Verify Your Compliance
First, select the method of payment your business uses for card acceptance:
You need to enter the login and password you created on Trustwave when you first registered on the site last year in order to continue.
Internet Commerce
If you offer online payment options to your customers, then you utilize an Internet gateway or online shopping cart to process credit and debit card transactions. Alternately, if you process credit or debit cards via an internet connection or a cash register system that utilizes third-party software, then you also use an IP Solution. To determine whether your procedures for handling cardholder data meet current PCI-DSS regulations, click on the Receipt Truncation and Secured Card Holder Data tabs.
Take the next step and Get Certified.
Already using TrustKeeper? Click here to renew.
Common IP Solutions:
- VirtualMerchant
- viaWarp
- Aloha
- PC Charge
- IP Terminals
- Authorize.net
- PayPal/Epay/Pass/Ebay
- USB Healthcare
The Fair and Accurate Credit Transaction Act of 2003 (FACTA), along with state governments and the card associations set forth various standards requiring truncation of credit card information. In order to adhere to the strictest of laws, Elavon recommends the following:
- Merchants should truncate both the merchant receipt and customer copy to include no more than the last four digits of the credit card number.
- The card expiration date should never be printed or displayed on either copy of receipts.
Depending on your vendor, you may already be compliant with the receipt provisions of FACTA, however laws vary from state to state with regard to additional requirements. If either your merchant copy or customer copy receipts print the entire credit card number and/or expiration date, you should contact your vendor to make the necessary updates to your software program.
Take the next step and Get Certified.
Already using TrustKeeper? Click here to renew.
Avoid Common Mistakes for Storing Cardholder Data
- Cardholder information should never be stored on any employee workstation. If it is, this data needs to be properly secured and must adhere to PCI standards for encryption software that protects sensitive data.
- Do not store paper receipts for more than 24 months. Never store paper receipts that have not been truncated to FACTA, state or card association guidelines, especially manual imprinter receipts, without insuring that they are stored in a lock box or safe that cannot be removed from the premises.
If you have any question regarding how you store cardholder data, or concerns about your compliance, we strongly recommend that you contact TrustWave to assess your needs.
Take the next step and Get Certified.
Already using TrustKeeper? Click here to renew.