Español Français Deutsch Italiano Nederlands Svenska Dansk Japanese Chinese (Simplified) Russian
 
AVForums.com twitter AVForums is a member of CEDIA. THX certified reviewer.  Click for more information. AVForums reviewers are ISF Certified.  Click for more information.
 
The UK's biggest and best home entertainment electronics forums  
4 million visitors each month


Forums Register Blogs Information Social Groups Search Today's Posts Mark Forums Read
Go Back   AVForums.com > Lifestyle Topics > General Chat

Latest AVForums Movie Reviews
Gray Lady Down - Original Motion Picture Soundtrack CD ReviewUp Blu-ray ReviewLéon Blu-ray ReviewNear Dark Blu-ray ReviewLogan's Run Blu-ray Review
Taking of Pelham 1 2 3, The Blu-ray ReviewStar Trek Blu-ray ReviewUFC 100: Lesnar vs. Mir (2009) Blu-ray ReviewThe New York Ripper Blu-ray ReviewHeat Blu-ray Review


Reply
 
Thread Tools Display Modes
Old 06-02-2007, 2:45 PM   #1 (permalink)
Member
 
Join Date: Sep 2006
Location: Berkshire
Posts: 666
Thanks: Gave 74, Got 64
What's the law on websites holding card details?

I've been going through some shopping websites removing my card details from them because I no longer use the sites. I managed to delete my card from a few until I got to a certain one which I won't name. They had no option on the site to remove my details, so I emailed them to which they replied asking why I wanted to take my details off. I explained I was removing my card from some websites. The reply I got was:

Quote:
Hi,

Your card is secure with us.

By law we have to keep all transactions details for 6 years therefore we
can't really cancel your details

Sorry I can't help you at this time

Regards

If that's the case, how come I can easily remove my details from other sites? I thought it was illegal for anyone to hold card details without my permission.
BrokenArrow is offline   Reply With Quote
Old 06-02-2007, 2:47 PM   #2 (permalink)
Conspicuous Member
 
Singh400's Avatar
 
Join Date: Feb 2006
Location: Earth
Posts: 8,364
Thanks: Gave 507, Got 1,150
Re: What's the law on websites holding card details?

Tell them to link you to the law that requires this.
__________________
[CPU: Q9450 @ 3.6Ghz|RAM: Corsair PC2-8500 (2x2GB)]
[MOBO: Asus P5Q Deluxe (1406)|HDD#1: Samsung F1 750GB]
[HDD#2: OCZ SSD V1 32GB|GFX: BFG 9800GTX+ OC|PSU: Corsair HX 620W]
Singh400 is offline   Reply With Quote
Old 06-02-2007, 2:52 PM   #3 (permalink)
Member
 
Paul_HDLover's Avatar
 
Join Date: Jan 2007
Location: Edinburgh
Posts: 323
Thanks: Gave 171, Got 77
Re: What's the law on websites holding card details?

My understanding is that all information a company holds on you, including your original application for services, which would subsequently include your bank details must be held for a period of 6 years before being securely destroyed.

This is for audit purposes and must be satisfied by law.

The other companies may have allowed you to delete your details, but they are still held historically I reckon, and will remain in this state for 6 years.

The thing with systems is that just because you cant see it anymore, by no means confirms they arent there as more often than not its all recorded and archived.
Paul_HDLover is offline   Reply With Quote
Thanks from:
BrokenArrow (06-02-2007)
Old 06-02-2007, 3:28 PM   #4 (permalink)
Senior Member
 
Mr_Wistles's Avatar
 
Join Date: Mar 2004
Location: Essex
Posts: 2,798
Thanks: Gave 73, Got 384
Re: What's the law on websites holding card details?

Quote:
Originally Posted by Paul_HDLover View Post
The thing with systems is that just because you cant see it anymore, by no means confirms they arent there as more often than not its all recorded and archived.
This is my understanding also.

I don't store card details but the banks I use do, I however cannot see them.
Mr_Wistles is offline   Reply With Quote
Old 06-02-2007, 3:33 PM   #5 (permalink)
Veteran Member
 
pixelpixel's Avatar
 
Join Date: Jul 2005
Location: mickey marley's roundabout
Posts: 6,320
Thanks: Gave 811, Got 704
Re: What's the law on websites holding card details?

Quote:
Originally Posted by Paul_HDLover View Post
My understanding is that all information a company holds on you, including your original application for services, which would subsequently include your bank details must be held for a period of 6 years before being securely destroyed.

This is for audit purposes and must be satisfied by law.

The other companies may have allowed you to delete your details, but they are still held historically I reckon, and will remain in this state for 6 years.

The thing with systems is that just because you cant see it anymore, by no means confirms they arent there as more often than not its all recorded and archived.
Yes correct, the details are removed from public view but for audit reasons your another number they need to store.

Have a look at http://www.out-law.com/page-431
__________________
:: Flickr ::
pixelpixel is online now   Reply With Quote
Thanks from:
BrokenArrow (06-02-2007)
Old 06-02-2007, 3:57 PM   #6 (permalink)
Member
 
Join Date: May 2003
Location: Munich
Posts: 574
Thanks: Gave 19, Got 48
Re: What's the law on websites holding card details?

My company (Amadeus) is currently undergoing a PCI (Payment Card Industry) audit. This is driven mainly by the large credit card companies such as Visa, Mastercard, Amex etc, but covers all forms of payment cards.

You can check out a bit more about it here if you're interested https://www.pcisecuritystandards.org/ but basically we have to justify to a team of independant authorised auditors (Deloitte Touche in our case) why we store payment card details, how we protect them, how we control access etc. In many cases we are being forced to change processes because they fall foul of the PCI standards. They are very thorough, and whilst they might not be so vigilant on a smaller company, they have the ability to prevent us accepting payment via card if we fail to satisfy the auditors. This would be disastrous to most businesses today, as you can imagine.

Some of the requirements do conflict with national laws to keep financial data for certain periods of time, but where this is the case, the security of the data is even more paramount.

Whilst I'd prefer no-one kept my credit card details, I think in this day and age that's not really practical, but I do think this initiative will make that data as secure as it can be.
KeithO is offline   Reply With Quote
Thanks from:
BrokenArrow (06-02-2007)
Old 06-02-2007, 3:59 PM   #7 (permalink)
Member
 
Join Date: Sep 2006
Location: Berkshire
Posts: 666
Thanks: Gave 74, Got 64
Re: What's the law on websites holding card details?

Thanks for clearing things up.

I don't mind them keeping details for audits. But it's the "removed from public view" bit that I've got problems with. Are audit details kept online?

I was sent another email saying "Will be easy and simple cancel the card and will be more secure for you". I don't want to cancel my card. They then said if I was worried I shouldn't bother to ever buy anything online.

Last edited by BrokenArrow; 06-02-2007 at 4:02 PM.
BrokenArrow is offline   Reply With Quote
Old 06-02-2007, 4:03 PM   #8 (permalink)
Member
 
Paul_HDLover's Avatar
 
Join Date: Jan 2007
Location: Edinburgh
Posts: 323
Thanks: Gave 171, Got 77
Re: What's the law on websites holding card details?

Quote:
Originally Posted by BrokenArrow View Post
I don't mind them keeping details for audits. But it's the "removed from public view" bit that I've got problems with. Are audit details kept online?

I was sent another email saying "Will be easy and simple cancel the card and will be more secure for you". I don't want to cancel my card. They then said if I was worried I shouldn't bother to ever buy anything online.
talking generally (As I dont know what company it is you are dealing with) Websites talk to databases. In the easiest way possible to explain a typical web application, when you buy something and are already a member, the website will display your current data. If you have cancelled your account or card, using your example when you log into your account, you see no details. Your details will however exist on the database still, but with a flag set showing your details as historic. This means when you pull a page requesting to see your details, it omits any data where this historic flag is set.

Sometimes this data is held in the same table, sometimes archived data is held in separate secure tables. In any case the environment is highly secure with only select DBA's allowed to access and even then their actions are traced.

Hope this gives you an idea of how your information is being looked after.
Paul_HDLover is offline   Reply With Quote
Old 06-02-2007, 4:19 PM   #9 (permalink)
Senior Member
 
Join Date: Nov 2004
Posts: 2,232
Thanks: Gave 53, Got 199
Re: What's the law on websites holding card details?

Quote:
Originally Posted by BrokenArrow View Post
I've been going through some shopping websites removing my card details from them because I no longer use the sites. I managed to delete my card from a few until I got to a certain one which I won't name. They had no option on the site to remove my details, so I emailed them to which they replied asking why I wanted to take my details off. I explained I was removing my card from some websites. The reply I got was:




If that's the case, how come I can easily remove my details from other sites? I thought it was illegal for anyone to hold card details without my permission.
Sure they keep transaction history. But that does not mean they are incapable of removing the C-C details from its 'on-line part'.
Of course if they have a poorly designed and managed system (those pesky PFCSKs..) it may be more difficult...Those other sites maybe have better systems but bearing in mind the number of off the shelf e-commerce solutions out there it seems likely that the site in question probably has the same capabilities. (name 'em, you will not be accusing them of anything, merely stating the facts of your customer experience).

Sounds like the brush off to me...
Send 'em a data protection subject access request maybe...
Steve.J.Davies is offline   Reply With Quote
Old 06-02-2007, 4:26 PM   #10 (permalink)
Senior Member
 
Join Date: Nov 2004
Posts: 2,232
Thanks: Gave 53, Got 199
Re: What's the law on websites holding card details?

Quote:
Originally Posted by Paul_HDLover View Post
talking generally (As I dont know what company it is you are dealing with) Websites talk to databases. In the easiest way possible to explain a typical web application, when you buy something and are already a member, the website will display your current data. If you have cancelled your account or card, using your example when you log into your account, you see no details. Your details will however exist on the database still, but with a flag set showing your details as historic. This means when you pull a page requesting to see your details, it omits any data where this historic flag is set.

Sometimes this data is held in the same table, sometimes archived data is held in separate secure tables. In any case the environment is highly secure with only select DBA's allowed to access and even then their actions are traced.

Hope this gives you an idea of how your information is being looked after.
You are right in that iit should be done along those lines. Often when you look under the covers though the reality is not so well delineated (have looked under a lot of covers...). prod data leaking into test, poor GRANTS, priviledge escalation, expediency subverting good practice etc etc.
Fact is that unless you look real close there is no way to tell. A surprising number of large (well known) companies have dodgy practices. Heck half of them are below average to start with
Steve.J.Davies is offline   Reply With Quote
Old 06-02-2007, 4:27 PM   #11 (permalink)
Member
 
Paul_HDLover's Avatar
 
Join Date: Jan 2007
Location: Edinburgh
Posts: 323
Thanks: Gave 171, Got 77
Re: What's the law on websites holding card details?

A Subject access request is essentially an audit albeit usually from the client, but can be instructed by other parties such as external auditors. Its due to SAR's and the necessity to audit financial records, that these details are held in the first place.
Paul_HDLover is offline   Reply With Quote
Old 06-02-2007, 4:45 PM   #12 (permalink)
Veteran Member
 
pixelpixel's Avatar
 
Join Date: Jul 2005
Location: mickey marley's roundabout
Posts: 6,320
Thanks: Gave 811, Got 704
Re: What's the law on websites holding card details?

Quote:
Originally Posted by KeithO View Post
My company (Amadeus) is currently undergoing a PCI (Payment Card Industry) audit. This is driven mainly by the large credit card companies such as Visa, Mastercard, Amex etc, but covers all forms of payment cards.

You can check out a bit more about it here if you're interested https://www.pcisecuritystandards.org/ but basically we have to justify to a team of independant authorised auditors (Deloitte Touche in our case) why we store payment card details, how we protect them, how we control access etc. In many cases we are being forced to change processes because they fall foul of the PCI standards. They are very thorough, and whilst they might not be so vigilant on a smaller company, they have the ability to prevent us accepting payment via card if we fail to satisfy the auditors. This would be disastrous to most businesses today, as you can imagine.

Some of the requirements do conflict with national laws to keep financial data for certain periods of time, but where this is the case, the security of the data is even more paramount.

Whilst I'd prefer no-one kept my credit card details, I think in this day and age that's not really practical, but I do think this initiative will make that data as secure as it can be.
Oh forgot about this.....I remember the fun and games. Good Luck.
__________________
:: Flickr ::
pixelpixel is online now   Reply With Quote
Thanks from:
KeithO (06-02-2007)
Old 06-02-2007, 5:02 PM   #13 (permalink)
Member
 
Join Date: Sep 2006
Location: Berkshire
Posts: 666
Thanks: Gave 74, Got 64
Re: What's the law on websites holding card details?

Thanks for the info, everyone. They say ignorance is bliss, but knowing what I do now I'm not so peeved.


Quote:
Originally Posted by Steve.J.Davies View Post
(name 'em, you will not be accusing them of anything, merely stating the facts of your customer experience).
Nah, I just wanted to know what they were on about, not start a potential slagging off.
BrokenArrow is offline   Reply With Quote
Old 06-02-2007, 5:18 PM   #14 (permalink)
Member
 
Join Date: Nov 2005
Posts: 213
Thanks: Gave 11, Got 56
Re: What's the law on websites holding card details?

As far as I'm aware, they have no right to hold your credit card details... They don't need them for any form of identification or anything, as whoever they submit your details to to take payment from your card (the bank) provides them with a unique reference that is used to trace this information if it's ever needed by auditors or the like.

You CAN ask them if they've got your CV2 data stored (the 3 digit number on your sig strip). If they have (which is illegal), or they have marked your card as "verified" (i.e. "they've supplied the CV2 number before, so we know they're legit"), you can ask them to un-mark your card - so no-one who gets onto their system can use your card without re-providing the CV2 number.

Not all payment gateways take the CV2 number though, so this might not be of any help!
__________________
“The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it”
OldAndSenile is offline   Reply With Quote
Thanks from:
BrokenArrow (06-02-2007)
Old 06-02-2007, 5:45 PM   #15 (permalink)
Moderator
 
LFC_SL's Avatar
 
Join Date: Feb 2005
Posts: 13,990
Thanks: Gave 969, Got 1,851
Blog Entries: 6
Re: What's the law on websites holding card details?

Interesting OldAndSenile. Every site I shop on asks me to re-enter my CV2 number, implying to me that they don't store it. Amazon UK are the only site that never asks to double check the details. I think I've only been asked to do so once in 6 months of purchases. Oh well!
__________________
Opinions expressed here are my own and do not represent those of the AV Forums or its associated websites
Selling my Aluminium Macbook | Trading Rules - Read for Your Protection | DVDs
LFC_SL is offline   Reply With Quote



Bookmarks

Tags
card, details, holding, law, websites
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


All times are GMT. The time now is 8:11 AM.

AV Forums
Optimised for Firefox.
RSS Feed
AVForums.com is owned and operated by M2N Limited.
Copyright © 2000-2009 M2N E. & O. E.
Global Gold
Web Hosting