Compliance
PCI DSS
Payment Card Industry Data Security Standard — a set of security requirements for organisations that handle credit card data.
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.
Key Requirements
PCI DSS includes 12 high-level requirements grouped into 6 goals:
- Build and maintain a secure network (firewalls, no vendor defaults)
- Protect cardholder data (encryption, tokenization)
- Maintain a vulnerability management program
- Implement strong access control measures
- Regularly monitor and test networks
- Maintain an information security policy
Compliance Levels
| Level | Criteria |
|---|---|
| Level 1 | >6 million transactions/year |
| Level 2 | 1–6 million transactions/year |
| Level 3 | 20,000–1 million transactions/year |
| Level 4 | <20,000 transactions/year |
Relationship to GDPR
PCI DSS and GDPR are complementary — PCI DSS focuses on payment card security, while GDPR covers all personal data. Both require appropriate security measures.