PCI DSS
Definition
The card industry's security rules for any business that takes cards.
Why It Matters
No statute creates it and no regulator enforces it. It reaches a business through the merchant agreement with whoever processes its cards, which is why it survives a change of owner exactly as far as that contract does and no further. What a buyer inherits is the gap: an old terminal, a point of sale system holding card numbers it should never have kept, a self assessment nobody has completed since the last owner did one. After a breach the card brands assess the processor and the processor charges the merchant, so a business with no compliance file has an open number sitting on it. Ask for the last attestation and who signed it.
In numbers: A restaurant taking 40% of its revenue on cards is inside the rules whatever its size, and the assessment after a breach lands on the merchant, never on the processor.