Skip to content

PCI DSS

Definition

The card industry's security rules for any business that takes cards.

Why It Matters

No statute creates it and no regulator enforces it. It reaches a business through the merchant agreement with whoever processes its cards, which is why it survives a change of owner exactly as far as that contract does and no further. What a buyer inherits is the gap: an old terminal, a point of sale system holding card numbers it should never have kept, a self assessment nobody has completed since the last owner did one. After a breach the card brands assess the processor and the processor charges the merchant, so a business with no compliance file has an open number sitting on it. Ask for the last attestation and who signed it.

In numbers: A restaurant taking 40% of its revenue on cards is inside the rules whatever its size, and the assessment after a breach lands on the merchant, never on the processor.

Where to Go Next