infocom:
Also, are there any definite guidlines/rules on this anywhere online I can send my client to? I cant seem to find anything that clearly states "you need to delete cvv numbers after processing" or "you must not store cc details unencrypted". That sort of thing. The websites I have found are quite vague and the ones I have found that state this are forums and just people saying it with no legal link from the cc companies to back it up.
So for example this site does not state either of the above:-
https://www.pcisecuritystandards.org/tech/index.htm
It states "Protect stored cardholder data" which I find a bit vague. Nothing about deleting cvv numers after processing.
Thanks
There are 2 things in play,
In the USA, legally you must follow PCI standards, it is illegal not to... the PDF you linked to says more than "you cant store cvv" it is the full security standard that says what can and cant be stores, and how it must be stored
a brief over view is
a> All customer data must be encrypted
b> All Access to Customer Data must be tracked per user
c> there are many hosting requirements, be sure to check with your host to see if the plan your client has meets PCI standards as well
While it may not be illegal in the UK, I can ensure you that your client will violate his merchant agreement if he does not follow PCI, every major card company required PCI compliance of their merchants, failure to meet PCi can result in the merchant account being suspended, and if it is suspended for security reason no other company will give your client a new account...
Plus storing card data can open you up to extreme civil liability, at least here in the USA, Just ask TJ MAxx