nonethefewer: (Default)
[personal profile] nonethefewer
Gah.  I need to find information on the laws in the US, and in Oregon, for how businesses must store credit card data in their databases -- encryption, length of time, whatever the hell.

I'm in the process of Googling this now, but if someone happens to know off the top of their head where some good info is, that'd be awesome.

Unrelated project: syncing Firefox's custom dictionary between computers.

(no subject)

Date: 2011-03-14 04:40 pm (UTC)
sara: S (Default)
From: [personal profile] sara
In my Oregon-based business, we do not retain credit card data for any length of time at all -- as long as it takes me to walk from the credit card machine to the shredder.

(no subject)

Date: 2011-03-14 04:48 pm (UTC)
moominmolly: (Default)
From: [personal profile] moominmolly
I don't know much, but I do know that PCI compliance requires that all ccard traffic be encrypted, and that access to the data be tightly controlled like so. Now you know about how much I know about PCI, despite the fact that I work for like ten different large e-business retailers.
Page generated Jan. 22nd, 2026 09:30 pm
Powered by Dreamwidth Studios