This Privacy Notice describes how we handle your Personal Information when you create a digital identity (“Digital Identity”) and use our digital identity service (“ID”). Where we say “we,” “us” and “Mastercard” we mean Mastercard International Incorporated, its affiliates and other entities within the Mastercard’s group of companies.
This Privacy Notice describes the types of Personal Information we process in connection with ID, the purposes for which we process that Personal Information, the other parties with whom it may be shared and the measures we take to protect the security of the data. It also tells you about your rights and choices with respect to your Personal Information, and how you can reach us to update your contact information or get answers to questions you may have about our privacy practices.
Your use of ID is subject to this Privacy Notice.
This Privacy Notice applies to Mastercard’s processing of your Personal Information in the context of ID only. It does not cover the processing of your Personal Information by Mastercard in the context of other Mastercard or third-party products or services or communications that may reference Mastercard outside of ID. For more information about Mastercard’s privacy practices, please visit Mastercard’s Global Privacy Notice.
ID allows you to create a Digital Identity that can be used to access services and goods that require proof of your identity on third-parties’ mobile applications, websites and services (each third party, a “Service Provider”). Using your Digital Identity saves you time and hassle, removing the need for passwords and manual entry of your information. It also helps protect your data from unauthorized access and use.
ID is provided by Mastercard, an international organization recognized for facilitating simple and secure payments all across the world.
The following categories of Personal Information are processed by ID: “Identity Information” and “Activity Information”.
Identity Information may include:
This Identity Information is encrypted and stored on your device, and used as necessary to facilitate your use of ID, for instance, to create your Digital Identity, interact with Service Providers online, in mobile apps, and when you want to prove your identity in physical settings. Identity Information may be stored for a limited time by IVPs for troubleshooting, fraud prevention and customer support purposes.
Activity Information refers to records of your usage of ID.
Activity Information includes:
The Activity Information does not contain your Identity Information and is encrypted and securely stored in Mastercard servers.
For the purpose of this Privacy Notice, “Personal Information” means any information relating to an identified or identifiable individual. There are two types of Personal Information processed by ID: “Identity Information” and “Activity Information”.
In connection with ID, Personal Information relating to you is obtained from various sources described below.
Where applicable, we indicate whether and why you must provide your Personal Information, as well as the consequences of failing to do so. If you do not provide certain Personal Information, you may not be able to benefit from ID if that information is necessary to provide you with it or if we are legally required to process that information.
Identity Information
You may create your Digital Identity using the Mastercard ID mobile app (Mastercard ID App) or the mobile app of a Trust Provider (e.g., your bank, your telecommunication provider etc.).
The Trust Provider may pre-populate your Digital Identity with information it already has about you. The exact data elements are determined by the Trust Provider, but they typically include:
You will be requested to confirm that information. When creating your Digital Identity, you may also choose to add an identification document (i.e., driver’s license, passport or other government identification), or other information to ID.
During the creation of your Digital Identity with a Trust Provider you will also enable face login, which involves taking a scan of your face in a similar manner as when setting up face authentication on your phone. This is required to enable secure access to your Digital Identity. ID will perform a match with the photo on your identity document, which helps to confirm you are really you. When you use your camera to take the facial scan, we will also perform a “liveness check”, for example, by capturing a short video or series of pictures to make sure the facial scan is not a picture or a mask.
You may choose to use your Digital Identity for authentication when you access services from Service Providers. Selecting to use your Digital Identity will prompt a request from the Service Provider, indicating the information they need to receive (e.g., your name, address, email address, phone number) in order for them to provide their service to you. With your consent, ID will provide the relevant information from your Digital Identity to the Service Provider. In some cases, some data may be optional. You will be able to select which optional data elements the Service Provider may receive.
We use IVPs to verify certain data elements in your Digital Identity (e.g., verifying your driver’s license, passport, address against the relevant authoritative sources, etc.). This ensures ID is providing accurate information to the Service Providers you interact with. The match results of these verifications are stored on your device.
Activity Information
The following information about your usage of ID may be processed when you create your Digital Identity to log in and interact with Service Providers online, in mobile apps, in physical settings, and for other purposes described in this Privacy Notice:
The Activity Information does not contain your Identity Information. The Activity Information is encrypted and securely stored in Mastercard servers.
The Identity Information in your Digital Identity is encrypted and used as necessary to provide and operate ID. ID uses your Identity Information to:
ID uses your Activity Information to:
We will only process your Personal Information for the above purposes when we have a valid legal ground for the processing, including if:
Where required under applicable law, we have carried out balancing tests for the data processing based on our or a third party’s legitimate interests to ensure that such legitimate interest is not overridden by your interests, fundamental rights or freedoms. For more information on our balancing tests, you may contact us as described in the “How to Contact Us” section below.
We will not subject you to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, unless you explicitly consented to the processing, the processing is necessary for entering into, or performance of a contract between you and Mastercard, or when we are legally required to use your Personal Information in this way, for example to prevent fraud.
Processing activity |
Legal Basis for Processing (where required under applicable law) |
Create and manage your Digital Identity, provide our services, operate the ID platform, facilitate identity verification and respond to your inquiries. |
In the context of ID, we process your Personal Information as a controller, provided that: |
Protect against and prevent fraud, unauthorised transactions, claims and other liabilities, and manage risk exposure and franchise quality with respect to the integrity and security in the context of ID. |
When we process Personal Information for fraud prevention, we act as a controller and rely on the following legal grounds: |
Share your Digital Identity with Relying Parties |
When we share your Personal Information with Relying Parties, we act as a controller and rely on the following legal grounds:
|
Perform analysis in order to maintain, protect and improve ID |
|
Comply with industry standards and our policies |
|
As may be required by applicable laws and regulations, including for compliance with Know Your Customers, Anti-Money Laundering, anti-corruption and sanctions screening requirements, or as requested by any judicial process, law enforcement or governmental agency having or claiming jurisdiction over Mastercard or Mastercard’s affiliates. |
|
We do not share or otherwise disclose Personal Information we process in the context of ID, except as described in this Privacy Notice or otherwise disclosed to you at the time the data is collected.
The Identity Information in your Digital Identity is stored on your device, and only disclosed as necessary to operate ID with Service Providers upon your request. Your Identity Information in your Digital Identity is also shared with other participants in the ID network, including IVPs as necessary to provide ID and technology service providers acting on our behalf to deliver ID. Identity Information may be stored for a limited time by IVPs for troubleshooting, fraud prevention and customer support purposes.
In addition, your Activity Information may be shared in the context of ID with:
Subject to applicable law, you have certain rights and choices regarding the Personal Information processed by ID. In particular, you have the right to:
You can exercise your rights by contacting your Trust Provider, who will liaise with us when handling your request. Please read your Trust Provider’s privacy notice for more information. In addition, your Identity Information can be accessed, rectified or deleted directly in your Digital Identity. At any time, you may access the information in your Digital Identity by using the mobile app that you created your Digital Identity with.
Where you have created your Digital Identity using the Mastercard ID App you have the right to opt-out of some collection or uses of your Personal Information, including the use of cookies and similar technologies, the use of your Personal Information for marketing purposes, and the anonymization of your Personal Information for data analyses.
Once in your Digital Identity, you can view your profile, make changes and add more information. You can also view your full history of your use of ID. If you wish, you can delete your Digital Identity. This will delete all Personal Information in the Digital Identity on your device. If the deletion function is not yet available, you can delete your Digital Identity by deleting the mobile app from your device.
Subject to applicable law, you have the right to:
The above rights apply to the extent they are provided by applicable law, and they may be limited in some circumstances by local law requirements. For instance, we may not be able to comply with a request to delete or rectify Activity Information in our servers because we need to keep the data for dispute resolution purposes or to comply with our legal obligations.
You can exercise your rights by contacting your Trust Provider, who will liaise with us when handling your request. We will handle such requests within one month unless applicable law provides for a different timeframe. Please read your Trust Provider’s privacy notice for information on how to exercise your rights.
In addition, your Identity Information can be accessed, rectified or deleted directly in your Digital Identity. At any time, you may access the information in your Digital Identity by using the mobile app that you created your Digital Identity with. Once in your Digital Identity, you can view your profile, make changes and add more information. You can also view the full history of your use of ID. If you wish, you can delete your Digital Identity. This will delete all Personal Information in the Digital Identity on your device. If the deletion function is not yet available, you can delete your Digital Identity by deleting the mobile app from your device. Please make sure to keep the Identity Information in your Digital Identity up-to-date at any times.
Finally, where you have created your Digital Identity using the Mastercard ID App, you can choose:
We maintain appropriate security safeguards to protect your Personal Information and only retain it for a limited period of time.
We maintain appropriate administrative, technical, and physical safeguards to protect Personal Information against accidental or unlawful destruction, accidental loss, unauthorized alteration, unauthorized disclosure or access, misuse, and any other unlawful form of processing of the Personal Information in our possession. We restrict access to Activity Information about you to those employees who need to know that information to provide products or services to you.
Access to your Digital Identity is secured via biometric authentication.
We take measures to delete, destroy or de-identify your Personal Information or keep it in a form that does not permit identifying you when this information is no longer necessary for the purposes for which we process it in the context of ID or when you request their deletion, unless we are required by law to keep the information for a longer period. When determining the retention period, we take into account various criteria, such as possible re-enrolment with ID, the impact on the services we provide to you if we delete some information about you, and mandatory retention periods provided by law and the statute of limitations.
We may retain your Personal Information if it is necessary to comply with applicable laws or if we need your Personal Information to establish, exercise or defend a legal claim. In those cases we will restrict the processing of your Personal Information for such limited purposes.
Your Personal Information may be transferred outside of your jurisdiction, including to the EEA and the United States, in compliance with our Binding Corporate Rules and other data transfer mechanisms. Mastercard’s privacy practices comply with the APEC Cross Border Privacy Rules System.
Mastercard is a global business. We may transfer or disclose Personal Information to recipients in countries other than your country, including to countries in the EEA and to the United States where our global headquarters are located. These countries may not have the same data protection laws as the country in which you initially provided the information. When we transfer or disclose your Personal Information to other countries, we will protect that information as described in this Privacy Notice.
We comply with applicable legal requirements providing adequate safeguards for the transfer of Personal Information to countries other than the country where you are located. In particular, we have established and implemented a set of Binding Corporate Rules (“BCRs”) that have been recognized by EEA data protection authorities as providing an adequate level of protection to the Personal Information we process globally. A copy of our BCRs is available here. We may also transfer Personal Information to countries for which adequacy decisions have been issued, use contractual protections for the transfer of Personal Information to third parties, such as the European Commission's Standard Contractual Clauses.
Mastercard’s privacy practices comply with the APEC Cross Border Privacy Rules System. The APEC CBPR system provides a framework for organizations to ensure protection of Personal Information transferred among participating APEC economies. More information about the APEC framework can be found here.
You may contact us as specified in the “How to Contact Us” section below to obtain a copy of the safeguards we use to transfer Activity Information outside of the EEA.
This Global Privacy Notice may be updated periodically to reflect changes in our privacy practices.
This Privacy Notice may be updated periodically to reflect changes in our Personal Information practices. We will notify you of any significant changes to our Privacy Notice by posting the new version on the Mastercard website and indicate at the top of the notice when it was most recently updated. If we update this Privacy Notice, in certain circumstances, we may seek your consent.
For any questions regarding ID, please contact your Trust Provider using the contact details provided in the Trust Provider’s terms of service or privacy notice. If you consider the Trust Provider did not adequately handle your request, or if you created your ID via the Mastercard ID App, you can e-mail us at privacyanddataprotection@mastercard.com.
For any queries regarding ID, please contact your Trust Provider using the contact details provided in the Trust Provider’s privacy notice. The Trust Provider will work with us when handling your request. If you consider the Trust Provider did not adequately handle your request, or if you created your ID via the Mastercard ID App, you can e-mail us at privacyanddataprotection@mastercard.com.
If you are located in Canada or the United States Mastercard International Incorporated is the entity responsible for the processing of your Personal Information. You may write to us at:
Global Privacy Office
Mastercard International Incorporated
2000 Purchase Street
Purchase, New York 10577
If you are located in the EEA, UK or Switzerland, Mastercard Europe SA is the entity responsible for the processing of your Personal Information. You can write to us at:
EEA Data Protection Officer
Mastercard Europe SA
Chaussée de Tervuren 198A
B-1410 Waterloo
Belgium
If you are located in Brazil, Mastercard Brasil Soluções de Pagamento Ltda. is the entity responsible for the processing of your Personal Information. You may write to us at:
Brazil Data Protection Officer
Mastercard Brasil Soluções de Pagamento Ltda.
Avenida das Nações Unidas, 14.171, 20º andar, Crystal Tower
São Paulo/SP
Brasil
CEP 04794-000
If you are located in Asia Pacific, Middle East and Africa, Mastercard Asia/Pacific Pte Ltd is the entity responsible for the processing of your Personal Information. You may write to us at:
Data Protection Officer
Mastercard Asia/Pacific Pte Ltd
3 Fraser Street, DUO Tower
Level 17
Singapore 189352
Mastercard will investigate your query or complaint as required by applicable law and will respond to you in writing within one month of receiving the written complaint, unless a different time frame is provided by applicable law. If we fail to respond to your complaint or if you are dissatisfied with the response that you receive from us, you may have the right to make a complaint to the applicable competent supervisory authority.
Mastercard is not responsible for any processing of your Personal Information by Trust Providers and Service Providers with whom you interact. To learn more about their practices, please read their privacy notices.
For information on Mastercard’s privacy practices in other contexts, please refer to our Global Privacy Notice.