A bit of good news for PCI compliance – but only in Washington

One of my big problems with PCI compliance is that it means nothing. The card brands will come in after the fact and find something, anything, to claim that the merchant wasn’t compliant when the breach occurred. That puts everything on the merchant. As always, the merchant is the low man on the hill, and we all know which way on the hill the stuff runs. If you don’t believe me, ask any PCI compliant merchant that was breached. That’s why the brands claim that no PCI compliant merchant was ever breached. They find something.

The fact is that a merchant can spend huge sums of money to become PCI compliant but it doesn’t give them safe harbor. Until now. But only in the State of Washington.

A new law signed by Washington’s Gov. Chris Gregoire finally gives a break to the State’s merchants. If they are compliant, they are protected from the card brands. The Washington law mandates that if a merchant is certified as PCI compliant by an annual assessment, that compliance is non-revocable for a year. The processors and issuing banks cannot go after the merchant for losses.

The law isn’t perfect, of course. They seldom are. There is no mention of consumer losses. We know that consumers suffer no direct monetary losses from credit card breaches but they do suffer lost time and aggravation in trying to get things straightened out. We can assume the merchant won’t have protection from them.

Still, the Washington law is pro merchant and a big step in the right direction. If nothing else, it gives the merchant some justification for the resources expended in getting compliant.

Now can Federal lawmakers get on board?

Similar Posts:

About Tom Mahoney

Tom Mahoney is the Founder and Director of Merchant911, a site dedicated to helping e-commerce merchants.
This entry was posted in Data Breach, Legal Issues, PCI Compliance, Security Standard and tagged . Bookmark the permalink.
Post comment as twitter logo facebook logo
Sort: Newest | Oldest

Check the bottom of the main pages- it's there.
contact at merchant911.org

Does your site have a contact page? I'm having a tough time locating it but, I'd like to send you an email. I've got some recommendations for your blog you might be interested in hearing. Either way, great site and I look forward to seeing it grow over time.

Trackbacks

  1. [...] This post was mentioned on Twitter by Joan Miller, Tom Mahoney. Tom Mahoney said: A bit of good news for PCI compliance – but only in Washington: One of my big problems with PCI compliance… http://bit.ly/dlCxAY [...]