 | | |
06-02-2007, 2:45 PM
|
#1 (permalink)
| | Member
Join Date: Sep 2006 Location: Berkshire
Posts: 666
Thanks: Gave 74, Got 64 | What's the law on websites holding card details?
I've been going through some shopping websites removing my card details from them because I no longer use the sites. I managed to delete my card from a few until I got to a certain one which I won't name. They had no option on the site to remove my details, so I emailed them to which they replied asking why I wanted to take my details off. I explained I was removing my card from some websites. The reply I got was: Quote:
Hi,
Your card is secure with us.
By law we have to keep all transactions details for 6 years therefore we
can't really cancel your details
Sorry I can't help you at this time
Regards
|
If that's the case, how come I can easily remove my details from other sites? I thought it was illegal for anyone to hold card details without my permission.
|
| |
06-02-2007, 2:47 PM
|
#2 (permalink)
| | Conspicuous Member
Join Date: Feb 2006 Location: Earth
Posts: 8,364
Thanks: Gave 507, Got 1,150 | Re: What's the law on websites holding card details?
Tell them to link you to the law that requires this.
__________________ [CPU: Q9450 @ 3.6Ghz|RAM: Corsair PC2-8500 (2x2GB)] [MOBO: Asus P5Q Deluxe (1406)|HDD#1: Samsung F1 750GB] [HDD#2: OCZ SSD V1 32GB|GFX: BFG 9800GTX+ OC|PSU: Corsair HX 620W] |
| |
06-02-2007, 2:52 PM
|
#3 (permalink)
| | Member
Join Date: Jan 2007 Location: Edinburgh
Posts: 323
Thanks: Gave 171, Got 77 | Re: What's the law on websites holding card details?
My understanding is that all information a company holds on you, including your original application for services, which would subsequently include your bank details must be held for a period of 6 years before being securely destroyed.
This is for audit purposes and must be satisfied by law.
The other companies may have allowed you to delete your details, but they are still held historically I reckon, and will remain in this state for 6 years.
The thing with systems is that just because you cant see it anymore, by no means confirms they arent there as more often than not its all recorded and archived.
|
| |
06-02-2007, 3:28 PM
|
#4 (permalink)
| | Senior Member
Join Date: Mar 2004 Location: Essex
Posts: 2,798
Thanks: Gave 73, Got 384 | Re: What's the law on websites holding card details? Quote:
Originally Posted by Paul_HDLover The thing with systems is that just because you cant see it anymore, by no means confirms they arent there as more often than not its all recorded and archived. | This is my understanding also.
I don't store card details but the banks I use do, I however cannot see them.
|
| |
06-02-2007, 3:33 PM
|
#5 (permalink)
| | Veteran Member
Join Date: Jul 2005 Location: mickey marley's roundabout
Posts: 6,320
Thanks: Gave 811, Got 704 | Re: What's the law on websites holding card details? Quote:
Originally Posted by Paul_HDLover My understanding is that all information a company holds on you, including your original application for services, which would subsequently include your bank details must be held for a period of 6 years before being securely destroyed.
This is for audit purposes and must be satisfied by law.
The other companies may have allowed you to delete your details, but they are still held historically I reckon, and will remain in this state for 6 years.
The thing with systems is that just because you cant see it anymore, by no means confirms they arent there as more often than not its all recorded and archived. | Yes correct, the details are removed from public view but for audit reasons your another number they need to store.
Have a look at http://www.out-law.com/page-431
__________________ :: Flickr :: |
| |
06-02-2007, 3:57 PM
|
#6 (permalink)
| | Member
Join Date: May 2003 Location: Munich
Posts: 574
Thanks: Gave 19, Got 48 | Re: What's the law on websites holding card details?
My company (Amadeus) is currently undergoing a PCI (Payment Card Industry) audit. This is driven mainly by the large credit card companies such as Visa, Mastercard, Amex etc, but covers all forms of payment cards.
You can check out a bit more about it here if you're interested https://www.pcisecuritystandards.org/ but basically we have to justify to a team of independant authorised auditors (Deloitte Touche in our case) why we store payment card details, how we protect them, how we control access etc. In many cases we are being forced to change processes because they fall foul of the PCI standards. They are very thorough, and whilst they might not be so vigilant on a smaller company, they have the ability to prevent us accepting payment via card if we fail to satisfy the auditors. This would be disastrous to most businesses today, as you can imagine.
Some of the requirements do conflict with national laws to keep financial data for certain periods of time, but where this is the case, the security of the data is even more paramount.
Whilst I'd prefer no-one kept my credit card details, I think in this day and age that's not really practical, but I do think this initiative will make that data as secure as it can be.
|
| |
06-02-2007, 3:59 PM
|
#7 (permalink)
| | Member
Join Date: Sep 2006 Location: Berkshire
Posts: 666
Thanks: Gave 74, Got 64 | Re: What's the law on websites holding card details?
Thanks for clearing things up.
I don't mind them keeping details for audits. But it's the "removed from public view" bit that I've got problems with. Are audit details kept online?
I was sent another email saying "Will be easy and simple cancel the card and will be more secure for you". I don't want to cancel my card.  They then said if I was worried I shouldn't bother to ever buy anything online.
Last edited by BrokenArrow; 06-02-2007 at 4:02 PM.
|
| |
06-02-2007, 4:03 PM
|
#8 (permalink)
| | Member
Join Date: Jan 2007 Location: Edinburgh
Posts: 323
Thanks: Gave 171, Got 77 | Re: What's the law on websites holding card details? Quote:
Originally Posted by BrokenArrow I don't mind them keeping details for audits. But it's the "removed from public view" bit that I've got problems with. Are audit details kept online?
I was sent another email saying "Will be easy and simple cancel the card and will be more secure for you". I don't want to cancel my card.  They then said if I was worried I shouldn't bother to ever buy anything online. | talking generally (As I dont know what company it is you are dealing with) Websites talk to databases. In the easiest way possible to explain a typical web application, when you buy something and are already a member, the website will display your current data. If you have cancelled your account or card, using your example when you log into your account, you see no details. Your details will however exist on the database still, but with a flag set showing your details as historic. This means when you pull a page requesting to see your details, it omits any data where this historic flag is set.
Sometimes this data is held in the same table, sometimes archived data is held in separate secure tables. In any case the environment is highly secure with only select DBA's allowed to access and even then their actions are traced.
Hope this gives you an idea of how your information is being looked after.
|
| |
06-02-2007, 4:19 PM
|
#9 (permalink)
| | Senior Member
Join Date: Nov 2004
Posts: 2,232
Thanks: Gave 53, Got 199 | Re: What's the law on websites holding card details? Quote:
Originally Posted by BrokenArrow I've been going through some shopping websites removing my card details from them because I no longer use the sites. I managed to delete my card from a few until I got to a certain one which I won't name. They had no option on the site to remove my details, so I emailed them to which they replied asking why I wanted to take my details off. I explained I was removing my card from some websites. The reply I got was:
If that's the case, how come I can easily remove my details from other sites? I thought it was illegal for anyone to hold card details without my permission. | Sure they keep transaction history. But that does not mean they are incapable of removing the C-C details from its 'on-line part'.
Of course if they have a poorly designed and managed system (those pesky PFCSKs..) it may be more difficult...Those other sites maybe have better systems but bearing in mind the number of off the shelf e-commerce solutions out there it seems likely that the site in question probably has the same capabilities. (name 'em, you will not be accusing them of anything, merely stating the facts of your customer experience).
Sounds like the brush off to me...
Send 'em a data protection subject access request maybe...
|
| |
06-02-2007, 4:26 PM
|
#10 (permalink)
| | Senior Member
Join Date: Nov 2004
Posts: 2,232
Thanks: Gave 53, Got 199 | Re: What's the law on websites holding card details? Quote:
Originally Posted by Paul_HDLover talking generally (As I dont know what company it is you are dealing with) Websites talk to databases. In the easiest way possible to explain a typical web application, when you buy something and are already a member, the website will display your current data. If you have cancelled your account or card, using your example when you log into your account, you see no details. Your details will however exist on the database still, but with a flag set showing your details as historic. This means when you pull a page requesting to see your details, it omits any data where this historic flag is set.
Sometimes this data is held in the same table, sometimes archived data is held in separate secure tables. In any case the environment is highly secure with only select DBA's allowed to access and even then their actions are traced.
Hope this gives you an idea of how your information is being looked after. | You are right in that iit should be done along those lines. Often when you look under the covers though the reality is not so well delineated (have looked under a lot of covers...). prod data leaking into test, poor GRANTS, priviledge escalation, expediency subverting good practice etc etc.
Fact is that unless you look real close there is no way to tell. A surprising number of large (well known) companies have dodgy practices. Heck half of them are below average to start with |
| |
06-02-2007, 4:27 PM
|
#11 (permalink)
| | Member
Join Date: Jan 2007 Location: Edinburgh
Posts: 323
Thanks: Gave 171, Got 77 | Re: What's the law on websites holding card details?
A Subject access request is essentially an audit albeit usually from the client, but can be instructed by other parties such as external auditors. Its due to SAR's and the necessity to audit financial records, that these details are held in the first place.
|
| |
06-02-2007, 4:45 PM
|
#12 (permalink)
| | Veteran Member
Join Date: Jul 2005 Location: mickey marley's roundabout
Posts: 6,320
Thanks: Gave 811, Got 704 | Re: What's the law on websites holding card details? Quote:
Originally Posted by KeithO My company (Amadeus) is currently undergoing a PCI (Payment Card Industry) audit. This is driven mainly by the large credit card companies such as Visa, Mastercard, Amex etc, but covers all forms of payment cards.
You can check out a bit more about it here if you're interested https://www.pcisecuritystandards.org/ but basically we have to justify to a team of independant authorised auditors (Deloitte Touche in our case) why we store payment card details, how we protect them, how we control access etc. In many cases we are being forced to change processes because they fall foul of the PCI standards. They are very thorough, and whilst they might not be so vigilant on a smaller company, they have the ability to prevent us accepting payment via card if we fail to satisfy the auditors. This would be disastrous to most businesses today, as you can imagine.
Some of the requirements do conflict with national laws to keep financial data for certain periods of time, but where this is the case, the security of the data is even more paramount.
Whilst I'd prefer no-one kept my credit card details, I think in this day and age that's not really practical, but I do think this initiative will make that data as secure as it can be. | Oh forgot about this.....I remember the fun and games. Good Luck.
__________________ :: Flickr :: |
| |
06-02-2007, 5:02 PM
|
#13 (permalink)
| | Member
Join Date: Sep 2006 Location: Berkshire
Posts: 666
Thanks: Gave 74, Got 64 | Re: What's the law on websites holding card details?
Thanks for the info, everyone. They say ignorance is bliss, but knowing what I do now I'm not so peeved. Quote:
Originally Posted by Steve.J.Davies (name 'em, you will not be accusing them of anything, merely stating the facts of your customer experience). | Nah, I just wanted to know what they were on about, not start a potential slagging off.
|
| |
06-02-2007, 5:18 PM
|
#14 (permalink)
| | Member
Join Date: Nov 2005
Posts: 213
Thanks: Gave 11, Got 56 | Re: What's the law on websites holding card details?
As far as I'm aware, they have no right to hold your credit card details... They don't need them for any form of identification or anything, as whoever they submit your details to to take payment from your card (the bank) provides them with a unique reference that is used to trace this information if it's ever needed by auditors or the like.
You CAN ask them if they've got your CV2 data stored (the 3 digit number on your sig strip). If they have (which is illegal), or they have marked your card as "verified" (i.e. "they've supplied the CV2 number before, so we know they're legit"), you can ask them to un-mark your card - so no-one who gets onto their system can use your card without re-providing the CV2 number.
Not all payment gateways take the CV2 number though, so this might not be of any help!
__________________ “The trouble with having an open mind, of course, is that people will insist on coming along and trying to put things in it” |
| |
06-02-2007, 5:45 PM
|
#15 (permalink)
| | Moderator
Join Date: Feb 2005
Posts: 13,990
Thanks: Gave 969, Got 1,851 | Re: What's the law on websites holding card details?
Interesting OldAndSenile. Every site I shop on asks me to re-enter my CV2 number, implying to me that they don't store it. Amazon UK are the only site that never asks to double check the details. I think I've only been asked to do so once in 6 months of purchases. Oh well!
__________________ Opinions expressed here are my own and do not represent those of the AV Forums or its associated websites |
| | | |