Mobile Payments: Key IT Law Issues Sony Gokhale October 26, 2015

Slides:



Advertisements
Similar presentations
European Consumer Summit 2014 On-line and mobile payments Dr Florent Frederix Trust & Security Unit, DG CONNECT, European Commission 1 th of April 2014.
Advertisements

Chang-ho CHUNG 정창호, 鄭彰鎬 Judge, Republic of Korea, since 1993 Head of UNCITRAL and UNIDROIT Research Team of Supreme Court of Korea SNU, LSE, HKU 1.
Learning Objectives Understand the shifts that are occurring with regard to online payments. Discuss the players and processes involved in using credit.
Financial Stability & Integrity Track: Innovations in Technology for Financial Inclusion & Managing Risks.
Mobile Payment Security The Good, the Bad and the Ugly
Accelerate the on-boarding of Service Providers in Trusted Infrasturcture Virginia Chan, Vice President Hong Kong Mar 19 th, 2014.
Mobile Communication MMS.
Ecosystem Scenarios for Cloud-based NFC Payments
Michal Bodlák. Referred to as mobile money, mobile money transfer, and mobile wallet generally refer to payment services operated under financial regulation.
HCE AND BLE UNIVERSITY TOMORROWS TRANSACTIONS LONDON, 20 TH MARCH 2014.
Zenith Visa Web Acquiring A quick over view. Web Acquiring Allows merchants to receive payments for goods and services through the Internet Allows customers.
The GSMA July 2014 Restricted - Confidential Information
NFC Devices: Security and Privacy
NFC Technology and Applications Assaf Sella CTO Texas Instruments Israel Feb
1 GP Confidential © GlobalPlatform’s Value Proposition for Mobile Point of Sale (mPOS)
Mobile Payments Commerce Without Cash or Credit Cards.
Contactless Payment. © Family Economics & Financial Education – January 2007 –– Financial Institution Unit – Contactless Payment - 2 Funded by a grant.
© 2012 Presented by: Preparation For EMV Chip Technology Keith Swiat.
Our Eyes are on the watch for you! One Stop Shop Payment Automation: Innovative and Smart platform that: Increase Sales and Merchant Retentions Creates.
LECTURE 7 REF: CHAPTER 11 ELECTRONIC COMMERCE PAYMENT SYSTEMS PREPARED BY : L. Nouf Almujally Copyright © 2010 Pearson Education, Inc. 1.
Building and Deploying Safe and Secure Android Apps for Enterprise Presented by Technology Consulting Group at Endeavour Software Technologies.
Dongyan Wang GlobalPlatform Technical Program Manager
Joe SimonettiT-FLEx Workshop T-FLEx October Workshop The Future of Fare Collection Bank Card Transactions & Merchant Processing Joseph Simonetti October.
Near Field Communication By Van Logan HTM 304. What is Near Field Communication Short range wireless communication technology between electronic devices.
Geneva, Switzerland, 4 December 2014 Evolving Payments into The Digital World Richard Smith, Vice President, MasterCard Customer Fraud Management
Travillon Consultants
THE TRANSFORMATION OF PAYMENTS. NFC Hosted Payments EMV in the US End-to-End Encryption Mobile POS.
Mobile Payments 101 Richard A. GibbsJune 1, 2011 Karen Ross Andrew Lorentz How do they work?
Philip is a subject matter expert in Accenture’s Payment practice with more than 30 years experience across payments, transaction processing, networks,
De Nederlandsche Bank Eurosysteem Card Payments and Internet Banking Thijs Kettenis 2nd Conference of the Macedonian Financial Sector on Payments and Securities.
. VISA The Payments Ecosystem VISA Barriers to Scale Interoperability Infrastructure KYC.
EPS (Electronic payment system) is an online business process used for fund transfer using electronic means, i.e  Personal computers  services  Mobile.
ITEC0722: Mobile Business and Implementation: Mobile Payment and Security Suronapee Phoomvuthisarn, Ph.D.
LEVERAGING UICC WITH OPEN MOBILE API FOR SECURE APPLICATIONS AND SERVICES Ran Zhou 1 9/3/2015.
Hsu-Chen Cheng, *Wen-Wei Liao, Tian-Yow Chi, Siao-Yun Wei
Connect and Collect: Strategies for connecting to your constituents in an electronic world.
Confidential and proprietary material for authorized Verizon Wireless personnel only. Use, disclosure or distribution of this material is not permitted.
UICC UICC is a smart card used in mobile terminals in GSM and UMTS networks It provides the authentication with the networks secure storage crypto algorithms.
Mobile Payments Antti Pihlajamäki Slide 2 Helsinki University of Technology Seminar on Networking Business Outline Introduction  Terminology.
Property of the Smart Card Alliance © 2011 The Future of NFC Mobile Payments Randy Vanderhoof Executive Director Transit Payments Markets Migration to.
·
© 2012-Robert G Parker May 24, 2012 Page: 1 © 2012-Robert G Parker May 24, 2012 Page: 1 © 2012-Robert G Parker May 24, 2012 Page: 1 © 2012-Robert G Parker.
Future Tense: Contemplating the Impending Transition to Digital Wallets and Mobile Prepaid Platforms Over the Next 5 Years Thursday, June 11, 2:25 p.m.
Near Field Communication Systems Patras, July 2006.
By: Ken Steinmann. A virtual wallet that securely stores your credit and debit cards, coupons, and rewards cards. You can make in-store payments by tapping.
, Josef NollNISnet NISnet meeting Mobile Applied Trusted Computing Josef Noll,
Leveraging UICC with Open Mobile API for Secure Applications and Services.
Chapter 4 E-commerce Security and Payment.
Team 13 Prathibha and Shrimi 11/12/13 Mobile Credit Card Processing.
Learning Objectives Understand the shifts that are occurring with regard to online payments. Discuss the players and processes involved in using credit.
By Hinal Pithia Monday, November 14, Overview The traditional wallet The digital wallet –How it works –Technology –Payment Models –The players –Considerations.
Payment systems. Debit or Credit cards  Let the customers pay by taking money directly form their account  Allow the money to borrow the money and the.
What does Chip offer Banks today?. CARD TYPES CREDIT DEBIT CHARGE PRIVATE LABEL PRE-PAYMENT MULTI FUNCTION.
Near Field Communication Armando Octavio Yesenia Sunny Nidia.
2016 Convention “New” Secure Transactions…What are the Differences? 1.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
1. Presentation Agenda  Identify Java Card Technology  Identify Elements of Java Card applications  Communicating with a Java Card Applet  Java Card.
Name: [Billwallet] Adapt and format this activity template according to your idea’s visual style and individual requirements. Please only ensure that you.
EMV.
A catalyst for mobile contactless payments adoption?
Decrypting Tokenization What is it and why is it important?
EMV® 3-D Secure - High Level Overview
Near Field Communication (NFC) Market
Chapter 4 E-commerce Security and Payment.
Cesar Lomeli.
Cesar Lomeli.
NEW PRODUCT INTRODUCTION CONEKT™ Mobile Smartphone Access Control Identification Solution June 2018.
DieboldNixdorf.com Tokenization Roman Cinkais |
Payment Innovations PAYMENT INNOVATIONS DIGITAL PAYMENT SOLUTIONS.
Presentation transcript:

Mobile Payments: Key IT Law Issues Sony Gokhale October 26, 2015 31021146

Presentation Summary What is mobile payment? A high level overview of the mobile payment ecosystem and its participants (as of today) Understanding the key mobile payment activities Key regulatory, privacy and security issues

What is Mobile Payment? Mobile payment is a very broad term and includes many different types of services, such as: Mobile credit card apps CIBC - “Mobile Payment App” (with Bell, Telus and Rogers) TD - “TD Mobile Wallet” (with Bell, Telus and Rogers) RBC - “RBC Wallet” / “Secure Cloud” (with Bell Bell and Virgin Mobile but allows credit and debit) ScotiaBank - “My Mobile Wallet” (with Bell, Telus and Rogers) BMO - “Paypass” / “Tap and Go” (sticker affixed to a mobile device and not tied to a specific Telco)

What is Mobile Payment? (continued) Closed loop mobile payment services Starbucks, Tim Hortons Direct carrier billing Google Play on Telco bill Mobile devices as a point-of-sale device Square Open wallets UGO Apple Pay Google Wallet Android Pay Suretap Each mobile payment offering is implemented through different technologies and may involve a variety of different players The landscape is changing at a rapid pace, both in terms of the expanding service offerings (credit, debit, prepaid, loyalty, etc.) and the technology used to implement them

A Mobile Payment Ecosystem BANKS/CREDENTIAL ISSUERS MNO/TELCO SERVICE PROVIDER TSM SECURE ELEMENT MANAGER WALLET APP SECURE ELEMENT SIM Secure SD Card Proximity Infrastructure Embedded Chip Contactless Services Others

Understanding Key Mobile Payment Activities (and their legal implications) Eligibility Provisioning Transaction processing Life cycle events (e.g. lost phones, suspended accounts, etc.)

Key Privacy and Security Issues Understanding the data flows and who controls the data The importance of understanding how and when data is exchanged and accessed Who is responsible for the consents? Understanding the consent process Allocating responsibility for obtaining

Key Privacy and Security Issues (continued) Managing disclosure and consent in a mobile world Presenting a suitable consent on a mobile device When and how to obtain consent Obtaining consent now and for the future New security risks to consider Lost or stolen devices NFC standards: password protection is optional Privacy compliance for the future Credential storage in the cloud Open wallets Loyalty Programs Geo-location data

Key Regulatory Issues Understanding the fragmented regulation of payments Financial institution regulation (Bank Act, trust companies legislation) Canadian Payments Association (CPA) Payment Card Networks Act (PCNA) Proceeds of Crime (Money Laundering) and Terrorist Financing Act Provincial Consumer Protection legislation (regulates gift cards)

Key Regulatory Issues – continued Informal regulation and Industry Standards Merchant agreements Acquirer agreements Interac Rules Card Brand Networks Rules Payment Card Industry Data Security Standard (PCI DSS) GlobalPlatform

A Glossary of Key Mobile Payment Terms Applet: An Applet allows a Credential to be used in a functional context. An example would be PayWave, which is an applet that allows a subscriber to use his/her Credit Card Credentials to make a payment using VISA. Credential: Personalized subscriber data (e.g. credit card information) issued by the Credential Issuer. Credentials can also include Applets for the purposes of provisioning. An issuer of Credentials. For example, a financial institution, retailer, government, transit authority, etc. Credential Issuer: An issuer of Credentials. For example, a financial institution, retailer, government, transit authority, etc. GUI (Graphical User Interface): The visual layer of an application that a subscriber interacts with. Also referred to as the “Wallet Application” or “Wallet”. HCE (Host Card Emulation): The software architecture that allows mobile applications to offer NFC payment solutions without the need for a Secure Element on the phone (UIC / SIM card). MNO (Mobile Network Operator): Also known as mobile phone operator (or simply mobile operator), carrier service provider (CSP), wireless service provider, wireless carrier, or cellular company, or mobile network carrier.

A Glossary of Key Mobile Payment Terms (cont’d) NFC (Near Field Communication): Short range radio communication technology. POS (Point of Sale): The location where a business transaction occurs. A POS terminal is a device by which sales transactions can be directly debited from the customer's bank account. Provisioning: The process to load the wallet on the mobile device and personalize the wallet for use. SD (Security Domain): The SD is an entity on the Secure Element which provides the support framework for the control, security and communication requirements of the Credential Issuer. SE (Secure Element): A platform that allows the installation, personalization and management of Credentials. It is a combination of hardware, software, interfaces and protocols that enable secure storage and usage of Credentials for payment, authentication and other services. The SE can be a portion of a UIC / SIM card, an embedded chip a SD card, or linked to a cloud solution. SEM (Secure Element Manager): The SEM enables the mobile network operator to provide a secure management framework to allow its Credential Issuer’s customers to manage their multiple Credentials within a Secure Element. The SEM controls access to the SE.

A Glossary of Key Mobile Payment Terms (cont’d) SIM (Subscriber Identity Module): An integrated circuit that securely stores the service-subscriber keys (IMSI) used to identify a subscriber on mobile devices. The SE can be a SIM card. SSD (Supplementary Security Domain): The SSD is a specific area on the SE designated specifically for the Credential Issuer that includes Credentials of such Credential Issuer. Tokenization: The process of substituting a sensitive data element (e.g. card data) with a non-sensitive equivalent (the token) that has no extrinsic or exploitable meaning or value. The token is an identifier that maps back to the sensitive data through a tokenization system. TSM (Trusted Service Manager): The TSM’s role is to establish a technical connection with the SEM or MNOs and to enable Credential Issuers to distribute and manage their Credentials remotely by allowing access to the Secure Element (via authentication by the SEM) in NFC-enabled handsets. The TSM is a hardware module that enables a link between the Credential Issuer and the Secure Element Manager. UICC (Universal Integrated Circuit Card): A smart card used in mobile devices. The UICC is commonly referred to as the SIM Card.

Contact Information: Sony Gokhale 416.862.6813 sgokhale@osler.com Osler, Hoskin & Harcourt LLP Box 50, 1 First Canadian Place Toronto, Ontario, Canada M5X 1B8