Detailed research note

WIPO ALERT-PAY: participant confirmation and provider decision rights

Part of the research through 9 September 2026. This dated note preserves its original findings; later developments are discussed in the synthesis and linked profiles.

9 September 2026. Bounded acquisition closed. Two PayPal policy originals were retained; Mastercard's complete public policy was read through the successful official reader after its ordinary GET failed. No report form, account, live list or payment operation was used. This is a scoped comparison of public rules, not confirmation of a signed WIPO-provider agreement.

The acquired provider policies show that a notification can enter a provider-controlled investigation and contract process. They do not establish exactly how ALERT-PAY notifications are classified within that process. In particular, Mastercard's public rules distinguish stopping payments for an infringing product from terminating the merchant and from wider notice through MATCH. Neither an alert nor an infringing-product finding proves that all three occurred.

What is confirmed about programme identity

Root retained the official [WIPO/ACE/18/40 presentation](http[local research file] whose [document index](http[local research file] records publication on 16 June 2026. This worker read original slides 4–7. Slide 4 names Mastercard and PayPal among payment service providers in the described development and says PSPs choose what action, if any, to take under their policies. Slide 5 describes WIPO checking formalities, administering notifications/review and aggregating lists. Slide 7 reports an anonymous six-rightsholder/two-PSP pilot; those numbers alone do not identify the two pilot firms.

The finite participant-owned searches did not locate a PayPal or Mastercard ALERT-PAY announcement, signed participation terms, programme-specific challenge rule or correction agreement. That is a public-source gap, not evidence that either company did not participate. WIPO fee-payment pages, Mastercard's own website-content copyright terms, and unrelated industry initiatives were excluded. No identity was inferred from adjacent programmes, logos or illustrative application screens.

Root's separate indexed-transcript review qualifies slide 6's test-purchase box: according to that reading, a purchase depends on the PSP and none was needed during the pilot. This worker's pinpoint attempt to reopen that transcript returned a zero-line page, so this is not an independently reread transcript claim here. Do not treat slide 6 as proof of a universal purchase requirement or a contradiction with the provider policy below. Root owns the reconciled programme chronology and transcript scope.

Mastercard: investigation, product-level action, and conditional wider notice

[Mastercard Anti-Piracy Policy](http[local research file] undated US public page observed 9 September 2026, numbered sections 1–4, allocates these roles:

Stage Public policy allocation
Intake Law-enforcement evidence, or a rightsholder/authorized trade-association referral supported by specified evidence and attestations
Investigation Mastercard identifies the acquiring relationship and requires the acquirer to investigate/report: two business days for the law-enforcement route, five for the private-referral route; extensions are discretionary
Finding An affirmative finding requires ending Mastercard acceptance for the infringing product; a negative finding requires compelling evidence
Termination If the acquirer terminates the merchant, Mastercard requires MATCH listing where applicable, notifying acquirers of termination and its reason code
Enforcement Mastercard retains interpretation/enforcement authority and may restrict or sanction a noncompliant acquirer's membership

Private referrals require ownership evidence, specific alleged products/locations, notice materials and payment-method evidence; a test transaction is optional. Submitters consent to disclosure and cooperation and may face indemnity requirements. The private-referral route includes reporting investigation results back to the rightsholder/association. Section 3 also addresses restricting cross-border acquiring where the product's legality differs by country.

This is the provider's general policy, not an acquired ALERT-PAY addendum. WIPO's institutional status does not establish that its alert enters the law-enforcement route. Do not add Mastercard's two/five-business-day clocks to WIPO's notification clocks. A merits response, merchant termination and MATCH entry remain distinct. No MATCH deletion/restoration rule or completed appeal was acquired in this lane; that does not establish that none exists elsewhere.

The policy's opening BRAM context also reserves discretion over transactions considered damaging to Mastercard's goodwill. That broader context should not be silently turned into an ALERT-PAY eligibility criterion. The inspected programme concerns counterfeit goods and subscription piracy; the underlying provider contract may have other grounds, whose application requires separate evidence.

PayPal: a short reporting policy, with distinct locale dates

The [UK Infringement Report Policy](http[local research file] is labelled 15 July 2026; the [US page](http[local research file] is labelled 6 May 2021. Both retained originals give the same operative policy paragraph: PayPal may take appropriate action where necessary concerning claimed infringement and invites IP rights owners to submit its report. The UK page separately identifies PayPal UK Ltd, company 14741686. That locale disclosure does not identify the legal PSP party to WIPO's pilot or contract.

These short pages do not state a fixed action deadline, evidential adjudication procedure, counter-notice timetable, automatic account termination or ALERT-PAY-specific correction rule. The blank report and broader account contracts were not opened. Absence from this paragraph is not absence of wider PayPal remedies. The different update dates cannot be treated as dates when ALERT-PAY was adopted or when the operative paragraph changed.

Evidence strength, useful relations and the next discriminator

The strongest supported interpretation is a notification channel feeding institutions that retain their own decision rights, with Mastercard's acquirer relationship adding another decision step. The strongest rival to a simple automatic cutoff model is an investigation that rejects the allegation, targets only the disputed product, or requires another response without terminating the merchant. The public rules permit that distinction; they do not reveal actual frequencies or outcomes. Conversely, retaining discretion and a negative-finding route does not prove that challenges succeed or that corrections propagate reliably.

Candidate relations for later review: WIPO to named PSPs, programme description only; rightsholder/authorized association to Mastercard, general referral right; Mastercard to acquirer, investigation/reporting and policy-enforcement duties; acquirer to infringing-product acceptance, conditional cessation; terminated merchant to MATCH, conditional subsequent notice; PayPal to IP rights owner, public reporting invitation. There is no acquired agreement edge binding either provider to act on every WIPO entry and no exercised payment-cutoff edge from these policies.

The next revealing record is the actual participation agreement or a public provider explanation tying an ALERT-PAY notification to a particular internal route, together with a redacted completed case showing review, reasoned outcome, correction and any merchant/MATCH restoration. Likely holders are WIPO's Building Respect for IP Division and the relevant PSP, with an acquirer involved for Mastercard. This names a record family and accountable actors, not a claim that a particular unpublished document exists. No broader bank, cryptocurrency or donor branch was opened.

Custody and reading scope

participant-captures.json records URLs, dates, source states, queries, originals, reader ancestry and the failed transcript pinpoint. The complete provider-reader output is retained in participant-policies.reader.txt. Mastercard original GET returned 403; its error hash is not policy custody, and neither that route nor a PDF variant was retried.

PayPal UK original SHA256: 9e0f6c2c882c7a8b3ec12d2bb65c0740297b97a01f06fb45bb1c3b15d309ba97. PayPal US original SHA256: ff31dfe0fe37189bb4321f48c0688eb5c9ce47239537dfd5d8c6560bf3305edd. Both complete short substantive policies were read from original HTML and through the primary reader; status/footer context was kept separate. No form or image was inspected.

Mastercard scope: entire substantive introductory policy and sections 1–4, reader lines 156–184, including both routes and the failure-to-comply section. Its linked forms, issuer process and general Rules/MATCH manuals were not read. WIPO scope: root's original slides 4–7 only, SHA256 e4afb3bdce8e4d4266a5d992abe117b95b38cf57ff27979ccf6d70af4b7e11a4, with a separate local extract; the presentation was not redownloaded. Root's programme packet supplies its fuller primary reading.

Acquisition closed for independent review and the combined forest. No case, atlas, current-work, forest, ZIP or visible UI changed.