Protecting Your Customers' Information

In addition to protecting your company from processing fraudulent transactions, you are also responsible for protecting your own customers' information from being compromised.

noate.gif 

As part of your PCI DSS (Payment Card Industry Data Security Standard) Compliance certification, you should have a security policy in place around how you store and protect customer information-- including credit card numbers.

Using ReceivablesPro for all of your electronic storage of cardholder data is a smart first step towards compliance. Once a credit card number is encrypted and securely stored in ReceivablesPro’s PCI Certified system, you can perform additional transactions without the need for external access to the full number again.

 

But, if you store card holder data in paper form—such a signed authorization forms for recurring schedules—you need to make certain that those forms are protected. The following are some guidelines to use:

If you store authorization forms in digital format, you need to remove the CVV2 number and all but the last 4 digits of the credit card number (after you have successfully processed a transaction of course). You can achieve this by redacting (cross-out with a dark pen) this information before scanning a written document for storage. Or, if the authorization form is already in digital format, use a tool such as Microsoft Paint or Adobe Acrobat Standard to delete it prior to storage.

 

Next >