Mastercard SPME §13.1.2
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Appendix A Omitted
This appendix has been omitted.
Omitted
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Appendix B Omitted
This appendix has been omitted.
Omitted
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Appendix C Omitted
This appendix has been omitted.
Omitted
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Appendix D Covered Programs Privacy and Data
Protection Standards
This appendix describes the privacy and data protection Standards for Covered Programs as they relate
to European Union (EU) Data Protection Law.
D.1 Purpose......................................................................................................................................................... 150 158
D.2 Scope.............................................................................................................................................................150 Scope.............................................................................................................................................................158
D.3 Definitions.....................................................................................................................................................150 Definitions.....................................................................................................................................................158
D.4 Acknowledgment of Roles......................................................................................................................... 151 159
D.5 The Corporation and Customer Obligations..........................................................................................152 Obligations..........................................................................................160
D.6 Data Transfers.............................................................................................................................................153 Transfers.............................................................................................................................................161
D.7 Data Disclosures..........................................................................................................................................153 Disclosures..........................................................................................................................................161
D.8 Security Measures.......................................................................................................................................154 Measures.......................................................................................................................................162
D.9 Confidentiality of Personal Data..............................................................................................................154 Data..............................................................................................................162
D.10 Personal Data Breach Notification Requirements..............................................................................154 Requirements..............................................................................162
D.11 Personal Data Breach Cooperation and Documentation Requirements........................................155 Requirements........................................163
D.12 Data Protection and Security Audit......................................................................................................155 Audit......................................................................................................163
D.13 Liability........................................................................................................................................................155 Liability........................................................................................................................................................163
D.14 Termination of the Covered Programs Use..........................................................................................156 Use..........................................................................................164
D.15 Invalidity and Severability........................................................................................................................156 Severability........................................................................................................................164
Annex 1 to Appendix D: Processing of Personal Data .................................................................................156 .................................................................................164
Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data.... 157 165
Covered Programs Privacy and Data Protection Standards
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
D.1 Purpose
This appendix provides Standards regarding the Processing of Personal Data of Data Subjects
subject to EU Data Protection Law by the Corporation and its Customers (collectively referred
to in this appendix as the “Parties”"Parties") in the context of the Covered Programs: following covered programs: Account Data ¶
Data Compromise events, Mastercard Alert to Control High-risk (Merchants) (MATCH™) system, the ¶ the Excessive Chargeback Program, the Merchant Registration
Program, and the Franchise ¶ Management Program. Program (collectively, the "Covered Programs"). For
privacy and data protection Standards applicable to Mastercard Alert to Control High-risk
(Merchants) (MATCH™ Pro system), refer to Appendix F of this manual.
D.2 Scope
The Standards in this appendix supplement the privacy and data protection Standards
contained in Section 1.5 of this manual and Rule 3.13 of the Mastercard Rules to the extent that
the requirements pertain to the Processing of Personal Data subject to EU Data Protection Law
in the context of the Covered Programs. In the event of a conflict, the Standards in this
appendix take precedence.
D.3 Definitions
As used solely for the purposes of this appendix, the following terms have the meanings set
forth below. Capitalized terms not otherwise defined herein have the meaning provided in
Appendix E of this manual.
Controller
The entity which alone or jointly with others determines the purposes and the means of the
Processing of Personal Data.
Criminal Data
Any Personal Data relating to criminal convictions, offenses, or related security measures.
EEA Standard Contractual Clauses (EEA SCCs)
The clauses annexed to the EU Commission Decision 2021/914 of June 4, 2021, on standard
contractual clauses for the transfer of personal data to third countries pursuant to Regulation
(EU) 2016/679 of the European Parliament and of the Council as amended from time to time.
EU Data Protection Law
The EU General Data Protection Regulation 2016/679 GDPR (as amended and replaced from
time to time) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC,
and as amended and replaced from time to time) and their national implementing legislations;
the Swiss Federal Data Protection Act (as amended and replaced from time to time); the
Covered Programs Privacy and Data Protection Standards
D.1 Purpose
Security Rules and Procedures—Merchant Edition • 11 February 2025
Monaco Data Protection Act 2018 (as amended and replaced from time to time); the UK Data ¶ Covered Programs Privacy and Data Protection Standards ¶ D.1 Purpose ¶ Security Rules and Procedures—Merchant Edition • 6 August 2024
Protection Act (as amended and replaced from time to time); and the Data Protection Acts of
the EEA countries (as amended and replaced from time to time).
Mastercard Binding Corporate Rules (Mastercard BCRs)
The Mastercard® Binding Corporate Rules as approved by the EEA and UK data protection
authorities and available on the Corporation’s public facing website.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration,
unauthorized disclosure of, or access to or other unauthorized Processing of Personal Data
transmitted, stored, or otherwise Processed.
Processor
The entity which Processes Personal Data on behalf of a Controller.
Sensitive Data
Any Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical
beliefs, trade union membership, genetic data, biometric data, data concerning health or data
concerning a natural person's sex life or sexual orientation, as well as any other type of data
that will be considered to be sensitive according to any future revision of EU Data Protection
Law.
UK Addendum
The addendum to the EEA Standard Contractual Clauses issued by the UK Information
Commissioner under Section 119A of the UK Data Protection Act 2018 (version B1.0, in force
March 21, 2022).
D.4 Acknowledgment of Roles
The Corporation and its Customers acknowledge and confirm that: (1) neither Party acts as a
Processor on behalf of the other Party; (2) each Party is an independent Controller; and (3) this
appendix does not create a joint-Controllership or a Controller-Processor relationship between
the Parties. The Corporation and its Customers acknowledge and agree that the scope of each
Party’s role as an independent Controller is as follows:
•
A Customer is a Controller for any Processing, including disclosing Personal Data to the
Corporation, for the purpose of developing enhanced or incremental risk information to aid
the Customer in its own determination of risk in its Merchant acquiring business.
•
The Corporation is a Controller for any Processing for the purpose of operating the Covered
Programs, including product development, support and maintenance, and making the
Covered Programs available to its Customers (e.g., as set out in Chapter 11) and for internal
Covered Programs Privacy and Data Protection Standards
D.4 Acknowledgment of Roles
Security Rules and Procedures—Merchant Edition • 11 February 2025
research, fraud, security, and risk management as listed in Rule 3.10 "Confidential
Information of Customers" of the Mastercard Rules. ¶ Covered Programs Privacy and Data Protection Standards ¶ D.4 Acknowledgment of Roles ¶ Security Rules and Procedures—Merchant Edition • 6 August 2024
D.5 The Corporation and Customer Obligations
The Corporation and each Customer independently is responsible for compliance with EU Data
Protection Law in relation to the Processing of Personal Data for which it is a Controller as
described in section D.4.
Notwithstanding the above, with regard to any Processing of Personal Data of Data Subjects
that a Customer adds to the Covered Programs, including the Processing for which the
Corporation is the Controller, a Customer must:
1.
Rely on a valid legal ground under EU Data Protection Law for each of the Processing
purposes, including obtaining Data Subjects’ consent if required or appropriate under EU
Data Protection Law.
2.
Provide appropriate notice to the Data Subjects regarding (i) the their Processing of
Personal Data, in a timely manner (e.g., informing Merchants about the possible use of
MATCH upon termination of the Merchant Agreement) and at the minimum with the
elements required under EU Data Protection Law, and (ii), as appropriate, the existence of
Mastercard BCRs. Each Customer must also provide a link to the Corporation’s privacy
notice for the Processing in relation to MATCH (available at https://www.mastercard.com/
global/en/vision/corp-responsibility/commitment-to-privacy/match-privacy.html ), where
applicable.
3.
Take reasonable steps to ensure that Personal Data are accurate, complete, and current;
adequate, relevant, and limited to what is necessary in relation to the purposes for which
they are Processed.
4.
Respond to Data Subjects’ requests to exercise their rights under EU Data Protection Law,
including the right of (i) access, (ii) rectification, (iii) erasure, (iv) data portability, (v)
restriction of Processing, and (vi) objection to the Processing, if and as required under EU
Data Protection Law. The Corporation agrees to cooperate with the Customer in
responding to such requests where appropriate.
5.
Limit its Processing of Personal Data to the Processing that is necessary for the purpose of
developing enhanced or incremental risk information to aid in its own determination of risk
in its Merchant acquiring business.
6.
Not engage in or otherwise perform any automated decision-making or profiling based on
Personal Data that are Processed in the context of the Covered Programs.
7.
Will add any Sensitive Data, Criminal Data, or government identification information of
Data Subjects to the Covered Programs.
8.
Only Process Personal Data in connection with the Covered Programs for as long as
necessary to achieve the purposes for which they are Processed. Any Personal Data
Processed in relation to MATCH must be deleted or destroyed after a maximum of five (5)
years.
Covered Programs Privacy and Data Protection Standards
D.5 The Corporation and Customer Obligations
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
D.6 Data Transfers
A Customer may transfer the Personal Data Processed in connection with the Covered
Programs outside of the EEA, the UK, and Switzerland in accordance with EU Data Protection
Law, including based on the EEA SCCs or the UK Addendum as appropriate.
The Corporation may transfer the Personal Data Processed in connection with the Covered
Programs outside of the EEA, the UK, and Switzerland in accordance with the Mastercard BCRs
or with any other lawful data transfer mechanism that provides an adequate level of protection
under EU Data Protection Law. The Corporation will abide by the Mastercard BCRs when
Processing Personal Data in the context of the Covered Programs.
D.7 Data Disclosures
The Corporation and its Customers must ensure that they will only disclose Personal Data
Processed in the context of the Covered Programs in accordance with EU Data Protection Law,
and in particular that they will require the data recipients to protect the data with at least the
same level of protection as described in this appendix. The Corporation represents and warrants
that it will only disclose Personal Data in accordance with the Mastercard BCRs.
Where the Corporation transfers Personal Data subject to the GDPR or the Swiss Data
Protection Act to a Customer in a country that is not part of the EEA or subject to a European
Commission adequacy decision, the Parties agree that the transfer shall be governed by the
EEA SCCs, which are hereby incorporated into this appendix by reference. The SCCs are
completed as follows: the Parties conclude Module One (controller-to-controller) of the EEA
SCCs. The “data exporter” is Corporation; the “data importer” is Customer; the optional docking
clause in Clause 7 is implemented; the optional paragraph in Clause 11(a) is struck; the
competent supervisory authority in Clause 13(a) shall be the supervisory authority of Belgium;
the governing law in Clause 17 is the law of the Belgium and the courts in Clause 18(b) are the
courts of the Belgium; Annex 1 and 2 to the EEA SCCs are Annex 1 and 2 to this appendix.
The Parties conclude the UK Addendum for transfers of Personal Data subject to the UK Data
Protection Act from Corporation to Customer in a country that is not subject to a UK adequacy
decision. The UK Addendum is hereby incorporated into this appendix by reference. Part 1 of the
UK Addendum is completed as follows: (i) in Table 1, the "Exporter" is Corporation and the
"Importer" is Customer (as set out in the paragraph above), their details are set forth in the
Acquirer license agreement and their signatures are included in the signature page of the
Acquirer license agreement; (ii) in Table 2, the first option is selected and the “Approved EU
SCCs” are those incorporated into this appendix as per the paragraph above; (iii) in Table 3,
Annexes 1 and 2 to the Approved EU SCCs are Annexes 1 and 2 to this appendix respectively;
and (iv) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.
If either Party’s compliance with EU Data Protection Law applicable to transfers of Personal
Data is affected by circumstances outside of either Party’s control, including if a legal
Covered Programs Privacy and Data Protection Standards
D.6 Data Transfers
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
instrument for transfers is invalidated, amended, or replaced, then the Parties will work
together in good faith to reasonably resolve such non-compliance.
D.8 Security Measures
The Corporation and its Customers must implement and maintain a comprehensive written
information security program with appropriate technical and organizational measures to ensure
a level of security appropriate to the risk, which includes, at a minimum, as appropriate: (1) the
pseudonymization and encryption of Personal Data; (2) the ability to ensure the ongoing
confidentiality, integrity, availability, and resilience of processing systems and services; (3) the
ability to restore the availability and access to Personal Data in a timely manner in the event of
a physical or technical incident; and (4) a process for regularly testing, assessing, and evaluating
the effectiveness of technical and organizational measures for ensuring the security of the
Processing.
In assessing the appropriate level of security, the Corporation and its Customers must take into
account the state of the art; the costs of implementation; and the nature, scope, context, and
purposes of Processing of Personal Data; as well as the risk of varying likelihood and severity for
the rights and freedoms of Data Subjects and the risks that are presented by the Processing of
Personal Data, in particular from accidental or unlawful destruction, loss, alteration,
unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise
Processed.
D.9 Confidentiality of Personal Data
The Corporation and its Customers must take steps to ensure that any person acting under
their authority who has access to Personal Data is subject to a duly enforceable contractual or
statutory confidentiality obligation, and if applicable, Process Personal Data in accordance with
the Controller’s instructions.
D.10 Personal Data Breach Notification Requirements
The Parties will assist each other in complying with their Personal Data Breach notification
obligations. Where required under EU Data Protection Law, the Party which became aware of a
Personal Data Breach will notify, without undue delay and, where feasible, not later than 72
hours after having become aware of it, the competent supervisory authority.
When the Personal Data Breach is likely to result in a high risk to the rights and freedoms of
Data Subjects or upon the competent supervisory authority’s request to do so, such Party must
communicate the Personal Data Breach to the Data Subject without undue delay, where
required under EU Data Protection Law.
Covered Programs Privacy and Data Protection Standards
D.8 Security Measures
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
D.11 Personal Data Breach Cooperation and Documentation
Requirements
Each Party must notify the other Party of a Personal Data Breach that relates to Personal Data
Processed in the context of the Covered Programs and for which the other Party is a Controller,
without undue delay, and not later than forty-eight (48) hours after having become aware of a
Personal Data Breach. Each Party must document all Personal Data Breaches, including the
facts relating to the Personal Data Breach, its effects, and the remedial action taken.
D.12 Data Protection and Security Audit
The Corporation and each Customer must conduct audits on a regular basis to control
compliance with EU Data Protection Law, including the security measures provided in section
D.8, and the Corporation must comply with the Mastercard BCRs.
Upon prior written request, the Corporation and each Customer agrees to cooperate and,
within reasonable time, provide the requesting Party with: (1) a summary of the audit reports
demonstrating its compliance with EU Data Protection Law obligations and the Standards in
this appendix, and as applicable Mastercard BCRs, after redacting any confidential and
commercially sensitive information; and (2) confirmation that the audit has not revealed any
material vulnerability, or to the extent that any such vulnerability was detected, that such
vulnerability has been fully remedied.
D.13 Liability
Subject to the liability clauses in the Standards, the Corporation and each Customer agrees
that it will be liable towards Data Subjects for the entire damage resulting from a violation of
EU Data Protection Law with regard to Processing of Personal Data for which it is a Controller.
Where the Parties are involved in the same Processing and where they are responsible for any
damage caused by the Processing of Personal Data, both the Corporation and each responsible
Customer may be held liable for the entire damage in order to ensure effective compensation of
the Data Subject.
If the Corporation paid full compensation for the damage suffered, the Corporation is entitled
to claim back from the Customer(s) that part of the compensation corresponding to each
Customer’s part of responsibility for the damage.
Covered Programs Privacy and Data Protection Standards
D.11 Personal Data Breach Cooperation and Documentation Requirements
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
D.14 Termination of the Covered Programs Use
Mastercard and its Customers agree that, apart from the data retention obligation in section
D.5, paragraph 8, the Standards in this appendix are no longer applicable to a Customer upon
the termination of such Customer’s use of the Covered Programs.
D.15 Invalidity and Severability
If any Standard in this appendix is found by any court or administrative body of competent
jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such Standard
shall not affect any other Standard in this appendix, and all Standards not affected by such
invalidity or unenforceability will remain in full force and effect.
Annex 1 to Appendix D: Processing of Personal Data
A. List of Parties
1.
Data exporter: Corporation
– Name and address of the Corporation as well as the name, position, and contact details
for the Corporation’s contact person: as stipulated in the Acquirer License agreement.
– Activities relevant to the data transferred: Providing the Covered Programs
– Signature and date: as stipulated in the Acquirer License agreement
– Role: controller for the purposes listed in Section D.4 of appendix D.
2.
Data importer: Customer
– Name and address of the Customer as well as the name, position, and contact details for
Customer’s contact person: as stipulated in the Acquirer License agreement
– Activities relevant to the data transferred: participating in, or benefiting from, the
Covered Programs
– Signature and date: as stipulated in the Acquirer License agreement
– Role: controller for the purposes listed in Section D.4 of appendix D
B. Description of the Transfer
Data Subjects
Data Subjects as defined in Appendix E.
Categories of data
Personal Data relating to a Merchant’s principal owners or sole proprietors.
Sensitive Data transferred
The Parties do not Process any Sensitive Data in the context of the Covered Programs.
Covered Programs Privacy and Data Protection Standards
D.14 Termination of the Covered Programs Use
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Frequency of the transfer
Upon Customer’s requests, such as on a per query basis or via batch file transfer.
Nature of the Processing
Collection, storage, analysis, disclosure by transfer or otherwise making available.
Purposes of the transfer(s)
The transfer is made for the purposes set forth in Section D.4 of appendix D.
Period for which the Personal Data will be retained
Personal Data will be retained only for as long as necessary to achieve the relevant purposes for
each of the Covered Programs.
C. Competent Supervisory Authority
The competent supervisory authority in accordance with Clause 13 of the EEA SCCs is the
Belgian Data Protection Authority.
Annex 2 to Appendix D: Technical and Organizational Measures
Ensure the Security of the Data
The Parties will, as a minimum, implement the following types of security measures:
1.
Physical access control
Technical and organizational measures to prevent unauthorized persons from gaining access
to the data processing systems available in premises and facilities (including databases,
application servers and related hardware), where Personal Data are processed, include:
– Establishing security areas, restriction of access paths;
– Establishing access authorizations for employees and third parties;
– Access control system (ID reader, magnetic card, chip card);
– Key management, card-keys procedures;
– Door locking (electric door openers, etc.);
– Security staff, janitors;
– Surveillance facilities, video/CCTV monitor, alarm system;
– Securing decentralized data processing equipment and personal computers.
2.
Virtual access control
Technical and organizational measures to prevent data processing systems from being used
by unauthorized persons include:
– User identification and authentication procedures;
– ID/password security procedures (special characters, minimum length, change of
password);
– Automatic blocking (e.g., password or timeout);
Covered Programs Privacy and Data Protection Standards
Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
– Monitoring of break-in-attempts and automatic turn-off of the user ID upon several
erroneous passwords attempts;
– Creation of one master record per user, user master data procedures, per data
processing environment.
3.
Data access control
Technical and organizational measures to ensure that persons entitled to use a data
processing system gain access only to such Personal Data in accordance with their access
rights, and that Personal Data cannot be read, copied, modified or deleted without
authorization, include:
– Internal policies and procedures;
– Control authorization schemes;
– Differentiated access rights (profiles, roles, transactions and objects);
– Monitoring and logging of accesses;
– Disciplinary action against employees who access Personal Data without authorization;
– Reports of access;
– Access procedure;
– Change procedure;
– Deletion procedure.
4.
Disclosure control
Technical and organizational measures to ensure that Personal Data cannot be read, copied,
modified or deleted without authorization during electronic transmission, transport or
storage on storage media (manual or electronic), and that it can be verified to which
companies or other legal entities Personal Data are disclosed, include:
– Tunneling
– Logging
– Transport security
5.
Entry control
Technical and organizational measures to monitor whether data have been entered,
changed or removed (deleted), and by whom, from data processing systems, include:
– Logging and reporting systems;
– Audit trails and documentation.
6.
Control of instructions
Technical and organizational measures to ensure that Personal Data are processed solely in
accordance with the Instructions of the Controller include:
– Unambiguous wording of the contract;
– Formal commissioning (request form);
– Criteria for selecting the Processor
7.
Availability control
Technical and organizational measures to ensure that Personal Data are protected against
accidental destruction or loss (physical/logical) include:
– Backup procedures;
Covered Programs Privacy and Data Protection Standards
Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
– Mirroring of hard disks (e.g., RAID technology);
– Uninterruptible power supply (UPS);
– Remote storage;
– Anti-virus/firewall systems;
– Disaster recovery plan.
8.
Separation control
Technical and organizational measures to ensure that Personal Data collected for different
purposes can be processed separately include:
– Separation of databases;
– "Internal client" concept / limitation of use;
– Segregation of functions (production/testing);
– Procedures for storage, amendment, deletion, transmission of data for different
purposes.
Covered Programs Privacy and Data Protection Standards
Annex 2 to Appendix D: Technical and Organizational Measures Ensure the Security of the Data
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Appendix E Definitions
The following terms as used in this manual have the meanings set forth below.
Acceptance Mark................................................................................................................................................166 ¶ Acceptor...............................................................................................................................................................166 Mark................................................................................................................................................174
Acceptor...............................................................................................................................................................174
Access Device......................................................................................................................................................166 ¶ Account.................................................................................................................................................................166 Device......................................................................................................................................................174
Account.................................................................................................................................................................174
Account Enablement System...........................................................................................................................167 System...........................................................................................................................175
Account Holder....................................................................................................................................................167 Holder....................................................................................................................................................175
Account PAN........................................................................................................................................................167 PAN........................................................................................................................................................175
Account PAN Range........................................................................................................................................... 167 ¶ Acquirer................................................................................................................................................................167 175
Acquirer................................................................................................................................................................175
Activity(ies)..........................................................................................................................................................167 ..........................................................................................................................................................175
Affiliate Customer, Affiliate..............................................................................................................................167 Affiliate..............................................................................................................................175
Applicable Data Protection Law......................................................................................................................167 Law......................................................................................................................175
Area of Use..........................................................................................................................................................168 Use..........................................................................................................................................................176
Association Customer, Association..................................................................................................................168 Association..................................................................................................................176
ATM Access Fee...................................................................................................................................................168 Fee...................................................................................................................................................176
ATM Owner Agreement.....................................................................................................................................168 Agreement.....................................................................................................................................176
ATM Terminal.......................................................................................................................................................168 Terminal.......................................................................................................................................................176
ATM Transaction.................................................................................................................................................169 Transaction.................................................................................................................................................177
Authenticating Entity........................................................................................................................................ 169 177
Automated Teller Machine (ATM)....................................................................................................................169 ....................................................................................................................177
Bank Branch Terminal........................................................................................................................................169 ¶ BIN.........................................................................................................................................................................169 Terminal........................................................................................................................................177
BIN.........................................................................................................................................................................177
Brand Fee.............................................................................................................................................................169 Fee.............................................................................................................................................................177
Brand Mark..........................................................................................................................................................170 ¶ Card.......................................................................................................................................................................170 ¶ Cardholder...........................................................................................................................................................170 Mark..........................................................................................................................................................178
Card.......................................................................................................................................................................178
Cardholder...........................................................................................................................................................178
Cardholder Communication............................................................................................................................. 170 178
Cardholder Verification Method (CVM)..........................................................................................................170 ..........................................................................................................178
Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC)........................................................... 171 179
Chip-only MPOS Terminal.................................................................................................................................171 Terminal.................................................................................................................................179
Chip Transaction.................................................................................................................................................171 Transaction.................................................................................................................................................179
Cirrus Acceptance Mark.................................................................................................................................... 171 179
Cirrus Access Device...........................................................................................................................................171 Device...........................................................................................................................................179
Cirrus Account.....................................................................................................................................................171 Account.....................................................................................................................................................179
Definitions
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Cirrus Brand Mark...............................................................................................................................................172 Mark...............................................................................................................................................180
Cirrus Card...........................................................................................................................................................172 Card...........................................................................................................................................................180
Cirrus Customer..................................................................................................................................................172 Customer..................................................................................................................................................180
Cirrus Payment Application..............................................................................................................................172 Application..............................................................................................................................180
Cirrus Word Mark................................................................................................................................................172 Mark................................................................................................................................................180
Competing ATM Network..................................................................................................................................172 Network..................................................................................................................................180
Competing EFT POS Network......................................................................................................................... 172 180
Competing International ATM Network.........................................................................................................173 Network.........................................................................................................181
Competing North American ATM Network....................................................................................................173 Network....................................................................................................181
Consumer Device Cardholder Verification Method, Consumer Device CVM, CDCVM...........................173 CDCVM...........................181
Contact Chip Transaction.................................................................................................................................174 Transaction.................................................................................................................................182
Contactless Payment Device............................................................................................................................174 Device............................................................................................................................182
Contactless Transaction....................................................................................................................................174 Transaction....................................................................................................................................182
Control, Controlled.............................................................................................................................................174 ¶ Corporation..........................................................................................................................................................174 Controlled.............................................................................................................................................182
Corporation..........................................................................................................................................................182
Corporation System...........................................................................................................................................175 System...........................................................................................................................................183
Credentials Management System...................................................................................................................175 System...................................................................................................................183
Cross-border Transaction..................................................................................................................................175 Transaction..................................................................................................................................183
Cryptocurrency, Crypto.....................................................................................................................................175 Crypto.....................................................................................................................................183
Cryptocurrency Merchant, Crypto Merchant................................................................................................175 Merchant................................................................................................183
Cryptocurrency Transaction, Crypto Transaction.........................................................................................175 ¶ Customer.............................................................................................................................................................176 Transaction.........................................................................................183
Customer.............................................................................................................................................................184
Customer Report................................................................................................................................................176 Report................................................................................................................................................184
Data Storage Entity (DSE)...............................................................................................................................176 ¶ Data Subject.......................................................................................................................................................176 ...............................................................................................................................184
Data Subject.......................................................................................................................................................184
Device Binding.....................................................................................................................................................176 Binding.....................................................................................................................................................184
Digital Activity(ies).............................................................................................................................................176 .............................................................................................................................................184
Digital Activity Agreement................................................................................................................................177 Agreement................................................................................................................................185
Digital Activity Customer..................................................................................................................................177 Customer..................................................................................................................................185
Digital Activity Service Provider (DASP)........................................................................................................ 177 185
Digital Activity Sponsoring Customer.............................................................................................................177 Customer.............................................................................................................185
Digital Goods.......................................................................................................................................................177 Goods.......................................................................................................................................................185
Digital Wallet.......................................................................................................................................................177 Wallet.......................................................................................................................................................185
Digital Wallet Operator (DWO).......................................................................................................................177 .......................................................................................................................185
Digital Wallet Operator Mark, DWO Mark.................................................................................................... 178 186
Digital Wallet Operator (DWO) Security Incident, DWO Security Incident............................................ 178 186
Digitization, Digitize...........................................................................................................................................178 Digitize...........................................................................................................................................186
Domestic Transaction........................................................................................................................................178 Transaction........................................................................................................................................186
Dual Interface......................................................................................................................................................178 Interface......................................................................................................................................................186
Definitions
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Electronic Money.................................................................................................................................................178 Money.................................................................................................................................................186
Electronic Money Institution.............................................................................................................................179 Institution.............................................................................................................................187
Electronic Money Issuer.....................................................................................................................................179 Issuer.....................................................................................................................................187
EMV Mode Contactless Transaction...............................................................................................................179 Transaction...............................................................................................................187
End User...............................................................................................................................................................179 User...............................................................................................................................................................187
Gateway Customer............................................................................................................................................179 Customer............................................................................................................................................187
Gateway Processing...........................................................................................................................................179 Processing...........................................................................................................................................187
Gateway Transaction.........................................................................................................................................179 Transaction.........................................................................................................................................187
Global Collection Only (GCO) Data Collection Program.............................................................................180 Program.............................................................................188
Host Card Emulation (HCE).............................................................................................................................180 .............................................................................................................................188
Hybrid Terminal...................................................................................................................................................180 ¶ ICA.........................................................................................................................................................................180 Terminal...................................................................................................................................................188
ICA.........................................................................................................................................................................188
Identification & Verification (ID&V).................................................................................................................180 .................................................................................................................188
Independent Sales Organization (ISO)...........................................................................................................180 ...........................................................................................................188
Installment Lending Agreement...................................................................................................................... 181 189
Interchange System...........................................................................................................................................181 System...........................................................................................................................................189
Inter-European Transaction..............................................................................................................................181 Transaction..............................................................................................................................189
Interregional Transaction..................................................................................................................................181 Transaction..................................................................................................................................189
Intracountry Transaction...................................................................................................................................181 Transaction...................................................................................................................................189
Intra–European Transaction.............................................................................................................................182 Transaction.............................................................................................................................190
Intra–Non–SEPA Transaction...........................................................................................................................182 Transaction...........................................................................................................................190
Intraregional Transaction..................................................................................................................................182 ¶ Issuer.....................................................................................................................................................................182 Transaction..................................................................................................................................190
Issuer.....................................................................................................................................................................190
License, Licensed.................................................................................................................................................182 ¶ Licensee................................................................................................................................................................182 ¶ Maestro................................................................................................................................................................182 Licensed.................................................................................................................................................190
Licensee................................................................................................................................................................190
Maestro................................................................................................................................................................190
Maestro Acceptance Mark................................................................................................................................183 Mark................................................................................................................................191
Maestro Access Device......................................................................................................................................183 Device......................................................................................................................................191
Maestro Account.................................................................................................................................................183 Account.................................................................................................................................................191
Maestro Brand Mark..........................................................................................................................................183 Mark..........................................................................................................................................191
Maestro Card...................................................................................................................................................... 183 191
Maestro Customer.............................................................................................................................................183 Customer.............................................................................................................................................191
Maestro Payment Application..........................................................................................................................183 Application..........................................................................................................................191
Maestro Word Mark...........................................................................................................................................183 Mark...........................................................................................................................................191
Magnetic Stripe Mode Contactless Transaction...........................................................................................184 Transaction...........................................................................................192
Manual Cash Disbursement Transaction........................................................................................................184 ¶ Marks....................................................................................................................................................................184 ¶ Mastercard...........................................................................................................................................................184 Transaction........................................................................................................192
Marks....................................................................................................................................................................192
Mastercard...........................................................................................................................................................192
Mastercard Acceptance Mark.......................................................................................................................... 184 192
Definitions
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Mastercard Access Device.................................................................................................................................184 Device.................................................................................................................................192
Mastercard Account...........................................................................................................................................185 Account...........................................................................................................................................193
Mastercard Biometric Card..............................................................................................................................185 Card..............................................................................................................................193
Mastercard-branded Application Identifier (AID).........................................................................................185 .........................................................................................193
Mastercard Brand Mark.....................................................................................................................................185 Mark.....................................................................................................................................193
Mastercard Card.................................................................................................................................................185 Card.................................................................................................................................................193
Mastercard Cloud-Based Payments............................................................................................................... 185 193
Mastercard Consumer-Presented QR Transaction.......................................................................................185 Transaction.......................................................................................193
Mastercard Customer........................................................................................................................................186 Customer........................................................................................................................................194
Mastercard Digital Enablement Service.........................................................................................................186 Service.........................................................................................................194
Mastercard Europe.............................................................................................................................................186 Europe.............................................................................................................................................194
Mastercard Incorporated..................................................................................................................................186 Incorporated..................................................................................................................................194
Mastercard Payment Application....................................................................................................................186 Application....................................................................................................................194
Mastercard Safety Net......................................................................................................................................186 Net......................................................................................................................................194
Mastercard Symbol............................................................................................................................................187 Symbol............................................................................................................................................195
Mastercard Token...............................................................................................................................................187 Token...............................................................................................................................................195
Mastercard Token Account Range...................................................................................................................187 Range...................................................................................................................195
Mastercard Token Vault.....................................................................................................................................187 Vault.....................................................................................................................................195
Mastercard Word Mark..................................................................................................................................... 187 195
Member, Membership........................................................................................................................................188 Membership........................................................................................................................................196
Merchandise Transaction.................................................................................................................................. 188 ¶ Merchant..............................................................................................................................................................188 196
Merchant..............................................................................................................................................................196
Merchant Agreement.........................................................................................................................................188 Agreement.........................................................................................................................................196
Merchant Token Requestor...............................................................................................................................188 Requestor...............................................................................................................................196
Mobile Payment Device.....................................................................................................................................188 Device.....................................................................................................................................196
Mobile POS (MPOS) Terminal..........................................................................................................................189 Terminal..........................................................................................................................197
MoneySend Payment Transaction...................................................................................................................189 Transaction...................................................................................................................197
Multi-Account Chip Card...................................................................................................................................189 Card...................................................................................................................................197
Multi-Factor Authentication Method, MFA Method.....................................................................................189 Method.....................................................................................197
Non-Mastercard Funding Source.....................................................................................................................189 Source.....................................................................................................................197
Non-Mastercard Receiving Account................................................................................................................189 Account................................................................................................................197
Non-Mastercard Systems and Networks Standards...................................................................................189 Standards...................................................................................197
On-behalf Token Requestor..............................................................................................................................190 Requestor..............................................................................................................................198
On-Device Cardholder Verification..................................................................................................................190 Verification..................................................................................................................198
Originating Account Holder..............................................................................................................................190 Holder..............................................................................................................................198
Originating Institution (OI)...............................................................................................................................190 ...............................................................................................................................198
Ownership, Owned.............................................................................................................................................190 ¶ Participation........................................................................................................................................................190 Owned.............................................................................................................................................198
Participation........................................................................................................................................................198
Pass-through Digital Wallet............................................................................................................................. 190 198
Definitions
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Pass-through Digital Wallet Operator (DWO)..............................................................................................191 ..............................................................................................199
Payment Account Reference (PAR).................................................................................................................191 .................................................................................................................199
Payment Application..........................................................................................................................................191 Application..........................................................................................................................................199
Payment Facilitator...........................................................................................................................................191 Facilitator...........................................................................................................................................199
Payment Transaction.........................................................................................................................................191 Transaction.........................................................................................................................................199
Payment Transfer Activity(ies) (PTA)..............................................................................................................191 ..............................................................................................................199
Personal Data......................................................................................................................................................192 Data......................................................................................................................................................200
Point of Interaction (POI)..................................................................................................................................192 ..................................................................................................................................200
Point-of-Sale (POS) Terminal...........................................................................................................................192 Terminal...........................................................................................................................200
Point–of–Sale (POS) Transaction....................................................................................................................192 ¶ Portfolio................................................................................................................................................................192 Transaction....................................................................................................................200
Portfolio................................................................................................................................................................200
Principal Customer, Principal............................................................................................................................193 Principal............................................................................................................................201
Processed PTA Transaction...............................................................................................................................193 Transaction...............................................................................................................................201
Processed Transaction.......................................................................................................................................193 Transaction.......................................................................................................................................201
Processing of Personal Data.............................................................................................................................193 ¶ Program................................................................................................................................................................193 Data.............................................................................................................................201
Program................................................................................................................................................................201
Program Service..................................................................................................................................................194 Service..................................................................................................................................................202
PTA Account.........................................................................................................................................................194 Account.........................................................................................................................................................202
PTA Account Number.........................................................................................................................................194 Number.........................................................................................................................................202
PTA Account Portfolio........................................................................................................................................194 Portfolio........................................................................................................................................202
PTA Agreement...................................................................................................................................................194 Agreement...................................................................................................................................................202
PTA Customer.....................................................................................................................................................194 Customer.....................................................................................................................................................202
PTA Originating Account...................................................................................................................................194 Account...................................................................................................................................202
PTA Program.......................................................................................................................................................194 Program.......................................................................................................................................................202
PTA Receiving Account.......................................................................................................................................195 Account.......................................................................................................................................203
PTA Settlement Guarantee Covered Program..............................................................................................195 Program..............................................................................................203
PTA Settlement Obligation ..............................................................................................................................195 ..............................................................................................................................203
PTA Transaction..................................................................................................................................................195 Transaction..................................................................................................................................................203
Quick Response (QR) Code ..............................................................................................................................195 ..............................................................................................................................203
Receiving Account Holder..................................................................................................................................195 Holder..................................................................................................................................203
Receiving Agent...................................................................................................................................................195 Agent...................................................................................................................................................203
Receiving Customer............................................................................................................................................196 Customer............................................................................................................................................204
Receiving Institution (RI)....................................................................................................................................196 ¶ Region...................................................................................................................................................................196 ....................................................................................................................................204
Region...................................................................................................................................................................204
Remote Electronic Transaction ....................................................................................................................... 196 204
Service Provider.................................................................................................................................................. 196 204
Settlement Obligation.......................................................................................................................................196 Obligation.......................................................................................................................................204
Shared Deposit Transaction.............................................................................................................................197 Transaction.............................................................................................................................205
Solicitation, Solicit..............................................................................................................................................197 Solicit..............................................................................................................................................205
Definitions
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Sponsor, Sponsorship.........................................................................................................................................197 Sponsorship.........................................................................................................................................205
Sponsored Digital Activity Entity.....................................................................................................................197 Entity.....................................................................................................................205
Sponsored Merchant..........................................................................................................................................198 Merchant..........................................................................................................................................206
Sponsored Merchant Agreement.....................................................................................................................198 Agreement.....................................................................................................................206
Staged Digital Wallet........................................................................................................................................198 Wallet........................................................................................................................................206
Staged Digital Wallet Operator (DWO).........................................................................................................198 ¶ Standards............................................................................................................................................................198 .........................................................................................................206
Standards............................................................................................................................................................206
Stand-In Parameters.........................................................................................................................................199 Parameters.........................................................................................................................................207
Stand-In Processing Service.............................................................................................................................199 Service.............................................................................................................................207
Strong Customer Authentication (SCA)........................................................................................................199 ¶ Sub-licensee.........................................................................................................................................................199 ¶ Terminal................................................................................................................................................................199 ........................................................................................................207
Sub-licensee.........................................................................................................................................................207
Terminal................................................................................................................................................................207
Third Party Processor (TPP)..............................................................................................................................199 ¶ Token.....................................................................................................................................................................200 ..............................................................................................................................207
Token.....................................................................................................................................................................208
Tokenization, Tokenize........................................................................................................................................200 Tokenize........................................................................................................................................208
Token Requestor..................................................................................................................................................200 Requestor..................................................................................................................................................208
Token Vault...........................................................................................................................................................200 ¶ Transaction..........................................................................................................................................................200 Vault...........................................................................................................................................................208
Transaction..........................................................................................................................................................208
Transaction Data................................................................................................................................................200 Data................................................................................................................................................208
Transaction Management System..................................................................................................................201 System..................................................................................................................209
Trusted Service Manager...................................................................................................................................201 Manager...................................................................................................................................209
Virtual Account....................................................................................................................................................201 ¶ Volume..................................................................................................................................................................201 Account....................................................................................................................................................209
Volume..................................................................................................................................................................209
Wallet Token Requestor.....................................................................................................................................201 Requestor.....................................................................................................................................209
Word Mark...........................................................................................................................................................201 Mark...........................................................................................................................................................209
Definitions
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Additional and/or revised terms may also be used for purposes of the Rules in a particular chapter or
section of this manual.
Acceptance Mark
Any one of the Corporation’s Marks displayed at a Point of Interaction (POI) to indicate brand
acceptance. See Cirrus® Acceptance Mark, Maestro® Acceptance Mark, Mastercard® Acceptance
Mark.
Acceptor
The Merchant, Sponsored Merchant, ATM owner, or other entity that accepts a Card pursuant
to a Merchant Agreement, Sponsored Merchant Agreement, or ATM Owner Agreement for
purposes of conducting a Transaction.
Access Device
A device other than a Card that has successfully completed all applicable Mastercard
certification and testing requirements, if any, and:
•
Uses at least one Payment Application provisioned to the device by or with the approval of a
Customer to provide access to an Account;
•
Supports the transmission or exchange of data using one or both of the following:
– Magnetic stripe or chip data containing a dynamic cryptogram to or with a Terminal, as
applicable, by implementing the EMV® Contactless Specifications (Book D) to effect
Transactions at the Terminal without requiring direct contact of the device to the Terminal
– Chip data containing a dynamic cryptogram to or with a Terminal, as applicable, by
implementing the Mastercard Cloud-Based Payments (MCBP) documentation to effect
Transactions at the Terminal by capture of a QR Code containing the Transaction Data
•
May also support the transmission of magnetic stripe data containing a dynamic cryptogram
to a Terminal to effect Transactions identified by the Acquirer in Transaction messages as
magnetic stripe Transactions.
A Cirrus Access Device, Maestro Access Device, and Mastercard Access Device is each an Access
Device. See also Mobile Payment Device.
Account
An account maintained by or on behalf of a Cardholder by an Issuer for the processing of
Transactions, and which is identified with a bank identification number (BIN) or Issuer
identification number (IIN) designated by the Corporation in its routing tables for routing to the
Interchange System. See also Cirrus Account, Maestro Account, Mastercard Account.
Definitions
Acceptance Mark
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Account Enablement System
Performs Account enablement services for Mastercard Cloud-Based Payments, which may
include Account and Access Device eligibility checks, Identification & Verification (ID&V),
Digitization, and subsequent lifecycle management.
Account Holder
A user who holds a PTA Account and has agreed to participate in a PTA Transaction.
Account PAN
The primary account number (PAN) allocated to an Account by an Issuer.
Account PAN Range
The range of Account PANs designated by an Issuer for Digitization.
Acquirer
A Customer in its capacity as an acquirer of a Transaction.
Activity(ies)
The undertaking of any lawful act that can be undertaken only pursuant to a License granted by
the Corporation. Payment Transfer Activity is a type of Activity. See also Digital Activity(ies).
Affiliate Customer, Affiliate
A Customer that participates indirectly in Activity through the Sponsorship of a Principal or,
solely with respect to Mastercard Activity, through the Sponsorship of an Association. An
Affiliate may not Sponsor any other Customer.
Applicable Data Protection Law
All applicable law, statute, declaration, decree, legislation, enactment, order, ordinance,
regulation or rule (each as amended and replaced from time to time) which relates to the
Definitions
Account Enablement System
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
protection of individuals with regards to the Processing of Personal Data to which the Parties
are subject, including but not limited to the EU General Data Protection Regulation 2016/679;
the e-Privacy Directive 2002/58/EC and their national implementing legislations the California
Consumer Privacy Act; the U.S. Gramm-Leach-Bliley Act; the Brazil General Data Protection
Act; the South Africa Protection of Personal Information Act; laws regulating unsolicited email,
telephone, and text message communications; security breach notification laws; laws imposing
minimum security requirements; laws requiring the secure disposal of records containing certain
Personal Data; laws governing the portability and/or cross-border transfer of Personal Data;
and all other similar international, federal, state, provincial, and local requirements; each as
applicable.
Area of Use
The country or countries in which a Customer is Licensed to use the Marks and conduct Activity
or in which a PTA Customer is permitted to Participate in a PTA Program, and, as a rule, set
forth in the License or PTA Agreement or in an exhibit to the License or PTA Agreement.
Association Customer, Association
A Mastercard Customer that participates directly in Mastercard Activity using its assigned BINs
and which may Sponsor one or more Mastercard Affiliates but may not directly issue
Mastercard Cards or acquire Mastercard Transactions, or in the case of a PTA Association, may
not directly hold PTA Accounts, without the express prior written consent of the Corporation.
ATM Access Fee
A fee charged by an Acquirer in connection with a cash withdrawal or Shared Deposit
Transaction initiated at the Acquirer’s ATM Terminal with a Card, and added to the total
Transaction amount transmitted to the Issuer.
ATM Owner Agreement
An agreement between an ATM owner and a Customer that sets forth the terms pursuant to
which the ATM accepts Cards.
ATM Terminal
An ATM that enables a Cardholder to effect an ATM Transaction with a Card (and if
contactless-enabled, an Access Device) in accordance with the Standards.
Definitions
Area of Use
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
ATM Transaction
A cash withdrawal effected at an ATM Terminal with a Card and processed through the
Mastercard ATM Network. An ATM Transaction is identified with MCC 6011 (Automated Cash
Disbursements—Customer Financial Institution).
Authenticating Entity
An Authenticating Entity is a Merchant, Service Provider, or Digital Wallet Operator that uses an
MFA Method to authenticate a Cardholder when a Token is used to conduct a Card-not-present
Transaction of any type (excluding mail order and telephone order [MO/TO] Transactions).
Automated Teller Machine (ATM)
An unattended self-service device that performs basic banking functions such as accepting
deposits, cash withdrawals, ordering transfers among accounts, loan payments and account
balance inquiries.
Bank Branch Terminal
An attended device, located on the premises of a Customer or other financial institution
designated as its authorized agent by the Corporation, that facilitates a Manual Cash
Disbursement Transaction by a Cardholder.
BIN
A bank identification number (BIN, sometimes referred to as an Issuer identification number, or
IIN) is a unique number assigned by Mastercard for use by a Customer in accordance with the
Standards.
Brand Fee
A fee charged for certain Transactions not routed to the Interchange System.
Definitions
ATM Transaction
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Brand Mark
A Word Mark as a custom lettering legend placed within the Corporation’s interlocking circles
device. The Mastercard Brand Mark, Maestro Brand Mark, and Cirrus Brand Mark is each a
Brand Mark. The Mastercard Symbol is also a Brand Mark.
Card
A card issued by a Customer pursuant to License and in accordance with the Standards and
that provides access to an Account. Unless otherwise stated herein, Standards applicable to the
use and acceptance of a Card are also applicable to an Access Device and, in a Card-not-present
environment, an Account. A Cirrus Card, Maestro Card, and Mastercard Card is each a Card.
Cardholder
The authorized user of a Card or Access Device issued by a Customer.
Cardholder Communication
Any communication by or on behalf of an Issuer to a Cardholder or prospective Cardholder. A
Solicitation is one kind of Cardholder Communication.
Cardholder Verification Method (CVM)
A process used to confirm that the person presenting the Card is an authorized Cardholder. The
Corporation deems the following to be valid CVMs when used in accordance with the Standards:
•
The comparison, by the Merchant or Acquirer accepting the Card, of the signature on the
Card’s signature panel with the signature provided on the Transaction receipt by the person
presenting the Card;
•
The comparison, by the Card Issuer or the EMV chip on the Card, of the value entered on a
Terminal’s PIN pad with the personal identification number (PIN) given to or selected by the
Cardholder upon Card issuance; and
•
The use of a Consumer Device CVM (CDCVM) that Mastercard approved as a valid CVM for
Transactions upon the successful completion of the certification and testing procedures set
forth in section 3.11 of the Security Rules and Procedures.
In certain Card-present environments, a Merchant may complete the Transaction without a
CVM (“no CVM” as the CVM), such as in Quick Payment Service (QPS) Transactions, Contactless
Transactions less than or equal to the CVM limit, and Transactions at an unattended Point-of-
Sale (POS) Terminal identified as Cardholder-activated Terminal (CAT) Level 2 or Level 3.
Definitions
Brand Mark
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC)
A Card with an embedded EMV-compliant chip containing memory and interactive capabilities
used to identify and store additional data about a Cardholder, an Account, or both.
Chip-only MPOS Terminal
An MPOS Terminal that has a contact chip reader and no magnetic stripe-reading capability
and that must:
1.
Operate as an online-only POS Terminal for authorization purposes;
2.
Support either signature or No CVM Required as a Cardholder Verification Method, and may
also support PIN verification if conducted by means of a PIN entry device (PED) that is in
compliance with the Payment Card Industry (PCI) POS PED Security Requirements and
Evaluation Program; and
3.
Otherwise comply with the Corporation’s requirements for Hybrid POS Terminals.
Chip Transaction
A Contact Chip Transaction or a Contactless Transaction.
Cirrus Acceptance Mark
A Mark consisting of the Cirrus Brand Mark placed on the dark blue acceptance rectangle,
available at www.mastercardbrandcenter.com.
Cirrus Access Device
An Access Device that uses at least one Cirrus Payment Application to provide access to a Cirrus
Account when used at an ATM Terminal or Bank Branch Terminal.
Cirrus Account
An account eligible to be a Cirrus Account and identified with a BIN/IIN associated with a
Portfolio designated by the Corporation as a Cirrus Portfolio in its routing tables.
Definitions
Chip Card (Smart Card, Integrated Circuit Card, IC Card, or ICC)
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Cirrus Brand Mark
A Mark consisting of the Cirrus Word Mark as a custom lettering legend placed within the
Corporation’s interlocking circles device. The Corporation is the exclusive owner of the Cirrus
Brand Mark.
Cirrus Card
A Card that provides access to a Cirrus Account.
Cirrus Customer
A Customer that has been granted a Cirrus License in accordance with the Standards.
Cirrus Payment Application
A Payment Application that stores Cirrus Account data.
Cirrus Word Mark
A Mark consisting of the word “Cirrus” followed by a registered trademark ® or ™ symbol
(depending on its trademark status in a particular country) or the local law equivalent. “Cirrus”
must appear in English and be spelled correctly, with the letter “C” capitalized. “Cirrus” must not
be abbreviated, hyphenated, used in the plural or possessive, translated from English into
another language, or appear in another alphabet except for specific authorized versions in
Chinese (translation), Arabic (transliteration), Georgian (transliteration), and Korean
(transliteration). The Corporation is the exclusive owner of the Cirrus Word Mark.
Competing ATM Network
A Competing International ATM Network or a Competing North American ATM Network, as the
case may be.
Competing EFT POS Network
A network, other than any network owned and operated by the Corporation, which provides
access to Maestro Accounts at POS Terminals by use of payment cards and has the following
characteristics:
Definitions
Cirrus Brand Mark
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
1.
It provides a common service mark or marks to identify the POS Terminal and payment
cards, which provide Maestro Account access;
2.
It is not an affiliate of the Corporation; and
3.
It operates in at least one country in which the Corporation has granted a License or
Licenses.
The following networks are designated without limitation to be Competing EFT POS Networks:
Interlink; Electron; and V-Pay.
Competing International ATM Network
A network of ATMs and payment cards, other than the Corporation, identified by a common
brand mark that is used exclusively or primarily for ATM interchange that:
1.
Operates in at least three countries;
2.
Uses a common service mark or marks to identify the ATMs and payment cards which
provide account access through it; and
3.
Provides account access to at least 40,000,000 debit cards and by means of at least 25,000
ATMs.
Competing North American ATM Network
A network of ATMs and access cards, other than the Corporation, identified by a common brand
mark that is used exclusively or primarily for ATM interchange and that possesses each of the
following characteristics:
1.
It operates in at least 40 of the states or provinces of the states and provinces of the United
States and Canada;
2.
It uses a common service mark or common service marks to identify the terminals and cards
which provide account access through it;
3.
There are at least 40,000,000 debit cards that provide account access through it; and
4.
There are at least 12,000 ATMs that provide account access through it.
Consumer Device Cardholder Verification Method, Consumer Device
CVM, CDCVM
A CVM that occurs when personal credentials established by the Cardholder to access an
Account by means of a particular Access Device are entered on the Access Device and verified,
either within the Access Device or by the Issuer during online authorization. A CDCVM is valid if
the Issuer has approved the use of the CVM for the authentication of the Cardholder.
Definitions
Competing International ATM Network
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Contact Chip Transaction
A Transaction in which data is exchanged between the Chip Card and the Terminal through the
reading of the chip using the contact interface, in conformance with EMV specifications.
Contactless Payment Device
A means other than a Card by which a Cardholder may access an Account at a Terminal in
accordance with the Standards. A Contactless Payment Device is a type of Access Device that
exchanges data with the Terminal by means of radio frequency communications. See also Mobile
Payment Device.
Contactless Transaction
A Transaction in which data is exchanged between the Chip Card or Access Device and the
Terminal through the reading of the chip using the contactless interface, by means of radio
frequency communications. See also EMV Mode Contactless Transaction, Magnetic Stripe Mode
Contactless Transaction.
Control, Controlled
As used herein, Control has such meaning as the Corporation deems appropriate in its sole
discretion given the context of the usage of the term and all facts and circumstances the
Corporation deems appropriate to consider. As a general guideline, Control often means to have,
alone or together with another entity or entities, direct, indirect, legal, or beneficial possession
(by contract or otherwise) of the power to direct the management and policies of another
entity.
Corporation
Mastercard International Incorporated, Maestro International Inc., and their subsidiaries and
affiliates. As used herein, Corporation also means the President and Chief Executive Officer of
Mastercard International Incorporated, or his or her designee, or such officers or other
employees responsible for the administration and/or management of a program, service,
product, system or other function. Unless otherwise set forth in the Standards, and subject to
any restriction imposed by law or regulation, or by the Board of Directors of Mastercard
International Incorporated, or by the Mastercard International Incorporated Certificate of
Incorporation or the Mastercard Incorporated Certificate of Incorporation (as each such
Certificate of Incorporation may be amended from time to time), each such person is authorized
to act on behalf of the Corporation and to so act in his or her sole discretion.
Definitions
Contact Chip Transaction
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Corporation System
The Interchange System as defined in this manual.
Credentials Management System
Facilitates credential preparation and/or remote mobile Payment Application management for
Mastercard Cloud-Based Payments.
Cross-border Transaction
A Transaction that occurs at a Card acceptance location in a different country from the country
in which the Card was issued.
Cryptocurrency, Crypto
A digital asset recognized as a medium of exchange, unit of account, and store of value that
uses cryptography to secure transactions associated with the digital asset, control the
generation of additional cryptocurrency units, and verify the transfer of funds.
The recognition of a Cryptocurrency as a medium of exchange, unit of account, and store of
value occurs only by agreement within the community of users of such Cryptocurrency. For the
avoidance of doubt, legal tender or virtual currency issued by a government or centralized
banking system is not considered Cryptocurrency.
Cryptocurrency Merchant, Crypto Merchant
A Merchant that sells or trades in Cryptocurrency.
Cryptocurrency Transaction, Crypto Transaction
A Card-present or Card-not-present Transaction in which a Cardholder uses an Account to
directly purchase Cryptocurrencies, or to purchase, sell, or trade Cryptocurrencies by means of a
digital currency, alternative currency, or virtual currency exchange platform.
A Cryptocurrency Transaction is identified with MCC 6051 (Quasi Cash: Merchant), TCC U, and
a Transaction Type Identifier (TTI) value of P70 (Cryptocurrency).
Definitions
Corporation System
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Customer
A financial institution or other entity that has been approved for Participation. A Customer may
be a Principal, Association, Affiliate, Digital Activity Customer, Sponsored Digital Activity Entity,
or PTA Customer. See also Cirrus Customer, Maestro Customer, Mastercard Customer, Member.
Customer Report
Any report that a Customer is required to provide to the Corporation, whether on a one-time or
repeated basis, pertaining to its License, Activities, Digital Activity Agreement, Digital Activities,
PTA Agreement, Payment Transfer Activities, use of any Mark, or any such matters. By way of
example and not limitation, the Quarterly Mastercard Report (QMR) is a Customer Report.
Data Storage Entity (DSE)
A Service Provider that performs DSE Program Service.
Data Subject
A Cardholder, a Merchant, or other natural person or entity whose Personal Data are Processed
by or on behalf of the Corporation, a Customer, or a Merchant.
Device Binding
The process by which a Wallet Token Requestor binds a Mastercard Token corresponding to a
Cardholder’s Account to that Cardholder’s Mobile Payment Device, which may consist of:
•
The provisioning of the Token and its associated encryption keys into the secure element
within the Mobile Payment Device;
•
The loading of an application for a remotely-managed secure server into the Mobile Payment
Device and the successful communication of the device with the application; or
•
Other methodology acceptable to the Corporation.
Digital Activity(ies)
The undertaking of any lawful act pursuant to approval by the Corporation as set forth in a
Digital Activity Agreement or other written documentation. Participation in the Mastercard
Digital Enablement Service as a Wallet Token Requestor is a Digital Activity.
Definitions
Customer
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Digital Activity Agreement
The contract between the Corporation and a Digital Activity Customer granting the Digital
Activity Customer the right to participate in Digital Activity and a limited License to use one or
more of the Marks in connection with such Digital Activity, in accordance with the Standards.
Digital Activity Customer
A Customer that participates in Digital Activity pursuant to a Digital Activity Agreement and
which may not issue Cards, acquire Transactions, or Sponsor any other Customer into the
Corporation.
Digital Activity Service Provider (DASP)
A Service Provider that performs DASP Program Service.
Digital Activity Sponsoring Customer
A Principal Customer or Digital Activity Customer that sponsors a Sponsored Digital Activity
Entity to participate in Digital Activity.
Digital Goods
Any goods that are stored, delivered, and used in electronic format, such as, by way of example
but not limitation, books, newspapers, magazines, music, games, game pieces, and software
(excluding gift cards). The delivery of a purchase of Digital Goods may occur on a one-time or
subscription basis.
Digital Wallet
A Pass-through Digital Wallet or a Staged Digital Wallet.
Digital Wallet Operator (DWO)
A Service Provider that operates a Staged Digital Wallet or a Customer that operates a Pass-
through Digital Wallet. A Merchant that stores Mastercard or Maestro Account data solely on
its own behalf to effect Transactions initiated by the consumer is not deemed to be a DWO.
Definitions
Digital Activity Agreement
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Digital Wallet Operator Mark, DWO Mark
A Mark identifying a particular Pass-through Digital Wallet and/or Staged Digital Wallet, and
which may be displayed at the POI to denote that a retailer, or any other person, firm, or
corporation, accepts payments effected by means of that Pass-through Digital Wallet and/or
Staged Digital Wallet. A “Staged DWO Mark” and a “Pass-through DWO Mark” are both types
of DWO Marks.
Digital Wallet Operator (DWO) Security Incident, DWO Security
Incident
Any incident pertaining to the unintended or unlawful disclosure of Personal Data in connection
with such Personal Data being processed through a DWO.
Digitization, Digitize
Data preparation performed by, or on behalf of, an Issuer prior to the provisioning of Account
credentials or a PTA Customer prior to the provisioning of PTA Account credentials, in the form
of a Mastercard Token, onto a Payment Device or into a server. Digitization includes
Tokenization.
Domestic Transaction
See Intracountry Transaction.
Dual Interface
The description of a Terminal or Card that is capable of processing Contactless Transactions by
means of its contactless interface and Contact Chip Transactions by means of its contact
interface.
Electronic Money
Electronically (including magnetically) accessed monetary value as represented by a claim on the
Electronic Money Issuer which:
1.
Is issued on receipt of funds for the purpose of making transactions with payment cards;
and
2.
Is accepted by the Electronic Money Issuer or a person other than the Electronic Money
Issuer.
Definitions
Digital Wallet Operator Mark, DWO Mark
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Electronic Money Institution
An entity authorized by applicable regulatory authority or other government entity as an
“electronic money institution”, “e-money institution”, “small electronic money institution”, or any
other applicable qualification under which an entity is authorized to issue or acquire Electronic
Money transactions under applicable law or regulation.
Electronic Money Issuer
An Electronic Money Institution with respect only to its issuing activities.
EMV Mode Contactless Transaction
A Contactless Transaction in which the Terminal and the chip exchange data, enabling the chip
to approve the Transaction offline on the Issuer’s behalf or to request online authorization from
the Issuer, in compliance with the Standards.
End User
Recipients of any lending services from the Installment Service Provider in accordance with an
Installment Lending Agreement. An End User can be a natural person or an entity.
Gateway Customer
A Customer that uses the Gateway Processing service.
Gateway Processing
A service that enables a Customer to forward a Gateway Transaction to and/or receive a
Gateway Transaction from the Mastercard® ATM Network.
Gateway Transaction
An ATM transaction effected with a payment card or other access device not bearing a Mark
that is processed through or using the Mastercard® ATM Network.
Definitions
Electronic Money Institution
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Global Collection Only (GCO) Data Collection Program
A program of the Corporation pursuant to which a Customer must provide collection-only
reporting of non-Processed Transactions effected with a Card, Access Device, or Account issued
under a Mastercard-assigned BIN via the Corporation’s Global Clearing Management System
(GCMS), in accordance with the requirements set forth in the Mastercard Global Collection Only
manual.
Host Card Emulation (HCE)
The presentation on a Mobile Payment Device of a virtual and exact representation of a Chip
Card using only software on the Mobile Payment Device and occurring by means of its
communication with a secure remote server.
Hybrid Terminal
A Terminal, including any POS or MPOS Terminal (“Hybrid POS Terminal”, “Hybrid MPOS
Terminal”), ATM Terminal (“Hybrid ATM Terminal”), or Bank Branch Terminal (“Hybrid Bank
Branch Terminal”), that:
1.
Is capable of processing both Contact Chip Transactions and magnetic stripe Transactions;
2.
Has the equivalent hardware, software, and configuration as a Terminal with full EMV Level
1 and Level 2 type approval status with regard to the chip technical specifications; and
3.
Has satisfactorily completed the Corporation’s Terminal Integration Process (TIP) in the
appropriate environment of use.
ICA
A unique number assigned by the Corporation to identify a Customer in relation to Activity.
Identification & Verification (ID&V)
The identification and verification of a person as the Cardholder to whom the Issuer allocated
the Account PAN to be Tokenized.
Independent Sales Organization (ISO)
A Service Provider that performs ISO Program Service.
Definitions
Global Collection Only (GCO) Data Collection Program
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Installment Lending Agreement
The agreement between the Installment Service Provider and an End User, which includes terms
and conditions governing the relationship between the parties, such as lending amount and
repayment terms.
Interchange System
The computer hardware and software operated by and on behalf of the Corporation for the
routing, processing, and settlement of Transactions and PTA Transactions including, without
limitation, the Mastercard Network, the Mastercard ATM Network, the Dual Message System,
the Single Message System, the Global Clearing Management System (GCMS), and the
Settlement Account Management (SAM) system.
Inter-European Transaction
A Transaction completed using a Card issued in a country or territory listed in Single European
Payments Area (SEPA) at a Terminal located in a country or territory listed in Non-Single
European Payments Area (Non-SEPA) or Transaction completed using a Card issued in a country
or territory listed in Non-Single European Payments Area (Non–SEPA) at a Terminal located in a
country or territory listed in Single European Payments Area (SEPA).
Interregional Transaction
A Transaction that occurs at a Card acceptance location in a different Region from the Region in
which the Card was issued. In the Europe Region, the term “Interregional Transaction” includes
any “Inter-European Transaction,” as such term is defined in the “Europe Region” chapter of the
Mastercard Rules.
Intracountry Transaction
A Transaction that occurs at a Card acceptance location in the same country as the country in
which the Card was issued. A Transaction conducted with a Card bearing one or more of the
Brand Marks, either alone or in combination with the marks of another payment scheme, and
processed as a Transaction, as shown by the Card type identification in the Transaction record,
via either the Interchange System or a different network, qualifies as an Intracountry
Transaction. “Domestic Transaction” is an alternative term for Intracountry Transaction.
Definitions
Installment Lending Agreement
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Intra–European Transaction
An Intra-Non-SEPA Transaction or an Intra–SEPA Transaction, but not an Inter–European
Transaction.
Intra–Non–SEPA Transaction
A Transaction completed using a Card issued in a country or territory listed in Non–Single
European Payments Area (Non–SEPA) at a Terminal located in a country or territory listed in
Non–Single European Payments Area (Non–SEPA).
Intraregional Transaction
A Transaction that occurs at a Card acceptance location in a different country from the country
in which the Card was issued, within the same Region. In the Europe Region, this term is
replaced by “Intra-European Transaction,” as such term is defined in the “Europe Region”
chapter of the Mastercard Rules.
Issuer
A Customer in its capacity as an issuer of a Card or Account.
License, Licensed
The contract between the Corporation and a Customer granting the Customer the right to use
one or more of the Marks in accordance with the Standards and in the case of Payment Transfer
Activity, includes a PTA Agreement. To be “Licensed” means to have such a right pursuant to a
License.
Licensee
A Customer or other person authorized in writing by the Corporation to use one or more of the
Marks.
Maestro
Maestro International Incorporated, a Delaware U.S.A. corporation or any successor thereto.
Definitions
Intra–European Transaction
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Maestro Acceptance Mark
A Mark consisting of the Maestro Brand Mark placed on the dark blue acceptance rectangle, as
available at www.mastercardbrandcenter.com.
Maestro Access Device
An Access Device that uses at least one Maestro Payment Application to provide access to a
Maestro Account when used at a Terminal.
Maestro Account
An account eligible to be a Maestro Account and identified with a BIN/IIN associated with a
Portfolio designated by the Corporation as a Maestro Portfolio in its routing tables.
Maestro Brand Mark
A Mark consisting of the Maestro Word Mark as a custom lettering legend placed within the
Corporation’s interlocking circles device. The Corporation is the exclusive owner of the Maestro
Brand Mark.
Maestro Card
A Card that provides access to a Maestro Account.
Maestro Customer
A Customer that has been granted a Maestro License in accordance with the Standards.
Maestro Payment Application
A Payment Application that stores Maestro Account data.
Maestro Word Mark
A Mark consisting of the word “Maestro” followed by a registered trademark ® or ™ symbol
(depending on its trademark status in a particular country) or the local law equivalent.
Definitions
Maestro Acceptance Mark
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
“Maestro” must appear in English and be spelled correctly, with the letter “M” capitalized.
“Maestro” must not be abbreviated, hyphenated, used in the plural or possessive, translated
from English into another language, or appear in another alphabet except for specific
authorized versions in Chinese (translation), Arabic (transliteration), Georgian (transliteration),
and Korean (transliteration). Maestro is the exclusive owner of the Maestro Word Mark.
Magnetic Stripe Mode Contactless Transaction
A Contactless Transaction in which the Terminal receives static and dynamic data from the chip
and constructs messages that can be transported in a standard magnetic stripe message
format, in compliance with the Standards.
Manual Cash Disbursement Transaction
A disbursement of cash performed upon the acceptance of a Card by a Customer financial
institution teller. A Manual Cash Disbursement Transaction is identified with MCC 6010 (Manual
Cash Disbursements—Customer Financial Institution).
Marks
The names, logos, trade names, logotypes, trademarks, service marks, trade designations, and
other designations, symbols, and marks that the Corporation owns, manages, licenses, or
otherwise Controls and makes available for use by Customers and other authorized entities in
accordance with a License. A “Mark” means any one of the Marks.
Mastercard
Mastercard International Incorporated, a Delaware U.S.A. corporation.
Mastercard Acceptance Mark
A Mark consisting of the Mastercard Brand Mark or Mastercard Symbol placed on the dark blue
acceptance rectangle, as available at www.mastercardbrandcenter.com.
Mastercard Access Device
An Access Device that uses at least one Mastercard Payment Application to provide access to a
Mastercard Account when used at a Terminal.
Definitions
Magnetic Stripe Mode Contactless Transaction
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Mastercard Account
Any type of account (credit, debit, prepaid, commercial, etc.) identified as a Mastercard Account
with a primary account number (PAN) that begins with a BIN in the range of 222100 to 272099
or 510000 to 559999.
Mastercard Biometric Card
A Mastercard or Maestro Chip Card containing a fingerprint sensor and compliant with the
Corporation’s biometric Standards.
Mastercard-branded Application Identifier (AID)
Any of the Corporation’s EMV chip application identifiers for Mastercard, Maestro, and Cirrus
Payment Applications as defined in the M/Chip Requirements manual.
Mastercard Brand Mark
A Mark consisting of the Mastercard Word Mark as a custom lettering legend placed within the
Mastercard Interlocking Circles Device. The Corporation is the exclusive owner of the Mastercard
Brand Mark. The Mastercard Symbol is also a Mastercard Brand Mark.
Mastercard Card
A Card that provides access to a Mastercard Account.
Mastercard Cloud-Based Payments
A specification that facilitates the provisioning of Digitized Account data into a Host Card
Emulation (HCE) server and the use of the remotely stored Digitized Account data, along with
single-use payment credentials, in Transactions effected by a Cardholder using a Mobile
Payment Device. The Mastercard Digital Enablement Service offers Mastercard Cloud-Based
Payments as an on-behalf service.
Mastercard Consumer-Presented QR Transaction
A Mastercard Consumer-Presented QR Transaction is an EMV Chip Transaction effected
through the presentment of a QR Code by the Cardholder, using a Mobile Payment Device, and
Definitions
Mastercard Account
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
the capture of the QR Code by the Merchant containing the Transaction Data required to
initiate a Transaction.
Each Mastercard Consumer-Presented QR Transaction must comply with all requirements set
forth in the Standards applicable to a Mastercard Consumer-Presented QR Transaction,
including but not limited to those herein, in the technical specifications for authorization
messages, in the M/Chip Requirements for Contact and Contactless manual, and in the
Mastercard Cloud-Based Payments (MCBP) documentation.
Mastercard Customer
A Customer that has been granted a Mastercard License in accordance with the Standards. See
also Member.
Mastercard Digital Enablement Service
Any of the services offered by the Corporation exclusively to Customers for the digital
enablement of Account and/or PTA Account data, including but not limited to ID&V Service,
Tokenization Service, Digitization Service, Token Mapping Service, Mastercard Cloud-Based
Payments, Digital Card Image Database, CVC 3 pre-validation and other on-behalf
cryptographic validation services, and Service Requests.
Mastercard Europe
Mastercard Europe SA, a Belgian private limited liability (company).
Mastercard Incorporated
Mastercard Incorporated, a Delaware U.S.A. corporation.
Mastercard Payment Application
A Payment Application that stores Mastercard Account data.
Mastercard Safety Net
A service offered by the Corporation that performs fraud monitoring at the network level for all
Transactions processed on the Mastercard Network. The service invokes targeted measures to
provide protective controls on behalf of a participating Issuer to assist in minimizing losses in the
event of a catastrophic fraud attack.
Definitions
Mastercard Customer
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Mastercard Symbol
A Mark consisting of the Mastercard interlocking circles device. The Corporation is the exclusive
owner of the Mastercard Symbol. The Mastercard Symbol is also a Mastercard Brand Mark.
Mastercard Token
A Token allocated from a Mastercard Token Account Range that the Corporation has designated
to an Issuer or PTA Customer and that corresponds to an Account PAN or a PTA Account
Number. The Corporation exclusively owns all right, title, and interest in any Mastercard Token.
Mastercard Token Account Range
A bank identification number (BIN) or portion of a BIN (“BIN range”) designated by the
Corporation to an Issuer or PTA Customer for the allocation of Mastercard Tokens in a particular
Token implementation. A Mastercard Token Account Range must be designated from a BIN
reserved for the Corporation by the ISO Registration Authority and for which the Corporation is
therefore the “BIN Controller,” as such term is defined in the EMV Payment Tokenization
Specification Technical Framework (also see the term “Token BIN Range” in that document). A
Mastercard Token Account Range is identified in the Corporation’s routing tables as having the
same attributes as the corresponding Account PAN Range or the range of PTA Account
Numbers.
Mastercard Token Vault
The Token Vault owned and operated by Mastercard and enabled by means of the Mastercard
Digital Enablement Service.
Mastercard Word Mark
A Mark consisting of the word “Mastercard” followed by a registered trademark ® symbol or the
local law equivalent. “Mastercard” must appear in English and be spelled correctly, with the
letter “M” capitalized. “Mastercard” must not be abbreviated, hyphenated, used in the plural or
possessive, translated from English into another language, or appear in another alphabet except
for specific authorized versions in Chinese (translation), Arabic (transliteration), Georgian
(transliteration), and Korean (transliteration). The Corporation is the exclusive owner of the
Mastercard Word Mark.
Definitions
Mastercard Symbol
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Member, Membership
A financial institution or other entity that is approved to be a Mastercard Customer in
accordance with the Standards and which, as a Mastercard Customer, has been granted
membership (“Membership”) in and has become a member (“Member”) of the Corporation.
“Membership” also means “Participation”.
Merchandise Transaction
The purchase by a Cardholder of merchandise or a service, but not currency, in an approved
category at an ATM Terminal and dispensed or otherwise provided by such ATM Terminal. A
Merchandise Transaction is identified with MCC 6012 (Merchandise and Services—Customer
Financial Institution), unless otherwise specified.
Merchant
A retailer, or any other person, firm or corporation that, pursuant to a Merchant Agreement,
agrees to accept Cards when properly presented.
Merchant Agreement
An agreement between a Merchant and a Customer that sets forth the terms pursuant to
which the Merchant is authorized to accept Cards.
Merchant Token Requestor
A Merchant Token Requestor is a Merchant that connects directly to the Mastercard Digital
Enablement Service (MDES) for the purpose of Tokenizing a Mastercard or Maestro Account
primary account number (PAN) provided by a Cardholder for use in a future Transaction with
the Merchant. A Merchant Token Requestor is a type of Token Requestor.
Mobile Payment Device
A Cardholder-controlled mobile device containing a Payment Application compliant with the
Standards, and which uses an integrated keyboard and screen to access an Account. A Mobile
Payment Device may also be a Contactless Payment Device or a Mastercard Consumer-
Presented QR payment device.
Definitions
Member, Membership
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Mobile POS (MPOS) Terminal
An MPOS Terminal enables a mobile device to be used as a POS Terminal. Card “reading” and
software functionality that meets the Corporation’s requirements may reside within the mobile
device, on a server accessed by the mobile device, or in a separate accessory connected (such as
via Bluetooth or a USB port) to the mobile device. The mobile device may be any multi-purpose
mobile computing platform, including, by way of example and not limitation, a feature phone,
smart phone, tablet, or personal digital assistant (PDA).
MoneySend Payment Transaction
A type of Payment Transaction that is effected pursuant to, and subject to, the Mastercard
MoneySend and Funding Transactions Program Standards.
Multi-Account Chip Card
A Chip Card with more than one Account encoded in the chip.
Multi-Factor Authentication Method, MFA Method
A Multi-Factor Authentication (MFA) Method is an authentication solution that includes two or
more factors from the following categories: possession, knowledge, or inherence, with no more
than one factor in any single category.
Non-Mastercard Funding Source
Any funding source used to fund a PTA Transaction other than an Account.
Non-Mastercard Receiving Account
Any receiving account used to receive a PTA Transaction other than an Account.
Non-Mastercard Systems and Networks Standards
The applicable rules, regulations, by-laws, standards, procedures, and any other obligations or
requirements of an applicable payment network or system that is not owned, operated, or
controlled by the Corporation.
Definitions
Mobile POS (MPOS) Terminal
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
On-behalf Token Requestor
A Digital Activity Customer or other Customer, approved by the Corporation to conduct Digital
Activity and authorized to Tokenize a Mastercard or Maestro primary account number (PAN)
using the Mastercard Digital Enablement Service (MDES) on behalf of a DWO or Merchant.
On-Device Cardholder Verification
The use of a CDCVM as the CVM for a Transaction.
Originating Account Holder
The Account Holder originating the PTA Transaction.
Originating Institution (OI)
A PTA Customer that Participates in a Payment Transfer Activity as an originator of PTA
Transactions.
Ownership, Owned
As used herein, ownership has such meaning as the Corporation deems appropriate in its sole
discretion given the context of the usage of the term in all facts and circumstances the
Corporation deems appropriate to consider. As a general guideline, ownership often means to
own indirectly, legally, or beneficially more than fifty percent (50 percent) of an entity.
Participation
The right to participate in Activity, Digital Activity, and/or Payment Transfer Activity granted to
a Customer by the Corporation. For a Mastercard Customer, Participation is an alternative term
for Membership.
Pass-through Digital Wallet
Functionality which can be used at more than one Merchant, and by which the Pass-through
Digital Wallet Operator stores Mastercard or Maestro Account data provided by the Cardholder
to the DWO for purposes of effecting a payment initiated by the Cardholder to a Merchant or
Definitions
On-behalf Token Requestor
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Sponsored Merchant, and upon the performance of a Transaction, transfers the Account data
to the Merchant or Sponsored Merchant or to its Acquirer or the Acquirer’s Service Provider.
Pass-through Digital Wallet Operator (DWO)
A Digital Activity Customer or other Customer, approved by the Corporation to engage in Digital
Activity, that operates a Pass-through Digital Wallet.
Payment Account Reference (PAR)
A unique non-financial alphanumeric value assigned to an Account PAN or PTA Account Number
that is used to link the Account PAN or PTA Account Number to all of its corresponding Tokens.
Payment Application
A package of code and data stored in a Card, an Access Device, a server, or a combination of
Access Device and server, that when exercised outputs a set of data that may be used to effect
a Transaction, in accordance with the Standards. A Mastercard Payment Application, Maestro
Payment Application, and Cirrus Payment Application is each a Payment Application.
Payment Facilitator
A Service Provider registered by an Acquirer to facilitate the acquiring of Transactions by the
Acquirer from Sponsored Merchant, and which in doing so, performs PF Program Service.
Payment Transaction
A PTA Transaction that transfers funds to an Account. A Payment Transaction is not a credit
that reverses a previous purchase. Includes MoneySend Payment Transaction and Gaming
Payment Transaction.
Payment Transfer Activity(ies) (PTA)
The undertaking of any lawful act that can be undertaken only pursuant to a PTA Agreement or
pursuant to a License granted by the Corporation. Participation in a PTA Program is Payment
Transfer Activity.
Definitions
Pass-through Digital Wallet Operator (DWO)
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Personal Data
Any information relating to an identified or identifiable individual, including contact information,
demographic information, passport number, Social Security number or other national
identification number, bank account information, Primary Account Number and authentication
information (e.g., identification codes, passwords).
Point of Interaction (POI)
The location at which a Transaction occurs or a PTA Transaction originates, as determined by
the Corporation.
Point-of-Sale (POS) Terminal
One of the following:
•
An attended or unattended device, including any commercial off-the-shelf (COTS) or other
device enabled with mobile point-of-sale (MPOS) functionality, that is in the physical
possession of a Merchant and is deployed in or at the Merchant’s premises, and which
enables a Cardholder to use a Card or Access Device to effect a Transaction for the purchase
of products or services sold by such Merchant; or
•
A Bank Branch Terminal.
A POS Terminal must comply with the POS Terminal security and other applicable Standards.
Point–of–Sale (POS) Transaction
The sale of products or services by a Merchant to a Cardholder pursuant to acceptance of a
Card by the Merchant or Manual Cash Disbursement Transaction. A POS Transaction may be a
Card-present Transaction taking place in a face-to-face environment or at an unattended POS
Terminal, or a Card-not-present Transaction taking place in a non-face-to-face environment (for
example, an e-commerce, mail order, phone order, or recurring payment Transaction).
Portfolio
All Cards issued bearing the same major industry identifier, BIN/IIN, and any additional digits
that uniquely identify Cards for routing purposes.
Definitions
Personal Data
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Principal Customer, Principal
A Customer that participates directly in Activity using its assigned BINs/IINs and which may
Sponsor one or more Affiliates.
Processed PTA Transaction
A PTA Transaction which is:
1.
Initiated by or on behalf of the Originating Institution via the Corporation System in
accordance with the Standards; and
2.
Cleared, meaning the Originating Institution transferred the PTA Transaction data within
the applicable time frame to the Corporation via the Corporation System, for the purpose
of a transfer of funds via the Corporation System, and such PTA Transaction data is
subsequently transferred by the Corporation to the Receiving Customer for such purpose.
Processed Transaction
A Transaction which is:
1.
Authorized by the Issuer via the Interchange System, unless a properly processed offline
Chip Transaction approval is obtained or no authorization is required, in accordance with the
Standards; and
2.
Cleared, meaning the Acquirer transferred the Transaction Data within the applicable
presentment time frame to the Corporation via the Interchange System, for the purpose of
a transfer of funds via the Interchange System, and such Transaction Data is subsequently
transferred by the Corporation to the Issuer for such purpose.
Processing of Personal Data
Any operation or set of operations which is performed on Personal Data or on sets of Personal
Data, whether or not by automated means, such as collection, recording, organization,
structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by
transmission, dissemination or otherwise making available, alignment or combination,
restriction, erasure or destruction of such data.
Program
A Customer’s Card issuing program, Merchant acquiring program, ATM Terminal acquiring
program, Digital Activity program, and/or a PTA Program in which a Customer is Participating.
Definitions
Principal Customer, Principal
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Program Service
Any service described in the Standards that directly or indirectly supports a Program and
regardless of whether the entity providing the service is registered as a Service Provider of one
or more Customers. The Corporation has the sole right to determine whether a service is a
Program Service.
PTA Account
A PTA Originating Account and/or a PTA Receiving Account.
PTA Account Number
The account number allocated to a PTA Account by a PTA Customer.
PTA Account Portfolio
All PTA Accounts issued by a PTA Customer.
PTA Agreement
The agreement between the Corporation and a PTA Customer granting the PTA Customer the
right to Participate in a PTA Program, in accordance with the Standards.
PTA Customer
A Customer that Participates in a PTA Program pursuant to a PTA Agreement.
PTA Originating Account
The funding source of the Originating Account Holder, from where funds are acquired by the
Originating Institution to initiate a PTA Transaction.
PTA Program
A type of Payment Transfer Activity that is identified in the applicable Standards as being a PTA
Program, including the MoneySend Program, the Mastercard Merchant Presented QR Program,
Definitions
Program Service
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
the Mastercard Send Cross-Border Service, and the Mastercard Gaming and Gambling
Payments Program.
PTA Receiving Account
The Account or, if applicable for a particular PTA Program (as set forth in the Standards for such
PTA Program), the Non-Mastercard Receiving Account, held by a Receiving Account Holder and
to which the Receiving Customer must ensure receipt of a PTA Transaction.
PTA Settlement Guarantee Covered Program
A PTA Settlement Obligation arising from a PTA Transaction conducted pursuant to a PTA
Program that is identified in the applicable Standards as being a PTA Settlement Guarantee
Covered Program.
PTA Settlement Obligation
A financial obligation of a Principal or Association PTA Customer to another Principal or
Association PTA Customer arising from a PTA Transaction.
PTA Transaction
A financial transaction in which funds are transferred from an Originating Institution to a
Receiving Customer on behalf of Account Holders pursuant to a PTA Program.
Quick Response (QR) Code
An ISO 18004-compliant encoding and visualization of data.
Receiving Account Holder
The Account Holder receiving the PTA Transaction.
Receiving Agent
A PTA Customer that Participates in Payment Transfer Activity as an agent for the purpose of
receiving a PTA Transaction.
Definitions
PTA Receiving Account
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Receiving Customer
A Receiving Agent or a Receiving Institution.
Receiving Institution (RI)
A PTA Customer that Participates in Payment Transfer Activity as a receiver of PTA
Transactions on behalf of a Receiving Account Holder.
Region
A geographic region as defined by the Corporation from time to time. See Appendix A of the
Mastercard Rules manual.
Remote Electronic Transaction
In the Europe Region, all types of Card-not-present Transaction (e-commerce Transactions,
recurring payments, installments, Card-on-file Transactions, in-app Transactions, and
Transactions completed through a Digital Wallet, including MasterPass®). Mail order and
telephone order (MO/TO) Transactions and Transactions completed with anonymous prepaid
Cards are excluded from this definition.
Service Provider
A person that performs Program Service. The Corporation has the sole right to determine
whether a person is or may be a Service Provider and if so, the category of Service Provider. A
Service Provider is an agent of the Customer that receives or otherwise benefits from Program
Service, whether directly or indirectly, performed by such Service Provider.
Settlement Obligation
A financial obligation of a Principal or Association Customer to another Principal or Association
Customer arising from a Transaction.
Definitions
Receiving Customer
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Shared Deposit Transaction
A deposit to a savings Account or checking Account conducted at an ATM Terminal located in
the U.S. Region, initiated with a Card issued by a U.S. Region Customer other than the Acquirer,
and processed through the Mastercard ATM Network.
Solicitation, Solicit
An application, advertisement, promotion, marketing communication, or the like distributed as
printed materials, in electronic format (including but not limited to an email, website, mobile
application, or social media platform), or both intended to solicit the enrollment of a person or
entity as a Cardholder or Account Holder or as a Merchant. To “Solicit” means to use a
Solicitation.
Sponsor, Sponsorship
The relationship described in the Standards between:
•
a Principal or Association and an Affiliate that engages in Activity indirectly through the
Principal or Association, in which case, the Principal or Association is the Sponsor of the
Affiliate and the Affiliate is Sponsored by the Principal or Association;
•
a Payment Facilitator and a Sponsored Merchant, in which case the Payment Facilitator is
the Sponsor of the Sponsored Merchant and the Sponsored Merchant is Sponsored by the
Payment Facilitator; or
•
a Digital Activity Sponsoring Customer and a Sponsored Digital Activity Entity, in which case
the Digital Activity Sponsoring Customer is the Sponsor of the Sponsored Digital Activity
Entity.
“Sponsorship” means the Sponsoring of a Customer, a Sponsored Merchant, or a Sponsored
Digital Activity Entity.
Sponsored Digital Activity Entity
A wholly-owned subsidiary (or other affiliated entity as approved by the Corporation) of a
Digital Activity Sponsoring Customer. The Sponsored Digital Activity Entity may be approved at
the sole discretion of the Corporation to participate in Digital Activity pursuant to a Digital
Activity Agreement or other agreement with the Corporation.
Definitions
Shared Deposit Transaction
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Sponsored Merchant
A merchant that, pursuant to an agreement with a Payment Facilitator, is authorized to accept
Cards when properly presented. A Sponsored Merchant is also referred to as a Submerchant.
Sponsored Merchant Agreement
An agreement between a Sponsored Merchant and a Payment Facilitator that sets forth the
terms pursuant to which the Sponsored Merchant is authorized to accept Cards. A Sponsored
Merchant Agreement is also referred to as a Submerchant Agreement.
Staged Digital Wallet
Functionality that can be used at more than one retailer, and by which the Staged Digital Wallet
Operator effects a two-stage payment to a retailer to complete a purchase initiated by a
Cardholder. The following may occur in either order:
•
Payment stage—In the payment stage, the Staged DWO pays the retailer by means of:
– A proprietary non-Mastercard method (and not with a Mastercard Card); or
– A funds transfer to an account held by the Staged DWO for or on behalf of the retailer.
•
Funding stage—In the funding stage, the Staged DWO uses a Mastercard or Maestro
Account provided to the Staged DWO by the Cardholder (herein, the “funding account”) to
perform a transaction that funds or reimburses the Staged Digital Wallet.
The retailer does not receive Mastercard or Maestro Account data or other information
identifying the network brand and payment card issuer for the funding account.
Staged Digital Wallet Operator (DWO)
A registered Service Provider that operates a Staged Digital Wallet.
Standards
The organizational documents, operating rules, regulations, policies, and procedures of the
Corporation, including but not limited to any manuals, guides, announcements or bulletins, as
may be amended from time to time.
Definitions
Sponsored Merchant
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Stand-In Parameters
A set of authorization requirements established by the Corporation or the Issuer that are
accessed by the Interchange System using the Stand-In Processing Service to determine the
appropriate responses to authorization requests.
Stand-In Processing Service
A service offered by the Corporation in which the Interchange System authorizes or declines
Transactions on behalf of and uses Stand-In Parameters provided by the Issuer (or in some
cases, by the Corporation). The Stand-In Processing Service responds only when the Issuer is
unavailable, the Transaction cannot be delivered to the Issuer, or the Issuer exceeds the response
time parameters set by the Corporation.
Strong Customer Authentication (SCA)
Authentication as required by the 2nd Payment Services Directive (Directive [EU] 2015/2366 of
25 November 2015) Regulatory Technical Standards on Strong Customer Authentication (as
amended and replaced from time to time).
Sub-licensee
A person authorized in writing to use a Mark either by a Licensee in accordance with the
Standards or by the Corporation.
Terminal
Any attended or unattended device capable of the electronic capture and exchange of Account
data that meets the Corporation requirements for Terminal eligibility, functionality, and security,
and permits a Cardholder to effect a Transaction in accordance with the Standards. An ATM
Terminal, Bank Branch Terminal, and POS Terminal is each a type of Terminal.
Third Party Processor (TPP)
A Service Provider that performs TPP Program Service.
Definitions
Stand-In Parameters
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Token
A numeric value that (i) is a surrogate for the primary account number (PAN) used by a
payment card issuer to identify a payment card account or is a surrogate for the PTA Account
Number used by a PTA Customer to identify a PTA Account; (ii) is issued in compliance with the
EMV Payment Tokenization Specification Technical Framework; and (iii) passes the basic
validation rules for a PAN, including the Luhn Formula for Computing Modulus 10 Check Digit.
See also Mastercard Token.
Tokenization, Tokenize
The process by which a Mastercard Token replaces an Account PAN or a PTA Account Number.
Token Requestor
An entity that requests the replacement of Account PANs with Mastercard Tokens.
Token Vault
A repository of tokens that are implemented by a tokenization system, which may also perform
primary account number (PAN) mapping and cryptography validation.
Transaction
A financial transaction arising from the proper acceptance of a Card or Account bearing or
identified with one or more of the Brand Marks, either alone or in combination with the marks of
another payment scheme, at a Card acceptance location and identified in messages with a Card
Program identifier.
Transaction Data
Any data and/or data element or subelement that the Standards and/or the Corporation’s
interface specifications require to be used to initiate, authorize, clear, and/or settle a
Transaction or PTA Transaction (whether authorized, cleared, and/or settled via the Interchange
System or otherwise) or that the Corporation requires to be provided.
Definitions
Token
Security Rules and Procedures—Merchant Edition • 6 August 2024 11 February 2025
Transaction Management System
Performs Transaction management services for Mastercard Cloud-Based Payments, which may
include credential authentication, application cryptogram mapping and validation, ensuring
synchronization with the Credentials Management System, and forwarding of Transactions to
the Issuer for authorization.
Trusted Service Manager
Provisions an Access Device with the Payment Application, personalization data, or post-
issuance application management commands by means of an over-the-air (OTA)
communication channel.
Virtual Account
A Mastercard Account issued without a physical Card or Access Device. A Virtual Account cannot
be electronically read.
Volume
The aggregate financial value of a group of Transactions. “Volume” does not mean the number
of Transactions.
Wallet Token Requestor
A Wallet Token Requestor is a Pass-through DWO that connects directly to the Mastercard
Digital Enablement Service (MDES) for the purpose of Tokenizing a Mastercard or Maestro
Account primary account number (PAN) provided by a Cardholder for use in a future
Transaction.
Word Mark
A Mark consisting of the name of one of the Corporation’s brands followed by a registered
trademark ® or ™ symbol (depending on its trademark status in a particular country) or the local
law equivalent. See Cirrus Word Mark, Maestro Word Mark, Mastercard Word Mark.
Definitions
Transaction Management System
Security Rules and Procedures—Merchant Edition • 6 August 2024 ¶ Notices ¶ Following 11 February 2025
Appendix F Privacy and Data Protection Standards for
MATCH Pro
F.1 Purpose..........................................................................................................................................................211
F.2 Scope..............................................................................................................................................................211
F.3 Definitions.....................................................................................................................................................211
F.4 Acknowledgment of Roles..........................................................................................................................213
F.5 The Corporation and Customer Obligations...........................................................................................214
F.6 Data Transfers .............................................................................................................................................216
F.7 Data Disclosures...........................................................................................................................................216
F.8 Security Measures........................................................................................................................................217
F.9 Confidentiality of Personal Information...................................................................................................218
F.10 Personal Information Breach Notification Requirements...................................................................218
F.11 Personal Information Breach Cooperation and Documentation Requirements.............................218
F.12 Data Protection and Security Audit.......................................................................................................218
F.13 Liability.........................................................................................................................................................219
F.14 Termination of MATCH Pro...................................................................................................................... 219
F.15 Invalidity and Severability.........................................................................................................................219
Annex 1 to Appendix F: Processing of Personal Data.................................................................................. 220
Annex 2 to Appendix F: Technical and Organizational Measures Ensure the Security of the Data.....221
Privacy and Data Protection Standards for MATCH Pro
Security Rules and Procedures—Merchant Edition • 11 February 2025
This appendix describes the privacy and data protection for MATCH Pro as they relate to the
Applicable Data Protection Law.
F.1 Purpose
This appendix provides Standards regarding the Processing of Personal Information of
Individuals subject to Applicable Data Protection Law by the Corporation and its Customers
(collectively referred to in this appendix as the "Parties") in the context of Mastercard Alert to
Control High-risk (Merchants) (MATCH Pro) system.
F.2 Scope
The Standards in this appendix supplement the privacy and data protection Standards
contained in Section 1.5 of this manual and Rule 3.13 of the Mastercard Rules to the extent that
the requirements pertain to the Processing of Personal Information subject to Applicable Data
Protection Law in the context of MATCH Pro. In the event of a conflict, the Standards in this
appendix take precedence.
F.3 Definitions
As used solely for the purposes of this appendix, the following terms have the meanings set
forth below. Capitalized terms not otherwise defined herein have the meaning provided in
Appendix E of this manual.
Applicable Data Protection Law
Any Law, statute, declaration, decree, legislation, enactment, order, ordinance, regulation, rule,
circular (as amended and replaced from time to time) that relates to the protection of
individuals with regards to the Processing of Personal Information to which the Parties are policies pertaining to proprietary rights, trademarks, translations, and details ¶ about the availability of additional information online. ¶ Proprietary Rights ¶ The information contained in this document is proprietary and confidential to Mastercard ¶ International Incorporated, one or more of its affiliated entities (collectively “Mastercard”), or ¶ both. ¶ This material may not be duplicated, published, or disclosed, in whole or in part, without the ¶ prior written permission of Mastercard. ¶ Trademarks ¶ Trademark notices and symbols used in this document reflect the registration status of ¶ Mastercard trademarks in the United States. Consult with the Global Customer Service team or ¶ the Mastercard Law Department for the registration status of particular product, program, or ¶ service names outside the United States. ¶ All third-party product and service names are trademarks or registered trademarks of their ¶ respective owners. ¶ EMV® is a registered trademark of EMVCo LLC in the United States and other countries. For ¶ more information, see http://www.emvco.com. ¶ Disclaimer ¶ Mastercard makes no representations or warranties of any kind, express or implied, with respect ¶ to the contents of this document. Without limitation, Mastercard specifically disclaims all ¶ representations and warranties with respect to this document and any intellectual property ¶ rights subsisting therein or any part thereof,
subject, including but not limited to any the EU Data Protection Law; California Consumer Privacy
Act of 2018 (California Civil Code §§ 1798.100 to 1798.199) and its implementing regulations
("CCPA"), as amended including by the California Privacy Rights Act ("CPRA"); California's
Data Breach Notification statue (California Civ. Code §1798.82 et seq.), the California
Commercial Credit Reporting Act (California Civ. Code §1785.41 et seq.); Personal Information
Protection and Electronic Documents Act , Quebec's Law 25 (or an Act to modernize legislative
provisions as regards the protection of personal information); the Brazil General Data
Protection Act; the South Africa Protection of Personal Information Act; the Personal
Information Protection Law of the PRC and other PRC Laws relating to privacy and protection
of Personal information; Kingdom of Saudi Arabia Personal Data Protection Law (amended
2023) and its Implementing Regulations; Nigeria Data Protection Act 2023 and its subsidiary
regulations and guidelines, Turkey Law on the Protection Of Personal Data (DPL) No. 6698 and
its regulations and successors; security breach notification Laws; Laws imposing minimum
Privacy and Data Protection Standards for MATCH Pro
F.1 Purpose
Security Rules and Procedures—Merchant Edition • 11 February 2025
security requirements; Laws requiring the secure disposal of records containing certain Personal
Information; Laws governing the portability and/or cross-border transfer of Personal
Information; and all implied ¶ warranties of title, non-infringement, or suitability other similar international, federal, state, national, provincial, and local
requirements; each as applicable, in connection with MATCH Pro.
Business
The entity which meets the definition of "Business" under CCPA.
Controller
The entity which alone or jointly with others determines the purposes and the means of the
Processing of Personal Information that is subject to Applicable Data Protection Law as
appropriated.
Criminal Data
Any Personal Information relating to criminal convictions, offenses, or related security measures.
EEA Standard Contractual Clauses (EEA SCCs)
The clauses annexed to the EU Commission Decision 2021/914 of June 4, 2021, on standard
contractual clauses for any purpose (the transfer of personal data to third countries pursuant to Regulation
(EU) 2016/679 of the European Parliament and of the Council as amended from time to time.
EU Data Protection Law
The EU General Data Protection Regulation 2016/679 GDPR (as amended and replaced from
time to time) and the e-Privacy Directive 2002/58/EC (as amended by Directive 2009/136/EC,
and as amended and replaced from time to time) and their national implementing legislations;
the Swiss Federal Data Protection Act (as amended and replaced from time to time); the
Monaco Data Protection Act 2018 (as amended and replaced from time to time); the UK Data
Protection Act (as amended and replaced from time to time); and the Data Protection Acts of
the EEA countries (as amended and replaced from time to time).
Mastercard Binding Corporate Rules (Mastercard BCRs)
The Mastercard Binding Corporate Rules as approved by the EEA and UK data protection
authorities and available on the Corporation's public facing website.
Personal Data or Personal Information
Any information relating to an identified or identifiable individual, whether or not Mastercard ¶ has been advised, has reason to know, or is otherwise in fact aware of any information) or ¶ achievement of any particular result. ¶ Translation ¶ A translation of any Mastercard manual, bulletin, release, or other Mastercard document into a ¶ language other than English is intended solely as a convenience to Mastercard customers. ¶ Mastercard provides any translated document to its customers “AS IS” and makes no ¶ representations or warranties of any kind with respect to the translated document, including, ¶ directly or indirectly
identifiable, including but not limited to, its accuracy or reliability. In no event shall Mastercard be liable to contact information, demographic information,
passport number, Social Security number or other national identification number, bank account
information, Primary Account Number and authentication information (e.g., identification
codes, passwords) or as defined under the Applicable Privacy and Data Protection Law.
Personal Data Breach or Personal Information Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration,
unauthorized disclosure of, or access to or other unauthorized Processing of Personal
Information transmitted, stored, or otherwise Processed.
Privacy and Data Protection Standards for any ¶ damages resulting from reliance on any translated document. The English version of any ¶ Mastercard document will take precedence over any translated version in any legal proceeding. ¶ Notices MATCH Pro
F.3 Definitions
Security Rules and Procedures—Merchant Edition • 6 August 2024 ¶ 11 February 2025
Processor
The entity which Processes Personal Information Available Online ¶ subject to Applicable Data Protection Law on
behalf of a Controller.
Sensitive Personal Information
Any Personal Information subject to the Applicable Data Protection Law revealing racial or
ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic
data, biometric data, data concerning health or data concerning a natural person's sex life or
sexual orientation, as well as any other type of data that will be considered to be sensitive
according to any future revision of EU Data Protection Law; or any Personal Information that is
defined as "sensitive personal information" under the Applicable Privacy Law.
Service Provider
The entity which Processes Personal Information subject to CCPA on behalf of a Business as
further described in Section F.4.
UK Addendum
The addendum to the EEA Standard Contractual Clauses issued by the UK Information
Commissioner under Section 119A of the UK Data Protection Act 2018 (Version B1.0, in force
March 21, 2022).
UK Standard Contractual Clauses or UK SCCs
The UK International Data Transfer Addendum to the EU Commission Standard Contractual
Clauses, issued under Section 119A of the Data Protection Act 2018 by the Information
Commissioner and laid before Parliament on 2 February 2022 in force 21 March 2022.
F.4 Acknowledgment of Roles
With respect to Personal Information subject to Applicable Data Protection Law: The
Corporation and its Customers acknowledge and confirm that: (1) neither Party acts as a
Processor on behalf of the other Party; (2) each Party is an independent Controller; and (3) this
appendix does not create a joint-Controllership or a Controller-Processor relationship between
the Parties. The Corporation and its Customers acknowledge and agree that the scope of each
Party’s role as an independent Controller is as follows:
•
A Customer is a Controller for any Processing, including disclosing Personal Information to
the Corporation, for the purpose of developing enhanced or incremental risk information to
aid the Customer in its own determination of risk in its Merchant acquiring business.
•
The Corporation is a Controller for any Processing for the purpose of operating MATCH Pro,
including product development, support and maintenance, and making the MATCH Pro
available to its Customers (e.g., as set out in Chapter 11) and for internal research, fraud,
security, and risk management as listed in Rule 3.10 Confidential Information of Customers
of the Mastercard provides details about the standards used Rules.
Privacy and Data Protection Standards for this document, including times ¶ expressed, language use, and contact information, on the Technical Resource Center (TRC). Go ¶ to the Rules collection of the References section for centralized information. ¶ Notices MATCH Pro
F.4 Acknowledgment of Roles
Security Rules and Procedures—Merchant Edition • 6 August 202411 February 2025
With respect to Corporation's Processing Personal Information subject to CCPA processed
within the MATCH Pro system: Where Acquirer is a Business under CCPA, the Corporation is a
Service Provider.
F.5 The Corporation and Customer Obligations
The Corporation and each Customer independently is responsible for compliance with their
obligations under Applicable Data Protection Law in relation to the Processing of Personal
Information in accordance with each Party's role as described in Section F.4.
Notwithstanding the above, with regard to any Processing of Personal Information of Individuals
that a Customer adds to MATCH Pro, the Customer must:
1.
Rely on a valid legal ground under Applicable Data Protection Law for each of the Processing
purposes, including obtaining Individuals' consent if required or appropriate under Applicable
Data Protection Law.
2.
Provide appropriate notice to the Individuals regarding (i) the their Processing of Personal
Information, in a timely manner (e.g., informing Merchants that Customers are using
MATCH Pro to assess Merchants prior to engaging them and about the possible use of
MATCH Pro upon termination of the Merchant Agreement) and at the minimum with the
elements required under Applicable Data Protection Law, and (ii), as appropriate, the
existence of Mastercard BCRs.
3.
Provide a link to the Corporation's privacy notice for the Processing in relation to Process of
Personal Information in MATCH Pro (available at www.mastercard.com/global/en/vision/
corp-responsibility/commitment-to-privacy/match-privacy.html), subject to Applicable Data
Protection Law, where applicable. Where such processing is subject to CCPA, each
Customer provide appropriate notice for the MATCH Pro processing activities within
Customer's own privacy statement or notice.
4.
Take reasonable steps to ensure that Personal Information are accurate, complete, and
current; adequate, relevant, and limited to what is necessary in relation to the purposes for
which they are Processed.
5.
Respond to Individuals' requests to exercise their rights as required under Applicable Data
Protection Law:
– With respect to the Processing of Personal Information subject to Applicable Data
Protection law, such rights may include the right of (i) access, (ii) rectification, (iii)
erasure, (iv) data portability, (v) restriction of Processing, and (vi) objection to the
Processing, if and as required under Applicable Data Protection Law.
– With respect to the Processing of Personal Information subject to CCPA, such rights may
include the right to (i) know; (ii) correct inaccurate Personal Information; (iv) request
deletion of Personal Information; (iv) opt-out from sale or sharing of Personal
Information (where applicable); or (v) request to limit use and disclosure of sensitive
personal information (where applicable). The Customer will be responsible for responding
to CCPA consumer' requests.
Privacy and Data Protection Standards for MATCH Pro
F.5 The Corporation and Customer Obligations
Security Rules and Procedures—Merchant Edition • 11 February 2025
The Acquirer is responsible for addressing the requests regarding the rectification or
correction and erasure or deletion of Personal Information with respect to Acquirer's MATCH
Pro listings. The Corporation will provide the Customer with reasonable cooperation in
responding to such requests where appropriate.
6.
Limit its Processing of Personal Information to the Processing that is necessary for the
purpose of developing enhanced or incremental risk information to aid in its own
determination of risk in its Merchant acquiring business.
7.
Not engage in or otherwise perform any automated decision-making with legal or similar
effect or profiling based on Personal Information that are Processed in the context of the
MATCH Pro.
8.
Add any Sensitive Personal Information, Criminal Data, or government identification
information of Individuals to MATCH Pro only as necessary for MATCH Pro.
9.
Only Process Personal Information in connection with MATCH Pro for as long as necessary to
achieve the purposes for which they are Processed. Any Personal Information processed in
relation to MATCH Pro must be deleted or destroyed after a maximum of five (5) years.