Network rules and shared records governing payment eligibility
Mastercard
Mastercard operates a payment network whose rules govern participating financial institutions and merchant-risk processes. It can require acquiring banks to investigate referrals and enforce network standards, and its MATCH system supplies risk information that other payment firms use when deciding whom to serve.
Mastercard is a payment network with rules that participating financial institutions must follow. In this investigation, its significance lies in that rulemaking position and in the shared merchant-risk infrastructure used by payment providers. A website may deal directly with a processor, but its ability to take card payments also depends on the acquiring bank and the network behind that relationship.
Its anti-piracy policy illustrates how outside information enters the system. Qualifying rights owners and authorized associations can submit referrals supported by evidence and attestations. Mastercard's policy requires the acquirer to investigate and report, with different response periods for law-enforcement evidence and qualifying private referrals. Mastercard reserves authority to interpret and enforce its policy and can impose restrictions or sanctions on network participants that fail to comply.
MATCH adds another mechanism. It stores specified merchant-risk information that prospective providers can consult. The rules include a five-year central listing period and certain grounds for early removal. Stripe's published practice generally disqualifies listed merchants, while allowing consideration of documented exceptional circumstances. A shared risk record can therefore influence a later commercial decision made by a different company.
The gaming controversy exposed how difficult it can be to see the whole chain from outside. Valve described indirect Mastercard communications through processors and acquiring banks; Mastercard publicly denied evaluating games or requiring game-platform restrictions. The original instructions and all counterparties remain unavailable. The established structural point is substantial: network policy, bank decisions and processor discretion together determine whether a lawful online business can accept a widely used form of payment.
Sky names Mastercard among early PDC participants. Its September 14 financing story describes a planned approximately £50m setup equity solicitation, not closed funding. No participant-specific contribution, equity percentage or voting right was acquired.
Letter dated 22 August 2025; announcement 26 August. Actual dispatch/receipt and response not acquired.
Addressed to Mastercard legal representatives: asks present controls and further action enforcing existing terms/acceptable-use policies against sellers of deepfake NCII tools/content. Seller-level scope; no named bank instruction, adjudication, compulsory response deadline or confirmed receipt/implementation. Not a general pornography ban.
Merchants and owners — MATCH rule scope → Mastercard
may seek applicable personal-information remedies
March2026 notice describes law-dependent access/correction/restriction/deletion/complaint routes, with California requests to relevant institutions and other requests possibly redirected. One-month written reply is not correction deadline; no universal processing entitlement.
Policy requires acquirer investigation/reporting within2businessdays for law-enforcement evidence or5 for qualifying private referrals, with discretionary extensions. WIPO is not classified as law enforcement here; clocks are not added to WIPO notice periods.
Section11.13 permits removal for erroneous addition reported by an authorized user or specified cured PCI code12 noncompliance. Merchant direct application when acquirer unwilling/unable is narrow PCI route, not general bypass.
Section11.10 provides5year listing retention/purge; recipient records persist at least2years after agreement end and inquiry records365days. Central purge does not erase all downstream records or restore processing.
IP owners and authorized associations — provider-policy role → Mastercard
may submit qualifying IP referrals under general policy
General Anti-Piracy Policy permits rights-owner/authorized-association referrals with evidence and attestations. This does not prove a WIPO ALERT-PAY intake route or accepted Creative request.
retains policy interpretation and membership sanctions
Mastercard reserves interpretation/enforcement and possible membership restriction or sanctions for noncompliance. No exercised sanction in this packet.
Mastercard: investigation, product-level action, and conditional wider notice
The policy's opening BRAM context also reserves discretion over transactions considered damaging to Mastercard's goodwill. That broader context should not be silently turned into an ALERT-PAY eligibility criterion. The inspected programme concerns counterfeit goods and subscription piracy; the underlying provider contract may have other grounds, whose application requires separate evidence.
This is the provider's general policy, not an acquired ALERT-PAY addendum. WIPO's institutional status does not establish that its alert enters the law-enforcement route. Do not add Mastercard's two/five-business-day clocks to WIPO's notification clocks. A merits response, merchant termination and MATCH entry remain distinct. No MATCH deletion/restoration rule or completed appeal was acquired in this lane; that does not establish that none exists elsewhere.
The Steam joint is Valve's processor notice and response, the corresponding Mastercard/acquirer message and the actual counterparty identities. Valve payments/legal and its processor counterparts should hold operational communications; Valve press and GamingOnLinux hold the identified company replies. The published replies establish an attributed account, not the contents of unrecovered upstream records.
The strongest new addition is Steam's own attributed notice chain. Valve supplied statements to the journalist who published them, including a rejected alternative and the precise Mastercard rule reportedly invoked. Separately, original itch records expose an earlier platform payout decision and a contemporaneous UK geographic-compliance decision. The bank behind itch's July 2025 restriction remains unidentified.
Mastercard's published response denies evaluating games or requiring restrictions on game platforms. This does not identify the downstream decision-maker.
Attribution published August 1, 2025; original message date unknown.
Reported by the cited source
Valve describes indirect Mastercard communications. Raw network instructions and counterparties are absent, so sender, scope and interpretation remain unresolved.
Letter dated 22 August 2025; announcement 26 August. Actual dispatch/receipt and response not acquired.
Addressed to Mastercard legal representatives: asks present controls and further action enforcing existing terms/acceptable-use policies against sellers of deepfake NCII tools/content. Seller-level scope; no named bank instruction, adjudication, compulsory response deadline or confirmed receipt/implementation. Not a general pornography ban.
WIPO slide4 names this provider in the programme description. Slide7 does not identify either historical pilot PSP; no provider-executed agreement acquired.
General Anti-Piracy Policy permits rights-owner/authorized-association referrals with evidence and attestations. This does not prove a WIPO ALERT-PAY intake route or accepted Creative request.
Policy requires acquirer investigation/reporting within2businessdays for law-enforcement evidence or5 for qualifying private referrals, with discretionary extensions. WIPO is not classified as law enforcement here; clocks are not added to WIPO notice periods.
Mastercard reserves interpretation/enforcement and possible membership restriction or sanctions for noncompliance. No exercised sanction in this packet.
Section11.10 provides5year listing retention/purge; recipient records persist at least2years after agreement end and inquiry records365days. Central purge does not erase all downstream records or restore processing.
Section11.13 permits removal for erroneous addition reported by an authorized user or specified cured PCI code12 noncompliance. Merchant direct application when acquirer unwilling/unable is narrow PCI route, not general bypass.
March2026 notice describes law-dependent access/correction/restriction/deletion/complaint routes, with California requests to relevant institutions and other requests possibly redirected. One-month written reply is not correction deadline; no universal processing entitlement.