opinion

Keeping Cardholder Data Safe, Secure

Keeping Cardholder Data Safe, Secure

Congratulations. It is 2021 and, so far, your business has survived the Great Culling of 2020, the global pandemic of COVID-19

Just as some people found ways to improve themselves while quarantined by learning to bake bread or brew beer, or taking up reading or yoga, some businesses thrived under quarantine protocols. Whether your business thrived or struggled to survive, it is safe to say that the phrase “adapt or die” truly showed its relevance in 2020 — especially for small businesses.

More credit card transactions mean more opportunities for them and more security obligations for you.

If your business is web-based, like Amazon or DoorDash, these may be bonanza times for you. If you run a brick-and-mortar business, then depending on the state you live in, you may have had to modify your business model, at least temporarily, in ways that had never before crossed your mind. Restaurants and auto-parts stores adopted curbside pickup, for instance, or became cash-free environments. Suddenly, you found yourself taking orders and billing information over the telephone.

Regardless, it is great that your business has found a way to make it in this year of the new normal, but survival means new responsibilities because, as you are likely aware, legitimate business owners are not the only ones adapting to this new world; cybercriminals love it. More credit card transactions mean more opportunities for them and more security obligations for you.

You may believe your primary obligation is getting your product to your customer, but in the grand scheme of things, protecting your customers' personal information and cardholder data is more important. While ensuring your customer receives what they paid for is important, hard goods can easily be replaced, whereas a security breach that reveals your customer’s personal information and cardholder data can result in such problems as identity theft, and there is a great chance that your failure to provide adequate protection will result in the permanent loss of that person as a customer in the future.

It is pretty easy to figure out what a customer’s personal information consists of; the obvious elements like name, address, telephone number and date of birth certainly fall under the category of personal information, but what else does cardholder data encompass?

Cardholder data, for the purpose of this article, is the Personal Identifiable Information (PII) that is kept on the magnetic strip found on the back of any credit, debit or ATM card. The cardholder data stored is typically the account number, cardholder name and expiration date, as well as the service code, also known as the CVV or CVV2, depending on the bank issuing the card.

Fortunately, for consumers and merchants alike, there is the Payment Card Industry Security Standards Council, hereafter referred to as the PCI SSC.

The PCI SSC was created in 2006 by American Express, Discover, JCB International, MasterCard and Visa, and its mission is to enhance credit card data security by developing standards, practices and services. Part of this was accomplished with the establishment of the PCI Data Security Standard (PCI DSS).

The PCI DSS lists 12 requirements for a merchant to become PCI-compliant. These requirements range from the basics such as using a proper firewall to protect unauthorized access to the servers that store and transmit your customer’s cardholder data, and not using default passwords provided by any third-party vendors you might use. Additionally, updating anti-virus software, testing your security systems and establishing a policy that addresses information security for employees and any relevant contractors is required.

Whether your business is face-to-face with your customers inserting their credit card into a terminal, or your business is entirely web-based and you never interact with the customer or their credit card information, if you accept any credit or debit card as a means of payment, you have an obligation to be PCI-compliant to some degree.

Failure to be PCI-compliant can be expensive as the penalties levied by the credit card company on the acquiring bank (credit card bank) can range from $5,000 to $100,000 per month, in addition to possible legal action, loss of revenue and the inevitable loss of consumers' trust.

Fortunately, becoming PCI-compliant does not have to be as difficult as it might seem on the surface. You will have to fill out a self-assessment questionnaire and the associated Attestation of Compliance annually, but the technical portion is easy and usually free as most merchant service providers have partnered with certified PCI vendors and assessors.

Jonathan Corona has 15 years of experience in the electronic payments industry. As MobiusPay’s EVP, Corona is primarily responsible for day-to-day operations as well as reviewing and advising merchants on a multitude of compliance standards set forth by the card associations. MobiusPay specializes in merchant accounts in the U.S., EU and Asia. Follow them @MobiusPay on Twitter, Facebook and IG.

Related:  

Copyright © 2026 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

Clips4Sale's Christy on Backing Creators and Fueling Growth

Understanding the industry from within goes beyond data. For Christy, Manager of Creator Experience at Clips4Sale, that insight is shaped by front-line conversations and years spent listening not just to trends, but to people.

Women In Adult ·
opinion

Breaking Down AI-Powered Moderation and Platform Safety

Adult platforms, including content sites, cam services and dating apps, consistently face a range of high-risk challenges. These include verifying consent, particularly for user-uploaded content, addressing non-consensual material such as leaks and so-called revenge porn, and ensuring effective age verification and protection for minors.

Christoph Hermes ·
opinion

How to Optimize Subscription Billing for Compliance and Stability

The Federal Trade Commission’s “click to cancel” rule is coming back around. Last year, a federal appeals court vacated the FTC’s Negative Option Rule, aimed at addressing deceptive or unfair practices and making it easier for consumers to cancel online subscriptions.

Jonathan Corona ·
opinion

Key Strategies for Streamlining Payment Processing Approval

Why is it taking so long to get my account approved? It's frustrating for everyone involved, but it's all part of the process. Over the past year, timelines have stretched to 60 days or more for merchants to complete onboarding, from internal compliance review to banking partner approval and final card brand registration.

Cathy Beardsley ·
opinion

What to Know About Alabama's Regulatory Push on Adult Content

Over the past two years, Alabama has quietly but aggressively transformed itself into one of the most restrictive and unfriendly jurisdictions for the adult entertainment industry. Through the enactment of House Bill 164 and related enforcement mechanisms, the state has layered taxation, compliance burdens and content restrictions in a way that goes far beyond traditional regulation.

Corey D. Silverstein ·
profile

Chaturbate's Emely Zuniga Talks Show Floor Magic and Creator Care

During industry events, you’ll likely find Zuniga gliding through the room, greeting creators, checking details and making sure everyone around her feels taken care of. With her colorful red hair, perfectly done nails and an easygoing, “work bestie” demeanor that instantly puts people at ease, she thrives in the fast-paced environment of conferences and trade shows.

Jackie Backman ·
opinion

What to Know About Deepfakes, Likeness Rights, and Digital Consent

AI is reshaping virtually every sector of the global economy, and the adult industry is no exception. Many adult companies have already explored or adopted AI in content production, and surveys indicate that around 65% have considered implementing AI technologies in their operations.

Christoph Hermes ·
opinion

Key Strategies for Adapting to Stricter PCI Compliance Standards

When it comes to PCI compliance, the days of simply filling out some paperwork and answering a few questions are gone. A casual approach is just not viable anymore.

Jonathan Corona ·
opinion

How to Maximize Value From Your Payment Processing Fees

Regulatory requirements are putting more and more pressure on the adult industry. To stay compliant, merchants need tools that help with content moderation, age verification and fraud solutions. Unfortunately, the fees for those tools are hitting merchants’ bottom lines — including fees charged by payment services providers.

Cathy Beardsley ·
opinion

Understanding Sin Taxes and the Legal Roadblocks Ahead

As of this writing, a bill sits on the desk of Utah’s governor, awaiting his signature to make it state law. That bill includes a provision imposing an excise tax of 2% on adult sites operating in the state.

Corey D. Silverstein ·
Show More