Updated Data-Security Standards for Credit-Card Transactions


New security standards are scheduled to be released by the PCI Security Standards Council on November 7th. The updated standards are expected to require companies to protect credit-card terminals from physical tampering and compile an inventory of system components (e.g., servers) that comply with the standards. Companies will also be required to evaluate evolving malware threats. Those that fail to comply could face fines and forced disclosure to consumers in the case of a data breach.

Small companies with few credit-card transactions can avoid many of the costs associated with becoming PCI compliant by performing a self-assessment. If you accept credit cards and never performed a self-assessment, it is something to look into doing because if you are found to be PCI non-compliant, an on-site compliance audit can cost $50,000 to $1.5 million.


Written by:

Published In:


DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Winthrop & Weinstine, P.A. | Attorney Advertising

Don't miss a thing! Build a custom news brief:

Read fresh new writing on compliance, cybersecurity, Dodd-Frank, whistleblowers, social media, hiring & firing, patent reform, the NLRB, Obamacare, the SEC…

…or whatever matters the most to you. Follow authors, firms, and topics on JD Supra.

Create your news brief now - it's free and easy »

All the intelligence you need, in one easy email:

Great! Your first step to building an email digest of JD Supra authors and topics. Log in with LinkedIn so we can start sending your digest...

Sign up for your custom alerts now, using LinkedIn ›

* With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name.