Network rules and shared records governing payment eligibility

Mastercard

Mastercard operates a payment network whose rules govern participating financial institutions and merchant-risk processes. It can require acquiring banks to investigate referrals and enforce network standards, and its MATCH system supplies risk information that other payment firms use when deciding whom to serve.

Mastercard is a payment network with rules that participating financial institutions must follow. In this investigation, its significance lies in that rulemaking position and in the shared merchant-risk infrastructure used by payment providers. A website may deal directly with a processor, but its ability to take card payments also depends on the acquiring bank and the network behind that relationship.

Its anti-piracy policy illustrates how outside information enters the system. Qualifying rights owners and authorized associations can submit referrals supported by evidence and attestations. Mastercard's policy requires the acquirer to investigate and report, with different response periods for law-enforcement evidence and qualifying private referrals. Mastercard reserves authority to interpret and enforce its policy and can impose restrictions or sanctions on network participants that fail to comply.

MATCH adds another mechanism. It stores specified merchant-risk information that prospective providers can consult. The rules include a five-year central listing period and certain grounds for early removal. Stripe's published practice generally disqualifies listed merchants, while allowing consideration of documented exceptional circumstances. A shared risk record can therefore influence a later commercial decision made by a different company.

The gaming controversy exposed how difficult it can be to see the whole chain from outside. Valve described indirect Mastercard communications through processors and acquiring banks; Mastercard publicly denied evaluating games or requiring game-platform restrictions. The original instructions and all counterparties remain unavailable. The established structural point is substantial: network policy, bank decisions and processor discretion together determine whether a lawful online business can accept a widely used form of payment.

Sky names Mastercard among early PDC participants. Its September 14 financing story describes a planned approximately £50m setup equity solicitation, not closed funding. No participant-specific contribution, equity percentage or voting right was acquired.

Assessment updated 2026-09-14

Detailed records and research

What the records show

22 August 2025 NCII payment-platform letterMastercard

requests proactive NCII seller payment-authorization removal

Letter dated 22 August 2025; announcement 26 August. Actual dispatch/receipt and response not acquired.

Addressed to Mastercard legal representatives: asks present controls and further action enforcing existing terms/acceptable-use policies against sellers of deepfake NCII tools/content. Seller-level scope; no named bank instruction, adjudication, compulsory response deadline or confirmed receipt/implementation. Not a general pornography ban.

Merchants and owners — MATCH rule scopeMastercard

may seek applicable personal-information remedies

March2026 notice describes law-dependent access/correction/restriction/deletion/complaint routes, with California requests to relevant institutions and other requests possibly redirected. One-month written reply is not correction deadline; no universal processing entitlement.

MastercardMastercard acquirers · rule scope

requires investigation and reporting

Policy requires acquirer investigation/reporting within2businessdays for law-enforcement evidence or5 for qualifying private referrals, with discretionary extensions. WIPO is not classified as law enforcement here; clocks are not added to WIPO notice periods.

MastercardMastercard MATCH Pro

permits early removal on specified grounds

Section11.13 permits removal for erroneous addition reported by an authorized user or specified cured PCI code12 noncompliance. Merchant direct application when acquirer unwilling/unable is narrow PCI route, not general bypass.

IP owners and authorized associations — provider-policy roleMastercard

may submit qualifying IP referrals under general policy

General Anti-Piracy Policy permits rights-owner/authorized-association referrals with evidence and attestations. This does not prove a WIPO ALERT-PAY intake route or accepted Creative request.

MastercardMastercard acquirers · rule scope

retains policy interpretation and membership sanctions

Mastercard reserves interpretation/enforcement and possible membership restriction or sanctions for noncompliance. No exercised sanction in this packet.

MastercardMastercard acquirers · rule scope

Network compliance obligations

Rules dated 2025-06-03; §§5.1.2, 5.12.7

Pre-event rules assign acquirer responsibilities and provide brand-harm enforcement measures. No incident-specific notice or penalty recovered.

From the investigation

Mastercard: investigation, product-level action, and conditional wider notice

The policy's opening BRAM context also reserves discretion over transactions considered damaging to Mastercard's goodwill. That broader context should not be silently turned into an ALERT-PAY eligibility criterion. The inspected programme concerns counterfeit goods and subscription piracy; the underlying provider contract may have other grounds, whose application requires separate evidence.

Read the research & sources ↗
Mastercard: investigation, product-level action, and conditional wider notice

This is the provider's general policy, not an acquired ALERT-PAY addendum. WIPO's institutional status does not establish that its alert enters the law-enforcement route. Do not add Mastercard's two/five-business-day clocks to WIPO's notification clocks. A merits response, merchant termination and MATCH entry remain distinct. No MATCH deletion/restoration rule or completed appeal was acquired in this lane; that does not establish that none exists elsewhere.

Read the research & sources ↗
The records still held elsewhere

The Steam joint is Valve's processor notice and response, the corresponding Mastercard/acquirer message and the actual counterparty identities. Valve payments/legal and its processor counterparts should hold operational communications; Valve press and GamingOnLinux hold the identified company replies. The published replies establish an attributed account, not the contents of unrecovered upstream records.

Read the research & sources ↗
Payment permissions: bounded acquisition return

The strongest new addition is Steam's own attributed notice chain. Valve supplied statements to the journalist who published them, including a rejected alternative and the precise Mastercard rule reportedly invoked. Separately, original itch records expose an earlier platform payout decision and a contemporaneous UK geographic-compliance decision. The bank behind itch's July 2025 restriction remains unidentified.

Read the research & sources ↗

Further reading

Public officials ask payment networks to use private rules

MATCH correction, privacy and a worked judicial challenge

MATCH Pro: required information sharing, independent admission, and correction duties

Baseline evidence custody

ICMEC acquisition findings — 8 September 2026

Payment permissions: bounded acquisition return

WIPO ALERT-PAY: participant confirmation and provider decision rights

WIPO ALERT-PAY: the programme, the described process, and what its pilot measures

Read the original sources 4

What the connections say

14 relationships
5

22 August 2025 NCII payment-platform letterrequests proactive NCII seller payment-authorization removalMastercard

Letter dated 22 August 2025; announcement 26 August. Actual dispatch/receipt and response not acquired.

Addressed to Mastercard legal representatives: asks present controls and further action enforcing existing terms/acceptable-use policies against sellers of deepfake NCII tools/content. Seller-level scope; no named bank instruction, adjudication, compulsory response deadline or confirmed receipt/implementation. Not a general pornography ban.

Read the original source 1
8

Mastercardrequires investigation and reportingMastercard acquirers · rule scope

Policy requires acquirer investigation/reporting within2businessdays for law-enforcement evidence or5 for qualifying private referrals, with discretionary extensions. WIPO is not classified as law enforcement here; clocks are not added to WIPO notice periods.

Read the original source 1
12

Merchants and owners — MATCH rule scopemay seek applicable personal-information remediesMastercard

March2026 notice describes law-dependent access/correction/restriction/deletion/complaint routes, with California requests to relevant institutions and other requests possibly redirected. One-month written reply is not correction deadline; no universal processing entitlement.

Read the original source 1

Read the wider story

The big picture

Who gets to operate the switches?

Governments, funders, campaigners and companies exchange different kinds of power. The consequential moment is when someone turns another institution’s input into a decision.

Read the story
Payments & platforms

When a classification reaches your wallet

A risk list, a payment-network rule and a processor’s decision can each contribute to a restriction. They are different steps, often controlled by different institutions.

Read the story