Home › Forums › General Trade Forum › PCI DSS
- This topic has 7 replies, 5 voices, and was last updated 18 years, 11 months ago by
Goatboy.
-
AuthorPosts
-
May 17, 2007 at 12:57 pm #27421
Goatboy
ParticipantWe recieved a letter from Barclaycard business about a week ago, saying that anyone that takes peoples c-card/d-card details, has to comply with new rules aiming to tighten card data.
If you’ve had one of these letters, then you’ll know what I’m talking about! To cut a long letter short it said…
1/ You can do a self-assesment, which is very hard
2/ You can let us do it, for £75 a year
3/ You can do nothing and be fined £100,000This displeased Goatboy 👿 And he has been doing something about it. I looked at the self-assesment, and it is extremely complicated! So, it looks like the only option, is to pay £75 a year for someone to do it for you, unless…
After many phone-calls, there is hope for business’ that don’t take payments over the internet. This review is mainly for data storage, and how safe customers details are stored on your computers. For a business like ours (somebody that just has a terminal in our shop) you can get a vastly-condensed (15 questions) version of the self-assesment questionaire, for £12.
Ring: 02079 938030
I know that sounds like alot of waffle and b*ll*cks, but if you got the letter, you know what I mean, and if your not trading over the interent, this seems like the best option for you! 8)
February 12, 2010 at 1:39 pm #213961Martin
ParticipantRe: PCI DSS
Goatboy wrote:Ring: 02079 938030
I know that sounds like alot of waffle and b*ll*cks, but if you got the letter, you know what I mean, and if your not trading over the interent, this seems like the best option for you! 8)
I was reminded of this thread whilst searching for PCI DSS. The subject came up once again in this thread and I would like to take this opportunity (rather belatedly :oops:) to thank Goatboy. I in fact rang that number he gave and a very nice gentleman asked a few simple questions whilst talking me through the on-line registration. The whole procedure took no more than 10 mins for me to be PCI DSS compliant (self assessment processed) and was registered there and then for a full year for just £11.99.
So if anyone of you guys like me carries a mobile credit card terminal into your customers home and/or processes payment (from landlords for example) over the phone and through that same mobile terminal? Then registering to be PCI DSS compliant is a piece of cake!
The trouble is that if you process credit/debit cards and DON’T REGISTER as being PCI DSS compliant then you can get in deep doodoo the longer you put it off. Now the authorities know full well you process payments in this way because your merchant service provider has an obligation to inform them of all their clients. But your merchant service provider cannot take responsibility toward you and the security systems your company should implement, that’s your job.
If you ring that number above they will put you on track and you’re in the clear from then on…..go for it! 😀
February 12, 2010 at 1:43 pm #213962eastlmark
ModeratorRe: PCI DSS
slight change in atitiude then Martin, your words in 2007 I believe:
Martin wrote:TBH Mark I’m with stratfordgirl on this in that it hardly applies to small independant companies the likes of us in this game, yourself included. I’ve not registered, I’m small fry in the grand scheme of things. I keep my head down too in avoiding these 3rd party money grabbing agents wanting registration fees for filling out reams of data they have no bl**dy business in having in the first place.:evil:
Sod ’em and if they stump me up a further 0.1{e5d1b7155a01ef1f3b9c9968eaba33524ee81600d00d4be2b4d93ac2e58cec2d} for non-compliance then I’ll still be able to sleep at night with a clear conscience.
COME THE REVOLUTION BROTHERS!!!!!
February 12, 2010 at 2:35 pm #213963Martin
ParticipantRe: PCI DSS
I’m so so grateful you brought that up Mark.
Shortly after I made that bold and radical statement, you so effectively highlighted, my accountant pointed out the error of my ways and I registered forthwith. What a shame I forgot to rescind it meanwhile on UKW eh? So today that fact comes back and bites my bum…..please forgive my human frailties and do please accept my apology for the sudden unexpected change of heart. 😳
February 12, 2010 at 7:27 pm #213964funkyboogy
ParticipantRe: PCI DSS
does anyone know if this rule applys if you use paypal for payments cheers ally
February 13, 2010 at 8:11 am #213965eastlmark
ModeratorRe: PCI DSS
funkyboogy wrote:does anyone know if this rule applys if you use paypal for payments cheers ally
no, Its PayPal’s job to have the compliance.
February 13, 2010 at 8:32 am #213966funkyboogy
ParticipantRe: PCI DSS
cheers ,
thought that was the case..i would pay-pal is the easiest way to process payments then, as you are directing customers to a secure online transaction between them and pay-pal..
just setup a paypal account , login and click request payment , this open ascreen where you are askes to enter customers email , the amount req,d and a box for any message you want to send with request..
when cust receives email , they click on link and that takes them to pay-pal ….wery easy transaction, i suppose the trick is the timing ..you need to make sure pay-pal been paid before you arrive , or if you have a phone with www access then you can process it at customers property …
ally
February 15, 2010 at 6:31 pm #213967squadman
ParticipantRe: PCI DSS
In the case of Barclays Merchant Services they make it relatively easy for you to become compliant, their partners a company by the name of Security Metrics charge £ 11.99 for enrolment into the scheme and you complete a online form in the process, doing this makes it easy as well as saving you monthly fees imposed by B.M.S and in the case of businesses who do not trade via the net and have only a fixed or mobile terminal its really all about keeping the card data secure, obvioulsy if you keep the data in a digital domain you require suitable measures to keep safe as you become responsible for any errors or fraud as a result .
Other than this its straight forward.
-
AuthorPosts
- You must be logged in to reply to this topic.
