02.02.2013 Views

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Security<br />

8.10 Site Data Protection Program<br />

Acquirer must notify the Corporation’s SDP Department in writing at<br />

sdp@mastercard.com.<br />

At its discretion and from time to time, the Corporation may also request the<br />

following information:<br />

• Merchant principal data<br />

• The name of any TPP or DSE that performs Transaction processing services<br />

for the Merchant’s Transactions<br />

• Whether the Merchant stores Card data<br />

When considering a Merchant that performs Data Storage, Acquirers should<br />

carefully survey each Merchant’s data processing environment. Merchants that<br />

do not store Card information in a database file still may accept payment<br />

card information via a Web page and therefore store Card data temporarily<br />

in memory files. Merchants that do not perform Data Storage never process<br />

the data in any form but may use a DSE for this purpose, such as in the case<br />

of a Merchant that outsources its environment to a Web hosting company,<br />

or an online Merchant that redirects customers to a payment page hosted by<br />

a third party.<br />

8.10.5 Implementation Schedule<br />

All onsite reviews, network security scans, and self-assessments must be<br />

conducted according to the guidelines in Rule 8.10.2 of this rulebook. For<br />

purposes of the SDP Program, Service Providers in this section refer to TPPs<br />

and DSEs.<br />

The Corporation has the right to audit compliance with the SDP Program<br />

requirements. Noncompliance on or after the required implementation date<br />

may result in the following assessments.<br />

Failure of the following to comply<br />

with the SDP Program mandate… May result in an assessment of…<br />

Classification Violations per calendar year<br />

Level 1 and Level 2 Merchants Up to USD 25,000 for the first violation<br />

Up to USD 50,000 for the second violation<br />

Up to USD 100,000 for the third violation<br />

Up to USD 200,00 for the fourth violation<br />

Level 3 Merchants Up to USD 10,000 for the first violation<br />

Up to USD 20,000 for the second violation<br />

Up to USD 40,000 for the third violation<br />

Up to USD 80,00 for the fourth violation<br />

Level 1 and Level 2 Service Providers Up to USD 25,000 for the first violation<br />

Up to USD 50,000 for the second violation<br />

Up to USD 100,000 for the third violation<br />

Up to USD 200,00 for the fourth violation<br />

©1993–2012 <strong>MasterCard</strong>. Proprietary. All rights reserved.<br />

8-20 9 November 2012 • <strong>Maestro</strong> <strong>Global</strong> <strong>Rules</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!