Related
Peter Harvey to depart DPO Group
22 Feb 2022
Don't let outdated security leave you red-faced on Black Friday
Simeon Tassev 17 Nov 2021
If they store, transmit or process any kind of credit or debit card information, it is their job, as the merchant to protect it. If cardholder data is stolen and the seller is responsible, the organisation could face fines, penalties and even lose the right to accept payment cards. The card associations are getting stricter about this.
This is an area where it is worth investing in professionalism. If the online channel is important to a business, the checkout and payment process can make or break it. This is the last place one should be stingy with the budget.
Secondly, ask for information about reliability and availability. It's no good having a cheap payment gateway if they're down one day out of seven and customers get turned away at the till. Ask about their downtime and contact some other customers to ask about their experience. Once one is satisfied that security and reliability needs are met, then is the time to let price be the deciding factor - not before.
Some online merchants prefer to control the user experience from beginning to end, including the payment process. In this case, merchants should use tokenisation. This means that instead of actual card information, one stores an encrypted token provided by the payment gateway. Next time one needs to process a transaction on that same card, one just sends the token. This is a simple but highly effective way to make sure one never has to store card numbers."