Apply now

Guide · Singapore

PCI DSS: what a Singapore merchant actually has to do

PCI DSS is the card schemes’ rulebook for handling cardholder data, and how much of it lands on you turns on one question: does card data ever touch systems you control? A shop using a supplied terminal and a website using a hosted checkout page carry far less of it than a business that captures card numbers itself — and most merchants are in the first group without realising it is a choice.

In short

  • It is a card scheme standard, not Singapore law. Your obligation reaches you through your acquirer contract.
  • The question that decides your scope: does card data touch your systems?
  • Supplied terminal + hosted checkout = the smallest scope available. Most merchants qualify.
  • The fastest way to increase your obligation is to start storing card numbers. Do not.
  • Compliance is evidenced by a self-assessment questionnaire for most merchants, not an audit.

What it is, and where the obligation comes from

PCI DSS — the Payment Card Industry Data Security Standard — is written by the card schemes, not by a government. In Singapore it is not a statute and MAS does not enforce it; the obligation reaches a merchant through the contract with their acquirer, which is itself bound by the scheme rules.

That distinction matters practically rather than legally. Nobody from a regulator is going to inspect your shop for PCI. What can happen is that a card scheme holds your acquirer responsible, and your acquirer holds you to what you agreed — which becomes real the day something goes wrong.

Singapore’s Personal Data Protection Act is a separate obligation and a real one. It covers personal data generally rather than card data specifically, and satisfying one does not satisfy the other.

The one question that sets your scope

Does cardholder data ever exist inside a system you control? Not "do you take cards" — every merchant does — but does the number pass through, or rest on, your hardware, your software or your paperwork.

Where most Singapore merchants actually sit
SetupDoes card data touch you?Practical scope
Supplied terminal at the counterNo — the terminal is the acquirer’s scopeSmallest
Hosted checkout page for the websiteNo — the customer types into the provider’s pageSmallest
SDK inside your own app, provider-hosted fieldsGenerally noSmall
Your own checkout form capturing the card numberYesSubstantially larger
Taking card numbers by phone, email or on paperYes, and worst of allLargest — avoid entirely

The last row is the one worth acting on today. A card number written on a booking form, left in an email inbox or read out over the phone and noted down puts a merchant into the largest obligation there is, for the sake of a convenience that a payment link solves.

What compliance actually looks like for a small merchant

For most merchants it is a self-assessment questionnaire — an SAQ — rather than an external audit. Which SAQ applies depends on the setup, and the ones covering merchants who never touch card data are dramatically shorter than the ones covering merchants who do.

Alongside it there are practices that are neither expensive nor technical, and that do most of the work:

  1. Never write down, photograph or email a card number. There is no situation where this is the only option.
  2. Change default passwords on anything that touches payments, including the router and the terminal.
  3. Keep the terminal’s software updated — the provider pushes these; do not defer them indefinitely.
  4. Restrict who can use the terminal’s administrative functions, and remove leavers.
  5. Use a hosted checkout rather than building your own card form, unless you have a specific reason and someone to own it.
  6. Ask your provider which SAQ applies to your setup, and keep the completed one.

A merchant doing those six things is in a materially different position from one who is not, regardless of paperwork.

What your provider carries, and what stays with you

The terminal, the gateway and the hosted checkout page are the provider’s scope. On a supplied smart terminal — Uniweb Pay’s is a Sunmi P3 — the card is read by a device the acquirer is responsible for, and the merchant never handles the number.

What stays with the merchant is everything around it: who has access to the device, what happens on your own network, whether staff are writing anything down, and whether a leaver still has a login. No provider can carry those for you, and they are where small merchants actually get into trouble.

Ask any provider directly: which SAQ applies to the setup you are proposing, and what changes if I add an online channel later. A provider who cannot answer the first question quickly is telling you something.

Where wallets and QR sit

Alipay+, WeChat Pay, UnionPay QR and Dynamic PayNow do not involve a card number reaching the merchant at all — the customer authorises inside their own app, or scans a code the terminal generated. From a data-handling point of view they are the simplest methods on the counter.

That is not a reason to prefer them over cards, since which one a customer uses is the customer’s choice. It is a reason not to assume that adding wallet acceptance adds obligation — usually it does not.

Apple Pay and Google Pay present a card over contactless, so they sit with the cards rather than with the wallets — but again on a supplied terminal the number does not reach the merchant. The Apple Pay and Google Pay page explains why they are not a separate enablement.

Questions merchants ask

Is PCI DSS a legal requirement in Singapore?

It is not Singapore law and MAS does not enforce it. It is a card scheme standard, and the obligation reaches a merchant through the contract with their acquirer. Singapore’s Personal Data Protection Act is a separate and genuinely legal obligation.

What decides how much PCI DSS applies to me?

Whether cardholder data ever touches systems you control. A supplied terminal and a hosted checkout page keep it out of your systems entirely, which is the smallest scope available.

Can I take a card number over the phone?

It puts you into the largest obligation there is, and it is the single most common avoidable mistake. Send a payment link instead.

Do I need an external audit?

Most merchants complete a self-assessment questionnaire rather than an external audit. Which one applies depends on the setup — ask your provider directly, and keep the completed questionnaire.

Do QR wallets add to my PCI obligation?

Generally not. Alipay+, WeChat Pay, UnionPay QR and Dynamic PayNow do not involve a card number reaching the merchant at all.

Talk to us about your counter

Uniweb Pay is a Singapore merchant acquirer, licensed by MAS as a Major Payment Institution (No. PS20200612). Tell us what you sell and who pays you, and we will tell you whether we are the right fit — including when we are not.

Published: 2026-08-03 · Last updated: 2026-08-03

Written by the Uniweb Pay team, Singapore. Licence details are checked against the MAS Financial Institutions Directory, which is the authoritative source — where anything here disagrees with the register, the register wins.