The Regulatory Ripple Effect – GDPR & Beyond

Slides:



Advertisements
Similar presentations
TOWARD FAIRER AND COMPETITIVE PAYMENT SOLUTIONS IN THE EU.
Advertisements

IS BIG DATA GIVING YOU A BIG HEADACHE? Risk Reduction - Transactional, International and Liability Issues Oregon State Bar Corporate Counsel Section Fall.
Identity Fraud Prevention 1 Copyright Identity Management Institute®
The European legal framework of payments Ayse Zoodsma-Sungur Sixth Macedonian Financial Sector Conference on Payments and Securities Settlement Systems.
MOBILE DEVICE SECURITY. WHAT IS MOBILE DEVICE SECURITY? Mobile Devices  Smartphones  Laptops  Tablets  USB Memory  Portable Media Player  Handheld.
The Digital Agenda for Payment Services
Dino Tsibouris & Mehmet Munur Privacy and Information Security Laws and Updates.
PSD2 and W3C Impact for account and payment processing.
Key Points for a Privacy Programme for Multinationals Steve Coope.
HHS Security and Improvement Recommendations Insert Name CSIA 412 Final Project Final Project.
2 PSD2- C HALLENGES AND OPPORTUNITIES Pascale-Marie BRIEN– Senior Policy Adviser.
Pioneers in secure data storage devices. Users have become more accustomed to using multiple devices, are increasingly mobile, and are now used to storing.
Consumer Authentication in e-Banking & Part 748 – Appendix B Response Program Catherine Yao Information Systems Officer NCUA.
The future of data protection: General Data Protection Regulation
DIGITAL CZECH REPUBLIC Impact of Digital Revolution
Fraud Prevention Solutions Make it secure, keep it simple!
6 October 2016 Social media: do you have the right social media strategy that will impact your business’ growth? - Legal and Regulatory Issues William.
Microsoft 365 Get help with regulatory compliance
Consider cards over cash
Consider cards over cash
General Data Protection Regulations: what you really need to know
General Data Protection Regulation
Open Banking & PSD2 How regulation is shaping the future of banking
General Data Protection Regulations Preparing for the upcoming changes in data protection law David Jones & Angharad Williams.
International Regulatory Trends
Privacy and Security in the Employment Relationship
The Payment Services Directive 2 (PSD2)
Key dates for PSD2 and implications to EU/UK payment processors
Data Protection Legislation
VAT system in the EU – why the talk of the need change
Mobile Payment Protocol 3D by Using Cloud Messaging
Chapter 3: IRS and FTC Data Security Rules
The introduction and the essential elements of E- Commerce.
Introducing GDPR: How the General Data Protection Regulation transforms the world Laura Mudd November 2016.
GDPR - New Data Protection Regulation
Introduction to GDPR 09/11/2018.
Who Uses Encryption? Module 7 Section 3.
Consider cards over cash
Sue Cawthray, CEO/ Gill Thrush, Catering Manager
GDPR and Health and Safety
Cyber Trends and Market Update
General Data Protection Regulation
Data Protection What’s new about The General Data Protection Regulation (GDPR) May 2018? Call Kerry on Or .
How we’ll prepare for the General Data Protection Regulation (GDPR)
The different players in the new PSD2 world E-Payment & SEPA Adviser
IMPLICATIONS OF GDPR ROBERT BELL.
GDPR enforcement begins
ELECTRONIC PAYMENT SYSTEM.
 How does GDPR impact your business? Pro Tip: Pro Tip: Pro Tip:
The General Data Protection Regulation Six months on – What’s changed
Clemson University Red Flags Rule Training
 GDPR Readiness Quiz Quick Insight: Quick Insight: Quick Insight:
The title: The implementation of Data Protection
General Data Protection regulation (GDPR)
Neopay Practical Guides #2 PSD2 (Should I be worried?)
The General Data Protection Regulations 2016
Data Protection What can I do? GDPR Principles General Data Protection
What is an anonymous reporting hotline?
General Data Protection Regulation
Colorado “Protections For Consumer Data Privacy” Law
Getting the Green Light on the Red Flags Rule
Privacy Update John L. Wood – Egerton, McAfee, Armistead & Davis, P.C.
How to Approach Subscription Payments
Your source for payments education
Increasing approval rates in the digital world
It Runs In The Family Fraud
Goodbye Fraud, Hello Customer Experience
Information Governance
The Importance of Sales & Use Tax
Presentation transcript:

The Regulatory Ripple Effect – GDPR & Beyond Your source for payments education The Regulatory Ripple Effect – GDPR & Beyond

Today’s Speakers Steve Durney – Ethoca Scott Williams – Digital River

How do these regulations impact you? General Data Protection Regulation (GDPR) Payment Services Directive (PSD2) California Automatic Renewal Law (ARL)

GDPR General Data Protection Regulation Implemented May 25, 2018 Applies to all organizations processing the personal data of EU subjects – wherever the organization is geographically based GDPR

2 By the Numbers: A Look at GDPR 1 3

£183 Million £99 Million $5 Billion Recent Fines £183 Million £99 Million GDPR $5 Billion FTC

GDPR in the US By the end of 2018, 74% of US companies expected to be compliant (Source: TrustArc) 93% project full compliance by the end of 2019 (Source: TrustArc) The main motivator for compliance isn’t the avoidance of fines, but to meet customer expectations.

GDPR and You: A Quick Guide U.S. firms that have employees or customers in Europe are affected by the GDPR. You must comply with a complex series of rules that include: Allow customers to see and delete the data that concerns them Provide notice of data breaches in 72 hours Make data policies transparent to an average person Hire a Chief Data Office (in some cases) Follow “privacy by design” principles Note that the rules are different depending on the data in question. Companies that touch special categories of sensitive data should be especially careful. What happens if a U.S. company doesn’t follow the rules? A fine amounting to the higher of 4% worldwide revenue or 20 million euros is the maximum punishment.

Merchant Experience GDPR

> > > Privacy Tracking Tool Client Rectification Privacy Tracker Vendor Erasure > > > Portability Compliance Team Email Summary Dashboard Inquiry Interested Party

How Does GDPR Impact You? NEGATIVE Possible abuse of the right to erasure Potential loss of fraud insights Merchant representment effectiveness could be impacted NOTE: It’s still too early to ascertain to true ‘ripple effects’ GDPR will have on fraud.

How Does GDPR Impact You? POSITIVE Data used for prevention of fraud protected from consent Organizations have improved their incident response strategies Internet of things security being taken more seriously Businesses are better prepared for U.S. data privacy regulations

PSD2 Payments Service Directive 2 Effective date: September 2019 Aims to better protect consumers when they pay online, promote the development and use of innovative online and mobile payments such as through open banking, and make cross-border European payment services safer. PSD2

STRONG CUSTOMER AUTHENTICATION (SCA) Knowledge Ownership Inherence something only the user knows (password, code, personal identification number) (or possession) something only the user possesses (token, smart card, mobile device). something the user is (biometric characteristic, such as a fingerprint)

PSD2 RTS – SCA Exceptions A PSP can be exempted of SCA in cases where the PSP’s overall fraud rate is below the EBA reference thresholds: Exemption Threshold Value Remote Card-Based Payment Credit Transfers €500 0.01% 0.005% €250 0.06% €100 0.13% 0.015% Note: EBA’s fraud requirements are significantly lower than current European CNP fraud rates (approx. 0.3-0.4%). At present both the payees’ and payers’ PSPs could trigger such an exemption but with the payers PSP having the final say. No SCA required below €30

PSD2 AND 3DS In order to comply with PSD2 and SCA requirements, the standard protocol for merchants is to rely on 3DS for affected transactions. 3DS2 has been designed to be less intrusive for customers than its predecessor. But it will introduce friction and will be required for every transaction, not just the riskiest.

Merchant Experience PSD2

How Does PSD2 Impact You? NEGATIVE Private consumer data will now be available to more players than ever before Increased payment friction Tighter issuer acceptance rates Banks and overall fraud rate Phone and mail order fraud may increase Fraud shift from EU to US and other regions Shift from transaction to account fraud

How Does PSD2 Impact You? POSITIVE Strong customer authentication and 3DS Easier to distinguish between genuine and friendly fraud

ARL California revised Automatic Renewal Law Came into force on July 1, 2018 The updated law requires e-commerce sellers, doing business in California, to allow online cancellation of auto-renewing memberships or recurring purchases that were initiated online. ARL

The Basics: California Automatic Renewal Law Online Cancellation  Pricing After a Trial Period Cancellation After a Trial Period

Merchant Experience ARL

How Does ARL Impact You? NEGATIVE Penalties for failing to comply Need to revise sales/renewal practices

How Does ARL Impact You? POSITIVE Better long-term customer experience

Questions?

Thank you Don’t forget to submit your session evaluation! Steve Durney, SVP Market Strategy (Ethoca) Scott Williams, Principal Product Manager (Digital River)