Mastercard GLB12111: The Acceptor Contact Data Mandate Explained | CatalystPay
NEW: Accept Bitcoin Lightning payments - instant settlement, zero chargebacks, and a faster alternative to cards. Learn More

Mastercard GLB12111: The Acceptor Contact Data Mandate Explained

Quick Answer

Mastercard Announcement GLB12111 adds new Data Integrity Monitoring Program edits that require online (card-not-present) transactions to carry valid Acceptor (merchant) contact data: a correctly formatted merchant website URL, or a customer service phone number where a URL is not available. It applies to every Mastercard online transaction, browser-based and app-based, whether routed directly through an acquirer, a PSP, or a payment orchestration setup. The edits take effect from 1 February 2026, monitoring is already under way, and formal non-compliance assessments begin on 27 September 2026, with acquirers expected to hold a 98% compliance rate on monitored transactions. If you are a CatalystPay merchant, this is already handled on our side and you do not need to do anything.

Table of contents

  1. What is changing
  2. It applies to all online transactions, not only "e-commerce"
  3. Key dates
  4. Who is impacted
  5. Why Mastercard is doing this
  6. What to do about it
  7. How CatalystPay handles it for you
  8. FAQ

What is changing

Mastercard's Data Integrity Monitoring Program (DIMP) checks the quality of the transaction data that acquirers, PSPs and processors submit to the network. Announcement GLB12111 introduces a new set of DIMP edits focused on Acceptor Contact Data, meaning the merchant's contact details attached to each transaction.

Under the new edits, an online transaction is expected to include either:

  • a valid, correctly formatted merchant website URL, or
  • a customer service phone number, where a URL is not available.

A valid merchant URL on its own is enough to meet the requirement. Transactions that arrive without valid acceptor contact data can be flagged as non-compliant under the monitoring programme.

Key dates

Milestone

Date

What it means

Edits take effect

1 February 2026

The acceptor contact data validations go live and monitoring begins

Monitoring period

Now

Mastercard is already evaluating transactions against the new edits

Formal assessments begin

27 September 2026

Non-compliance assessments and monitoring evaluations start, with potential penalties

Compliance threshold

98%

Acquirers and applicable participants are expected to keep monitored transactions at 98% compliance

Dates and thresholds are per Mastercard Announcement GLB12111. Confirm the exact timeline that applies to your setup with your provider, as scheme programmes can be revised.

Who is impacted

Every merchant processing Mastercard online transactions is in scope, regardless of how the transaction is routed:

  • directly with an acquirer,
  • via a Payment Service Provider (PSP), or
  • through a payment orchestration setup.

High-risk merchants should pay particular attention: as you might already operate closer to scheme monitoring thresholds, you have the least room to absorb an avoidable data-quality flag on top of programmes like the Mastercard SMMP and Visa VAMP.

Why Mastercard is doing this

The goal is transaction transparency. When the cardholder can see who they paid, through a recognisable merchant URL or a reachable phone number, they are more likely to recognise the charge and less likely to raise a dispute. Cleaner acceptor data means fewer "I don't recognise this" chargebacks and clearer records across the ecosystem. In other words, it sits alongside the wider scheme push to reduce disputes and improve data quality, and it rewards merchants who present themselves clearly at the point of payment.

What to do about it

We recommend an acquirer-agnostic approach: always provide the merchant.url directly in the payment request, even if a given card payment provider might add it automatically. Sending it consistently means:

  • compliance holds independently of any single acquirer or PSP's behaviour,
  • you avoid integration-specific assumptions that break when routing changes, and
  • your orchestration stays simple, predictable and scalable.

If you work with multiple providers or route through orchestration, this is the difference between one clean rule you control and a patchwork of provider-specific behaviours you have to monitor. If you are not sure whether your current setup sends this data, that is the question to put to your PSP now, ahead of the September assessment date.

How CatalystPay handles it for you

If you process with CatalystPay, this is already taken care of and you do not need to do anything. Where your acquirer already supplies the acceptor contact data, it flows through as normal. Where it does not, our systems populate the required merchant URL on your behalf, so every Mastercard online transaction leaves us correctly formatted and compliant, regardless of how it is routed. We process and forward the acceptor contact data exactly as provided in the transaction request, and fill the gap where it is missing.

If you would like to walk through how this works for your specific integration, your account manager is happy to help.

If you are not yet with us and want a payment setup that stays compliant across acquirers without you managing each scheme change by hand, talk to our team.

Frequently Asked Questions

  • What is Mastercard GLB12111?

    It is a Mastercard announcement introducing new Data Integrity Monitoring Program edits that require online transactions to carry valid Acceptor (merchant) contact data, either a correctly formatted merchant website URL or a customer service phone number where a URL is not available.

  • Does GLB12111 only affect e-commerce transactions?

    It applies to all Mastercard online, card-not-present transactions, including both browser-based and in-app payments, not just traditional e-commerce checkouts.

  • What is the deadline of Mastercard GLB12111?

    The edits took effect on 1 February 2026 and monitoring is already under way. Formal non-compliance assessments and monitoring evaluations begin on 27 September 2026, with acquirers expected to maintain a 98% compliance rate on monitored transactions.

  • Is a merchant URL or a phone number required?

    Either can satisfy the rule, but a valid, correctly formatted merchant website URL on its own is sufficient. A customer service phone number is the alternative where a URL is not available.

  • What happens if my transactions do not include valid contact data?

    They can be flagged as non-compliant under the monitoring programme. Over time that can lead to monitoring notifications and potential assessments, which is why sending a valid merchant URL on every online transaction is the safe default.

Was the article useful?
Also Read