---
title: Payments | PCI Compliance Requirements for Merchants
description: In 2018 British Airways leaked 400,000 customer records, costing $26 million in fines. Learn how this data leak happened here!
image: https://blog.hotellinksolutions.com/hubfs/42.png
---

[Skip to content](https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants#main-content)

- [English](https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants)
- [Tiếng Việt - Việt Nam](https://blog.hotellinksolutions.com/vi-vn/tieu-chuan-bao-mat-du-lieu-the-thanh-toan-pci-compliance)

English

Show submenu for translations

[![Hotel Link\_Logo-1](https://blog.hotellinksolutions.com/hs-fs/hubfs/Hotel%20Link_Logo-1.png?width=149&height=55&name=Hotel%20Link_Logo-1.png)](https://www.hotellinksolutions.com/)

- [Core Solutions](https://www.hotellinksolutions.com/hotel-marketing-solutions)
  
  Show submenu for Core Solutions 
  
    - [Channel Manager](https://www.hotellinksolutions.com/hotel-marketing-solutions/channel-manager)
    - [Booking Engine](https://www.hotellinksolutions.com/hotel-marketing-solutions/booking-engine)
    - [Front Desk](https://www.hotellinksolutions.com/hotel-marketing-solutions/front-desk)
    - [Payments](https://www.hotellinksolutions.com/hotel-link-pay)
    - [Smart Rate](https://www.hotellinksolutions.com/hotel-marketing-solutions/smart-rate)
    - [Website](https://www.hotellinksolutions.com/hotel-marketing-solutions/website)
    - [Yield Management](https://www.hotellinksolutions.com/hotel-marketing-solutions/yield-management)
- [Premium Services](https://www.hotellinksolutions.com/premium-services/)
  
  Show submenu for Premium Services 
  
    - [Google Free Booking Links](https://www.hotellinksolutions.com/premium-services/google-free-booking-links-for-hotels/)
    - [Custom Websites](https://www.hotellinksolutions.com/premium-services/custom-websites/)
- [Blog](https://blog.hotellinksolutions.com/)

Open main navigation

Close main navigation

- [Core Solutions](https://www.hotellinksolutions.com/hotel-marketing-solutions)
  
  Show submenu for Core Solutions 
  
    - [Channel Manager](https://www.hotellinksolutions.com/hotel-marketing-solutions/channel-manager)
    - [Booking Engine](https://www.hotellinksolutions.com/hotel-marketing-solutions/booking-engine)
    - [Front Desk](https://www.hotellinksolutions.com/hotel-marketing-solutions/front-desk)
    - [Payments](https://www.hotellinksolutions.com/hotel-link-pay)
    - [Smart Rate](https://www.hotellinksolutions.com/hotel-marketing-solutions/smart-rate)
    - [Website](https://www.hotellinksolutions.com/hotel-marketing-solutions/website)
    - [Yield Management](https://www.hotellinksolutions.com/hotel-marketing-solutions/yield-management)
- [Premium Services](https://www.hotellinksolutions.com/premium-services/)
  
  Show submenu for Premium Services 
  
    - [Google Free Booking Links](https://www.hotellinksolutions.com/premium-services/google-free-booking-links-for-hotels/)
    - [Custom Websites](https://www.hotellinksolutions.com/premium-services/custom-websites/)
- [Blog](https://blog.hotellinksolutions.com/)
- - [English](https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants)
    - [Tiếng Việt - Việt Nam](https://blog.hotellinksolutions.com/vi-vn/tieu-chuan-bao-mat-du-lieu-the-thanh-toan-pci-compliance)

  English
  
  Show submenu for translations
- [Get Started!](https://www.hotellinksolutions.com/sign-up/)

[Get Started!](https://www.hotellinksolutions.com/sign-up/)

 Jan 18, 2024, 10:36:59 AM

# Payments | PCI Compliance Requirements for Merchants

![Picture of Hotel Link](https://blog.hotellinksolutions.com/hs-fs/hubfs/Hotel%20Link%20Logo_PNG/Logo%20Icon_Transparent.png?width=50&name=Logo%20Icon_Transparent.png) [Hotel Link](https://blog.hotellinksolutions.com/author/hotel-link)

Share: [facebook-f icon](http://www.facebook.com/share.php?u=https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants) [linkedin-in icon](http://www.linkedin.com/shareArticle?mini=true&url=https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants) [Twitter icon](https://twitter.com/intent/tweet?url=https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants) [pinterest-p icon](http://pinterest.com/pin/create/link/?url=https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants) [envelope icon](mailto:?body=https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants)

In 2018 British Airways leaked 400,000 customer records, costing **$26 million** in fines. Fines aren’t the only issue when it comes to ensuring your business is PCI compliant.

This article includes:

1. What is PCI Compliance?
2. The 12 requirements for PCI DSS Compliance.
3. Benefits of PCI Compliance.
4. Potential setbacks of being non-compliant.
5. Resources.

## What is PCI Compliance?

A few other potential repercussions from failure to be PCI Compliant are:

1. **Loss of Customers:** How likely do you think a customer will return to your business (hotel, restaurant…etc) after their data has been compromised?
2. **Lawsuits:** Failure to comply with PCI standards can result in lawsuits from customers, credit card companies, and even the government.
3. **Audits:** Failure to comply with PCI standards can result in an audit from the PCI Security Council, Card Companies, and yes…also the government.
4. **Tarnished Brand Image:** Best case, an unhappy customer voicing their displeasure on the internet post-data breach. Worst case, the press may likely pick up the news and make it known to your entire industry that your company can not keep sensitive data safe.

You can see why it is important to have an understanding of PCI Compliance and how to take the proper precautions in order to keep yourself safe from the issues above. Let’s dive in…

Launched September 7, 2006, [The Payment Card Industry Data Security Standard (PCI DSS)](https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security) is a set of requirements intended to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. Visa, MasterCard, American Express, Discover, and JCB created an independent body, [The PCI Security Standards Council (PCI SSC)](https://www.pcisecuritystandards.org/), that administers and manages the PCI DSS. Somewhat ironically, the payment brands and acquirers are responsible for enforcing compliance, rather than the PCI SSC.

![PCI-compliance](https://blog.hotellinksolutions.com/hs-fs/hubfs/PCI-compliance.png?width=1024&height=489&name=PCI-compliance.png)

*PCI DSS ensures the secure processing, storing, or transmitting credit card information which is complied by companies*

## The 12 requirements of PCI DSS Compliance

The PCI SSC lists out specific requirements for what is needed to become and remain compliant, the 12 commandments of PCI Compliance if you will. Abide by these requirements, and you will be much safer from a data breach and less liable to incur catastrophic fines and lawsuits.

**1. Install and maintain a firewall configuration to protect cardholder data**

Usually the first line of defense against hackers. Firewalls help prevent unauthorized access.

**2. Do not use supplied default system passwords and other security parameters**

Routers, modems, point of sale (POS) systems, Property Management Systems (PMS), and other third-party products often come with generic passwords and security measures easily accessed by the public or hackers. It is required that these are changed.

**3. Protect stored cardholder data**

Card data must be encrypted. Regular maintenance and scanning of primary account numbers (PAN) are necessary to ensure no unencrypted data exists.

**4. Encrypt transmission of cardholder data across open, public networks**

Cardholder data must be encrypted whenever it is sent to any connection for your company. Account numbers should also never be sent to any unknown locations.

**5. Use and regularly update anti-virus software or programs**

Installing anti-virus software is required for all devices that interact with and/or store PAN. This software must be regularly patched and updated.

**6. Develop and maintain secure systems and applications**

Update every piece of software in your business. These updates are especially required for all software on devices that interact with or store cardholder data.

**7. Restrict access to cardholder data by business need-to-know**

Does the hotel receptionist need to see the card data? Cardholder data is required to be strictly “need to know.” All staff, executives, and third parties who do not need access to this data should not have it. The roles that do need sensitive data should be well-documented and regularly updated.

**8. Assign a unique ID to each person with computer access**

Individuals who do have access to cardholder data should have individual credentials and identification for access.

**9. Restrict physical access to cardholder data**

Any cardholder data must be physically kept in a secure location. Both data that is physically written or typed and data that is digitally-kept (e.g., on a hard drive) should be locked in a secure room, drawer, or cabinet. Not only should access be limited, but anytime the sensitive data is accessed, it should be kept in a log to remain compliant.

**10. Track and monitor all access to network resources and cardholder data**

All activity dealing with cardholder data and primary account numbers (PAN) require a log entry. Compliance requires documenting how data flows into your organization and the number of times access is needed.

**11. Regularly test security systems and processes**

PCI DSS requires regular scans and vulnerability testing across all aspects of the business.

**12. Maintain a policy that addresses information security for employees and contractors**

Inventory of equipment, software, and employees that have access will need to be documented for compliance as well as the logs of accessing cardholder data. How information flows into your company, where it is stored, and how it is used will also all need to be documented.

## Benefits of PCI Compliance.

Complying with PCI Security Standards can seem like an impossible and costly task. The number of standards and issues seems like a lot to keep up with, especially for smaller companies with limited resources. Yet, as compliance is becoming more important it may not be such a mountain to climb with the proper tools and partners in place.

Many businesses get around all of the nuances that come with being PCI Compliant by outsourcing all of their PCI Compliance and payment requirements. Companies such as [Kovena](https://www.kovena.com/), a global payments and compliance company, store all customer information in a tokenized vault and connect to a businesses infrastructure in a PCI Compliant manner…taking all the weight off their shoulders. When looking for a partner to outsource this, make sure to choose a system that seamlessly fits into your operating structure and if possible, provides [a fully embedded system](https://www.hotellinksolutions.com/benefits-of-an-embedded-payment-system/) to help with organisational efficiencies. By either building a compliant system yourself or outsourcing this, you gain some valuable benefits.

We’ve listed just a few of the benefits to being PCI Compliant below:

1. Improves your reputation with customers by showing that your systems are secure and they can trust you with their sensitive information. More loyalty, more return customers.
2. Improves your reputation with acquirers and payment partners.
3. PCI Compliance likely leads to improving IT infrastructure efficiency, so you’re better prepared to comply with additional regulations, such as HIPAA, SOX, and others.
4. PCI Compliance is an ongoing process that aids in preventing security breaches and payment card data theft in the present and in the future; PCI compliance means you are contributing to a global payment card data security solution.

## Tools and resources available from PCI SSC:

Fortunately, the PCI Security Standards Council (SSC) provides comprehensive [standards and resources](https://www.pcisecuritystandards.org/document_library), which include specification frameworks, tools, measurements, and support resources to help organizations ensure the security of cardholder information, measures to prevent a data breach, and appropriate reaction to security incidents.

1. [Self-Assessment Questionnaires](https://www.pcisecuritystandards.org/pci_security/completing_self_assessment) to assist organizations in validating their PCI DSS compliance.
2. [PIN Transaction Security (PTS) requirements](https://www.pcisecuritystandards.org/document_library?category=pci_pin&document=pcipinpin__sec_req_pdf) for device vendors and manufacturers and a list of approved PIN transaction devices.
3. Public resources:
   
     1. [Lists of Qualified Security Assessors (QSAs)](https://www.pcisecuritystandards.org/assessors_and_solutions/qualified_security_assessors)
     2. [Payment Application Qualified Security Assessors (PA-QSAs)](https://www.pcisecuritystandards.org/assessors_and_solutions/payment_application_assessors)
     3. [Approved Scanning Vendors (ASVs)](https://www.pcisecuritystandards.org/assessors_and_solutions/approved_scanning_vendors)
     4. [Qualified PIN Assessors (QPAs)](https://www.pcisecuritystandards.org/assessors_and_solutions/qpa_assessors)
     5. [Internal Security Assessor (ISA) education program](https://www.pcisecuritystandards.org/program_training_and_qualification/internal_security_assessor_certification)

We hope this information helps on your mission to become PCI Compliant. If you have any questions or are interested in more details on how Kovena or our partners can assist you in your payments and compliance needs, please feel free to contact us using the form below.

If you’re interested in learning how you can outsource your PCI compliance, [contact us now](https://www.hotellinksolutions.com/partner-us/).

[Industry Insight](https://blog.hotellinksolutions.com/tag/industry-insight), [Hotel Management](https://blog.hotellinksolutions.com/tag/hotel-management)

## Related posts

[![Experience Seamless Payments At Your Hotel With Expedia Virtual Card!](https://blog.hotellinksolutions.com/hs-fs/hubfs/Expedia%20Virtual%20Card%20Eng%20thumbnail.png?height=200&name=Expedia%20Virtual%20Card%20Eng%20thumbnail.png)](https://blog.hotellinksolutions.com/experience-seamless-payments-at-your-hotel-with-expedia-virtual-card?hsLang=en)

[Hotel Management](https://blog.hotellinksolutions.com/tag/hotel-management)

## [Experience Seamless Payments At Your Hotel With Expedia Virtual Card!](https://blog.hotellinksolutions.com/experience-seamless-payments-at-your-hotel-with-expedia-virtual-card?hsLang=en)

[Hotel Link](https://blog.hotellinksolutions.com/author/hotel-link-1) 

 Sep 6, 2024, 3:24:27 PM

Efficient payment processing is one of the key factors to maintain stable cash flow and smooth...

[Read more](https://blog.hotellinksolutions.com/experience-seamless-payments-at-your-hotel-with-expedia-virtual-card?hsLang=en)

[![hotel link pay](https://blog.hotellinksolutions.com/hs-fs/hubfs/40.png?height=200&name=40.png)](https://blog.hotellinksolutions.com/understanding-about-hotel-link-pay?hsLang=en)

[Hotel Management](https://blog.hotellinksolutions.com/tag/hotel-management)

## [Understanding about Hotel Link Pay](https://blog.hotellinksolutions.com/understanding-about-hotel-link-pay?hsLang=en)

![Picture of Hotel Link](https://blog.hotellinksolutions.com/hs-fs/hubfs/Hotel%20Link%20Logo_PNG/Logo%20Icon_Transparent.png?width=50&name=Logo%20Icon_Transparent.png) [Hotel Link](https://blog.hotellinksolutions.com/author/hotel-link) 

 Jan 18, 2024, 10:45:25 AM

General Overview of Embedded Payment System What is an embedded payment system? An embedded payment...

[Read more](https://blog.hotellinksolutions.com/understanding-about-hotel-link-pay?hsLang=en)

[![PMS Migration: Why Small & Medium-sized Hotels Are Switching Systems in 2026](https://blog.hotellinksolutions.com/hs-fs/hubfs/Global%20Hotel%20Link/Marketing%20team/Marketing/2025/Blog%20Visual/pms-migration-why-small-and-medium-sized-hotels-hotels-are-switching-systems-in-2026-thumbnail.png?height=200&name=pms-migration-why-small-and-medium-sized-hotels-hotels-are-switching-systems-in-2026-thumbnail.png)](https://blog.hotellinksolutions.com/pms-migration-why-small-medium-sized-hotels-are-switching-systems-in-2026?hsLang=en)

[Travel Trend](https://blog.hotellinksolutions.com/tag/travel-trend)

## [PMS Migration: Why Small & Medium-sized Hotels Are Switching Systems in 2026](https://blog.hotellinksolutions.com/pms-migration-why-small-medium-sized-hotels-are-switching-systems-in-2026?hsLang=en)

[Hotel Link](https://blog.hotellinksolutions.com/author/hotel-link-1) 

 Aug 18, 2026, 1:55:47 PM

In the 2026 hospitality technology landscape, Property Management System (PMS) migration is...

[Read more](https://blog.hotellinksolutions.com/pms-migration-why-small-medium-sized-hotels-are-switching-systems-in-2026?hsLang=en)

[![Logo Icon\_Transparent](https://blog.hotellinksolutions.com/hs-fs/hubfs/Logo%20Icon_Transparent.png?width=88&height=88&name=Logo%20Icon_Transparent.png "Logo Icon_Transparent")](https://www.hotellinksolutions.com/)

**More Info**

- [Integrations](https://www.hotellinksolutions.com/ota-pms-integrations)
- [Marketing e-Book](https://www.hotellinksolutions.com/online-marketing-guide-for-accommodations)
- [Our Local Partners](https://www.hotellinksolutions.com/local-partners)
- [Become a Partner](https://www.hotellinksolutions.com/become-a-partner)
- [Referrals Program](https://www.hotellinksolutions.com/customers-referrals-program)

**Payments**

- [Hotel Link Pay](https://www.hotellinksolutions.com/hotel-link-pay)
- [Terms of Service](https://www.hotellinksolutions.com/hotel-link-pay-terms-of-service)
- [FAQs](https://www.hotellinksolutions.com/hotel-link-pay-faqs)

**Company**

- [Contact Us](https://www.hotellinksolutions.com/partner-us)
- [About Us](https://www.hotellinksolutions.com/about-us)

**Dowload the App**

[![app-store-2](https://blog.hotellinksolutions.com/hs-fs/hubfs/app-store-2.png?width=120&height=40&name=app-store-2.png "app-store-2")](https://apps.apple.com/app/id1498157206)

[![google-play](https://blog.hotellinksolutions.com/hs-fs/hubfs/google-play.png?width=120&height=40&name=google-play.png "google-play")](https://play.google.com/store/apps/details?id=com.hotellinksolutions.HotelLink&pcampaignid=pcampaignidMKT-Other-global-all-co-prtnr-py-PartBadge-Mar2515-1)

**Connect Us**

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png)](https://www.facebook.com/hotellink.official) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png)](https://www.linkedin.com/company/hotel-link-solutions/) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png)](https://twitter.com/HotelLink_GB)

**Journey of Excellence**

[![Booking\_CPP\_Badge\_PP\_Premier\_Blue](https://blog.hotellinksolutions.com/hs-fs/hubfs/Booking_CPP_Badge_PP_Premier_Blue.png?width=185&height=52&name=Booking_CPP_Badge_PP_Premier_Blue.png "Booking_CPP_Badge_PP_Premier_Blue")](https://www.hotellinksolutions.com/hotel-link-officially-becomes-booking-com-premier-connectivity-partner-2023/)

[![EG-Preferred](https://blog.hotellinksolutions.com/hs-fs/hubfs/EG-Preferred.png?width=99&height=50&name=EG-Preferred.png "EG-Preferred")](https://blog.hotellinksolutions.com/hotel-link-awarded-expedia-group-2024-preferred-partner-status?hsLang=en)

**Journey of Excellence**

[![Booking\_Com\_Logotype\_Aug2020\_Blue](https://blog.hotellinksolutions.com/hs-fs/hubfs/Booking_Com_Logotype_Aug2020_Blue.png?width=176&height=52&name=Booking_Com_Logotype_Aug2020_Blue.png "Booking_Com_Logotype_Aug2020_Blue")](https://www.hotellinksolutions.com/hotel-link-officially-becomes-booking-com-premier-connectivity-partner-2023/)

[![EG-Preferred](https://blog.hotellinksolutions.com/hs-fs/hubfs/EG-Preferred.png?width=104&height=52&name=EG-Preferred.png "EG-Preferred")](https://www.hotellinksolutions.com/hotel-link-officially-becomes-booking-com-premier-connectivity-partner-2023/)

[![Agoda\_Image badge 800x800\_Preferred@2x](https://blog.hotellinksolutions.com/hs-fs/hubfs/Agoda_Image%20badge%20800x800_Preferred@2x.png?width=1600&height=400&name=Agoda_Image%20badge%20800x800_Preferred@2x.png "Agoda_Image badge 800x800_Preferred@2x")](https://www.hotellinksolutions.com/hotel-link-officially-becomes-booking-com-premier-connectivity-partner-2023/)

[![tripcom-badge (1)](https://blog.hotellinksolutions.com/hs-fs/hubfs/tripcom-badge%20(1).png?width=150&height=51&name=tripcom-badge%20(1).png "tripcom-badge (1)")](https://www.hotellinksolutions.com/hotel-link-officially-becomes-booking-com-premier-connectivity-partner-2023/)

© 2026 Hotel Link Solutions Limited

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Hotel Link",
    "url" : "https://blog.hotellinksolutions.com/author/hotel-link"
  },
  "dateModified" : "2024-03-24T20:16:42.549Z",
  "datePublished" : "2024-01-18T03:36:59.000Z",
  "headline" : "Payments | PCI Compliance Requirements for Merchants",
  "image" : [ "https://blog.hotellinksolutions.com/hubfs/42.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.hotellinksolutions.com/payments-pci-compliance-requirements-for-merchants",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.hotellinksolutions.com/hubfs/Hotel-Link_Logo.png"
    },
    "name" : "Hotel Link"
  }
}
```