Archive for February 6, 2007

Increased Scrutiny From Card Associations in 2007

In the latest issue of The Green Sheet, David H. Press writes about the increased scrutiny to expect in 2007 from the credit card associations. He cites a Visa announcement that states: “By combining both incentives and fines, we expect acquirers to increase their efforts with merchants to accelerate their progress toward becoming PCI-compliant and eliminating the storage of sensitive card data. Nothing is more important to Visa than securing commerce.”

Visa estimated that PCI compliance among level 1 merchants would be only 65% at the end of 2006. Effective Oct. 1, 2007, acquirers whose merchants have validated their PCI-compliance may qualify to get lower interchange rates for both Visa and Interlink tiers. Visa has also announced fines for data compromises – regardless of the size of the merchants.

Visa has also stepped up their enforcement of PCI-compliance for merchants and service providers, even before data breaches occur. Visa stated, “For prohibited data storage, acquirers failing to provide confirmation that their level 1 and 2 merchants are not storing full track data, CVV2 or PIN data by March 31, 2007, will be eligible for fines up to $10,000 a month per merchant, subject to escalation in the event material progress toward compliance is not made in a timely manner.”

|