PCI DSS
Definition
The card industry's security rules for any business that takes cards.
Why It Matters
No statute creates it, though Nevada, for one, requires by law that a business there taking cards comply. Elsewhere it reaches a business through the merchant agreement with whoever processes its cards, which is why it survives a change of owner exactly as far as that contract does and no further. What a buyer inherits is the gap: an old terminal, a point of sale system holding card numbers it should never have kept, a self assessment nobody has completed since the last owner did one. After a breach the card brands assess the processor and the processor charges the merchant, so a business with no compliance file has an open number sitting on it. Ask for the last attestation and who signed it.
In numbers: A restaurant taking 40% of its revenue on cards is inside the rules whatever its size, and the card brands' assessment after a breach is levied on the processor, which passes it to the merchant.