Payment Card Industry Data Security Standard
PCI DSS · The security standard created by the card brands that every organisation storing, processing or transmitting card data must follow.
- 01
Why it matters
Leaking card data has serious consequences for both customers and the business; non-compliance can lead to fines and losing the ability to take payments. The compliance burden depends on how much card data touches your systems. Leaving payment to the payment provider's secure page narrows the scope considerably.
- 02
Example
Instead of taking card details in its own form and passing them on, a shop uses the payment page hosted by its payment provider. Because card data never enters the shop's servers, the annual compliance assessment becomes much simpler.
- 03
Common mistake
Keeping card numbers in order notes, e-mails or customer service records. Wherever card data is kept, that system falls within the standard's scope.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.