Eftpos Technical, Operational and Security Rules
Total Page:16
File Type:pdf, Size:1020Kb
eftpos Technical, Operational and Security Rules V2.15 effective 27 April 2021 eftpos Technical, Operational and Security Rules V2.15 Copyright and disclaimer Information in this document is the confidential information of eftpos Payments Australia Limited and is subject to change without notice. No part of it may be copied, reproduced, translated, or reduced to any electronic medium or machine-readable form without prior written permission from eftpos Payments Australia Limited. Written and published in Sydney, Australia by eftpos Payments Australia Limited. ABN 37 136 180 366 ©2010 - 2021 eftpos Payments Australia Limited. All Rights Reserved. Commercial-in-Confidence eftpos Payments Australia Limited ABN 37 136 180 366 Head Office Level 11, 45 Clarence Street, Sydney NSW 2000 | GPO Box 126, Sydney NSW 2001 Telephone +61 2 8270 1800 | Facsimile +61 2 9299 2885 | Email: [email protected] www.eftposaustralia.com.au 1 eftpos Technical, Operational and Security Rules V2.15 Amendment Certificate The responsibility for amending this document rests with the Chief Operating Officer. Version Date Key Changes 0.2.1 21 Sep 2010 Review prepaid sections 0.2.2 29 Sep 2010 Progression of the above and interaction with CECS rules. 0.3.1 3 Nov 2010 Change of abbreviated name from TOS rules to Operational Rules. Identification of Confidential clauses. 1.0 7 Dec 2010 As approved by Board on 07/12/10. 1.1 11 Oct 2011 Changes to Section 8. Addition of eftpos batch file format and reporting requirements in new Part 11. Amendments to floor limit for cash or cash/purchase combined transactions. 1.2 16 Apr 2012 As approved by Board Updated requirements for eftpos fee code in F047 for 0200/0220 messages. As per Member Advice 006-12, Changed field length for F025 in the 0200 and 9200 messages from 3 to 2. Changed reference to standard for F018 to Merchant category code AS2805 part 16. Added 11C.1.6 Technical Contacts. Removed footnote 7 for F04 of 0200 message as it relates to ATM direct charge. AmendedF028 footnote as the field is used for ATM fees. Removed references to “common fields” section and ensured all fields referenced are contained in the Fields section of Appendix 5I. Corrected field length for F055 Tags 9F26 and 9F27. Removed reference to AS3521 Identification cards - Physical characteristics standard withdrawn. Commercial-in-Confidence eftpos Payments Australia Limited ABN 37 136 180 366 Head Office Level 11, 45 Clarence Street, Sydney NSW 2000 | GPO Box 126, Sydney NSW 2001 Telephone +61 2 8270 1800 | Facsimile +61 2 9299 2885 | Email: [email protected] www.eftposaustralia.com.au 2 eftpos Technical, Operational and Security Rules V2.15 1.3 31 Oct 2012 As approved by the Board 4 October 2012. 1.2 Amended definition for Service provider. 8.5.3 Replaced transaction diagram and amended description for eftpos cash out as it contained ATM processing information. 6.4.1 Fees. Added details of where fees are published. 11.1 & 11.3.3 Added clauses for reporting of data breach or compromise. 11.2 Added clauses relating to disclosure of reporting information. 3A.3 Severity Levels. Minor edits. 3A.5 Added notifications received by the company. 3A.6 Added Post Incident outage report. 6B.1.7 Added File compression. 6c.1.2 Corrected reference from SHA-2 to SSH-2. 6C.1.7 Amended contact details for technical staff. 1.4 1 May 2013 5.12.5, 6.1.1, 6.1.2, 6.1.3, 8.9.1, 11.3.1, 11.3.2&6C.1.3 Minor edits and corrections. 6B.1.8, 6B.1.9&6B.1.10Amended field description of Field 11 Systems Trace Audit Number (STAN), to reflect the field description in the Original message. 6B.1.8, 6B.1.9, 6B.1.10&6B.1.11Amended field description of Field 15 Settlement date, to reflect the field description in the Original message. Commercial-in-Confidence eftpos Payments Australia Limited ABN 37 136 180 366 Head Office Level 11, 45 Clarence Street, Sydney NSW 2000 | GPO Box 126, Sydney NSW 2001 Telephone +61 2 8270 1800 | Facsimile +61 2 9299 2885 | Email: [email protected] www.eftposaustralia.com.au 3 eftpos Technical, Operational and Security Rules V2.15 2.0 15 Apr 2014 Document restructured for eftpos Chip and Contactless processing. Added definitions for Chip and Contactless. Amended references to message format to include Appendix 5 for bilateral messages and the eftpos Hub Link Specification document for eftpos Hub direct connectors including Chip and Contactless messages. Amalgamated all fallback and dispute sections to 2.7 Common requirements. Updated limits and fallback types to include eftpos EMV fallback processing. Document restructured and definitions added for the introduction of the eftpos Hub and the incorporation of the eftpos Access Code connectivity arrangements into the eftpos Scheme Rules. Deleted contingency file processing as not supported by Members. Updated registration and certification requirements to support eftpos Chip and Contactless processing. Clarified requirements for Cash and Cash/Purchase transactions. 2.1 1 Oct 2014 Clarification of requirements for short duration pre- authorisation transactions. Change requirement for F55 in batch file reporting to optional. Added definitions for TAV and CTAV. Updated document names referenced in the manual. Minor amendments requiring Acquirers to provide merchants with guidelines for processing cash out and surcharges. Minor clarifications to some clauses for unattended devices General corrects/edits for typographical errors and cross references. 2.2 1 Apr 2015 Version 2.1 Re-published without change. Commercial-in-Confidence eftpos Payments Australia Limited ABN 37 136 180 366 Head Office Level 11, 45 Clarence Street, Sydney NSW 2000 | GPO Box 126, Sydney NSW 2001 Telephone +61 2 8270 1800 | Facsimile +61 2 9299 2885 | Email: [email protected] www.eftposaustralia.com.au 4 eftpos Technical, Operational and Security Rules V2.15 2.3 1 Nov 2015 Restructure of TOSR document. Changes to add requirements for eftpos Digital for eftpos Online. Rewrite of Disputes and Chargebacks Section. Updates to Reporting requirements. 2.4 28 April 2016 Introduction of requirements for eftpos Mobile. Introduction of tokenisation requirements. 2.5 26 October 2016 Minor and technical changes regarding: o eftpos Chip and Contactless o eftpos Mobile and Tokenisation o Changes to regulatory requirements Other minor changes and clarifications 2.6 27 April 2017 Changes for: o Updates to eftpos Mobile o Introduction of eftpos Settlement Service o Introduction of support for eftpos In-App Updates to Disputed Transactions and Chargebacks 2.7 25 October 2017 Changes for: o In-App Payments to support Refund Transactions o Clarification for Cashout support across interfaces o Issuer support for default account o Updates to eftpos Settlement Service following RBA feedback o Updates to Disputed Transaction and Chargebacks reporting Other minor changes and clarifications 2.8 25 April 2018 Changes for: o Introduction of eftpos Digital Acceptance (formerly eftpos Online) through the eftpos Digital Acceptance Framework. o Updates to Disputed Transactions and Chargebacks to address card not present transactions. o Addition of a Corrective Batch as part of eSS. o Updates to requirements for certification of eftpos Acceptance Devices. Commercial-in-Confidence eftpos Payments Australia Limited ABN 37 136 180 366 Head Office Level 11, 45 Clarence Street, Sydney NSW 2000 | GPO Box 126, Sydney NSW 2001 Telephone +61 2 8270 1800 | Facsimile +61 2 9299 2885 | Email: [email protected] www.eftposaustralia.com.au 5 eftpos Technical, Operational and Security Rules V2.15 o Updates to the eftpos Certification Body pre- requisites for Acceptance Devices. Removal of Bilateral Interchange Specification. 2.9 24 October 2018 Changes for: o Clarifications relating to eftpos Digital Acceptance, as a result of eftpos Digital Acceptance Reference Group feedback. o Introduction of eftpos Open Loop Transit. o Additional requirements relating to Merchant routed transactions. o Clarifications relating to Acceptance Devices, Cashout and Fallback processing. o Clarification of eftpos Disputed Transactions and Chargebacks reason codes. Amendments to bilateral Interchange Link and bilateral Settlement provisions. 2.10 30 April 2019 Changes for: o Introduction of Merchant Token Requester, Merchant Initiated Transactions and Staged Digital Wallets (eDAF) o Clarification of eftpos Disputed Transactions and Chargebacks. o Clarifications relating to Acceptance Devices, Cashout and Fallback processing. o Amendments to bilateral Interchange Link and bilateral Settlement provisions. Other summary minor and technical corrections. 2.11 07 July 2019 Changes for: o Requirement regarding CNP Fraud rates - AusPayNet CNP Framework o Updates to support new eftpos Digital use cases o Updates to Member obligations regarding the Service Providers o Updates to support Open Loop Transit transactions on eftpos Form factors. o Updates to cater for Consumer Data Right regulations 2.12 05 May 2020 Changes for: Commercial-in-Confidence eftpos Payments Australia Limited ABN 37 136 180 366 Head Office Level 11, 45 Clarence Street, Sydney NSW 2000 | GPO Box 126, Sydney NSW 2001 Telephone +61 2 8270 1800 | Facsimile +61 2 9299 2885 | Email: [email protected] www.eftposaustralia.com.au 6 eftpos Technical, Operational and Security Rules V2.15 o Inclusion of requirements for BIN Controller for allocating PARs to the eftpos proprietary cards. o Updates to Authorised eftpos Digital