Skip to main content
Rules Mate

PCI DSS card data security (contractual, via your acquirer)

Merchants that accept card payments must protect cardholder data to PCI DSS — a requirement of the card schemes, enforced through your merchant agreement, not an Australian statute.

mediumcurrentannual

Who must comply

Merchants accepting card payments and service providers that store, process or transmit cardholder data — as a term of the merchant or scheme agreement.

What triggers it

Accepting card payments, or handling cardholder data for someone who does.

When due

Continuous; validation annually (SAQ or Report on Compliance), plus quarterly external vulnerability scans where your SAQ type requires them. Your acquirer sets the deadline.

Evidence required

Completed SAQ (correct type for your payment channel) or Report on Compliance; Attestation of Compliance; quarterly ASV scan reports where required; list of third-party payment service providers and their attestations; cardholder-data-flow diagram.

Max penalty

No statutory penalty — PCI DSS is contractual. Consequences come from the merchant agreement and card scheme rules (acquirer-imposed fees, higher charges or termination of card acceptance), plus Privacy Act exposure if card data is breached.

Summary

The Payment Card Industry Data Security Standard (PCI DSS) applies to every entity that stores, processes or transmits cardholder data or sensitive authentication data, or could affect the security of the cardholder data environment — merchants, processors, acquirers, issuers and service providers. It is NOT Australian law: the PCI Security Standards Council states that whether an entity must comply with or validate compliance is at the discretion of the organisations that manage compliance programs, such as a payment brand or acquirer. In practice your merchant agreement with your bank or payment provider requires it. How you validate depends on your level: Mastercard Level 1 merchants (over 6 million Mastercard/Maestro transactions a year) need an annual assessment; Level 2–4 merchants generally complete an annual Self-Assessment Questionnaire (SAQ), with Level 2 merchants on SAQ A, A-EP or D also engaging a QSA or ISA. Mastercard does not require Level 3 and 4 merchants to validate to it, but your acquirer can. Separately, card data you hold is personal information for APP 11 security purposes if you are an APP entity.

Topics

paymentspci-dsscybercontractual

Related

Frequently asked questions

Who must comply with PCI DSS card data security (contractual, via your acquirer)?
Merchants accepting card payments and service providers that store, process or transmit cardholder data — as a term of the merchant or scheme agreement.
What triggers PCI DSS card data security (contractual, via your acquirer)?
Accepting card payments, or handling cardholder data for someone who does.
When is PCI DSS card data security (contractual, via your acquirer) due?
Continuous; validation annually (SAQ or Report on Compliance), plus quarterly external vulnerability scans where your SAQ type requires them. Your acquirer sets the deadline.
What is the maximum penalty for PCI DSS card data security (contractual, via your acquirer)?
No statutory penalty — PCI DSS is contractual. Consequences come from the merchant agreement and card scheme rules (acquirer-imposed fees, higher charges or termination of card acceptance), plus Privacy Act exposure if card data is breached.
What evidence is required for PCI DSS card data security (contractual, via your acquirer)?
Completed SAQ (correct type for your payment channel) or Report on Compliance; Attestation of Compliance; quarterly ASV scan reports where required; list of third-party payment service providers and their attestations; cardholder-data-flow diagram.

Source: https://www.pcisecuritystandards.org/standards/pci-dss/. Rules Mate is not a law firm. Always verify against the live regulator source before acting.