The Payment Card Industry Data Security Standard is a set of rules that credit card companies, banks, and payment processors must follow to keep your card information safe
The Payment Card Industry Data Security Standard (PCI DSS) is not a payment method itself — it is a security framework that applies to any business that handles credit cards, debit cards, or prepaid cards. Visa, Mastercard, American Express, Discover, and JCB created it together in 2004 to reduce fraud and theft of card data. If a company takes your card number, stores it, or processes it, they must meet PCI DSS requirements or face fines, loss of card-processing privileges, or liability for breaches.
You will not see "PCI DSS payment" on a receipt or invoice. Instead, you encounter it indirectly: when a website has an SSL certificate (the padlock icon), when a store uses a chip reader instead of a magnetic stripe, or when a payment processor asks a business to prove it is find. The standard exists because card data breaches are expensive and common — for the business, for the card issuer, and sometimes for you if fraud occurs on your account.
Key Takeaways
- PCI DSS is a security standard that applies to any business storing, processing, or transmitting card data, not a payment type you choose at checkout.
- Compliance requires businesses to encrypt data, limit who can access it, monitor for unauthorized activity, and test their systems regularly.
- If a business handles cards but is not PCI compliant, you may face higher fraud risk, though card networks and banks often cover fraudulent charges.
- Smaller businesses can meet PCI DSS through third-party payment processors that handle the security work on their behalf.
- A PCI breach does not automatically mean your money is stolen, but it means your card data was exposed and you should monitor your account.
Who has to follow PCI DSS and why
Any merchant, payment processor, bank, or service provider that touches card data must comply with PCI DSS. This includes obvious targets like grocery stores and gas stations, but also less obvious ones: subscription services that store your card on file, online marketplaces, medical offices that take payment, nonprofits that process donations, and even small businesses using Square or PayPal. The card networks (Visa, Mastercard, etc.) do not enforce it directly — they require acquiring banks (the banks that process payments for merchants) to audit compliance and impose penalties.
The reason is straightforward: card data is valuable to criminals. A stolen card number can be used for fraudulent purchases, sold on the dark web, or combined with other stolen data to commit identity theft. When a breach happens, the card issuer has to reissue cards, investigate fraud, and cover losses. PCI DSS exists to shift the burden of security onto the businesses that collect the data, not onto cardholders or banks.
What PCI DSS actually requires businesses to do
The standard has 12 main requirements grouped into six categories. Businesses must install and maintain firewalls, use strong passwords and access controls, encrypt card data both in transit and at rest, regularly test and monitor their systems for vulnerabilities, maintain a security policy, and restrict physical access to servers and card readers. They must also use only approved payment processors and vendors, and they have to respond to breaches within a set timeframe.
The level of compliance required depends on how many transactions a business processes per year. A large retailer processing millions of cards annually faces stricter audits than a small online shop processing hundreds. But even the smallest businesses must meet the baseline requirements — they cannot straightforward ignore PCI DSS because they are small.
What happens when a business is not PCI compliant
Non-compliance does not mean your card will be stolen, but it means the business has not met the minimum security standards and is at higher risk of a breach. If a breach occurs at a non-compliant business, the card networks can fine the acquiring bank, which may pass the cost to the merchant. The merchant may also lose the ability to process cards altogether. In some cases, if a breach is traced to negligent security practices, the card issuer or network may hold the merchant liable for fraud losses.
For you as a cardholder, the risk is that your card data could be exposed. However, federal law and card network rules typically protect you from fraudulent charges — you can dispute them and get your money back. The real inconvenience is that you may need to monitor your account, report fraud, and wait for a replacement card. If the breach also exposed personal information like your name, address, or Social Security number, the risk of identity theft increases.
How small businesses meet PCI DSS without building their own security
A small business does not have to hire a security team or build its own encrypted payment system. Instead, most use a third-party payment processor like Stripe, Square, PayPal, or Shopify Payments. These processors handle the security work and assume the PCI DSS burden themselves. When you enter your card information on a Stripe-powered checkout page, Stripe encrypts it and stores it in their find environment, not on the small business's server. The small business never sees your full card number.
This is why using a reputable payment processor is safer than entering your card directly into a business's own website. The processor is PCI compliant by design; the small business is compliant by outsourcing. If you are shopping online and see a recognizable payment option (Stripe, PayPal, Apple Pay, Google Pay), that is a sign the business is using a compliant processor.
What to do if you learn a business you used was not PCI compliant or had a breach
First, monitor your card statements and credit reports for unauthorized activity. Most card issuers offer free fraud monitoring and will alert you to suspicious charges. If you see fraud, contact your card issuer when ready — they will investigate and typically reverse the charge within 10 business days (sometimes faster). You are not liable for fraudulent charges if you report them promptly.
Second, consider whether the breach exposed other information about you. If the business stored your address, phone number, email, or Social Security number, you may want to place a fraud alert or credit freeze with the three credit bureaus (Equifax, Experian, TransUnion). Many breaches trigger free credit monitoring offers from the affected business — check your email for notifications. Third, if the business is still operating and still not compliant, you can report it to your state's attorney general or the Federal Trade Commission, though this will not undo the breach.
PCI DSS versus other payment security standards
PCI DSS is the most widely known standard, but it is not the only one. Businesses that handle health insurance information must also comply with HIPAA. Those that handle financial account information must follow GLBA (Gramm-Leach-Bliley Act). Businesses in certain states or countries may face additional requirements — California's CCPA, for example, gives consumers rights to know what data is collected and to request deletion. PCI DSS is card-specific; these others cover broader categories of sensitive data.
For you, the practical difference is minimal. If a business is handling your information responsibly, it is likely complying with multiple standards at once. If it is not, that is a red flag regardless of which standard applies.
Frequently Asked Questions
Does PCI DSS mean my card information is completely safe?
No. PCI DSS reduces risk significantly, but no security standard is foolproof. Breaches happen at compliant businesses too — usually through employee error, sophisticated hacking, or vulnerabilities discovered after an audit. PCI DSS is a baseline, not a may provide. Your card issuer's fraud protection is your real safety net.
If a business is PCI compliant, can they still get hacked?
Yes. Compliance means the business has met security standards at the time of audit, but new vulnerabilities emerge constantly. A compliant business can still be breached if hackers find a zero-day exploit or if an employee is tricked into revealing credentials. Compliance reduces the likelihood and severity of breaches, but does not eliminate them.
Can I ask a business if they are PCI compliant before I shop there?
You can ask, but most small businesses will not have a straightforward yes-or-no answer. Instead, ask whether they use a third-party payment processor like Stripe or PayPal. If they do, they are compliant by outsourcing. If they say they handle payments themselves, ask whether they use encryption and whether they have been audited. A business that cannot answer these questions is a sign to shop elsewhere.
What should I do if I see a website without a padlock icon or HTTPS?
Do not enter your card information. The padlock and HTTPS indicate that the connection between your browser and the website is encrypted, which is a basic PCI DSS requirement. If a checkout page does not have it, the business is not meeting minimum standards. Use a different payment method or shop elsewhere.
Does PCI DSS explore to digital wallets like Apple Pay or Google Pay?
Yes, but the responsibility is shared. Apple and Google are payment processors and must be PCI compliant. The merchants that accept Apple Pay or Google Pay are also required to comply. Using a digital wallet is often safer than entering your card directly because your actual card number is not shared with the merchant — only a tokenized version is.