EMV® 3-D Secure Browser Flow Best Practices
Last Updated: April 17, 2020
- Terms of Sale; Participation Programs. Except as otherwise stated on the Site, all sales transactions on the Site are governed by EMVCo’s Terms of Sale. Your participation in EMVCo’s participation programs (such as the EMVCo Subscriber Programme or EMVCo Associates Programme) is governed by the applicable EMVCo agreement presented at registration for the program.
- Acceptable Use. As a condition of using the Site, you agree not to do any of the following:
- use the Site or Site Materials in violation of applicable law or in a manner that facilitates or furthers the violation of applicable law;
- use the Site or Site Materials in a way that harms EMVCo or EMVCo’s members, affiliates or vendors, or other users of the Site;
- use any portion of the Site as a destination linked from any unsolicited bulk messages or unsolicited commercial messages (such as “spam”);
- use or access, or attempt to use or access, any EMVCo account that is not yours;
- damage, disable, overburden or impair the Site (or the network(s) connected to the Site) or otherwise interfere with anyone’s use and enjoyment of the Site;
- attempt to reverse-engineer or otherwise discover or recreate any part of the Site or Site Materials (including any code, technology or methodology used in connection with the Site);
- except as otherwise may be authorized by EMVCo in a separate document, resell or redistribute the Site or Site Materials or any part of the Site or Site Materials, or otherwise use the Site or Site Materials for any purpose other than your own internal business use;
- use the Site (including any Site Materials) other than for its intended purpose.
- License to Site, Site Materials and Intellectual Property Associated with Compliance with Specifications. The Site Materials are the proprietary property of EMVCo or its licensors. EMVCo hereby grants to you a perpetual, worldwide, nonexclusive, nontransferable, royalty-free, paid-up license (without the right to sublicense) to:
- reproduce Site Material documents and files that are specifically made available on the Site for the general public to download without a Subscriber or Associate account (“Public Documents”), and share such Public Documents internally within your Organization, provided that any copyright notices on each page of Public Document reproductions are reproduced in full and that you agree to comply with all such notices;
- prepare translations of the Public Documents into your local language(s) solely for internal use within your Organization, without distribution to third parties;
- in the past and future, make (including have made), use, sell, offer to sell and/or import integrated circuit cards, terminals, applications and systems that practice, in whole or in part, any final (non-draft) version of the EMV Specifications; and
- modify, use, and incorporate into your EMV Products any final (non-draft) API, SDK, software, scripts and other code that are specifically described by EMVCo as being provided for such incorporation.
- This is an unofficial translation for [Organization] internal use only. Do not distribute outside [Organization]. EMVCo is not responsible for this translation. Only documents published by EMVCo are the official versions for EMV testing and approval. EMVCo reserves all rights.
And after the cover page of each copy of a translation, the following (or a substantially similar notice) must be printed:
- Unofficial translation for [Organization] internal use only. EMVCo is not responsible for this translation
Notwithstanding the foregoing, the Public Documents may be subject to a separate agreement you may have with EMVCo or to supplemental terms and conditions that are included in or accompany Public Documents, in which case you agree that such separate agreement or supplemental terms and conditions will apply to your use of the Public Documents. Any use of the Site or Site Materials other than as specifically authorized herein (or in such separate agreement or supplemental terms and conditions) is strictly prohibited and will automatically terminate the foregoing license without notice.
- Trademarks. EMVCo, EMV®, the EMVCo logo, the EMV Secure Remote Commerce payment icon, the EMV Contactless Marks, the EMV QR Marks, the EMVCo Certification Marks, EMVCo Relationship Marks, and any other product or service name or slogan contained in the Site are trademarks of EMVCo and its licensors and may not be copied, imitated or used, in whole or in part, without the prior written permission of EMVCo or the applicable trademark holder. Use of any EMVCo trademarks is subject to the trademark license agreement(s) you may have with EMVCo and your compliance with any applicable EMVCo trademark usage guidelines. You may not use any metatags or any other “hidden text” utilizing “EMVCo,” “EMV” or any other name, trademark or product or service name of EMVCo without our prior written permission. In addition, the look and feel of the Site, including all page headers, graphics, button icons and scripts, is the service mark, trademark or trade dress of EMVCo and its licensors and may not be copied, imitated or used, in whole or in part, without our prior written permission. All other trademarks, registered trademarks, product names and company names or logos mentioned on the Site are the property of their respective owners. Reference to any product vendors, laboratories, auditors, test tools, products, services, processes or other information, whether by trade name, trademark, manufacturer, supplier or otherwise, does not constitute or imply endorsement, sponsorship or recommendation thereof by EMVCo.
- Framing and Hyperlinks. You may not frame or utilize framing techniques to enclose any EMVCo trademark, logo or other Site Materials, including the images found at the Site, the content of any text or the layout/design of any page or form contained on a page on the Site, without EMVCo’s written consent. EMVCo makes no claim or representation regarding, and accepts no responsibility for, the quality, content, nature or reliability of third-party Web sites accessible by hyperlink from the Site or of Web sites linking to the Site. Such sites are not under the control of EMVCo and EMVCo is not responsible for the contents of any linked site or any link contained in a linked site, or any review, changes or updates to such sites. EMVCo provides these links to you only as a convenience, and the inclusion of any link does not imply affiliation, endorsement or adoption by EMVCo of any site or any information contained therein. When you leave the Site, you should be aware that our terms and policies no longer govern. You should review the applicable terms and policies, including privacy and data gathering practices, of any site to which you navigate from the Site.
- Submissions. You agree that any idea, method, concept, invention, suggestion, design, technology, information, process, formula, software, technique, drawings, data, know how, or other item or material which is provided by you (including your Organization or any other employee or representative of your Organization) to EMVCo regarding the Site, Site Materials (including without limitation any EMV Specifications (defined below)), other documents and materials of EMVCo, any EMVCo-related technologies and approval processes, or other offerings of EMVCo or its affiliates in the form of email or through a web form on the Site (“Submissions”) are non-confidential. You agree to grant, and hereby grant, to EMVCo a perpetual, worldwide, nonexclusive, royalty-free, fully sublicensable and irrevocable license to all intellectual property and proprietary rights in any Submissions to (a) make, have made, use, sell, offer for sale, and import integrated circuit cards, terminals, applications, test tools, systems, services and other items that practice, in whole or in part, the EMV® Specifications, and (b) use, reproduce, distribute, prepare derivative works of, publicly perform or display, and otherwise fully exploit any Submissions and any intellectual property and proprietary rights therein. Further, you agree to waive and forego asserting any moral rights you may have in the Submissions. By submitting a Submission to EMVCo, you represent and warrant that you have authority to provide such Submission to EMVCo and grant the rights to the Submission granted herein, and that doing so does not and will not constitute the infringement or misappropriation of the trade secrets or other confidential information of your Organization or any third party. You agree to execute such documents and otherwise provide such reasonable assistance, and to cause your affiliates to execute and provide such assistance, as is necessary to give full force and effect to this paragraph. As used herein, “EMV® Specifications” means any and all existing and future specifications developed or issued by or on behalf of EMVCo, all technical bulletins to such specifications, and any related requirements documents, process documents, guidelines, and related materials. EMV® Specifications are included in the definition of Site Materials.
- Disclosure and Use of Information about Site Users. Although it is not EMVCo’s preference to provide governmental authorities with access to information about Site users, you acknowledge that EMVCo may be required to do so from time to time. As such, you authorize EMVCo to deliver or furnish any information about your use of the Site and such other information in connection with your use of the Site, to such governmental authorities as may order or demand the same, with or without notice to you.
- Indemnification. You will defend and indemnify EMVCo, its affiliates, independent contractors and service providers, and each of their respective members, directors, officers, employees and agents (“EMVCo Parties”), from and against all claims, damages, costs, liabilities and expenses (including reasonable attorneys’ fees) arising out of or related to your use of, or inability to use, the Site or Site Materials.
- Disclaimers. THE SITE AND ALL SITE MATERIALS (INCLUDING THE EMV® SPECIFICATIONS) AND LICENSES ARE PROVIDED ON AN “AS IS” BASIS WITHOUT WARRANTIES OF ANY KIND. EMVCO DOES NOT PROMISE THAT THE SITE OR SITE MATERIALS WILL BE FREE OF INACCURACIES OR ERRORS, OR THAT YOUR USE OF THE SITE OR SITE MATERIALS WILL PROVIDE SPECIFIC RESULTS. EMVCO DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, WITHOUT LIMITATION, IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NON-INFRINGEMENT. YOU ARE SOLELY RESPONSIBLE FOR THE ACCURACY OF ANY TRANSLATIONS YOU MAKE.
- Limitation of Liability. TO THE FULLEST EXTENT PERMITTED BY LAW, IN NO EVENT SHALL ANY OF THE EMVCO PARTIES BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY INDIRECT, CONSEQUENTIAL, SPECIAL OR PUNITIVE DAMAGES (INCLUDING LOSS OF PROFITS), WHETHER IN AN ACTION IN CONTRACT, TORT (INCLUDING NEGLIGENCE) OR OTHERWISE, ARISING OUT OF OR RELATING TO THE SITE (INCLUDING ANY SITE MATERIALS), EVEN IF AN EMVCO PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. IN NO EVENT SHALL THE AGGREGATE LIABILITY OF EMVCO PARTIES (WHETHER IN CONTRACT, WARRANTY, TORT, PRODUCT LIABILITY, STRICT LIABILITY OR OTHER THEORY) ARISING OUT OF OR RELATING TO THE SITE OR SITE MATERIALS (INCLUDING THE EMV® SPECIFICATIONS) EXCEED THE AMOUNT YOU PAID, IF ANY, FOR YOUR USE OF THE SITE DURING THE YEAR BEFORE THE CAUSE OF ACTION AROSE.
- Export Laws; Use by U.S. Government. The Site Materials, including technical data, may be subject to U.S. export control laws, including the U.S. Export Administration Act and its associated regulations, and may be subject to export or import laws and regulations in other countries. You agree to comply strictly with all such laws and regulations and acknowledge that you have the responsibility to obtain any licenses or other approvals, if applicable, to export, re-export, or import the Site Materials. The Site Materials may not be downloaded, or otherwise exported or re-exported (i) into, or to a national or resident of, Cuba, Iran, North Korea, Sudan, Syria or any other country subject to a U.S. embargo; (ii) to any person or entity on the U.S. Treasury Department’s Office of Foreign Assets Control’s list of Specially Designated Nationals, or the U.S. Commerce Department’s Bureau of Industry and Security’s Denied Parties, Unverified or Entity Lists; or (iii) for any purpose prohibited by U.S. export control laws (e.g., nuclear, biological, or chemical weapons or missile technology).Use, duplication or disclosure by the United States government is subject to the restrictions as set forth in the Rights in Technical Data and Computer Software Clauses in DFARS 252.227-7013(c) (1) (ii) and FAR 52.227-19(a) through (d) as applicable.
- Questions. If you have any questions about EMVCo or the Site, please contact us by submitting a Public Comment at Contact Us or a Query (for Subscribers and Associates) at Submit a Query.