GDPR / KYC type question for online purchase
GDPR / KYC type question for online purchase
Author
Discussion

anonymous-user

Original Poster:

84 months

Wednesday 22nd August 2018
quotequote all
Interested in views on this one

Ordered, by phone, some paving stones from a builder's merchant. Paid by VISA card by giving the the card details over the phone.

Then, an hour or so later, this email arrives

"Thank you very much for the Order you have placed with ****.

Please be advised that due to the Value of your Order, it is currently on HOLD. We are not verified by Visa and therefore have to conduct in-house security checks on any order over a certain amount to help prevent fraudulent transactions.

Could you please provide 2 forms of ID: Driving License/Utility Bill to confirm Billing Address details. Please feel free to reply via this email or send via Text **** FAO Security). Please note this does not include passports or headed paper, as it has to be two official forms of ID showing your billing address, and if it is a utility bill it must be dated within the last three months.
Please also provide a landline telephone number (if you haven't already provided).

The lead time will re-start from the day after ID is provided.

Kind Regards,
The Security Team"

Let's presume the email is real for now (easy to check tomorrow and the phone numbers / other stuff on the email do stack up).

I am not willing to participate in this "in house security check." My view is that the business should be a member of verified by visa if it feels such things are important

Moreover, I am not sure they have any right to collect / handle such information in this way.

Anyone with knowledge on the relevant rules able to comment?

Butter Face

34,875 posts

190 months

Wednesday 22nd August 2018
quotequote all
Sounds scammy as fk.

anonymous-user

Original Poster:

84 months

Wednesday 22nd August 2018
quotequote all
Butter Face said:
Sounds scammy as fk.
I don't think it is scammy.

Card not present transactions aren't the best way to sell things and I think they are trying to avoid being defrauded, but don't want to pay the verified by visa fee (or can't join that scheme for some other reason).

The place is only down the road, so my offer to them will be that I will go to the shop and conclude the transaction through chip & pin

If that doesn't do it for them, then they are choosing to walk away from the order

That is their choice

I will seek an official view by reporting the email to the ICO

Vaud

59,562 posts

185 months

Wednesday 22nd August 2018
quotequote all
Find a different supplier? Those that can't be bothered (or perhaps have had withdrawn by the provider) to be verified are probably the same companies that might then be lax with the storage of your proof of identity??

TooMany2cvs

29,008 posts

156 months

Wednesday 22nd August 2018
quotequote all
JPJPJP said:
I am not willing to participate in this "in house security check."
Cancel the order, then.

Mojooo

13,291 posts

210 months

Wednesday 22nd August 2018
quotequote all
If you consent to it I am not sure what the problem is with them holding the data.

Vaud

59,562 posts

185 months

Wednesday 22nd August 2018
quotequote all
Mojooo said:
If you consent to it I am not sure what the problem is with them holding the data.
See my comment. I'd be asking why they aren't verified. It's not a hard process.

deckster

9,631 posts

285 months

Wednesday 22nd August 2018
quotequote all
JPJPJP said:
I don't think it is scammy.

Card not present transactions aren't the best way to sell things and I think they are trying to avoid being defrauded, but don't want to pay the verified by visa fee (or can't join that scheme for some other reason).

The place is only down the road, so my offer to them will be that I will go to the shop and conclude the transaction through chip & pin

If that doesn't do it for them, then they are choosing to walk away from the order

That is their choice

I will seek an official view by reporting the email to the ICO
I agree it's a pain in the bum and clearly absolutely your prerogative to walk away from the order. But why do you think the ICO will be interested?

Gavia

7,627 posts

121 months

Wednesday 22nd August 2018
quotequote all
JPJPJP said:
Interested in views on this one

Ordered, by phone, some paving stones from a builder's merchant. Paid by VISA card by giving the the card details over the phone.

Then, an hour or so later, this email arrives

"Thank you very much for the Order you have placed with ****.

Please be advised that due to the Value of your Order, it is currently on HOLD. We are not verified by Visa and therefore have to conduct in-house security checks on any order over a certain amount to help prevent fraudulent transactions.

Could you please provide 2 forms of ID: Driving License/Utility Bill to confirm Billing Address details. Please feel free to reply via this email or send via Text **** FAO Security). Please note this does not include passports or headed paper, as it has to be two official forms of ID showing your billing address, and if it is a utility bill it must be dated within the last three months.
Please also provide a landline telephone number (if you haven't already provided).

The lead time will re-start from the day after ID is provided.

Kind Regards,
The Security Team"

Let's presume the email is real for now (easy to check tomorrow and the phone numbers / other stuff on the email do stack up).

I am not willing to participate in this "in house security check." My view is that the business should be a member of verified by visa if it feels such things are important

Moreover, I am not sure they have any right to collect / handle such information in this way.

Anyone with knowledge on the relevant rules able to comment?
What has any of this got to do with GDPR? The way some on here discuss it, you’d think it meant that all companies have been banned from holding any data about any customer and the penalty for holding it is immediate death by firing squad for all directors, employees and subcontractors.

GDPR was a tightening up of some of the DPA rules around marketing and ways of contacting Joe Public. It really isn’t much else.

rallycross

13,752 posts

267 months

Thursday 23rd August 2018
quotequote all
This is a good thing, and has nothing to do with GDPR.

This is your bank/card/lender (you chose) making sure this is a genuine transaction/purchase by you the account holder.

Remote card payments are at the top of the list for these checks, the security models will also pick out unusual transactions and transactions associated with products/sectors that suffer from higher than average credit fraud - eg building trade/materials.

The CRA's will also help with this type of check if the purchase involves credit as the lender will do its first checks with the CRA (credit reference agency).

For example, KBA questions to the account holder (knowledge based answers) helps stop fraudulent credit purchases - ie those questions should in theory only be answered correctly by the account owner, a fraudulent application will not know those exact details, so this = a strong 2nd line of defence against fraud.

The Moose

23,677 posts

239 months

Thursday 23rd August 2018
quotequote all
JPJPJP said:
Butter Face said:
Sounds scammy as fk.
I don't think it is scammy.

Card not present transactions aren't the best way to sell things and I think they are trying to avoid being defrauded, but don't want to pay the verified by visa fee (or can't join that scheme for some other reason).

The place is only down the road, so my offer to them will be that I will go to the shop and conclude the transaction through chip & pin

If that doesn't do it for them, then they are choosing to walk away from the order

That is their choice

I will seek an official view by reporting the email to the ICO
Verified by visa is part of 3D Secure. It applies to online transactions, not payments over the phone (assuming they are playing it straight).

manracer

1,548 posts

127 months

Thursday 23rd August 2018
quotequote all
Gavia said:
What has any of this got to do with GDPR? The way some on here discuss it, you’d think it meant that all companies have been banned from holding any data about any customer and the penalty for holding it is immediate death by firing squad for all directors, employees and subcontractors.

GDPR was a tightening up of some of the DPA rules around marketing and ways of contacting Joe Public. It really isn’t much else.
Actually, it is much more.

GDPR imposes strict requirements on the way businesses collect, store and manage personal data,
It provides citizens of the EU with much greater control over their personal data and assures that their information is being securely protected.

I think you would be well within your rights to find out how your data would be stored, for how long and why.

I would, from experience of project managing the GDPR implementation for 2 UK banks, a credit card company as well as a Telco, hazard a guess from their email that you could be onto something OP.

rallycross

13,752 posts

267 months

Thursday 23rd August 2018
quotequote all
manracer said:
Actually, it is much more.

GDPR imposes strict requirements on the way businesses collect, store and manage personal data,
It provides citizens of the EU with much greater control over their personal data and assures that their information is being securely protected.

I think you would be well within your rights to find out how your data would be stored, for how long and why.

I would, from experience of project managing the GDPR implementation for 2 UK banks, a credit card company as well as a Telco, hazard a guess from their email that you could be onto something OP.
sorry but that is rubbish.

anonymous-user

Original Poster:

84 months

Thursday 23rd August 2018
quotequote all
Given they are so local, I would be happy to show them the documents physically, but not for them to take copies.

If I was a retailer taking cnp payments on the phone, I would mention my requirement for such checks before taking the payment

As thing stand right now, they have my money and are refusing to deliver the patio stones unless they have copies of the kyc documents - something they had not mentioned at all until they had my money

Had the matter been raised before they took the payment, then maybe it could have gone differently. I could, for example, have asked them how many paving stones they would sell to me without triggering this ‘high value’ special process and ordered accordingly.

I’m hoping it can be easily resolved by a quick phone call and, perhaps, a visit to their premises. I suppose I will know soon after they open.

Alucidnation

16,810 posts

200 months

Thursday 23rd August 2018
quotequote all
JPJPJP said:
Given they are so local....
So why didn't you just go and order the stuff in person?

defblade

8,061 posts

243 months

Thursday 23rd August 2018
quotequote all
JPJPJP said:
Had the matter been raised before they took the payment, then maybe it could have gone differently. I could, for example, have asked them how many paving stones they would sell to me without triggering this ‘high value’ special process and ordered accordingly.
Because that's certainly not exactly what a scammy scammster would do wink



Turn it around, aren't you glad they're checking? If your card had been nicked/cloned, you'd be furious if someone else had spent your money on the stuff. And double furious if the merchant had accepted several small orders, all just under the check threshold...

Hol

9,316 posts

230 months

Thursday 23rd August 2018
quotequote all
rallycross said:
This is a good thing, and has nothing to do with GDPR.
^^ This.

Unless, you are one of these people who likes complaining, for the sake of it.


Xerstead

724 posts

208 months

Thursday 23rd August 2018
quotequote all
I have seen a few posts on here with businesses being defrauded by dodgy card payments. As said above, phone orders are a high risk for the businesses taking payment and it's often recommended to check the customer is genuine before proceeding with the order. There may be flaws in how it was presented to you but not unreasonable.
They would probably be more comfortable with chip and pin as well, so if they're local I'd pop in and sort it out.

Greshamst

2,481 posts

150 months

Thursday 23rd August 2018
quotequote all
rallycross said:
This is a good thing, and has nothing to do with GDPR.

This is your bank/card/lender (you chose) making sure this is a genuine transaction/purchase by you the account holder.

Remote card payments are at the top of the list for these checks, the security models will also pick out unusual transactions and transactions associated with products/sectors that suffer from higher than average credit fraud - eg building trade/materials.

The CRA's will also help with this type of check if the purchase involves credit as the lender will do its first checks with the CRA (credit reference agency).

For example, KBA questions to the account holder (knowledge based answers) helps stop fraudulent credit purchases - ie those questions should in theory only be answered correctly by the account owner, a fraudulent application will not know those exact details, so this = a strong 2nd line of defence against fraud.
Whilst I admire your enthusiasm, the email is from the builder's merchants, not the bank, card or lender.

A builder's merchants are not going to access your credit file information. Good info, wrong situation though.

ElectricPics

761 posts

111 months

Thursday 23rd August 2018
quotequote all
Card Not Present fraud is the bane of merchants, card issuers and banks and 3D secure can't be used so ensuring your transaction is legit is a good thing, but they should have told you what their procedure was while you were placing the order, although I think you'd have probably just ordered elsewhere so that 's a bit sneaky.

Did you give them the card CVV? That should never be recorded anywhere such as on an order form, so if they need it they should call you back to take it as they enter your card details again.