Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
Storing credit card info
Message
From
26/09/2013 14:52:38
Al Doman (Online)
M3 Enterprises Inc.
North Vancouver, British Columbia, Canada
 
 
To
26/09/2013 12:10:21
Mike Cole
Yellow Lab Technologies
Stanley, Iowa, United States
General information
Forum:
Business
Category:
Legal
Miscellaneous
Thread ID:
01584217
Message ID:
01584261
Views:
50
>>>>>I know, I know, avoid if at all possible and use something like Authorize.NET.
>>>>>
>>>>>I'm being asked to store CC info in our DBs to perform recurring billing. "We're compliant" has been said and I've been told to use our broken encryption libraries to encrypt it. I need some info to throw back. Links to laws (state of Iowa), etc.
>>>>
>>>>Details of requirements for compliance here I think : https://www.pcisecuritystandards.org/documents/pci_dss_v2.pdf
>>>>
>>>>But If they are not already storing this information how can they claim to be compliant ?
>>>
>>>They're already storing it other places (projects I wasn't involved with).
>>>
>>>Is PCI the law or a guideline? I understand it to be the law, no exceptions. Just wanted to verify
>>
>>I'm no expert but I believe it is a *requirement* of all major CC companies that any merchant.that 'accepts, transmits or stores any cardholder data' be PCI compliant. Level of compliance required depends on the number of transactions/pa made by the merchant.
>>
>>Saw this as well:
>>
>>"The payment brands may, at their discretion, fine an acquiring bank $5,000 to $100,000 per month for PCI compliance violations. The banks will most likely pass this fine on downstream till it eventually hits the merchant. "
>
>Thanks for the info. I'm quite distressed about this.

If you're a contractor (and maybe even if you're not) don't let them push any risk due to non-compliance onto you.
Regards. Al

"Violence is the last refuge of the incompetent." -- Isaac Asimov
"Never let your sense of morals prevent you from doing what is right." -- Isaac Asimov

Neither a despot, nor a doormat, be

Every app wants to be a database app when it grows up
Previous
Reply
Map
View

Click here to load this message in the networking platform