Standard Terminals
Wireless Terminals
All-In-One POS System
Pin Pads
Printers
MICR Readers
Cash Register Machines
ATM Machines
Other Supplies & Accessories
Credit Card Acceptance
Communication-Virtual Office
90 Days Same As Cash
Gift & Loyalty Card Programs
Cash Advance Programs
Check Acceptance Options
Medical & Dental Benefits Processing
EBT Card Program
Website Solutions
Credit Rehab Assistance
Free Monthly Newsletters
Part-Time
Full-Time
Recurring Revenue
Join Our Affiliate Program
Join Our Trusted Partnership Program
Home >> Industry Updates
Industry Updates
Several businesses have been fined in the last few months due to not complying with PCI DSS. This is in reference to the full
credit card number being printed on the cardholder's copy of the receipt. Please remember it is the business owner's
responsibility to ensure that all mandatory security issues are complied with. See below:
PAN - Primary Account Number is the payment card number (credit or debit) that identifies the issuer and the particular cardholder account. Also called Account Number
PCI DSS requirement 3.3 states "Mask PAN when displayed (the first six and last four digits are the maximum number of digits to be displayed)." See also the note under PCI DSS requirement 3.3 - "This requirement does not apply to employees and other parties with a legitimate business need to see the full PAN. This requirement does not supersede stricter requirements in place for displays of cardholder data (for example, for point-of-sale (POS) receipts)." Since this requirement covers all displays of PAN, including those on paper reports, computer screens, and receipts, the maximum digits allowed may be more than are specified in existing regulations (see FACTA below). Please note, however, that PCI DSS does not override any other laws that legislate what can be printed on receipts (such as the U.S. Fair and Accurate Credit Transactions Act (FACTA) or any other applicable laws). Also note that any paper receipts stored by merchants for legitimate business reasons and which contain the full PAN must adhere to the PCI DSS, especially requirement 9 regarding physical security.
PAN - Primary Account Number is the payment card number (credit or debit) that identifies the issuer and the particular cardholder account. Also called Account Number
PCI DSS requirement 3.3 states "Mask PAN when displayed (the first six and last four digits are the maximum number of digits to be displayed)." See also the note under PCI DSS requirement 3.3 - "This requirement does not apply to employees and other parties with a legitimate business need to see the full PAN. This requirement does not supersede stricter requirements in place for displays of cardholder data (for example, for point-of-sale (POS) receipts)." Since this requirement covers all displays of PAN, including those on paper reports, computer screens, and receipts, the maximum digits allowed may be more than are specified in existing regulations (see FACTA below). Please note, however, that PCI DSS does not override any other laws that legislate what can be printed on receipts (such as the U.S. Fair and Accurate Credit Transactions Act (FACTA) or any other applicable laws). Also note that any paper receipts stored by merchants for legitimate business reasons and which contain the full PAN must adhere to the PCI DSS, especially requirement 9 regarding physical security.
As the July 1, 2010, deadline approaches for mandatory Payment Application Data Security Standard-compliance, countless merchants
may require new equipment and processors. Please review some of the frequently asked questions:
Does PCI DSS apply to merchants who use payment gateways to process transactions on their behalf, and thus never store, process or transmit cardholder data?
PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed, or transmitted. If PAN is not stored, processed, or transmitted, PCI DSS requirements do not apply. However, under PCI DSS requirement 12.8, if the merchant shares cardholder data with a third party processor or service provider, the merchant must ensure that there is an agreement with that third party processor/service provider that includes their acknowledgement that the third party processor/service provider is responsible for the security of the cardholder data it possesses. In lieu of a direct agreement, the merchant must obtain evidence of the third-party processor/service provider's compliance with PCI DSS via other means, such as via a letter of attestation.
What is the Payment Card Industry (PCI) Data Security Standard (DSS)?
The PCI Data Security Standard represents a common set of industry tools and measurements to help ensure the safe handling of sensitive information. Initially created by aligning Visa's Account Information Security (AIS)/Cardholder Information Security (CISP) programs with MasterCard's Site Data Protection (SDP) program, the standard provides an actionable framework for developing a robust account data security process - including preventing, detecting and reacting to security incidents. The updated version, version 1.1, developed by the founding members of the PCI Security Standards Council, became effective with the launch of the PCI Security Standards Council.
Does PCI DSS apply to merchants who use payment gateways to process transactions on their behalf, and thus never store, process or transmit cardholder data?
PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed, or transmitted. If PAN is not stored, processed, or transmitted, PCI DSS requirements do not apply. However, under PCI DSS requirement 12.8, if the merchant shares cardholder data with a third party processor or service provider, the merchant must ensure that there is an agreement with that third party processor/service provider that includes their acknowledgement that the third party processor/service provider is responsible for the security of the cardholder data it possesses. In lieu of a direct agreement, the merchant must obtain evidence of the third-party processor/service provider's compliance with PCI DSS via other means, such as via a letter of attestation.
What is the Payment Card Industry (PCI) Data Security Standard (DSS)?
The PCI Data Security Standard represents a common set of industry tools and measurements to help ensure the safe handling of sensitive information. Initially created by aligning Visa's Account Information Security (AIS)/Cardholder Information Security (CISP) programs with MasterCard's Site Data Protection (SDP) program, the standard provides an actionable framework for developing a robust account data security process - including preventing, detecting and reacting to security incidents. The updated version, version 1.1, developed by the founding members of the PCI Security Standards Council, became effective with the launch of the PCI Security Standards Council.
Visa and MasterCard will be increasing several Interchange categories. Normally rate change notifications will be included in
the monthly statement the month before the increase. These increases will be effect as of April 2007. Please check back later
for specifics.
The Debit Network Acquirer ACCEL has announced several Interchange fee increases. These increases will affect
the Retail, Supermarket, Wholesale Club and QSR (Quick Service Restaurant) categories. These changes will be in effect as of
February 2007.
The staff and I have recently updated and revised our "Dictionary" of terms you will need to understand when dealing with
merchant services. Click to view the Dictionary.
Visa and MasterCard announced some Interchange category increases and have added several Interchange categories. These will
be in effect as of April 2006
Click here to read recent industry updates.
Click Here to look through the newsletter archives.
E-mail us here with any questions or concerns, or fill out our online contact form.
It is our sincere hope that you take the time to review the definitions contained in our Dictionary of Merchant Service terms.
I wish you all the best in your endeavor to learn and understand more about merchant services.
WARNING:
The Dictionary is copywrited material. Please review the Copyright section on page 2.
SUGGESTION:
I highly suggest you use the Bookmarks tab to easily scroll through the terms as they are in alphabetical order.
NOTE:
To read our Dictionary you will need to have Adobe Reader. If you do not, please select the link below and follow the directions to download the "free" version.
WARNING:
The Dictionary is copywrited material. Please review the Copyright section on page 2.
SUGGESTION:
I highly suggest you use the Bookmarks tab to easily scroll through the terms as they are in alphabetical order.
NOTE:
To read our Dictionary you will need to have Adobe Reader. If you do not, please select the link below and follow the directions to download the "free" version.

Contact Us
You may use this online form instead of email.
Merchant Services Form
This is a worksheet to help us provide you with the latest and greatest information available.
Merchant Services Quick Application
Apply today!
Newsletter Subscription-Merchant Services
Our free monthly newsletter will help you use your merchant account and other strategies to grow your business.
Affiliate Sign-up
Once registered, we will contact you to go over the pertinent details.
Business Opportunity Program Information
Part-time or full-time, supplement your current income or generate enough revenue to make a career change. Ask us how!
Trusted Partnership Program Information
Learn more about our Trusted Partnership program.
You may use this online form instead of email.
Merchant Services Form
This is a worksheet to help us provide you with the latest and greatest information available.
Merchant Services Quick Application
Apply today!
Newsletter Subscription-Merchant Services
Our free monthly newsletter will help you use your merchant account and other strategies to grow your business.
Affiliate Sign-up
Once registered, we will contact you to go over the pertinent details.
Business Opportunity Program Information
Part-time or full-time, supplement your current income or generate enough revenue to make a career change. Ask us how!
Trusted Partnership Program Information
Learn more about our Trusted Partnership program.
Guardian Debt Settlement
Jim Goodpaster
Looking to lower your unsecured debt by 60 percent? See why our settlement program is better than credit counseling or consolidation and will get you the relief you need.
Guardian Financial Group
Jim Goodpaster
Indiana Residential & Commercial Mortgages
Credit Report tune-Up Kit
Over 65 pages of information on CD, 4-Step Inquiry Guide creates professional and accepted documents for submission to the Credit Reporting Agencies and much more.
Windsor Capital
Mark Grossi
California Residential & Commercial Mortgages
Jim Goodpaster
Looking to lower your unsecured debt by 60 percent? See why our settlement program is better than credit counseling or consolidation and will get you the relief you need.
Guardian Financial Group
Jim Goodpaster
Indiana Residential & Commercial Mortgages
Credit Report tune-Up Kit
Over 65 pages of information on CD, 4-Step Inquiry Guide creates professional and accepted documents for submission to the Credit Reporting Agencies and much more.
Windsor Capital
Mark Grossi
California Residential & Commercial Mortgages
Click on any image for more information on what we have to offer.
















