3 ms·
This is second-hand information but I have reasonable confidence in it: PCI-DSS (payment card companies) requirements forbid the slabs' use anymore. You instan
by Multicomp 9y ago
This is second-hand information but I have reasonable confidence in it:
PCI-DSS (payment card companies) requirements forbid the slabs' use anymore. You instantly fail your payment card audit if you have one on site, and that can cause you to assume liability for all subsequent customer fraud incidents for the next X months, and in bad cases massive fines and possibly losing your payment processing equipment licenses (the ability to take EFT cards of all types)
It's not considered secure storage of cardholder data, just as bad as if someone wrote down the cardholder information in full.
Interestingly enough, mail-order magazines still try to get you to write down your CC data directly. I wonder if that is sanctioned?