Skip to content

PCI DSS

Definition

The card industry's security rules for any business that takes cards.

Why It Matters

No statute creates it, though Nevada, for one, requires by law that a business there taking cards comply. Elsewhere it reaches a business through the merchant agreement with whoever processes its cards, which is why it survives a change of owner exactly as far as that contract does and no further. What a buyer inherits is the gap: an old terminal, a point of sale system holding card numbers it should never have kept, a self assessment nobody has completed since the last owner did one. After a breach the card brands assess the processor and the processor charges the merchant, so a business with no compliance file has an open number sitting on it. Ask for the last attestation and who signed it.

In numbers: A restaurant taking 40% of its revenue on cards is inside the rules whatever its size, and the card brands' assessment after a breach is levied on the processor, which passes it to the merchant.

Where to Go Next