Tomcat
Professional
- Messages
- 2,687
- Reaction score
- 1,036
- Points
- 113
Appendix 1
to Agreement No. ____________
on settlements with the Client on transactions performed using payment cards (in the Client's electronic terminals)
INSTRUCTIONS ON THE ORDER OF WORK WITH BANK CARDS
The specified PCI DSS requirements include, in particular, the following (but not limited to) provisions:
- a three-digit security code located in the last three positions on the card signature strip.
- the first six and last four digits of the Card number, is the validity period of the Card.
At the same time, the storage and transmission of the specified data is carried out in accordance with the requirements of the PS to ensure the security of Card data, the requirements of the PCI DSS standard. In particular, the following (but not only) security measures must be strictly observed in the implementation of the specified storage and transfer:
- storage and transmission of information is carried out with the adoption of the necessary measures of physical protection of information carriers, including paper and electronic media, excluding the possibility of unauthorized access to them;
- storage and transmission of information in electronic form, including through communication channels, by e-mail are carried out only with the use of cryptographic protection, carried out by strong encryption;
- the storage period for the Card data must be determined, after which the data and (or) data carriers must be destroyed, ensuring the guaranteed impossibility of recovering the indicated data.
- a document that is such in accordance with the current legislation of the Russian Federation:
a) for citizens of the Russian Federation:
- a passport of a citizen of the Russian Federation,
- a general civil foreign passport,
- a sailor's identity card,
- a serviceman's identity card or military ID - for military personnel of the Russian Federation,
- a temporary identity card of a citizen of the Russian Federation issued by an internal affairs body before a passport is issued
- other documents recognized as identity documents in accordance with the legislation of the Russian Federation;
b) for foreign citizens:
- passport of a foreign citizen,
- another document established by federal law or recognized in accordance with an international treaty of the Russian Federation as an identity document;
c) for stateless persons, if they permanently reside on the territory of the Russian Federation - a residence permit in the Russian Federation;
d) for other stateless persons:
- a document issued by a foreign state and recognized in accordance with an international treaty of the Russian Federation as an identity document of a stateless person,
- a temporary residence permit,
- a residence permit,
- other documents provided for by federal laws or recognized in accordance with an international treaty of the Russian Federation as documents proving the identity of a stateless person;
e) for refugees:
- a certificate of consideration of an application for recognition of a person as a refugee issued by a diplomatic or consular institution of the Russian Federation or an immigration control post or a territorial federal executive body for the migration service,
- a refugee certificate.
Documents drawn up in whole or in any part of them in a foreign language (with the exception of documents proving the identity of an individual, issued by the competent authorities of foreign states, drawn up in several languages, including Russian), are submitted with a duly certified translation into Russian. The requirement to submit documents with a properly certified translation into Russian does not apply to documents issued by the competent authorities of foreign states that certify the identity of an individual, provided that the individual has a document confirming the right to legally stay on the territory of the Russian Federation (for example, a visa, migration card).
In this case, the cashier has the right to ask the Holder to present the Card and an identity document in order to determine its compliance with the PS Cards standards specified in Section 5 of this Instruction, as well as in case of suspicion of the Unlawful use of the Card.
If signs of counterfeiting are detected, follow clause 2.4 of this Instruction.
to Agreement No. ____________
on settlements with the Client on transactions performed using payment cards (in the Client's electronic terminals)
INSTRUCTIONS ON THE ORDER OF WORK WITH BANK CARDS
- General Provisions
- The Card is the property of the Issuer that issued it and can be used to purchase goods, receive services only by the legal Holder using the Card on the basis of an agreement with the Issuer.
- When carrying out Transactions using the Cards, it is necessary to ensure the safe processing, transfer, storage of information about the Cards in accordance with the requirements of the PS to ensure the security of the Cards data, the requirements of the PCI DSS standard.
The specified PCI DSS requirements include, in particular, the following (but not limited to) provisions:
- Access to Card data is provided only to authorized persons from among the Client's employees who need this access to perform their job duties.
- It is prohibited to store the following confidential Card data in any form:
- a three-digit security code located in the last three positions on the card signature strip.
- If necessary, it is allowed to store and transfer the following confidential Card data:
- the first six and last four digits of the Card number, is the validity period of the Card.
- The storage and transfer of full Card numbers separately or together with other Card data by the Client is possible only if the Bank has a written consent to this.
At the same time, the storage and transmission of the specified data is carried out in accordance with the requirements of the PS to ensure the security of Card data, the requirements of the PCI DSS standard. In particular, the following (but not only) security measures must be strictly observed in the implementation of the specified storage and transfer:
- storage and transmission of information is carried out with the adoption of the necessary measures of physical protection of information carriers, including paper and electronic media, excluding the possibility of unauthorized access to them;
- storage and transmission of information in electronic form, including through communication channels, by e-mail are carried out only with the use of cryptographic protection, carried out by strong encryption;
- the storage period for the Card data must be determined, after which the data and (or) data carriers must be destroyed, ensuring the guaranteed impossibility of recovering the indicated data.
- Provide the necessary protection of information systems, information and telecommunication networks, information carriers under the control of the Client in order to ensure confidentiality, integrity, availability of the processed Card data, in accordance with the requirements of the PS to ensure the safety of Card data, the requirements of the PCI DSS standard. The specified protection should prevent unauthorized actions in relation to the protected information carried out by both third parties, including preventing the possibility of external penetration of an intruder from the Internet, and by persons from among the Client's employees.
- Require the fulfillment of the PS requirements for ensuring the security of Card data, PCI DSS standard requirements, including the above requirements, by all third-party organizations that are or will be engaged in the processing, transfer or storage of Card data on behalf of the Client, as well as provider companies that are suppliers to the Client services, equipment or software involved in the processing, transmission or storage of Card data.
- All Transactions using the Cards are allowed only if the Card is presented by the legal Holder, whose name is indicated on the face of the Card (if the Card is personalized). The Card cannot be transferred by the legal Holder for use to another person under any circumstances.
- An illegal Operation using the Card means:
- use or attempted use of the Card by an unauthorized Holder;
- use of a counterfeit Card;
- fraudulent use of the Card details during operations without presenting the Card;
- use instead of the Card of clean plastic (without indicating the logo of the Issuer and the PS, holograms and other degrees of protection) with data embossed on it or encoded on a magnetic stripe from a genuine Card (so-called "white plastic");
- an operation in which the signatures on the ET Check and on the Card were not identical 1;
- forgery of the ET Check (forgery of the Holder's signature).
- The Customer's cashiers are not allowed to issue cash / replenish the bank account with cash using the Cards.
- If you identify transactions with Visa Electron, Maestro, Mastercard Electronic Cards, which do not have the name of the Holder, to identify the latter, you must call the Call Center of PJSC Bank ZENIT (hereinafter referred to as the Bank).
- When carrying out a Transaction using the Maestro Card, ET asks the Holder to enter the PIN using the ET keyboard. If it is impossible to carry out a transaction with the introduction of a PIN, the cashier must refuse to accept the Maestro Card for service.
- The Client's cashier has the right to request an identity document if the Holder's identity is in doubt. If it is necessary to establish the identity of the Holder, the Client's cashier can accept the documents specified in clause 1.9 of these Instructions.
- Identity document:
- a document that is such in accordance with the current legislation of the Russian Federation:
a) for citizens of the Russian Federation:
- a passport of a citizen of the Russian Federation,
- a general civil foreign passport,
- a sailor's identity card,
- a serviceman's identity card or military ID - for military personnel of the Russian Federation,
- a temporary identity card of a citizen of the Russian Federation issued by an internal affairs body before a passport is issued
- other documents recognized as identity documents in accordance with the legislation of the Russian Federation;
b) for foreign citizens:
- passport of a foreign citizen,
- another document established by federal law or recognized in accordance with an international treaty of the Russian Federation as an identity document;
c) for stateless persons, if they permanently reside on the territory of the Russian Federation - a residence permit in the Russian Federation;
d) for other stateless persons:
- a document issued by a foreign state and recognized in accordance with an international treaty of the Russian Federation as an identity document of a stateless person,
- a temporary residence permit,
- a residence permit,
- other documents provided for by federal laws or recognized in accordance with an international treaty of the Russian Federation as documents proving the identity of a stateless person;
e) for refugees:
- a certificate of consideration of an application for recognition of a person as a refugee issued by a diplomatic or consular institution of the Russian Federation or an immigration control post or a territorial federal executive body for the migration service,
- a refugee certificate.
Documents drawn up in whole or in any part of them in a foreign language (with the exception of documents proving the identity of an individual, issued by the competent authorities of foreign states, drawn up in several languages, including Russian), are submitted with a duly certified translation into Russian. The requirement to submit documents with a properly certified translation into Russian does not apply to documents issued by the competent authorities of foreign states that certify the identity of an individual, provided that the individual has a document confirming the right to legally stay on the territory of the Russian Federation (for example, a visa, migration card).
- In certain types of ET, it is possible for the Holder to independently conduct a Transaction using the Card (without presenting the Card to the cashier) by using the Card's chip or its magnetic stripe, as well as by entering the PIN (for Cards with a chip and Maestro Card) or affixing a signature on the ET Check (for Cards with magnetic stripe), taking into account the requirements specified in clause 3.5.4 of this Instruction.
In this case, the cashier has the right to ask the Holder to present the Card and an identity document in order to determine its compliance with the PS Cards standards specified in Section 5 of this Instruction, as well as in case of suspicion of the Unlawful use of the Card.
- When carrying out transactions using a Card with the PayPass function / Card with the payWave function, the Holder does not need to present the Card with the PayPass function / Card with the payWave function and identification documents to the cashier. The merchant cashier has the right to ask the Cardholder to present the Card with the PayPass function / Card with the payWave function and an identity document to determine its compliance with the standards of MasterCard Worldwide PS Cards, Visa International PS specified in cl. 5.1, 5.2 of these Instructions, as well as in case of suspicion of the Unlawful use of the Card.
- The operation using the Card with the PayPass function / Card with the payWave function is carried out by the Cardholder by presenting the Card with the PayPass function / Card with the payWave function to the ET reader, taking into account the requirements specified in clause 3.5.4 of these Instructions.
- Safety measures when servicing the Cards
- When checking the Card, follow the following rules:
- Check the expiration date of the Card. The validity period of the Card is indicated on its front side in the format 00/00 (month / year). Do not service Cards that have not yet expired or have already expired.
- Make sure that the Card meets the PS standards specified in section 5 of this manual and that its use is not limited to one country (for example, the inscription “ Valid only in (country)”). Cards with the indication “Valid only in Russia” - “Valid only in Russia” can be accepted for payment.
- Make sure the Card is not damaged . The card should not have holes, fractures, deliberately made scratches, cracks, cuts.
- Check if there are any signs of forgery of the Card (clause 2.2 of these Instructions).
- Check the signature on the signature panel - no signature The card is not accepted for service.
- If there is no signature, ask the Holder to present an identity document and, after identifying the Holder by photo and name, offer to sign the Card.
- If the Holder refuses to sign the Card, it is prohibited to execute the transaction.
- Carry out an Authorization request in accordance with section 3 of these Instructions.
- Make sure that the data of the presented Card (number or part of the number printed on the Card; validity period of the Card; the name of the Holder, if it is stamped on the Card) corresponds to the data on the display / Check ET - their discrepancy is possible in case of counterfeiting the magnetic stripe of the Card. If a discrepancy is revealed (a discrepancy between at least one number, letter or different spelling on the Card or ET Check, for example, the Card shows IVAN P FILATOV, and the ET Check shows IVAN FILATOV) or in the absence of the Holder's name on the Card, the cashier should call Call - the center of the Bank for identification of the Holder.
- Make sure that the signature on the ET Check matches the sample signature on the Card .
- If the signatures are not identical, then, without returning the Card, ask the Holder to present an identity document and identify the Holder by photo, name and, additionally, by signature.
- If any of the identifying signs does not correspond to reality, you need to call the Bank's Call Center using the “CODE 10” procedure 2 .
- Some signs of counterfeit Visa, MasterCard or UnionPay cards:
- the name of the Issuer and the PS logo are printed with poor quality, inks may be washed out and rubbed off;
- the first 4 digits of the Card number, typed under or above the embossed number, are erased or missing;
- The last 4 digits of the UnionPay Card number are not located on the hologram (except for cases when the hologram is placed on the back of the card or is missing);
- the hologram is glued, it can peel off at the edges;
- the Card number is embossed in the center of the hologram;
- when embossing the name of the Holder, mistakes were made (different from the name indicated in the identity document).
- errors in microprinting of the Visa logo (instead of the manufacturer's code and the first 4 digits of the Card number, there is a solid blue line or the word Visa is printed - it looks like a dotted line);
- there is no image visible in ultraviolet light;
- there is no protective special symbol on the cards, where it is needed;
- the magnetic strip is glued, and not soldered into the plastic (detected by holding the nail in the perpendicular direction);
- the magnetic stripe is located unevenly relative to the horizontal edge of the Card;
- the Card number / the last 4 digits of the Card number on the signature strip do not coincide with the Card number / the last 4 digits of the Card number on its front side;
- the Card number / the last 4 digits of the Card number and the three-digit security code on the signature strip are not tilted to the left or are absent on those Cards where they are needed;
- changes have been made to the embossed details of this Card;
- mismatch of the number on the face of the Card with the number on the ET Check / ET display.
If signs of counterfeiting are detected, follow clause 2.4 of this Instruction.
- Positive Authorization is not a proof of the authenticity of the presented Card or the legality of its use by the Holder, it only confirms the sufficiency of funds in the bank account. Please note that an Authorization code may be given to counterfeit or just stolen Cards. Obtaining an Authorization code is not a basis for the provision of services for such Cards. Therefore, when conducting Transactions using the Cards, pay attention to the suspicious or unusual behavior of the Holders, who:
- show nervousness;
- try to distract the cashier during the operation or exert psychological pressure;
- within a short period of time, repeatedly, pay for purchases by presenting Cards from different Issuers;
- upon receipt of a negative answer to the Authorization, present for payment other Cards, different Issuers and PS;
- upon receipt of the response of the Authorization “Withdraw the card”, they explain this by the bank's mistake and present the Card of another Issuer for payment;
- repeatedly ask to lower the request amount upon receipt of the Authorization response “insufficient funds”, and also after several such attempts, present Cards of other Issuers;
- the purchase / withdrawal of cash is made by a group of people who are ready to present their Cards for payment;
- make a purchase for a small amount, leave the store, and then return and make a purchase for a large amount;
- make expensive purchases right after the store opens or in the last minutes before it closes;
- do not ask questions before paying for an expensive purchase;
- refuse free delivery of bulky goods;
- buy many things at once without choosing them by size, style, color or price;
- purchase several identical goods for a significant amount;
- take out the Card not from the wallet, but directly from the pocket;
- unsure of signing or trying to forge a signature;
- refuse to present an identity document;
- The card for a woman's name is presented by a man and vice versa;
- have an appearance that does not correspond to the nature and value of the purchase being made or deliberately demonstrate accessories of a wealthy person;
- ask about the amount of unauthorized transactions in a given outlet.
- At the slightest suspicion that the Card is counterfeit, presented not by its legal Cardholder, or if the behavior of the Cardholder makes you suspicious:
- In the case of a transaction in ET by a cashier, without returning the Card to the Holder, conduct an Authorization request, regardless of the amount of the transaction. Do not forget that an Authorization code may be given to counterfeit or just stolen Cards;
- Following the results of the Transaction using the Card, try to establish the identity of the Holder by asking for identification documents. Identify the photograph in the document with the identity of the Holder. In all cases, when you ask for documents, indicate on the front side of the ET Check the data of the presented document (type of document, its series and number);
- Call the Bank's Call Center and report your suspicions. In this case, a conditional signal - "CODE 10" can be used, which makes it possible for the cashier to report an attempt to illegally use the Card, without arousing suspicion from the criminal. Speak in your usual tone. Follow the instructions of the operator of the Bank's Call-center.
- When confirming the fact of using the Card in a false name or a counterfeit Card, try to seize the Card in accordance with clauses 2.6.3 - 2.6.4 of these Instructions, and take all measures to ensure the possibility of arresting the offender with the help of guards / employees of district police departments.
- Withdrawal of Cards
- The grounds for withdrawing the Card are:
- receiving the “Withdraw card” command via ET in response to an Authorization request;
- receiving the “Withdraw card” command from the Bank's Call-center;
- the presence of signs of forgery of the Card;
- presentation of the Card in someone else's name.
- The order of the cashier's actions upon receipt of the “Withdraw card” command:
- if the Holder asks to return the Card, referring to the fact that it is his Card, then politely try to explain to him that the Card is not his property, but the property of the Issuer, and you are following the Issuer's order;
- Withdraw the Card only if it can be done without risk to yourself and others. If the Holder starts to threaten you - immediately return the Card to him;
- inform the Bank's Call-center about the withdrawal of the Card;
- issue the "Certificate of withdrawal of the card" (Appendix 1 to these Instructions);
- transfer the withdrawn Card to the Bank in accordance with clause 2.6.5 of this Instruction.
- if you failed to withdraw the Card, inform the Bank's Call-center of the reasons for the withdrawal.
- The order of actions of the cashier in case of detecting a counterfeit Card:
- without informing the Holder about the detection of a forgery, request a Voice Authorization by calling the Bank's Call Center. In this case, use the conditional signal "CODE 10";
- ask the Holder to present an identity document and write down its details (type of document, number, series, registration address, date and place of issue);
- without returning the Card and documents to the fraudster, take measures to arrest him with the help of your security personnel;
- in case of arrest of a swindler, call an employee of the district police department or the Department of Economic Crimes of the Central Internal Affairs Directorate on your own or through the operator of the Bank's Call-center;
- draw up the "Certificate of seizure of the card" (appendix 1 to this Instruction) in two copies with additional indication of the data of the police officer who arrived for the arrest (surname, ID number, police station number, position and telephone number). Let the police officer sign the “Card Withdrawal Act” (Appendix 1 to these Instructions).
- transfer the withdrawn Card to the Bank in accordance with clause 2.6.5 of this Instruction;
- if you failed to withdraw the Card, inform the Bank's Call-center of the reasons for the withdrawal.
- If the Card is presented in someone else's name:
- inform the Bank's Call-center about presenting the Card in someone else's name;
- Withdraw the Card only if it can be done without risk to yourself and others. If the Holder starts to threaten you - immediately return the Card to him;
- fill out the "Certificate of withdrawal of the card" (Appendix 1 to this Instruction) indicating the reasons for confirming the validity of the withdrawal (for example, indicate the discrepancy between the name of the Holder on the Card and in the presented document, the Card is presented in a woman's name by a man or vice versa, etc.) ... If possible, indicate in the "Certificate of withdrawal of the card" (Appendix 1 to this Instruction) the data of the identity document of the Holder (type of document, its number and series, full name).
- transfer the withdrawn Card to the Bank in accordance with clause 2.6.5 of this Instruction.
- if you failed to withdraw the Card, inform the Bank's Call-center of the reasons for the withdrawal.
- Withdrawn Cards together with the completed "Certificate of withdrawal of the card" (Appendix 1 to this Instruction) and the Check ET must be delivered to the Bank within 3 (Three) business days from the date of withdrawal of the Cards for the subsequent return of the Card to its Issuer. The Card Withdrawal Act (addendum 1 to this Instruction) must indicate: the name and address of the Client, the Card number and the name of the Holder, the date and reason for the withdrawal, the surname, name, patronymic of the Client's employee who seized the Card, his contact phone number.
- The Bank pays remuneration for the withdrawal of Visa International and MasterCard Worldwide PS Cards from illegal circulation, performed on the grounds specified in clause 2.6.1. of this Instruction, subject to the provisions of this Instruction and in accordance with the terms of the Agreement. No remuneration is provided for the withdrawal of Maestro Cards.
Last edited:
