Re-using Existing Global Financial Networks to authenticate Card Not Present (CNP) Payments

Size: px
Start display at page:

Download "Re-using Existing Global Financial Networks to authenticate Card Not Present (CNP) Payments"

Transcription

1 Re-using Existing Global Financial Networks to authenticate Card Not Present (CNP) Payments isignthis Ltd every card, any IP device, anywhere EurIng John Karantzis B.E. LL.M Contact : john.karantzis@isignthis.com Australian Patents AU A4 & AU US Patent Application 13/576,477 International Patent Application No : PCT/AU2011/ International Patent Applications Pending /Granted in Europe, Africa, Asia, Oceania, North and South America

2 Overview What is Authentication Regulation (Global, SEPA : PSD+ ECB) : Authentication Possible Solutions Open Acceptance Models v Card Scheme Specific Re-using existing network to authenticate payments Other Applications Terminology : In-Band - is the sending of control information within the core message. Ie a message within a message. Out of Band (OOB) the use of an independent means to transfer control information. Eg SMS is independent to . PAN is the primary or personal account number, usually 16 digits for a credit card. 2

3 About isignthis Ltd isignthis Ltd is a Melbourne, Australia, headquartered company. We provide authentication solutions in response to ongoing market & regulatory requirements. Introduction We manage CNP/online risk by authenticating transactions. We provide EU27/SEPA ECB/PSD mandatory compliance solutions for payment service providers/acquirers/ewallets (PSP s). Patents in process/granted in Europe, Americas, Asia, Africa & Oceania. isignthis Ltd : Identity Authentication 3

4 What is Authentication? Background Authentication is a means of verifying a persons identity. Financial Authentication relies upon verified KYC credentials from trusted sources (eg Issuer). Risk Based Assessment (RBA) is NOT authentication. RBA includes AI/predictive/Rules Based/ Neural Nets/Adaptive/Fuzzy logic systems etc 4

5 Plugging the RBA Gaps via Authentication Background ~Low Risk Transactions, 85% processed & passed through In markets where authentication not mandated, use authentication for revenue assurance and minimise revenue leakage, in conjunction with RBA. Also solves the foregone revenue challenge. In the SEPA > what will PSP s risk appetite be? What % will be authenticated? 5

6 European PSP s The mandatory compliance Issue Compliance Euro Central Bank (ECB) has mandated on the 31/1/13 that strong authentication (two factor) required for all online transactions from Feb 2015, for SEPA zone. PSD Articles impose strict liability and responsibility on acquiring PSP s and ewallets for fraud, unless strong authentication is in use. Liability shift from PSP* to issuer upon use of strong authentication. PSP is most often not the issuer or acquirer for any given transaction (even if an issuer/acquirer associated with card schemes/association(s) themselves). isignthis Ltd : Identity Authentication 6

7 EU27/SEPA Payment Services Directive (PSD) & ECB 31 st Jan 2013 Regulations: The 2015 Challenge Compliance All acquiring PSP s / ewallets to authenticate transactions using the issuer s cardholder credentials. How are PSP s to do this if there is no relationship between PSP/acquirer/eWallet and the issuer? What incentive/penalty does issuer have to comply? How to use existing networks to provide the causal link without new dedicated networks and complex technical interfaces to issuer? How to reduce PSP risk whilst promoting multi card scheme acceptance? isignthis Ltd : Identity Authentication 7

8 Solution Overview Uses Issuer Cardholder KYC Credentials for Authentication (Euro Central Bank Compliant) Value Proposition High Rollout Cost / Complexity Issuer Authentication Quadrant Acquirer Authentication Quadrant On the fly Enrolment / 100% reach of cards Issuer or Continuous Notification (Black List) Quadrant Risk Based Assessment (RBA) Quadrant Low Rollout Cost / Complexity isignthis Ltd : Identity Authentication Use Data Profiling for Risk Based Assessment (Not Euro Central Bank Compliant) 8

9 Build or re-use? The Solutions to ECB Requirements Solutions Issuer s develop a networked, dedicated, independent database of cardholder KYC credentials per PAN and confirm during registration. >>>> 3D Secure. (issuing side authentication) Acquirer s/ewallets re-use existing Issuer online/phone banking and Issuer KYC credentials to register PAN/authenticate. >>>> isignthis. (acquiring side authentication) isignthis Ltd : identity Authentication 9

10 Open up Acceptance with Universal Authentication Solutions isignthis Ltd : Identity Authentication 10

11 In-Band OTP Generation (Patented) Say, agreed transaction sum : 100 > A isignthis : 1 st Split : (random) > B 2 nd Split $29.30 (balancing) > C A=B+C (always) and (B/A)% + (C/A)% = (A/A)= 100% (works for forex) B+C are processed as two normal charges via existing financial networks in real time. B and C are unique to any Trx, forming OTP s. Only cardholder can pass issuer security to retrieve Generate in Band OTP isignthis Ltd : Identity Authentication 11

12 Re-Using Existing Networks 12 isignthis Ltd : Identity Authentication 12 3/22/2013

13 >Could Classify Transactions with Risk Based Assessment >Low frequency requirement. >Initial enrolment, and validate every 6 months. OR/ >If risk profile changes OOB Retrieval of OTP isignthis Ltd : Identity Authentication 13

14 isignthis Card Enrolment/Primary Authentication/Mobile Link Infrequent. Low friction. Post sale. Enrolment of Card PAN without intrusive signup or PII being requested OOB Response isignthis Ltd : Identity Authentication 14

15 Secondary Authentication Process (post PAN enrolment + Mobile linked) Independent Secondary OOB 15

16 Feb 2015: PSD Compliance Comparison >Card scheme agnostic/independent >IP Device Agnostic (any internet device) >Single Integration for all schemes >Global Reach >No issuer involvement 16 >Card Scheme centric/dependent >Often Separate card scheme by card scheme integration. >Limited reach based on pre-enrolment >Major involvement by issuer

17 ewallet operators want the broadest sources of funding Application Authenticate incoming funds to create a trusted micropayment source promote ewallet top up, similar to real wallet use Encourages frictionless outbound micropayments larger or riskier outgoing transactions can still be authenticated case by case using OTP via SMS. 17

18 Other Applications Once strong authentication (with verified KYC) is available, there are new opportunities/possibilities for ; e-contract signing e-mandates e-conveyancing i-identity with tokenisation 18

19 Thank you Thank you Links: & ECB 31/1/13 Regulations : (Note : These are recommendations that must be implemented by EU27 as minimum requirements, The detailed recommendations will be integrated into existing oversight frameworks for payment schemes and supervisory frameworks for PSPs and are to be considered as common minimum requirements for internet payment services. The members of the Forum are committed to supporting the implementation of the recommendations in their respective jurisdictions and will strive to ensure effective and consistent implementation within the EEA. ) Financial Services Authority (UK) & the PSD : and The information in this presentation is not legal advice, and are the views of the presenter. PSP s should seek legal advice in order to determine their compliance requirements. isignthis Ltd : Identity Authentication 19

20 Appendices isignthis Ltd : identity Authentication 20

21 Inserting In-Band OTP s into Existing Networks 21

22 Compliance & InfoSec Security isignthis Ltd : Identity Authentication 22

23 isignthis Process Combining Proven Best Practice & Customer Experience with Patented Innovation Web isignthis enhances & simplifies proven customer experience interfaces by eliminating intrusive PII request and advance signup requirements. Mobile isignthis adopts streamlined practice to cell/mobile by using SMS to deliver OTP, post enrolment. We enhance security by adding PIN We mitigate high abandonment rate by an improved customer experience isignthis uses Issuer s Cardholder KYC, and Banking portal Security, and Existing Banking Portals to identify customers. Existing payment networks For PSP s isignthis vastly simplifies Integration We encompass all cards/schemes with single point integration ECB 31/1/13 Reg. compliant 23 Card Schemes / Associations isignthis use as is legacy transaction Networks We don t require a dedicated authentication network (eg 3DSecure.)

24 The Rest of the World Market Value proposition should include: For merchants; Revenue assurance maximisation Revenue leakage minimisation Eliminate false positives and false negatives from RBA systems. Provide open acceptance of many/all card types/schemes Eliminate manual reviews and checks Provide cross border authentication For PSP/Acquirer/eWallet Reduce internal fraud team & call center costs. Minimise chargebacks and administrative costs Single global solution with low rollout capital expenditure an independent all card scheme authentication system. Compliance with EU27 Euro Central Bank regulations 24

25 Comparison 3DSecure / isignthis Feature 3DSecure (3 Domains) isignthis (1 Domain) Acquirer pre-enrolment/ technical links required Issuer pre-enrolment/ technical links required Yes, complex Yes Pre Sale Keystrokes Yes, including leave merchant s website No No No Benchmarking Sales Abandonment Rate (Impact on sale) High (Pre Sale steps) Very Low (Post Sale step) HTML5/.app No, not available Yes, implemented. Card Coverage/Reach 15% Visa, 15% MCard, <1% Amex, <1%JCB, 0% Discover/Diners, 0% CB, 0%CUP or circa 6% overall Liability Shift Limited to reach/enrolled cards, then applicable law. 100% of all card associations and cards issued globally. EC/EU27 Law, Australian EFT Code of Conduct, India. Singapore, Canada? Personal Data (PII) Disclosure High, with Complex signup None Interface Separate iframe per participating bank Customers familiar, trusted online banking interface Integration V Complex: multiple parties, issuers, card associations, acquirers, service providers Risk Based Assessment Yes Yes 25 Single interface at merchant Payment Gateway/PSP for all card types.

26 Card Enrolment: Familiar Customer Experience Our card enrolment process is similar to that experienced by over 90 million PayPal customers to register accounts. Its got some key differences and advantages however. Why isignthis? isignthis is: An improved customer experience (no intrusive signup/ PII requested) Faster (isignthis charges are handled real time versus PayPal which take 3-5 days) Transaction specific, so can be primary transaction authentication. Not limited to verifying just the card per PayPal process. Cross currency capable (without needing exchange rate details) also patented and protected* isignthis Ltd : Identity Authentication 26

27 Card Enrolment Comparison isignthis is simpler, without PII disclosure isignthis Step 1 : Confirm your identity by accessing your credit card statement using phone or online banking, and locating the two charges from the participating merchant. Note : You can access your bank at any time within the next 10 days. A slight delay may be experienced, as some banks process charges overnight to online accounts. Instant access to charges s is available by phoning your bank. Step 2 : Enter the two values you located above, together with your mobile # and a 6 digit PIN. Safekey (from AMEX Help page) Step 1 : Accept the SafeKey Terms and Conditions. Step 2 : Enter your 15-digit Card number. Verified by Visa / (SecureCode) (from ANZ Help page) Step 1 :To enrol, go shopping online at a participating Verified by Visa merchant. When you are ready to buy, enter your Visa card details in the payment page. Step 2 You will automatically be prompted for Verified by Visa enrolment. Enter the following details: Name shown on your ANZ Visa card Signature panel code - the last three digits on the signature panel on the back of your card Card expiry date Your date of birth. Click the 'Enrol Now' button. Note: none of this information will be disclosed to the merchant. Step 3 : Simultaneously authenticate your order & optionally register your mobile upon accepting the isignthis terms and conditions Step 3 : Confirm your identity by entering some security information, which you have given us previously on your Card account Step 3 You will now be asked to create a personal message and Verified by Visa password. Make sure you remember your password; you will be prompted for it each time you shop online at a Verified by Visa store. Click the Submit button.. Step 4 : Create your SafeKey password and personal message Step 4 A confirmation page will be displayed. Your ANZ Visa card is now enrolled for Verified by Visa. isignthis uses issuer s security and KYC, No PII requested. 27 3DSecure involves Intrusive PII demands, contributing to abandonment

PSD2 Compliance - Q&A

PSD2 Compliance - Q&A PSD2 Compliance - Q&A Q: How do hardware-based solutions such as OTP tokens provide dynamic linking with single transactions? In general, users can enter payment information such as the amount of money

More information

Session 2: Understanding the payment ecosystem and the issues Visa Europe

Session 2: Understanding the payment ecosystem and the issues Visa Europe Session 2: Understanding the payment ecosystem and the issues Visa Europe Agnes Revel Martineau VP, Head of Product Specifications, Standards and Industry Liaison ETSI 01st, July, 2014 Agenda You said

More information

White Paper

White Paper White Paper 12.07.11 Augmenting 3-D Secure with Comprehensive Controls for Fraud Prevention Accertify supplements the 3-D Secure authentication tool with fully-integrated risk management for all payment

More information

PSD2 webinar session - Q&A

PSD2 webinar session - Q&A PSD2 webinar session - Q&A Q: How does hardware based solutions such as OTP tokens will provide dynamic linking with single transactions? In general, users can enter payment information, such as the amount

More information

Oracle Banking Digital Experience

Oracle Banking Digital Experience Oracle Banking Digital Experience Wallets User Manual Release 18.1.0.0.0 Part No. E92727-01 January 2018 Wallets User Manual January 2018 Oracle Financial Services Software Limited Oracle Park Off Western

More information

MASTERCARD PRICELESS SPECIALS INDIA PRIVACY POLICY

MASTERCARD PRICELESS SPECIALS INDIA PRIVACY POLICY Effective Date: 12 September 2017 MASTERCARD PRICELESS SPECIALS INDIA PRIVACY POLICY Mastercard respects your privacy. This Privacy Policy describes how we process personal data, the types of personal

More information

White Paper. The Impact of Payment Services Directive II (PSD2) on Authentication & Security

White Paper. The Impact of Payment Services Directive II (PSD2) on Authentication & Security White Paper The Impact of Payment Services Directive II (PSD2) on Authentication & Security First Edition June 2016 Goode Intelligence All Rights Reserved Published by: Goode Intelligence Sponsored by:

More information

Will you be PCI DSS Compliant by September 2010?

Will you be PCI DSS Compliant by September 2010? Will you be PCI DSS Compliant by September 2010? Michael D Sa, Visa Canada Presentation to OWASP Toronto Chapter Toronto, ON 19 August 2009 Security Environment As PCI DSS compliance rates rise, new compromise

More information

MOBILE.NET PRIVACY POLICY

MOBILE.NET PRIVACY POLICY MOBILE.NET PRIVACY POLICY As the operator of the Mobile.net website (https://mobile.net.ltd/) (Website), ADX Labs, LLC. (Company, we or us) is committed to protecting and respecting your privacy. The data

More information

2016 ConCardis GmbH. Fraud Detection Module (basic)

2016 ConCardis GmbH. Fraud Detection Module (basic) Fraud Detection Module (basic) Table of contents 1. Introduction 1.1 Benefits 1.2 Contents 2. Activation and configuration 2.1 Blocking rules 2.1.1 Card country 2.1.2 IP address country 2.1.3 Country consistency

More information

Merchant Guide to PCI DSS

Merchant Guide to PCI DSS 0800 085 3867 www.cardpayaa.com Merchant Guide to PCI DSS Contents What is PCI DSS and why was it introduced?... 3 Who needs to become PCI DSS compliant?... 3 Card Pay from the AA Simple PCI DSS - 3 step

More information

Hertfordshire Natural History Society

Hertfordshire Natural History Society Hertfordshire Natural History Society Privacy Policy This privacy policy sets out how the Hertfordshire Natural History Society (and Herts Bird Club) ( HNHS ) complies with its data protection obligations

More information

A Layered Approach to Fraud Mitigation. Nick White Product Manager, FIS Payments Integrated Financial Services

A Layered Approach to Fraud Mitigation. Nick White Product Manager, FIS Payments Integrated Financial Services A Layered Approach to Fraud Mitigation Nick White Product Manager, FIS Payments Integrated Financial Services Session Agenda Growing Fraud Concerns Old Habits Die Hard Maneuvering through the Barriers

More information

One Sector Community Limited ACN ( OSC ) Privacy Policy

One Sector Community Limited ACN ( OSC ) Privacy Policy One Sector Community Limited ACN 623 427 323 ( OSC ) Privacy Policy General Collection OSC and its related entities (referred to in this document as we, us or our ) are committed to protecting the personal

More information

Privacy Policy Statement Last update 25 th May 2018.

Privacy Policy Statement Last update 25 th May 2018. Privacy Policy Statement Last update 25 th May 2018. Introduction We want our customers to receive a prompt, efficient and courteous service that is delivered in a positive and transparent manner. The

More information

Country Update Germany & Austria

Country Update Germany & Austria Country Update Germany & Austria Martin Thor Sales Unit Manager, Mobile Entertainment DIMOCO Carrier Billing 2000 2006 2011 2015 2016 DIMOCO was founded, aiming to pioneer the mobile payments & messaging

More information

Maintaining Trust: Visa Inc. Payment Security Strategy

Maintaining Trust: Visa Inc. Payment Security Strategy Maintaining Trust: Visa Inc Payment Security Strategy Ellen Richey 2010 Payments Conference Chicago Federal Reserve Global Electronic Payments Protecting the payment system is a shared responsibility among

More information

FREQUENTLY ASKED QUESTIONS

FREQUENTLY ASKED QUESTIONS FREQUENTLY ASKED QUESTIONS 1. What is the YES BANK MasterCard SecureCode? The MasterCard SecureCode is a service offered by YES BANK in partnership with MasterCard. This authentication is basically a password

More information

June 2012 First Data PCI RAPID COMPLY SM Solution

June 2012 First Data PCI RAPID COMPLY SM Solution June 2012 First Data PCI RAPID COMPLY SM Solution You don t have to be a security expert to be compliant. Developer: 06 Rev: 05/03/2012 V: 1.0 Agenda Research Background Product Overview Steps to becoming

More information

Baptist Financial Services

Baptist Financial Services Baptist Financial Services BFS Visa Prepaid PayCard FREQUENTLY ASKED QUESTIONS (FAQ S) Questions for Employers 1 What is a BFS Visa Prepaid PayCard? 2 How do I get a BFS Visa Prepaid PayCard? 3 How does

More information

The Honest Advantage

The Honest Advantage The Honest Advantage READY TO CHALLENGE THE STATUS QUO GSA Security Policy and PCI Guidelines The GreenStar Alliance 2017 2017 GreenStar Alliance All Rights Reserved Table of Contents Table of Contents

More information

Country Update Germany & Austria

Country Update Germany & Austria Country Update Germany & Austria Martin Thor Sales Unit Manager, Mobile Entertainment DIMOCO Carrier Billing Headquartered in Austria with offices in Germany, Hungary and Greece FinTech philosophy at its

More information

Guidelines. on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 (PSD2) EBA/GL/2017/17

Guidelines. on the security measures for operational and security risks of payment services under Directive (EU) 2015/2366 (PSD2) EBA/GL/2017/17 GUIDELINES ON SECURITY MEASURES FOR OPERATIONAL AND SECURITY RISKS UNDER EBA/GL/2017/17 12/01/2018 Guidelines on the security measures for operational and security risks of payment services under Directive

More information

Operator cooperation in South Korea has created a successful identity solution. SK Telecom South Korea

Operator cooperation in South Korea has created a successful identity solution. SK Telecom South Korea Operator cooperation in South Korea has created a successful identity solution SK Telecom South Korea SK Telecom Operator cooperation in South Korea has created a successful identity solution Operator

More information

Authorize.Net Magento 2.x Payment Module

Authorize.Net Magento 2.x Payment Module Authorize.Net Magento 2.x Payment Module User Guide Revision 1.0.1 September 17, 2018 Sep 17 2018 Authorize.Net Global Payment Management for Magento 2.x 1 Contents Document History... 4 1. Introduction...

More information

PCI DSS and the VNC SDK

PCI DSS and the VNC SDK RealVNC Limited 2016. 1 What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) compliance is mandated by many major credit card companies, including Visa, MasterCard, American Express,

More information

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready? European Union (EU) General Data Protection Regulation (GDPR) Do you handle EU residents personal data? The GDPR update is coming May 25, 2018. Are you ready? What do you need to do? Governance and Accountability

More information

TRANSCORP INTERNATIONAL LTD. FAQs: TRANSCORP PREPAID CARD. It can be used for Shopping Outlets, online portals and for cash withdrawal at ATMs.

TRANSCORP INTERNATIONAL LTD. FAQs: TRANSCORP PREPAID CARD. It can be used for Shopping Outlets, online portals and for cash withdrawal at ATMs. TRANSCORP INTERNATIONAL LTD FAQs: TRANSCORP PREPAID CARD Prepaid Reloadable Card Q. What is a TRANSCORP Reloadable Prepaid Card? Transcorp Prepaid Reloadable Card is a Rupee denominated magnetic strip

More information

We may change the privacy notice from time to time by amending this page.

We may change the privacy notice from time to time by amending this page. Holland & Odam Updated 4 th May 2018 This privacy notice sets out how we will process personal data we collect from or about you, or which you provide to us. Please read this notice carefully to understand

More information

Subscriptions and Payment Pages Version 2

Subscriptions and Payment Pages Version 2 Version 2 Published: 26 April 2018 2.1.21 (c) Table of Contents 1 Introduction... 3 1.1 About Subscriptions... 3 1.2 Process Overview... 3 1.3 Pre-requisites... 3 2 Processing a Subscription through Payment

More information

It applies to personal information for individuals that are external to us such as donors, clients and suppliers (you, your).

It applies to personal information for individuals that are external to us such as donors, clients and suppliers (you, your). Our Privacy Policy 1 Purpose Mission Australia is required by law to comply with the Privacy Act 1988 (Cth) (the Act), including the Australian Privacy Principles (APPs). We take our privacy obligations

More information

Starflow Token Sale Privacy Policy

Starflow Token Sale Privacy Policy Starflow Token Sale Privacy Policy Last Updated: 23 March 2018 Please read this Privacy Policy carefully. By registering your interest to participate in the sale of STAR tokens (the Token Sale ) through

More information

The types of personal information we collect and hold

The types of personal information we collect and hold Privacy Policy Modified 22 October, 2018 Our privacy obligations Matriks IT takes privacy seriously and cares about personal information. 'Personal information' means information or an opinion about an

More information

Magento Extension User Guide: Web Services Version 3.6.1

Magento Extension User Guide: Web Services Version 3.6.1 Version 3.6.1 This document explains how to install the official Secure Trading extension on your Magento store. Published: 3 August 2017 Table of Contents 1 Introduction... 3 1.1 Features... 3 1.2 Requirements...

More information

Personal account manual A ME

Personal account manual A ME Personal account manual A.005.34.01-01.ME 05.07.2018 Table of Contents 1. Logging in... 4 2. Main page... 6 3. Orders monitor... 6 3.1. Orders search... 7 3.2. Search results... 8 3.3. Saving data to file...

More information

PCI DSS and VNC Connect

PCI DSS and VNC Connect VNC Connect security whitepaper PCI DSS and VNC Connect Version 1.2 VNC Connect security whitepaper Contents What is PCI DSS?... 3 How does VNC Connect enable PCI compliance?... 4 Build and maintain a

More information

Elders Estates Privacy Notice

Elders Estates Privacy Notice 15A Bath Street, Ilkeston Derbyshire. DE7 8AH 01159 32 55 23 info@eldersestates.co.uk 31 Market Place, Ripley Derbyshire. DE5 3HA 01773 30 44 44 info@eldersestates.co.uk Elders Estates Privacy Notice Introduction

More information

Professional Certificate in Complex Financial Instruments in International Financial Services

Professional Certificate in Complex Financial Instruments in International Financial Services International Financial Services MEMBERSHIP In order to register to an Institute of Banking (IoB) programme you must be a current member of the Institute. The membership fee of 40 is applicable upon joining

More information

GDPR Compliance. Clauses

GDPR Compliance. Clauses 1 Clauses GDPR The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a privacy and data protection regulation in the European Union (EU). It became enforceable from May 25 2018. The

More information

BT Assure Cloud Identity Annex to the General Service Schedule

BT Assure Cloud Identity Annex to the General Service Schedule 1 Defined Terms The following definitions apply, in addition to those in the General Terms and Conditions and the General Service Schedule of the Agreement. Administrator means a Customer-authorised person

More information

Endpoint Security for Wholesale Payments

Endpoint Security for Wholesale Payments Endpoint Security for Wholesale Payments 2018 CHICAGO PAYMENTS SYMPOSIUM EMILY CARON MANAGER, FMI RISK & POLICY FEDERAL RESERVE BOARD The views expressed in this presentation are those of the speaker and

More information

Wirecard CEE Integration Documentation

Wirecard CEE Integration Documentation Created on: 20180117 21:34 by Wirecard CEE Integration Documentation () Created: 20180117 21:34 Online Guides Integration documentation 1/9 Created on: 20180117 21:34 by Credit Card General information

More information

Joint Initiative on a PSD2 Compliant XS2A Interface NextGenPSD2 XS2A Framework Operational Rules

Joint Initiative on a PSD2 Compliant XS2A Interface NextGenPSD2 XS2A Framework Operational Rules Joint Initiative on a PSD2 Compliant XS2A Interface NextGenPSD2 XS2A Framework Operational Rules 02.10.2017 Notice This Specification has been prepared by the Participants of the Joint Initiative pan-european

More information

Personal account manual A ME

Personal account manual A ME Personal account manual A.005.34.01-01.ME 08.04.2019 Table of Contents 1. Logging in... 4 2. Main page... 6 3. Orders monitor... 6 3.1. Orders search... 7 3.2. Search results... 9 3.3. Saving data to file...

More information

Business Question Dictionary

Business Question Dictionary Business Question Dictionary Referral Partner/Parent Affiliation Are any fees to be billed to someone other than the contact listed in the header? Answering 'Yes' to this question will allow you to set

More information

Token Sale Privacy Policy

Token Sale Privacy Policy Token Sale Privacy Policy PRIVACY POLICY LAST UPDATED ON: [11 SEP 2018] A. OVERVIEW You must read the entirety of this Privacy Policy carefully before making any decision to purchase Tokens. You must also

More information

SBI Mingle Mobile App User Manual

SBI Mingle Mobile App User Manual SBI Mingle Mobile App User Manual 1. Registration i. SBI Facebook User Registration SBI customer who has a facebook account need to follow the below steps for Registration process Download SBI Mingle application

More information

PCI DSS 3.1 is here. Are you ready? Mike Goldgof Sr. Director Product Marketing

PCI DSS 3.1 is here. Are you ready? Mike Goldgof Sr. Director Product Marketing PCI DSS 3.1 is here. Are you ready? Mike Goldgof Sr. Director Product Marketing 1 WhiteHat Security Application Security Company Leader in the Gartner Magic Quadrant Headquartered in Santa Clara, CA 320+

More information

PCI DSS. Compliance and Validation Guide VERSION PCI DSS. Compliance and Validation Guide

PCI DSS. Compliance and Validation Guide VERSION PCI DSS. Compliance and Validation Guide PCI DSS VERSION 1.1 1 PCI DSS Table of contents 1. Understanding the Payment Card Industry Data Security Standard... 3 1.1. What is PCI DSS?... 3 2. Merchant Levels and Validation Requirements... 3 2.1.

More information

Reference Offer for Wholesale Roaming Access

Reference Offer for Wholesale Roaming Access Reference Offer for Wholesale Roaming Access Published on the grounds of Article 3 of Regulation (EU) No 531/2012 of the European Parliament and the Council of 13 June 2012 Whereas, Regulation (EU) No

More information

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information Privacy Statement Introduction Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information about how IT Support (UK) Ltd handle personal information.

More information

BFS VISA PREPAID CARDS FREQUENTLY ASKED QUESTIONS (FAQ S)

BFS VISA PREPAID CARDS FREQUENTLY ASKED QUESTIONS (FAQ S) BFS VISA PREPAID CARDS FREQUENTLY ASKED QUESTIONS (FAQ S) 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 What is a BFS Visa Prepaid

More information

PRIVACY POLICY TABLE OF CONTENTS. Last updated October 05, 2018

PRIVACY POLICY TABLE OF CONTENTS. Last updated October 05, 2018 PRIVACY POLICY Last updated October 05, 2018 Thank you for choosing to be part of Vistalytics Inc., ( Company, we, us, or our ). We are committed to protecting your personal information and your right

More information

Trusted Identities That Drive Global Commerce

Trusted Identities That Drive Global Commerce Trusted Identities That Drive Global Commerce For information of the BCS/EEMA Community A truly Federated Trust Network - Building upon core competences of the worlds banks & payments systems Governance

More information

PRIVACY STATEMENT OF TIBBAA SMARTCARD

PRIVACY STATEMENT OF TIBBAA SMARTCARD PRIVACY STATEMENT OF TIBBAA SMARTCARD 1. PERSONAL USE OF DATA 2. TS INFORMATION COLLECTED AND USED 3. INFORMATION ACCESSED BY TS FROM THIRD PARTIES 4. INFORMATION COLLECTED ON WEBSITES 5. INFORMATION OF

More information

Section 3.9 PCI DSS Information Security Policy Issued: November 2017 Replaces: June 2016

Section 3.9 PCI DSS Information Security Policy Issued: November 2017 Replaces: June 2016 Section 3.9 PCI DSS Information Security Policy Issued: vember 2017 Replaces: June 2016 I. PURPOSE The purpose of this policy is to establish guidelines for processing charges on Payment Cards to protect

More information

PCI compliance the what and the why Executing through excellence

PCI compliance the what and the why Executing through excellence PCI compliance the what and the why Executing through excellence Tejinder Basi, Partner Tarlok Birdi, Senior Manager May 27, 2009 Agenda 1. Introduction 2. Background 3. What problem are we trying to solve?

More information

Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE

Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE Beam Suntory Privacy Policy WEBSITE PRIVACY NOTICE Beam Suntory ("we"; "us"; "our") respects your privacy and is committed to protecting your personal information at all times in everything we do. We are

More information

Universal Representation of a Consumer's Identity Is it Possible? Presenter: Rob Harris, VP of Product Strategy, FIS

Universal Representation of a Consumer's Identity Is it Possible? Presenter: Rob Harris, VP of Product Strategy, FIS Universal Representation of a Consumer's Identity Is it Possible? Presenter: Rob Harris, VP of Product Strategy, FIS Topics Consumer identity why it is important How big a problem is identity fraud? What

More information

How PayPal can help colleges and universities reduce PCI DSS compliance scope. Prepared by PayPal and Sikich LLP.

How PayPal can help colleges and universities reduce PCI DSS compliance scope. Prepared by PayPal and Sikich LLP. How PayPal can help colleges and universities reduce PCI DSS compliance scope. Prepared by PayPal and Sikich LLP. Reduce time and resources needed for PCI DSS compliance. Campus merchants want to offer

More information

IP Pay. End User System Reference Manual. Document revision October 2008

IP Pay. End User System Reference Manual. Document revision October 2008 IP Pay End User System Reference Manual Document revision 1.3 6 October 2008 1 Table of Contents Introduction 3 DECLINE Response Codes 4 AVS Result Codes 7 CVV2/CVC/CID Result Codes 9 CAVV Result Codes

More information

What is HIPPA/PCI? Understanding HIPAA. Understanding PCI DSS

What is HIPPA/PCI? Understanding HIPAA. Understanding PCI DSS What is HIPPA/PCI? In this digital era, where every bit of information pertaining to individuals has gone digital and is stored in digital form somewhere or the other, there is a need protect the individuals

More information

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk

CURTIS BANKS LIMITED. Privacy Information Notice. curtisbanks.co.uk CURTIS BANKS LIMITED Privacy Information Notice curtisbanks.co.uk Contents Section Page 1 Who we are 3 2 Why we need to collect, use and process personal information 3 3 The information we may collect,

More information

MasterPass Guide. Business Gateway. V1.1 February Use this guide to:

MasterPass Guide. Business Gateway. V1.1 February Use this guide to: Business Gateway MasterPass Guide V1.1 February 2015 Use this guide to: Learn about the MasterPass digital wallet service Anticipate how MasterPass may affect your system and procedures MasterPass Guide

More information

STPP Testing Published: 8 December 2017

STPP Testing Published: 8 December 2017 During integration with Secure Trading s systems, the Merchant can perform tests on the system using the details supplied within this document. Published: 8 December 2017 1.18 Table of Contents 1 Introduction...

More information

2012PHILIPPINES ECC International :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA

2012PHILIPPINES ECC International :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA Effective Data Security Measures on Payment Cards through PCI DSS 2012PHILIPPINES ECC International :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA Learning Bites Comprehend the foundations, requirements,

More information

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe

Robert Bond. Respecting Privacy, Securing Data and Enabling Trust a view from Europe Respecting Privacy, Securing Data and Enabling Trust a view from Europe Robert Bond, Partner & Notary Public Robert Bond Robert Bond has nearly 40 years' experience in advising national and international

More information

Join the Revolution in prepaid payments!

Join the Revolution in prepaid payments! Join the Revolution in prepaid payments! Executives With Extensive Expertise Gotawallet was created by a team of executives with a deep understanding and extensive expertise Telecom Billing Payment Remittance

More information

ekashu Frequently Asked Questions

ekashu Frequently Asked Questions ekashu Frequently Asked Questions Document addressing commonly raised support queries and issues for new integrators. Issue: 1 (November 2013) Author: Fred Spooner (Integration Support) Action Name Date

More information

PCI Compliance: It's Required, and It's Good for Your Business

PCI Compliance: It's Required, and It's Good for Your Business PCI Compliance: It's Required, and It's Good for Your Business INTRODUCTION As a merchant who accepts payment cards, you know better than anyone that the war against data fraud is ongoing and escalating.

More information

GLOBAL MOBILE PAYMENT METHODS: FIRST HALF 2016

GLOBAL MOBILE PAYMENT METHODS: FIRST HALF 2016 PUBLICATION DATE: OCTOBER 2016 PAGE 2 GENERAL INFORMATION I PAGE 3 KEY FINDINGS I PAGE 4-8 TABLE OF CONTENTS I PAGE 9 REPORT-SPECIFIC SAMPLE CHARTS I PAGE 10 METHODOLOGY I PAGE 11 RELATED REPORTS I PAGE

More information

GDPR Compliant. Privacy Policy. Updated 24/05/2018

GDPR Compliant. Privacy Policy. Updated 24/05/2018 GDPR Compliant Privacy Policy Updated 24/05/2018 Overview This privacy policy is in compliance with the General Data Protection Act which aims to empower all EU citizens data privacy and to reshape the

More information

Depending on the Services or information you request from us, we may ask you to provide the following personal information:

Depending on the Services or information you request from us, we may ask you to provide the following personal information: LINK HUNGARY PRIVACY POLICY PROTECTING YOUR DATA 1. Who are Link Asset Services and Link Hungary? Link Asset Services ( Link ) is a trading name of companies which offer a range of services, principally

More information

Table of Contents. PCI Information Security Policy

Table of Contents. PCI Information Security Policy PCI Information Security Policy Policy Number: ECOMM-P-002 Effective Date: December, 14, 2016 Version Number: 1.0 Date Last Reviewed: December, 14, 2016 Classification: Business, Finance, and Technology

More information

CHAPTER 13 ELECTRONIC COMMERCE

CHAPTER 13 ELECTRONIC COMMERCE CHAPTER 13 ELECTRONIC COMMERCE Article 13.1: Definitions For the purposes of this Chapter: computing facilities means computer servers and storage devices for processing or storing information for commercial

More information

Privacy Policy Effective May 25 th 2018

Privacy Policy Effective May 25 th 2018 Privacy Policy Effective May 25 th 2018 1. General Information 1.1 This policy ( Privacy Policy ) explains what information Safety Management Systems, 2. Scope Inc. and its subsidiaries ( SMS ), it s brand

More information

Global Trends in Payment Systems

Global Trends in Payment Systems Global Trends in Payment Systems Summary of 2010 Survey Findings May 2011 Global Payment Trends Survey Overview For the 3 rd year running, Edgar, Dunn & Company has conducted a survey of payments professionals

More information

GDPR AMC SAAS AND HOSTED MODULES. UK version. AMC Consult A/S June 26, 2018 Version 1.10

GDPR AMC SAAS AND HOSTED MODULES. UK version. AMC Consult A/S June 26, 2018 Version 1.10 GDPR AMC SAAS AND HOSTED MODULES UK version AMC Consult A/S June 26, 2018 Version 1.10 INDEX 1 Signatures...3 2 General...4 3 Definitions...5 4 Scoping...6 4.1 In scope...6 5 Responsibilities of the data

More information

VIRTUAL TERMINAL GUIDE

VIRTUAL TERMINAL GUIDE VIRTUAL TERMINAL GUIDE Version 1.4 Jan 2017 1 TABLE OF CONTENTS ABOUT THIS GUIDE... 2 INTRODUCTION... 3 ACCESSING THE VIRTUAL TERMINAL... 4 SUBMITTING A PAYMENT... 5 VIEWING YOUR TRANSACTIONS... 7 Virtual

More information

ETSY.COM - PRIVACY POLICY

ETSY.COM - PRIVACY POLICY At Etsy, we value our community. You trust us with your information, and we re serious about that responsibility. We believe in transparency, and we re committed to being upfront about our privacy practices,

More information

Mobile Phone Banking Users Guide

Mobile Phone Banking Users Guide Internet Business Service Provider Mobile Phone Banking Users Guide IBSP Hong Kong Ltd Suite 2909-10, 29/F. China Resources Building, No. 26 Harbour Road, Wanchai, Hong Kong 2012-05-01 Version 1.7 IBSP

More information

N Touch Treasury. Getting Started

N Touch Treasury. Getting Started N Touch Treasury Getting Started Revised 12-15-17 TreasurySupport@NTouchBanking.com (833) 846-2699 How Do I Log into N Touch Treasury? You will be provided a Company ID and Login ID prior to logging in

More information

DECISION OF THE EUROPEAN CENTRAL BANK

DECISION OF THE EUROPEAN CENTRAL BANK L 74/30 Official Journal of the European Union 16.3.2013 DECISIONS DECISION OF THE EUROPEAN CENTRAL BANK of 11 January 2013 laying down the framework for a public key infrastructure for the European System

More information

2017 NACHA Third-Party Sender Initiatives

2017 NACHA Third-Party Sender Initiatives 2017 NACHA Third-Party Sender Initiatives Jordan Bennett Senior Director, Network Risk NACHA 2 MAC is an organization of Bankcard professionals involved in the risk management side of Card Processing.

More information

Executive Summary of the Prepaid Rule

Executive Summary of the Prepaid Rule 1700 G Street NW, Washington, DC 20552 October 5, 2016 This summary is current as of October 5, 2016. It has not been updated to reflect final rules, guidance, or other interpretations issued after this

More information

Important Notice. All company and brand products and service names are trademarks or registered trademarks of their respective holders.

Important Notice. All company and brand products and service names are trademarks or registered trademarks of their respective holders. Important Notice Magento reserves the right to make corrections, modifications, enhancements, improvements, and other changes to its products and services at any time and to discontinue any product or

More information

Nespresso Consumer Privacy Notice

Nespresso Consumer Privacy Notice Nespresso Consumer Privacy Notice Effective: March 4, 2015 Last Updated On: March 4, 2015 Please read this Notice carefully to understand our policies and practices regarding your personal information

More information

Magento 2 Community / Enterprise Plugin

Magento 2 Community / Enterprise Plugin Realex Payments Magento 2 Community / Enterprise Plugin Configuration Guide Version: 1.1 A web version of this guide is available on the Realex Developer Hub 1 Document Information Document Name: Magento

More information

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business Comodo HackerGuardian PCI Security Compliance The Facts What PCI security means for your business Overview The Payment Card Industry Data Security Standard (PCI DSS) is a set of 12 requirements intended

More information

Open Banking Consent Model Guidelines. Part 1: Implementation

Open Banking Consent Model Guidelines. Part 1: Implementation Open Banking Consent Model Guidelines Part 1: Implementation Open Banking Read/Write API October 2017 Contents 1 Introduction 3 2 Open Banking Consent Model - Consent, Authentication and Authorisation

More information

Introduction. When it comes to GDPR compliance, is OK for now enough? Minds made for protecting financial services

Introduction. When it comes to GDPR compliance, is OK for now enough? Minds made for protecting financial services When it comes to GDPR compliance, is OK for now enough? EY CertifyPoint s GDPR certification process will help you achieve and demonstrate compliance. Minds made for protecting financial services Introduction

More information

Identity & security CLOUDCARD+ When security meets convenience

Identity & security CLOUDCARD+ When security meets convenience Identity & security CLOUDCARD+ When security meets convenience CLOUDCARD+ When security meets convenience We live in an ever connected world. Digital technology is leading the way to greater mobility and

More information

Oracle Banking Digital Experience

Oracle Banking Digital Experience Oracle Banking Digital Experience Retail Accounts User Manual Release 17.2.0.0.0 Part No. E88573-01 July 2017 Retail Accounts User Manual July 2017 Oracle Financial Services Software Limited Oracle Park

More information

POMONA EUROPE ADVISORS LIMITED

POMONA EUROPE ADVISORS LIMITED POMONA EUROPE ADVISORS LIMITED Personal Information Notice Pomona Europe Advisors Limited (Pomona, we/us/our) wants you to be familiar with how we collect, use and disclose personal information. This Personal

More information

white paper SMS Authentication: 10 Things to Know Before You Buy

white paper SMS Authentication: 10 Things to Know Before You Buy white paper SMS Authentication: 10 Things to Know Before You Buy SMS Authentication white paper Introduction Delivering instant remote access is no longer just about remote employees. It s about enabling

More information

Prizetech Privacy Policy

Prizetech Privacy Policy Prizetech Privacy Policy Last updated: 13 July 2018 Privacy Policy Prizetech Pty Ltd is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

More information

PCI Data Security. Meeting the Challenges of PCI DSS Payment Card Security

PCI Data Security. Meeting the Challenges of PCI DSS Payment Card Security White Paper 0x8c1a3291 0x56de5791 0x450a0ad2 axd8c447ae 8820572 0x5f8a153d 0x19df c2fe97 0xd61b5228 0xf32 4856 0x3fe63453 0xa3bdff82 0x30e571cf 0x36e0045b 0xad22db6a 0x100daa87 0x48df 0x5ef8189b 0x255ba12

More information

Submission to the International Integrated Reporting Council regarding the Consultation Draft of the International Integrated Reporting Framework

Submission to the International Integrated Reporting Council regarding the Consultation Draft of the International Integrated Reporting Framework Submission to the International Integrated Reporting Council regarding the Consultation Draft of the International Integrated Reporting Framework JULY 2013 Business Council of Australia July 2013 1 About

More information

Google Cloud & the General Data Protection Regulation (GDPR)

Google Cloud & the General Data Protection Regulation (GDPR) Google Cloud & the General Data Protection Regulation (GDPR) INTRODUCTION General Data Protection Regulation (GDPR) On 25 May 2018, the most significant piece of European data protection legislation to

More information

Bye Bye Paper! Getting to 100% Electronic Payroll. Presenter: John Laudani

Bye Bye Paper! Getting to 100% Electronic Payroll. Presenter: John Laudani Bye Bye Paper! Getting to 100% Electronic Payroll Presenter: John Laudani Agenda Market Update Electronic Payroll and Paycards Employer and Employee Benefits Questions and Comments PlanSource & rapid!

More information