PCI DSS
The Payment Card Industry Data Security Standard — the card schemes’ rules for handling cardholder data. What a merchant has to do under it depends mostly on whether card data ever touches their own systems: a shop using a supplied terminal, or a website using a hosted checkout page, carries far less of it than one that captures card numbers itself.
Why it matters to a merchant
The standard is far smaller for most merchants than the name suggests, and the reason is scope: what applies depends on how much cardholder data the merchant touches. A shop taking payment on a terminal it does not own, and never storing a card number, is in a different world from one storing card data in its own system. Establishing which one you are is the first step and it usually shortens the list.
Where this comes up
Pages on this site that deal with this in context:
Related terms
In this section: Licensing and regulation in Singapore
- MAS (Monetary Authority of Singapore)
- Payment Services Act 2019
- MPI (Major Payment Institution)
- SPI (Standard Payment Institution)
- MAS Financial Institutions Directory
- KYC / KYB
- Beneficial owner
- Merchant Acquisition (licensed activity)
- UEN (Unique Entity Number)
- ACRA
- PDPA (Personal Data Protection Act)
- AML / CFT