At Mastercard, we develop market-leading applications, products, and services to underpin, enable and safeguard the Open Banking ecosystem. We provide account information services ("AIS" or "Data") and payment initiation services ("PIS" or "Pay") (collectively “Open Banking Solutions”). This Open Banking Notice (“Notice”) describes how Mastercard Europe SA and other entities within the Mastercard group of companies (collectively, “Mastercard”, “us” or “we”) process Personal Information in connection with our Open Banking Solutions in Europe.
This Notice describes our processing of Personal Information as a data controller in connection with our Open Banking Solutions, such as:
This Notice does not cover the processing of Personal Information in connection with our Spiir product. Please consult the Spiir Privacy Notice for more information.
This Notice also does not cover the processing of Personal Information that we perform as a data processor, on behalf of our customers (such as financial institutions and merchants) who use our Open Banking Solutions. Please refer to our customers’ respective privacy notices for more information regarding the processing of your Personal Information.
“Personal Information” means any information relating to an identified or identifiable individual. We may collect the following types of Personal Information:
In connection with the provision of the Open Banking Solutions, we obtain Personal Information relating to you from the various sources described below.
a. Personal Information provided by third parties
b. Personal Information provided by third parties
c. Personal Information automatically obtained from your interaction with the Open Banking Solutions
We may use your Personal Information to:
Where required under applicable law, we will only use your Personal Information as necessary to provide you with our Open Banking Solutions; with your consent; to comply with a legal obligation; or when there is a legitimate and overriding interest that necessitates the use. We have carried out balancing tests for the data processing based on this basis to ensure that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms.
We may use Personal Information we obtain about you for the purposes set out below. Depending on the country in which you are located, we will only process your Personal Information when we have a legal basis for the processing as identified in the table below.
Processing purposes | Legal basis | Categories of Personal Information |
---|---|---|
Provide and operate our Open Banking Solutions and related services. This includes creating your and managing your user account, enabling the sharing of your Financial Information with third parties at your instruction and remembering your Credentials and preferred settings within the Open Banking Solutions. For our AIS, it also includes providing you with a consolidated view of your various bank accounts (including spending and income) and enabling spending categorization. For our PIS, it also includes facilitating direct and account-to-account payments from your linked payment account. |
We rely on the “performance of a contract” legal ground to provide our Open Banking Solutions to you. |
|
Troubleshoot our Open Banking Solutions and provide customer support, ensuring the accuracy of our features and quality control. This includes our ticketing system where you contact us for assistance when you are experiencing a technical issue as well as analysis to ensure quality control. |
This processing is necessary for performance of a contract to which you are party. In some cases, we have a legitimate interest in ensuring the safety, security, and performance of our Open Banking Solutions. Where required under applicable laws, we obtain your prior consent to access Financial Information and Transaction Information for these purposes. |
|
Monitor and understand IT performance. |
This processing is necessary for performance of a contract to which you are party. In some cases, we have a legitimate interest in monitoring and understanding IT performance to ensure the stability and the integrity of our Solutions. |
|
Market, promote and advertise our Open Banking Solutions |
We have a legitimate interest in promoting our business. Where required under applicable laws, we will obtain your prior consent to send you electronic direct marketing communications. |
|
Comply with legal obligations, and to establish, exercise, or defend against legal claims. |
Compliance with a legal obligation (e.g., to respond to law enforcement requests). We, or a third party, have a legitimate interest in protecting against legal claims. |
|
Develop new features and improvements to the Open Banking Solutions where possible based on de-identified information. |
This processing is necessary for performance of a contract to which you are party (e.g., improve the categorization model). Where required under applicable law, we obtain your prior consent to process your Financial Information and Transaction Information for this purpose. |
|
Detect, investigate, and prevent possible fraud. This includes tracking and hindering any possible illegal activities and abuse of our Open Banking Solutions. |
We have a legitimate interest in detecting, investigating, and preventing fraud, such as illegal activities or abuse of our Open Banking Solutions, or we must do so to comply with legal obligations (e.g., under anti-money laundering laws). |
|
To manage our customer and vendor relationships. |
This processing is necessary for performance of a contract to which you are party. |
|
We may share Personal Information with the following third parties:
The entity responsible for the processing of your Personal Information (or data controller) varies depending on the type of Open Banking Solutions that you use:
Europe Data Protection Office
Mastercard Europe SA
Chaussée de Tervuren 198A
B-1410 Waterloo
Belgium
Aiia A/S
Att.: Privacy
Artillerivej 86, st. tv.,
2300, Copenhagen
Denmark
You have certain rights and choices regarding the Personal Information we maintain about you. For more information about your rights, or to learn more about how we share, transfer, retain and protect your Personal Information, please read our Global Privacy Notice.
Our Spiir Open Banking Solution has its own specific privacy notices. Please consult that notice for more information about our processing in that context. For enquiries about your Mastercard card and your purchase, please contact your financial institution or merchant. More information about how to contact them can be found on their websites.