PCI Compliance - Data Security and Your Business
Your customers want assurance that their credit card account information is safe. But offering your customers a secure way to pay is more than just a good business practice—it’s a requirement. Every merchant who touches credit card account information is responsible for safeguarding that information and can be held liable for security compromises if they have not taken the required precautions.
The Payment Card Industry (PCI) Data Security Council—an organization founded by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa, Inc. provides a comprehensive guide to meeting compliance requirements.
Cynergy Data is a recognized provider of compliant merchant services.
See our listing on page 7 of Visa's list of PCI-compliant providers.
Merchants must currently meet all PCI Data Security Standard (PCI DSS) requirements
Merchants must meet all PCI DSS requirements and use PCI compliant processing equipment. Failure to meet PCI compliance regulations will result in fines and possibly the inability to accept card-based payments.
Important facts
- Merchants who don’t comply with the PCI Data Security Standard may face fines from the credit card companies. Additionally, the credit card companies have reserved the right to terminate credit card acceptance privileges for merchants who don’t comply with the PCI Data Security Standard.
- Following the PCI Data Security Standard helps protects you and your customers from hacking and other fraudulent credit card activities.
PIN Entry Devices (PED)
The PCI PED Security Requirements focus on protection of the cardholder's PIN when used in connection with a financial transaction. To gain approval by the PCI Security Standards Council, PIN entry devices must comply with the requirements and guidelines specified by the Council.
More information about PCI PED and a listing of PCI Security Standards Council approved PIN entry devices is available online at
https://www.pcisecuritystandards.org/security_standards/ped/index.shtml.
Payment Application Data Security Standard (PA-DSS)
PA-DSS is the Council-managed program formerly under the supervision of the Visa Inc. program known as the Payment Application Best Practices (PABP). The goal of PA-DSS is to help software vendors and others develop secure payment applications that do not store prohibited data, such as full magnetic stripe, CVV2 or PIN data, and ensure their payment applications support compliance with PCI DSS. More information about PA-DSS is available online at
https://www.pcisecuritystandards.org/security_standards/pa_dss.shtml.
Learn more about PCI compliance
The PCI Data Security Standards Council offers comprehensive guidelines. For information from the Council, you can write, call, or visit the website:
401 Edgewater Place
Suite 600
Wakefield, MA USA 01880
https://www.pcisecuritystandards.orgTelephone: (781) 876-8855