5 ms·
Cardholders name is PCI data. So in most cases the customer?s name and the cardholders name would fall under the auspices of PCIDSS. This is definitely a breach
by pchap10k 13y ago
Cardholders name is PCI data. So in most cases the customer?s name and the cardholders name would fall under the auspices of PCIDSS. This is definitely a breach.
- jarito 13y agoCorrect. From the DSS, 'Cardholder data includes: Primary Account Number (PAN), Cardholder Name, Expiration Date, Service Code'
- wmboy 13y agoThis is not true, I used to work in the industry and you can use a hosted credit card solution (where you transfer customers to a secure payment page) without needing PCI compliance. If it were correct, and the card holder name needed to be secure, the company I worked at would not have received level 1 PCI compliance. The solution sends back the truncated card number, expiry date and the full card holder name. Of course I'm assuming the banks wouldn't want you to make that data public, but you are allowed to store it without needing to be PCI compliant. CVV code is another matter, under no circumstances are you allowed to store it, unless you're a level 1 compliant payment processor.
- nexfina 13y agoPhew! At least we can all take comfort in the fact that ClickBank is a Level 1 compliant payment processor. http://www.clickbank.com/press/clickbank-achieves-level-1-payment-card-industry-pci-compliance-certification/ http://www.clickbank.com/press/clickbank-achieves-level-1-pa...