SHARE
Facebook X Pinterest WhatsApp

Feud Over PCI DSS Comes to a Head

A long simmering feud between retailers and credit card issuers over data security came to a head early this month with the National Retail Federation formally asking the Federal Trade Commission to determine whether the credit card industry is in breach of antitrust regulations. The core issue is the way credit card issuers have been […]

Written By
thumbnail Michael Vizard
Michael Vizard
Jun 3, 2016
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A long simmering feud between retailers and credit card issuers over data security came to a head early this month with the National Retail Federation formally asking the Federal Trade Commission to determine whether the credit card industry is in breach of antitrust regulations.

The core issue is the way credit card issuers have been trying to enforce the Payment Card Industry Data Security Standard (PCI DSS). Many retailers perceive that the audits associated with this standard are arbitrary, resulting in fines imposed by credit card issuers that are at the very least questionable in terms of their legal authority to impose.

According to NRF Senior Vice President and General Counsel Mallory Duncan, “PCI itself is an inappropriate exercise of market power by the dominant U.S. payment card networks and PCI should not continue setting data security standards through its current processes.”

Naturally, solution providers that specialize in IT security are caught in the middle of this quagmire. They are frequently asked to help IT organizations comply with a broad range of PCI DSS requirements. On one hand, that creates a significant opportunity. Some even perform PCI DSS audits. But there have been complaints for years concerning how strictly those PCI DSS standards should be interpreted. In many instances, retailers shop around for auditors that interpret those standards are leniently as possible.

But more often than not, in the event of a breach, the credit card carriers almost invariably find that at the time of the breach a retailer was out of PCI DSS compliance, which makes them in the eye of the carrier liable for the loss. The trouble is that even when an organization is in PCI DSS compliance, it’s almost impossible to stay that way. Any change to the IT environment subsequent to the last PCI DSS audit usually winds up taking the retailer out of compliance. In this day and age, it’s almost impossible to go a week without having to change an IT configuration one way or another.

The NRF and the credit card issuers are involved in data security gamesmanship. It will be years before the FTC formally rules on the NRF request and even longer before any actual court battle is concluded. In the meantime, solution providers would do well to take simple note of the fact that no matter what they do in regard to PCI DSS, nobody is going to be entirely happy with the result.

Michael Vizard has been covering IT issues in the enterprise for more than 25 years as an editor and columnist for publications such as InfoWorld, eWEEK, Baseline, CRN, ComputerWorld and Digital Review.

thumbnail Michael Vizard

Michael Vizard is a seasoned IT journalist, with nearly 30 years of experience writing and editing about enterprise IT issues. He is a writer for publications including Programmableweb, IT Business Edge, CIOinsight, Channel Insider and UBM Tech. He formerly was editorial director for Ziff-Davis Enterprise, where he launched the company’s custom content division, and has also served as editor in chief for CRN and InfoWorld. He also has held editorial positions at PC Week, Computerworld and Digital Review.

Recommended for you...

Sherweb Expanding Portfolio Offerings With Expert Guidance
Jordan Smith
Aug 15, 2025
Arctic Wolf Research: Cyber Insurance Driving Security Needs
Victoria Durgin
Aug 14, 2025
Brivo Launching New Solution to Boost Security Suite
Jordan Smith
Aug 13, 2025
MetTel to Modernize Communication Lines for VA
Jordan Smith
Aug 8, 2025
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.