PCI DSS Compliance
Your Responsibilities
The Payment Card Industry (PCI) launched the Data Security Standard (DSS) back in 2007 to protect merchants from the increasing risk of fraud.
PCI DSS is a combination of security policies, technology and network changes aimed at minimising fraud by reducing system exposure. The main issue addressed by PCI compliance is data storage, making it an offence to store both the credit card numbers and three-digit security codes on premises, which together can be used to make fraudulent transactions.
Mandatory Compliance
From 1st October 2010 every merchant in the UK will have to be compliant, but at present compliance is only mandatory for Level 1 & 2 merchants. These levels apply to the volume of transactions your business processes each year. Level 1 is more than £6 million, Level 2 £1-6 million, Level 3 20k – 1 million and Level 4 up to 20k.
If your business is in the lower levels then missing the October deadline will result in fines which could be in the region of £10,000, with Visa and Mastercard issuing ongoing fines on a monthly basis until compliance has been reached. In extreme cases merchants may even lose their merchant codes, effectively ended their ability to trade.
CCT recommends visiting the PCI SSC website for the latest updates and information when it comes to your responsibilities.