Visa Sets Penalties for Security Breaches

SAN FRANCISCO – Visa USA announced yesterday it will begin fining participating merchants up to $25,000 a month for non-compliance with its Payment Card Industry Data Security Standard, which sets minimum security requirements for card using and storing card data. Those who storing prohibited data will be fined up to $10,000 a month. The storage of consumer card data where it can be stolen by hackers has been identified as one of the greatest risks to identity theft. The world’s largest payments company also said it is creating a $20 million fund which it will reward to acquiring banks and credit unions who have or will validate compliance with the PCI rules by August 31, 2007 and have not been involved in a data breach. The program, which targets the largest 1,200 merchant users of Visa, aims to eliminate the storage of full-track data, CVV2 and PIN data, and expand PCI compliance with the merchants, who account for two-thirds of all Visa transactions in the U.S.

Processing Content

For reprint and licensing requests for this article, click here.
MORE FROM AMERICAN BANKER
Load More