11 September 2024
If your business takes card payments, either in person or online, then it will have to meet the Payment Card Industry Data Security Standard, also known as PCI DSS.
These are a set industry-wide requirements to protect you and your customers when taking payments. Even if you outsource your payment system to a third-party payment supplier, such as Stripe, you still need to follow the security protocols to be PCI DSS compliant.
Strident has extensive experience in providing both the IT technical expertise in maintaining a secure system but also writing compliance processes and policies to ensure your business meets the Payment Card Industry Data Security Standard.
The standard is an agreement between the major card payment businesses, such as Mastercard and Visa, and is operated Payment Card Industry Security Standards Council. The latest version of the PCI DSS (Version 4) was released at the end of March 2022.
All merchants and payment supplier that process, transmit or store cardholder data must comply with the PCI DSS.
Although not a legal requirement yet, if your business does not meet the standard, you could be fined. The Security Standards Council will fine your bank for a security/data breach and if your business is not PCI DSS compliant, your bank provider could pass these fines onto your business.
In addition, your business may be breaching the Data Protection Act 2018 if payment card data is breached. This could be subject to enforcement action from the Information Commissioners Office (ICO).
There are twelve steps PCI DSS requirements. The include technical actions as well as on-going policies to maintain security.
We understand that not all businesses are the same, and the processes that need to be put in place are quite different if you are a small business accepting card payments for services or a large multi-site retailer.
Strident has both the IT technical and compliance expertise to ensure you can meet the Payment Card Industry Data Security Standard. Working with our Compliance team, we can help your organisation meet, maintain and prove to customers and suppliers that you meet this standard.
To discuss PCI DSS Compliance or our Data Protection services for your business, please get in touch.