PCI DSS card data security (contractual, via your acquirer)
Merchants that accept card payments must protect cardholder data to PCI DSS — a requirement of the card schemes, enforced through your merchant agreement, not an Australian statute.
Who must comply
Merchants accepting card payments and service providers that store, process or transmit cardholder data — as a term of the merchant or scheme agreement.
What triggers it
Accepting card payments, or handling cardholder data for someone who does.
When due
Continuous; validation annually (SAQ or Report on Compliance), plus quarterly external vulnerability scans where your SAQ type requires them. Your acquirer sets the deadline.
Evidence required
Completed SAQ (correct type for your payment channel) or Report on Compliance; Attestation of Compliance; quarterly ASV scan reports where required; list of third-party payment service providers and their attestations; cardholder-data-flow diagram.
Max penalty
No statutory penalty — PCI DSS is contractual. Consequences come from the merchant agreement and card scheme rules (acquirer-imposed fees, higher charges or termination of card acceptance), plus Privacy Act exposure if card data is breached.
Summary
The Payment Card Industry Data Security Standard (PCI DSS) applies to every entity that stores, processes or transmits cardholder data or sensitive authentication data, or could affect the security of the cardholder data environment — merchants, processors, acquirers, issuers and service providers. It is NOT Australian law: the PCI Security Standards Council states that whether an entity must comply with or validate compliance is at the discretion of the organisations that manage compliance programs, such as a payment brand or acquirer. In practice your merchant agreement with your bank or payment provider requires it. How you validate depends on your level: Mastercard Level 1 merchants (over 6 million Mastercard/Maestro transactions a year) need an annual assessment; Level 2–4 merchants generally complete an annual Self-Assessment Questionnaire (SAQ), with Level 2 merchants on SAQ A, A-EP or D also engaging a QSA or ISA. Mastercard does not require Level 3 and 4 merchants to validate to it, but your acquirer can. Separately, card data you hold is personal information for APP 11 security purposes if you are an APP entity.
Topics
Related
- CWLTHNotifiable Data Breach (NDB) schemeUnder the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- CWLTHPublish a Privacy Policy that meets APP 1Every APP entity needs a clearly-expressed Privacy Policy covering APP 1.4 requirements.
- CWLTHReport cyber security incidents to ASD (SOCI)Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
- CWLTHAdopt Essential Eight Maturity Level 2 (federal subcontractors)Federal government contractors handling OFFICIAL: Sensitive must meet Right Fit For Risk (RFFR) including E8 ML2.
- CWLTHComply with APRA CPS 234 (Information Security)APRA-regulated entities must maintain information security capability commensurate with the size and extent of threats.
- CWLTHComply with SOCI Positive Security Obligation (PSO) per sectorSector-specific cyber + risk obligations under SOCI Part 2.
Reading
Frequently asked questions
- Who must comply with PCI DSS card data security (contractual, via your acquirer)?
- Merchants accepting card payments and service providers that store, process or transmit cardholder data — as a term of the merchant or scheme agreement.
- What triggers PCI DSS card data security (contractual, via your acquirer)?
- Accepting card payments, or handling cardholder data for someone who does.
- When is PCI DSS card data security (contractual, via your acquirer) due?
- Continuous; validation annually (SAQ or Report on Compliance), plus quarterly external vulnerability scans where your SAQ type requires them. Your acquirer sets the deadline.
- What is the maximum penalty for PCI DSS card data security (contractual, via your acquirer)?
- No statutory penalty — PCI DSS is contractual. Consequences come from the merchant agreement and card scheme rules (acquirer-imposed fees, higher charges or termination of card acceptance), plus Privacy Act exposure if card data is breached.
- What evidence is required for PCI DSS card data security (contractual, via your acquirer)?
- Completed SAQ (correct type for your payment channel) or Report on Compliance; Attestation of Compliance; quarterly ASV scan reports where required; list of third-party payment service providers and their attestations; cardholder-data-flow diagram.
Source: https://www.pcisecuritystandards.org/standards/pci-dss/. Rules Mate is not a law firm. Always verify against the live regulator source before acting.