How to comply with the PCI DSS.
Merchants who process card transactions must comply with Payment Card Industry Data Security Standard (PCI DSS). Find out how to help your business become compliant.
What is the PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) sets out the security requirements Merchants must meet if they process, transmit, store or have access to card payment data.
These requirements were developed by the PCI Council whose members include global card schemes such as Visa, Mastercard®, UnionPay International.
The purpose of the PCI DSS is to:
- Protect card payment data
- Reduce the risk of unauthorised access and misuse of cardholder information.
Why is it important to protect card payment data?
If an unauthorised person gains access to card payment data you have stored in your organisations environment, this is known as an Account Data Compromise (ADC).
An ADC can lead to financial penalties, additional audit requirements, reputational damage, and the suspension or termination of your merchant facility.
Making sure your business complies with the PCI DSS requirements greatly reduces the possibility of falling victim to an ADC. Get help to prevent and respond to an ADC.
What are the PCI DSS requirements?
The PCI DSS is a checklist of security requirements that apply to people, processes and technology involved in processing, transmitting, storing or accessing card payment data.
- Install and maintain a firewall configuration to protect cardholder data
- Do not use vendor-supplied defaults for system passwords and other security parameters
- Protect stored cardholder data
- Encrypt transmission of cardholder data across open, public networks
- Use and regularly update anti-virus software or programmes
- Develop and maintain secure systems and applications
- Restrict access to cardholder data by business need-to-know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain a policy that addresses information security for employees and contractors.
What are my PCI DSS obligations as a Westpac merchant?
If you're a Westpac merchant, it is a condition of your merchant agreement with us that your organisation, and any third-party that processes, transmits, stores or accesses card payment data on your behalf, complies with the PCI DSS requirements.
PCI DSS merchant levels & process.
Your merchant level is based on the annual volume of card transactions you process each year. As transaction volumes increase, the PCI DSS validation requirements become more comprehensive. Our PCI DSS compliance team will confirm your merchant level and validation requirements.
To make this process easier, we have partnered with Foregenix. Where required, we will enrol you into the Foregenix portal, where you can manage and track your PCI DSS compliance requirements in one place, with guidance and support available along the way.
If you would like to be set up on the Foregenix portal, please contact your Westpac Relationship Manager or email our PCI DSS Compliance team at PCI.DSS.Compliance@westpac.co.nz
|
Table of transaction volume and merchant levels |
|
|
Transaction volume |
Merchant level |
|
More than 6 million card transactions per year |
1 |
|
Between 1 and 6 million card transactions per year |
2 |
|
Less than 1 million card transactions per year |
3 |
Understanding PCI DSS terms.
FAQs.
What will happen if I don't comply with the PCI DSS?
If your systems are not well protected and a data breach occurs, you could face significant costs, including financial penalties. Your customers trust you to keep their card information safe, and failing to do so can harm both them and your reputation. Maintaining PCI DSS compliance helps reduce the risk of a breach and can also limit the impact if one does happen.
Westpac also reserves the right to terminate a merchant facility under the contractable obligations in our Merchant Services Agreement (MSA). That means your business may lose the ability to accept card payments.
I only process a small amount of card transactions. Do I still need to comply with PCI DSS?
Yes. Every merchant that processes, stores, transmits or has access to card payment data must comply with PCI DSS, regardless of the frequency or value of their transactions. You can find out about your obligations in section 7.5 of your Merchant Services Agreement with Westpac.
If I comply with the PCI DSS, is it a guarantee that my business won't be compromised?
No. The PCI DSS is a minimum security standard that helps to maintain a secure payment environment and protect card payment data at a basic level. Complying with PCI DSS greatly reduces the risk of an account data compromise but does not guarantee that your business is completely secure.
What else can I do to protect my business?
You can find more security tips for each type of payment channel on our accepting cards safely page.
Get help with PCI DSS compliance.
Contact your Westpac Relationship Manager or email the PCI DSS compliance team at PCI.DSS.Compliance@westpac.co.nz.
Things you should know.
The information on this page is intended as a guide only. We make no warranty or representation, express or implied, regarding the accuracy of any information, statement or advice contained on this page. We recommend you seek independent advice before acting or relying on any of the information on this page. All opinions, statements and analysis expressed are based on information current at the time of writing from sources which Westpac believes to be authentic and reliable. Westpac issues no invitation to anyone to rely on this material.
Links to other sites are provided for convenience only and Westpac accepts no responsibility for the availability or content of such websites.