Notices
Reply

Thread: Networks require Advertisers to be PCI compliant?

 
Tools Search
  #1  
Old November 26th, 2011, 06:33 AM
Full Member
Join Date: April 7th, 2010
Location: Deep South
Posts: 287
Yesterday, in the afternoon (E.S.T.), on Fox News Channel, I saw an interview with a man from McAfee. The security man said that only 20% of ecommerce web sites are PCI compliant.

Question: Do LS, CJ and SAS require their advertisers to be PCI compliant?
  #2  
Old November 26th, 2011, 12:38 PM
ABestWeb Admin
Join Date: October 5th, 2005
Location: Park City Utah
Posts: 8,972
Send a message via AIM to Chuck Hamrick Send a message via MSN to Chuck Hamrick Send a message via Yahoo to Chuck Hamrick
Not that I am aware of. I did have a merchant who was looking at retargeting and it had to pass PCI compliance. To tell you the truth I am not familiar with PCI compliance, do you have further details?
  #3  
Old November 26th, 2011, 09:00 PM
Full Member
Join Date: November 21st, 2010
Posts: 220
I don't know, but they shouldn't as it's really not for them to enforce. If you a company is retaining cardholder data, it's simply obligated to be PCI complaint to its respective level and it's up to its merchant bank (if anyone) to enforce it. But even if the bank does nothing and the company gets caught, fines can still be levied.

so if you aren't PCI compliant now, you may want to check your agreement with your bank because I doubt the bank will eat the fines (which could be upwards of $100,000)
Join ABW to remove this sponsored message.
  #4  
Old November 27th, 2011, 05:58 AM
Full Member
Join Date: April 7th, 2010
Location: Deep South
Posts: 287
I believe many of the smaller merchants outsource their credit card processing to third parties and that those merchants do not have credit card numbers, or, other confidential data, on their servers.

Probably any company that does have credit card numbers, etc., on their servers, needs to be PCI compliant.

Sounds like the networks (LS, CJ, SAS, etc.) do not require PCI compliance.

Thanks for the feedback!

@Chuck - I am not sure what the PCI requirements are, however, I believe they are very tough.

Last edited by Lanny; November 27th, 2011 at 06:00 AM. Reason: @Chuck not sure of the PCI requirements
  #5  
Old November 27th, 2011, 12:04 PM
Full Member
Join Date: November 21st, 2010
Posts: 220
Yes, using something like PayPal to handle your billing definitely takes a lot of pressure and the onus off of a merchant.
  #6  
Old November 27th, 2011, 03:21 PM
Newbie
Join Date: November 27th, 2011
Location: England
Posts: 6
There seems to be more and more regulation creeping in to the Internet Marketing Industry. I hope that the PCI law works in the way it's supposed to. Without being to interfering.

You can read more about the new PCI rules here
Join ABW to remove this sponsored message.
  #7  
Old November 27th, 2011, 04:15 PM
Member
Join Date: February 5th, 2009
Posts: 136
Send a message via AIM to shuvee Send a message via Yahoo to shuvee
Yes, in order to keep a merchant account with a major bank, you must be PCI compliant. Most merchant banks require that your server is scanned periodically to ensure compliance. It's actually a pain in the neck because as often as not the "issues" are either administrative (you have not done your annual "self assessment"), or - worse yet - they find you out of compliance because of a bug in their testing. I just passed for the 2nd quarter in a row without having to update anything; and I am breathing a sigh of relief.

Unfortunately, the banks are all so large that by the time something gets implemented in software, the chances that it addresses what it should, in the proper way, are greatly reduced. I continue to marvel at the antiquated and poorly thought out systems they have in place to handle chargebacks.

PayPal is not a great solution for merchants. Because it handles everything, and gives you less information (they tell you if there is an address mismatch, but not whether it's the "street" portion or the zip code), you have a greater chance of a lost package due to a typo, or a reversal by PayPal after the fact. I accept credit cards, but not PayPal, for that reason. Although your merchant bank can reverse the transaction (and does if it is challenged by the customer), you can usually get the money restored when you provide transaction documentation. I shudder to think what happens with PayPal; I haven't heard anything reassuring about that ...

There is no way for the networks to know whether you are PCI Compliant, plus it is common to be out of compliance for short periods (from when you are notified of a missing software upgrade to the time you can apply it). They can't even know if your servers are being tested. If you, as an affiliate, are concerned about sending your site visitors to non-compliant (or non-tested) merchant systems, I'd stick to major companies, and even there compliance does not mean total security. It is the large companies whose systems are targeted, and which are most likely to "lose" credit card information. However, small companies, fi they are with merchant account resellers who are not careful (and there are probably many of those), may be totally irresponsible about protecting credit card information. Too many little companies buy a store/cart system and install it on their own servers, with little or no understanding of security. They don't want to hire anyone to ensure that they aren't at risk, but doing it right is not something you can learn overnight.

I guess that was a rant. Sorry.
__________________
---
Valerie Magee
MageeNET
Thanks From:
  #8  
Old November 28th, 2011, 08:05 AM
Newbie
Join Date: November 27th, 2011
Location: England
Posts: 6
In other words Valerie. We are well and truly screwed

Last edited by paulas; November 28th, 2011 at 08:07 AM. Reason: Used the wrong name
Old November 30th, 2011, 06:23 AM
Jashandeep
This message has been deleted by BurgerBoy. Reason: Spam
  #9  
Old December 1st, 2011, 08:08 AM
Full Member
Join Date: April 7th, 2010
Location: Deep South
Posts: 287
@Shuvee (Valerie) Thank you for all of the data you provided. Interesting! I am aware that there are issues for Merchants who accept PayPal payments. My #1 Merchant does accept PayPal and that is a big plus for me. I keep hoping that my #2 Merchant will begin accepting paypal. Hopefully, during 2012! Lanny
Join ABW to remove this sponsored message.
Old December 1st, 2011, 08:27 AM
Todd2012
This message has been deleted by Chuck Hamrick. Reason: image link spam
Old December 13th, 2011, 05:32 AM
Robert2012
This message has been deleted by BurgerBoy. Reason: Image Spam
Old December 22nd, 2011, 05:39 AM
Sue2046
This message has been deleted by BurgerBoy. Reason: Image Spam
Reply

Tags
advertisers, networks, pci compliant, security

Tools Search
Search:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Do CPA advertisers have to log into multiple networks? eSilverBullet Midnight Cafe' 0 October 25th, 2010 03:00 PM
I've found my niche, I know my advertisers, how do I find the affiliate networks? tieTYT Newbie FAQs 9 August 19th, 2008 03:28 PM
Being W3C compliant Cav Programming / Datafeeds / Tools 1 August 18th, 2008 04:32 PM
Advertisers and Networks - Frustrating adFinityJoe Midnight Cafe' 26 May 17th, 2007 04:49 PM
Why Don't the Networks Require Non-Tracking to be Reported to Affiliates? Snowman Midnight Cafe' 8 April 14th, 2007 12:42 PM


Content Relevant URLs by vBSEO ©2010, Crawlability, Inc.