Malek + Malek
contact@malekattorneys.com (208) 215-2411
×
  • About Us
    • Our Firm
    • Team
    • Awards
    • Careers
  • Practices
    • General Counsel
    • Contract Law
    • Mergers & Acquisitions
    • Real Estate Transactions
    • Human Resources Law
    • Corporate Litigation
    • Appellate Law
    • Healthcare Law
  • Licensed States
    • Alaska
    • California
    • Idaho
    • Montana
    • Oregon
    • Utah
    • Washington
    • Wyoming
  • Resources
    • Blog
    • In the News
    • Newsletter Signup
  • Offices
    • Boise
    • Coeur d’Alene
    • Kennewick
    • Spokane
  • Contact Us
Business

Guidelines for 2021 PCI Compliance

Feb 26, 2021

During the age of online purchases and subscription-based services, many small businesses are inclined to keep customer cardholder information stored. Before this information is stored, small business owners need to understand the compliance that comes along with it. Whether it be for a monthly refresh of your favorite groceries or an annual gym membership, small business owners should think twice before retaining customer’s cardholder data.

The Payment Card Industry Data Security Standards (“PCI DSS”) are a set of requirements for handling credit cardholder information. Developed and maintained by the PCI Security Standards Council (“PCI SSC”), founded by five of the largest card brands (American Express, Discover, JCB International, Mastercard, and Visa Inc.) the standards set out to be a collaborative effort to protect the integrity of the payments system and maintain security for cardholders. 

PCI DSS applies to any entity — large or small — that stores, processes, or transmits cardholder data. For the purposes of the PCI DSS, a “merchant” is defined as any entity that accepts payment cards bearing the logos of any of the five members of PCI SSC as payment for goods and/or services. 

Cardholder information should never be stored unless it is necessary for the business. Before a merchant retains credit card data, the merchant must be PCI DSS compliant. To be compliant, a merchant must meet twelve operational and technical requirements, including the storage must be approved by the purchaser, be encrypted, firewalls are utilized, and testing is done over the merchant’s network to ensure security. A merchant is able to retain the cardholder name, primary account number (16 digit number) and the expiration date if compliant. It is strictly against PCI DSS regulation for a merchant to store the card verification value/code (CVV/CVC) or information embedded in the magnetic strip.

As payment processing is an intricate web between the cardholder, merchant, financial institutions, and processing providers, many small merchants contract with a PCI-compliant payment processing company. This alleviates the need to keep apprised of the latest versions of PCI DSS and other compliance requirements. Merchants don’t have to lose the look and feel of their website while working with a payment provider’s hosted payment page. This can result in a PCI-compliant website that appears transparent to the consumer. Merchants should ensure that their contracts with PCI-compliant processing systems put all PCI compliance on the processor. 

PCI DSS is a standard and not a law. This means PCI compliance is enforced through contracts between merchants, financial institutions, and payment brands. In the event of a breach, payment brands may fine a bank anywhere from $5,000 to $100,000 per month for violations. If the merchant was PCI compliant, they may find themselves shielded from a portion of the liability. Otherwise, the banks trickle down the fine to the merchant or terminate the relationship. Penalties are not publicized, but present real risks to business operations. If you are a small business facing the decision of whether or not to store cardholder information, we are here to help you resolve the matter. 

This blog post is designed to provide general information on pertinent legal topics. The statements made are provided for educational purposes only. This blog does not provide legal advice. This blog does not create an attorney-client relationship between you and Malek + Malek, PLLC. If you want to create an attorney-client relationship and have specific questions regarding the application of the law to your own circumstances, you should contact our office.

This blog is not legal advice and does not create an attorney-client relationship with our firm. The content is intended to promote a general understanding of legal concepts and should not be relied upon as a substitute for obtaining legal advice from a qualified attorney regarding the reader’s specific circumstances. Readers should consult legal counsel for advice concerning their individual situations. All content is provided without any representations or warranties regarding completeness, accuracy, or timeliness.

Topics Covered Here

Related Articles

How to Terminate an Employee Without Creating a Lawsuit

By the time a business owner or HR lead calls an attorney about an employee problem, the issue has usually been building for weeks, if not months. This slow...

Read more
Idaho’s Bathroom Bill: What Business Owners Need to Know

Idaho’s House Bill 752 was originally scheduled to take effect on July 1, 2026, but faces an uncertain future. At the time of this writing, it is pending a...

Read more
What Every Business Owner Should Know About Succession Planning

Most business owners spend years building something valuable, but not nearly as much time thinking through how to hand it off. This gap is expensive. Whether you plan to...

Read more

Ready to work with us?

This field is for validation purposes and should be left unchanged.
We are committed to keeping you up to date on legal matters that may impact you. We send 1-2 informative emails per month.
Consent: By hitting submit, you understand that we do not become your attorneys. That only happens if we both agree to the representation.(Required)

Our vision is to be a force of justice for the world. Since 2015, Malek + Malek has partnered with businesses and healthcare providers across Idaho, Washington, and the Pacific Northwest, delivering tailored legal counsel in business law, corporate litigation, and regulatory compliance so you can focus on changing the world for the better.

About Us
  • Our Firm
  • Team
  • Awards
  • Careers
Practice Areas
  • General Counsel
  • Contract Law
  • Mergers & Acquisitions
  • Real Estate Transactions
  • Human Resource Law
  • Corporate Litigation
  • Appellate Law
  • Healthcare Law
States We Practice In
  • Alaska
  • California
  • Idaho
  • Montana
  • Oregon
  • Utah
  • Washington
  • Wyoming
Resources
  • Blog
  • In the News
  • Newsletter
Contact Us
  • Get In Touch
  • contact@malekattorneys.com
  • (208) 215-2411
Office Locations
Boise
101 S. Capitol Boulevard, Suite 301
Boise, ID 83702
208.473.7009
Coeur d’Alene
601 E. Front Avenue, Suite 304
Coeur d’Alene, ID 83814
208.215.2411
Spokane
601 W. Riverside Avenue, Suite 1320
Spokane, WA 99201
509.606.1500
Kennewick
Columbia Center Heights Executive Suites
Kennewick, WA 99336
509.606.1500

© 2026 Malek + Malek. All Rights Reserved.

  • Disclaimer
  • Privacy Policy
  • Sitemap