10.6.2.1, Appendix F.

Source authority: Mastercard SPME §13.1.2.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -1,5 +1,5 @@
 program: ATO Detection
-authority: Mastercard SPME 10.6.2.1, 10.6.4
+authority: Mastercard SPME 10.6.2.1, 10.6.4, Appendix F
 risk_threshold_for_3ds_challenge: 0.5
 risk_score_range: [0.0, 1.0]
 signals:
@@ -12,4 +12,11 @@
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
 
-# This ATO Detection policy incorporates Mastercard SPME .6.4 updates that affect Account Data Compromise (ADC) event mitigation. It adjusts risk evaluation processes by recognizing that merchants in the U.S. and Canada with high tokenization rates and e-commerce transaction volumes may benefit from reduced or waived reimbursement requirements during such events. This complements detection signal thresholds by informing downstream operational decisions on ADC events, ensuring alignment with Mastercard's revised criteria for operational reimbursement and event assessment.+# This ATO Detection policy incorporates updates from Mastercard SPME including Appendix F, which replaces prior privacy and data protection standards related to the Mastercard Alert to Control High-risk (MATCH) system with those specific to MATCH Pro.
+#
+# The policy continues to address Account Data Compromise event mitigation by adjusting risk evaluation for transactions, particularly acknowledging requirements for merchants in the U.S. and Canada with high tokenization and e-commerce volumes.
+#
+# The inclusion of Appendix F guidance ensures compliance with updated data handling, privacy, and processing standards affecting the use of MATCH Pro data in ATO detection, aligning operational and reimbursement decision processes with Mastercard’s latest criteria.
+#
+# For comprehensive privacy and data protection provisions applying to MATCH Pro, reference Mastercard SPME Appendix F.
+

--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -1,24 +1,24 @@
 # Account-Takeover (ATO) Detection
 
-Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.
+Account-takeover fraud involves unauthorized access to a cardholder's account to perform transactions. Halyard Pay employs real-time risk scoring of authentication events combined with mandatory 3DS challenges for sessions surpassing defined risk thresholds.
 
 ## Detection signals
 
-The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.
+The risk model uses behavioral indicators such as location inconsistencies, device fingerprint changes, transaction velocity anomalies, and signs of credential-stuffing.
 
 ## Required actions
 
-1. Evaluate each authentication event against the defined signal list in real time.
-2. Compute a normalized risk score between 0.0 and 1.0.
-3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.
-4. Log all ATO signals and outcomes in the case management system.
-5. Escalate persistent high-risk accounts to the ATO response team for manual review.
-6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical.
-7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of the forensic investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1.
-8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities.
-9. Verify timely receipt by Mastercard of unedited forensic examination findings.
-10. Ensure that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved.
+1. Analyze each authentication event using the specified signals instantly.
+2. Generate a risk score from 0.0 to 1.0.
+3. A score ≥ 0.5 triggers a compulsory 3DS challenge before transaction approval.
+4. Document all ATO signals and their resolutions within the case management system.
+5. Escalate accounts with ongoing high risk for manual assessment by the ATO team.
+6. On detection of an Account Data Compromise (ADC), Terminal Servicers (TS) must promptly engage a PCI Forensic Investigator (PFI) to conduct a forensic investigation within 72 hours and complete it expediently.
+7. Require Terminal Servicers to revalidate PCI DSS compliance within 90 calendar days of investigation completion and comply with PCI DSS Data Encryption and Software Validation (DESV) Appendix standards within 12 months, as outlined in Mastercard SPME §10.6.2.1.
+8. Mandate registration of all involved Terminal Servicers with Mastercard Connect within 10 calendar days of incident awareness and ensure full cooperation with Mastercard and law enforcement authorities.
+9. Verify Mastercard receives full forensic examination reports without edits.
+10. Confirm that all recommended containment measures from forensic reviews are enacted by the Terminal Servicers.
 
-These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened ADC event protocols, supporting minimized risk and financial exposure through compliance and timely remediation.
+These controls align with Mastercard's updated protocols for Covered Programs and MATCH Pro privacy standards (Mastercard SPME Appendix F), ensuring robust risk mitigation and compliance in handling ATO and ADC events.
 
-Source authority: Mastercard SPME §6.2, §10.6.2.1.+Source authority: Mastercard SPME §6.2, §10.6.2.1, Appendix F.