PCI Compliance - some guidance

L

LMDServicesUK

Fellow users

Now I have been active for a while, I have noticed a trend with regards to the subject of PCI Compliance which is an issue that affects any Merchant that HANDLES card holder data (even just the card itself).

This affects people who use systems such as iZettle, Intuit or any other system where you use either a reading device or enter a card holders details into your phone/tablet/PC..

Two points are very important re PCI Compliance, specifically this scheme is operated on behalf of the major card schemes MasterCard, Visa, Am Ex, JCB & Diners, it is only operated by the Merchant acquirers on their behalf, so whilst the ISO/Provider should tell you about it, it is YOUR responsibility to ensure you register using the Self Assessment Questionnaire provided by the various acquirers get your certification registered. It then has to be renewed every year.

The management fees will vary between the various providers, but if you do not get your certification sorted out within the first three months you will incur non registration fees that start at £ 10 a month and can rise to £ 50 a month for non compliance.

Hopefully this will de-mystify this area a little for most SME businesses. It is quite straight forward to get PCI compliance, and I will always help any Merchant that signs up with us (for merchant services) with the process, and ensure they are compliant as part of our service at no charge.

Finally remember why this was introduced, to reduce card fraud and it is working very well, and is demonstrably reducing card fraud, which is good for all businesses, so whilst a pain it is doing what it set out to do e.g. protect cardholder data and ensure that Merchants treat it correctly.

I would welcome any feedback..

Hope this is of use to all my fellow UK forum members and visitors.

Kind regards

Mark
 
  • Like
Reactions: CAEDAN

EDRIAT

Free Member
Oct 3, 2011
101
24
PCI Compliance or more specifically the Self Assessment Questionnaire is a well intentioned joke.

We're effectively a two-man band... The questionnaire asks questions more befitting of a huge corporation... We choose to pay the per-transaction non-compliance fees imposed by Barclays rather than spend weeks creating unnecessary documented 'policies' for every single aspect of our business.

I once challenged the PCI Compliance company contracted by Barclays as to the relevance of the various questions and the 'Policies/Procedures' they demand we have in place (some of which I don't remotely comprehend) in order to be compliant and was told to answer the questions hypothetically on the basis that the policies/procedures were documented and not bother actually documenting them... Kinda makes the whole exercise a little pointless!

I agree with the sentiment of PCI Compliance but the demands it places on a small business just to comprehend the terminology used in the SAQ let alone the documentation it expects you to produce, is frankly, rediculous.
 
  • Like
Reactions: TheGeekestLink
Upvote 0

Latest Articles

Join UK Business Forums for free business advice