PCI DSS is a global security standard established in 2004 by major credit card networks to protect payment card data for any organization that stores, processes, or transmits cardholder information. Unlike consumer privacy laws, it prescribes specific technical controls and compliance requirements that scale based on transaction volume and data handling practices.
PCI DSS Overview
The Payment Card Industry Data Security Standards, or PCI DSS, was put into place to protect credit card data — essentially any company that processes credit cards.
All of the big credit card companies, like Visa, Mastercard, Discover and many more, got together and decided that they needed to protect this credit card processing, and that anybody that stored or processed credit card information needed to have a stricter level of security to protect this data. In essence, it's protecting these credit card companies and also protecting us consumers, to make sure that our credit card information was safe.
The standard was put into place in 2004 and really applies to anybody that's processing credit card information. So if you're collecting any kind of credit card information, or processing it, you must comply with it.
PCI DSS is really not designed around consumer privacy. A lot of laws and regulations are designed to protect the consumer and the privacy of that data that's being collected on that consumer. PCI DSS is much different: it's designed to protect the credit card information, and in its nature it's much more technical in detail.
Where a lot of our privacy laws are designed around general guidelines of what you need to implement to make sure that your network is secure and that data is secure, when it comes to PCI DSS it gets much more technical in detail and lays out all of the steps, all of the controls, that you need to put into place to protect that credit card information. So it gets a lot into your network and how your network is designed, and specific design principles within your network.
Here are some highlights around PCI DSS.
There's this compliance level with it, and there's different levels, so you have to comply with these different levels based off of what you're doing with the credit card information.
If you're just collecting it, processing it, and it's not at a high volume, then you fall under the basic level, and there might be just some self-evaluations that you go through to comply with PCI DSS. Much bigger companies, though, that are doing things on a much more global level and also saving this information long term, have to comply with a much stricter level of PCI DSS. Some of that may include having a third party come and do an evaluation on your company to make sure that you are complying with the different controls involved and the different standards.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →