Item 1. Business
ITEM 1. BUSINESS
network from being used to facilitate money laundering and other illicit activity and to address these legal and regulatory requirements and assist in managing money laundering and terrorist financing risks. The economic sanctions programs administered by OFAC restrict financial transactions and other dealings with certain countries and geographies (specifically Crimea, Cuba, Iran, North Korea and Syria) and with persons and entities included in OFAC sanctions lists including its list of Specially Designated Nationals and Blocked Persons (the “SDN List”). We take measures to prevent transactions that do not comply with OFAC and other applicable sanctions, including establishing a risk-based compliance program that has policies, procedures and controls designed to prevent us from having unlawful business dealings with prohibited countries, regions, individuals or entities. As part of this program, we obligate issuers and acquirers to comply with their local sanctions obligations and the U.S. sanctions programs, including requiring the screening of account holders and merchants, respectively, against OFAC sanctions lists (including the SDN List). Iran and Syria have been identified by the U.S. State Department as terrorist-sponsoring states, and we have no offices, subsidiaries or affiliated entities located in these countries and do not license entities domiciled there. We are also subject to anti-corruption laws and regulations globally, including the U.S. Foreign Corrupt Practices Act and the U.K. Bribery Act, which, among other things, generally prohibit giving or offering payments or anything of value for the purpose of improperly influencing a business decision or to gain an unfair business advantage. We have implemented policies, procedures and internal controls to proactively manage corruption risk.
Financial Sector Oversight. We are or may be subject to regulations related to our role in the financial industry and our relationship with our financial institution customers. In addition, we are or may be subject to regulation by a number of agencies charged with oversight of, among other things, consumer protection, financial and banking matters. The regulators have supervisory and independent examination authority as well as enforcement authority that we may be subject to because of the services we provide to financial institutions that issue and acquire our products.
Issuer and Acquirer Practices Legislation and Regulation. Our issuers and acquirers are subject to numerous regulations and investigations applicable to banks, financial institutions and other licensed entities, impacting us as a consequence. Additionally, regulations such as the revised Payment Services Directive (commonly referred to as “PSD2”) in the EEA require financial institutions to provide third-party payment processors access to consumer payment accounts, enabling them to route transactions away from Mastercard products and provide payment initiation and account information services directly to consumers who use our products. PSD2 also requires a new standard for authentication of transactions, which necessitates additional verification information from consumers to complete transactions. This may increase the number of transactions that consumers abandon if we are unable to ensure a frictionless authentication experience under the new standards.
Regulation of Internet, Digital Transactions and High-Risk Merchant Categories. Various jurisdictions have enacted or have proposed regulation related to internet transactions. The legislation applies to payments system participants, including us and our customers, and is implemented through a federal regulation. We may also be impacted by evolving laws surrounding gambling, including fantasy sports, as well as certain legally permissible but high-risk merchant categories, such as alcohol, tobacco, firearms and adult content.
Privacy, Data and Information Security. Aspects of our operations or business are subject to increasingly complex privacy and data protection laws in the United States, the European Union and elsewhere around the world. For example, in the United States, we and our customers are respectively subject to Federal Trade Commission and federal banking agency information safeguarding requirements under the Gramm-Leach-Bliley Act that require the maintenance of a written, comprehensive information security program. In the European Union, we are subject to the General Data Protection Regulation (the “GDPR”), which requires a comprehensive privacy and data protection program to protect the personal and sensitive data of EEA residents. A number of regulators and policymakers around the globe are using the GDPR as a reference to adopt new or updated privacy and data protection laws, including in the U.S. (California, Virginia and Colorado), Argentina, Brazil, Canada (Quebec), Chile, China, India, Indonesia, Kenya and Saudi Arabia. Due to increasing data collection and data flows, numerous data breaches and security incidents as well as the use of emerging technologies such as artificial intelligence, regulations in this area are constantly evolving with regulatory and legislative authorities in numerous parts of the world adopting proposals to regulate data and protect information. In addition, the interpretation and application of these privacy and data protection laws are often uncertain and in a state of flux, thus requiring constant monitoring for compliance.
Sustainability. Various jurisdictions are increasingly considering or adopting laws and regulations that would impact us pertaining to ESG performance, transparency and reporting. Regulations being considered include mandated corporate reporting on sustainability matters generally (such as the European Union Corporate Sustainability Reporting Directive) as well as in specific areas such as mandated reporting on climate-related financial disclosures.
Additional Regulatory Developments. Various regulatory agencies also continue to examine a wide variety of issues that could impact us, including evolving laws surrounding marijuana, prepaid payroll cards, virtual currencies, identity theft, account management guidelines, disclosure rules, security and marketing that would impact our customers directly.
22 MASTERCARD 2021 FORM 10-K
PART I
ITEM 1. BUSINESS
Additional Information
Mastercard Incorporated was incorporated as a Delaware corporation in May 2001. We conduct our business principally through our principal operating subsidiary, Mastercard International Incorporated, a Delaware non-stock (or membership) corporation that was formed in November 1966. For more information about our capital structure, including our Class A common stock (our voting stock) and Class B common stock (our non-voting stock), see Note 16 (Stockholders' Equity) to the consolidated financial statements included in Part II, Item 8.
Website and SEC Reports
Our internet address is www.mastercard.com. From time to time, we may use our corporate website as a channel of distribution of material company information. Financial and other material information is routinely posted and accessible on the investor relations section of our corporate website. You can also visit “Investor Alerts” in the investor relations section to enroll your email address to automatically receive email alerts and other information about Mastercard.
Our annual report on Form 10-K, quarterly reports on Form 10-Q, current reports on Form 8-K and amendments to those reports are available for review, without charge, on the investor relations section of our corporate website as soon as reasonably practicable after they are filed with, or furnished to, the U.S. Securities and Exchange Commission (the “SEC”). The information contained on our corporate website, including, but not limited to, our Sustainability Report, our Global Inclusion Report and our U.S. Consolidated EEO-1 Report, is not incorporated by reference into this Report. Our filings are also available electronically from the SEC at www.sec.gov.
Item 1A. Risk factors
RISK HIGHLIGHTS
Legal and Regulatory Business and Operations
Payments Industry Regulation COVID-19 Global Economic and Political Environment
Preferential or Protective Government Actions Competition and Technology Brand and Reputational Impact
Privacy, Data and Security Information Security and Service Disruptions Talent and Culture
Other Regulation Stakeholder Relationships Acquisitions
Litigation Settlement and Third-Party Obligations
Class A Common Stock and Governance Structure
Legal and Regulatory
Payments Industry Regulation
Global regulatory and legislative activity directly related to the payments industry may have a material adverse impact on our overall business and results of operations.
Regulators increasingly seek to regulate certain aspects of payments systems such as ours, or establish or expand their authority to do so. Many jurisdictions have enacted such regulations, establishing, and potentially further expanding, obligations or restrictions with respect to the types of products and services that we may offer, the countries in which our integrated products and services
MASTERCARD 2021 FORM 10-K 23
PART I