GDPR / KYC type question for online purchase
Discussion
Interested in views on this one
Ordered, by phone, some paving stones from a builder's merchant. Paid by VISA card by giving the the card details over the phone.
Then, an hour or so later, this email arrives
"Thank you very much for the Order you have placed with ****.
Please be advised that due to the Value of your Order, it is currently on HOLD. We are not verified by Visa and therefore have to conduct in-house security checks on any order over a certain amount to help prevent fraudulent transactions.
Could you please provide 2 forms of ID: Driving License/Utility Bill to confirm Billing Address details. Please feel free to reply via this email or send via Text **** FAO Security). Please note this does not include passports or headed paper, as it has to be two official forms of ID showing your billing address, and if it is a utility bill it must be dated within the last three months.
Please also provide a landline telephone number (if you haven't already provided).
The lead time will re-start from the day after ID is provided.
Kind Regards,
The Security Team"
Let's presume the email is real for now (easy to check tomorrow and the phone numbers / other stuff on the email do stack up).
I am not willing to participate in this "in house security check." My view is that the business should be a member of verified by visa if it feels such things are important
Moreover, I am not sure they have any right to collect / handle such information in this way.
Anyone with knowledge on the relevant rules able to comment?
Ordered, by phone, some paving stones from a builder's merchant. Paid by VISA card by giving the the card details over the phone.
Then, an hour or so later, this email arrives
"Thank you very much for the Order you have placed with ****.
Please be advised that due to the Value of your Order, it is currently on HOLD. We are not verified by Visa and therefore have to conduct in-house security checks on any order over a certain amount to help prevent fraudulent transactions.
Could you please provide 2 forms of ID: Driving License/Utility Bill to confirm Billing Address details. Please feel free to reply via this email or send via Text **** FAO Security). Please note this does not include passports or headed paper, as it has to be two official forms of ID showing your billing address, and if it is a utility bill it must be dated within the last three months.
Please also provide a landline telephone number (if you haven't already provided).
The lead time will re-start from the day after ID is provided.
Kind Regards,
The Security Team"
Let's presume the email is real for now (easy to check tomorrow and the phone numbers / other stuff on the email do stack up).
I am not willing to participate in this "in house security check." My view is that the business should be a member of verified by visa if it feels such things are important
Moreover, I am not sure they have any right to collect / handle such information in this way.
Anyone with knowledge on the relevant rules able to comment?
Butter Face said:
Sounds scammy as f
k.
I don't think it is scammy.
k.Card not present transactions aren't the best way to sell things and I think they are trying to avoid being defrauded, but don't want to pay the verified by visa fee (or can't join that scheme for some other reason).
The place is only down the road, so my offer to them will be that I will go to the shop and conclude the transaction through chip & pin
If that doesn't do it for them, then they are choosing to walk away from the order
That is their choice
I will seek an official view by reporting the email to the ICO
JPJPJP said:
I don't think it is scammy.
Card not present transactions aren't the best way to sell things and I think they are trying to avoid being defrauded, but don't want to pay the verified by visa fee (or can't join that scheme for some other reason).
The place is only down the road, so my offer to them will be that I will go to the shop and conclude the transaction through chip & pin
If that doesn't do it for them, then they are choosing to walk away from the order
That is their choice
I will seek an official view by reporting the email to the ICO
I agree it's a pain in the bum and clearly absolutely your prerogative to walk away from the order. But why do you think the ICO will be interested?Card not present transactions aren't the best way to sell things and I think they are trying to avoid being defrauded, but don't want to pay the verified by visa fee (or can't join that scheme for some other reason).
The place is only down the road, so my offer to them will be that I will go to the shop and conclude the transaction through chip & pin
If that doesn't do it for them, then they are choosing to walk away from the order
That is their choice
I will seek an official view by reporting the email to the ICO
JPJPJP said:
Interested in views on this one
Ordered, by phone, some paving stones from a builder's merchant. Paid by VISA card by giving the the card details over the phone.
Then, an hour or so later, this email arrives
"Thank you very much for the Order you have placed with ****.
Please be advised that due to the Value of your Order, it is currently on HOLD. We are not verified by Visa and therefore have to conduct in-house security checks on any order over a certain amount to help prevent fraudulent transactions.
Could you please provide 2 forms of ID: Driving License/Utility Bill to confirm Billing Address details. Please feel free to reply via this email or send via Text **** FAO Security). Please note this does not include passports or headed paper, as it has to be two official forms of ID showing your billing address, and if it is a utility bill it must be dated within the last three months.
Please also provide a landline telephone number (if you haven't already provided).
The lead time will re-start from the day after ID is provided.
Kind Regards,
The Security Team"
Let's presume the email is real for now (easy to check tomorrow and the phone numbers / other stuff on the email do stack up).
I am not willing to participate in this "in house security check." My view is that the business should be a member of verified by visa if it feels such things are important
Moreover, I am not sure they have any right to collect / handle such information in this way.
Anyone with knowledge on the relevant rules able to comment?
What has any of this got to do with GDPR? The way some on here discuss it, you’d think it meant that all companies have been banned from holding any data about any customer and the penalty for holding it is immediate death by firing squad for all directors, employees and subcontractors. Ordered, by phone, some paving stones from a builder's merchant. Paid by VISA card by giving the the card details over the phone.
Then, an hour or so later, this email arrives
"Thank you very much for the Order you have placed with ****.
Please be advised that due to the Value of your Order, it is currently on HOLD. We are not verified by Visa and therefore have to conduct in-house security checks on any order over a certain amount to help prevent fraudulent transactions.
Could you please provide 2 forms of ID: Driving License/Utility Bill to confirm Billing Address details. Please feel free to reply via this email or send via Text **** FAO Security). Please note this does not include passports or headed paper, as it has to be two official forms of ID showing your billing address, and if it is a utility bill it must be dated within the last three months.
Please also provide a landline telephone number (if you haven't already provided).
The lead time will re-start from the day after ID is provided.
Kind Regards,
The Security Team"
Let's presume the email is real for now (easy to check tomorrow and the phone numbers / other stuff on the email do stack up).
I am not willing to participate in this "in house security check." My view is that the business should be a member of verified by visa if it feels such things are important
Moreover, I am not sure they have any right to collect / handle such information in this way.
Anyone with knowledge on the relevant rules able to comment?
GDPR was a tightening up of some of the DPA rules around marketing and ways of contacting Joe Public. It really isn’t much else.
This is a good thing, and has nothing to do with GDPR.
This is your bank/card/lender (you chose) making sure this is a genuine transaction/purchase by you the account holder.
Remote card payments are at the top of the list for these checks, the security models will also pick out unusual transactions and transactions associated with products/sectors that suffer from higher than average credit fraud - eg building trade/materials.
The CRA's will also help with this type of check if the purchase involves credit as the lender will do its first checks with the CRA (credit reference agency).
For example, KBA questions to the account holder (knowledge based answers) helps stop fraudulent credit purchases - ie those questions should in theory only be answered correctly by the account owner, a fraudulent application will not know those exact details, so this = a strong 2nd line of defence against fraud.
This is your bank/card/lender (you chose) making sure this is a genuine transaction/purchase by you the account holder.
Remote card payments are at the top of the list for these checks, the security models will also pick out unusual transactions and transactions associated with products/sectors that suffer from higher than average credit fraud - eg building trade/materials.
The CRA's will also help with this type of check if the purchase involves credit as the lender will do its first checks with the CRA (credit reference agency).
For example, KBA questions to the account holder (knowledge based answers) helps stop fraudulent credit purchases - ie those questions should in theory only be answered correctly by the account owner, a fraudulent application will not know those exact details, so this = a strong 2nd line of defence against fraud.
JPJPJP said:
Butter Face said:
Sounds scammy as f
k.
I don't think it is scammy.
k.Card not present transactions aren't the best way to sell things and I think they are trying to avoid being defrauded, but don't want to pay the verified by visa fee (or can't join that scheme for some other reason).
The place is only down the road, so my offer to them will be that I will go to the shop and conclude the transaction through chip & pin
If that doesn't do it for them, then they are choosing to walk away from the order
That is their choice
I will seek an official view by reporting the email to the ICO
Gavia said:
What has any of this got to do with GDPR? The way some on here discuss it, you’d think it meant that all companies have been banned from holding any data about any customer and the penalty for holding it is immediate death by firing squad for all directors, employees and subcontractors.
GDPR was a tightening up of some of the DPA rules around marketing and ways of contacting Joe Public. It really isn’t much else.
Actually, it is much more.GDPR was a tightening up of some of the DPA rules around marketing and ways of contacting Joe Public. It really isn’t much else.
GDPR imposes strict requirements on the way businesses collect, store and manage personal data,
It provides citizens of the EU with much greater control over their personal data and assures that their information is being securely protected.
I think you would be well within your rights to find out how your data would be stored, for how long and why.
I would, from experience of project managing the GDPR implementation for 2 UK banks, a credit card company as well as a Telco, hazard a guess from their email that you could be onto something OP.
manracer said:
Actually, it is much more.
GDPR imposes strict requirements on the way businesses collect, store and manage personal data,
It provides citizens of the EU with much greater control over their personal data and assures that their information is being securely protected.
I think you would be well within your rights to find out how your data would be stored, for how long and why.
I would, from experience of project managing the GDPR implementation for 2 UK banks, a credit card company as well as a Telco, hazard a guess from their email that you could be onto something OP.
sorry but that is rubbish.GDPR imposes strict requirements on the way businesses collect, store and manage personal data,
It provides citizens of the EU with much greater control over their personal data and assures that their information is being securely protected.
I think you would be well within your rights to find out how your data would be stored, for how long and why.
I would, from experience of project managing the GDPR implementation for 2 UK banks, a credit card company as well as a Telco, hazard a guess from their email that you could be onto something OP.
Given they are so local, I would be happy to show them the documents physically, but not for them to take copies.
If I was a retailer taking cnp payments on the phone, I would mention my requirement for such checks before taking the payment
As thing stand right now, they have my money and are refusing to deliver the patio stones unless they have copies of the kyc documents - something they had not mentioned at all until they had my money
Had the matter been raised before they took the payment, then maybe it could have gone differently. I could, for example, have asked them how many paving stones they would sell to me without triggering this ‘high value’ special process and ordered accordingly.
I’m hoping it can be easily resolved by a quick phone call and, perhaps, a visit to their premises. I suppose I will know soon after they open.
If I was a retailer taking cnp payments on the phone, I would mention my requirement for such checks before taking the payment
As thing stand right now, they have my money and are refusing to deliver the patio stones unless they have copies of the kyc documents - something they had not mentioned at all until they had my money
Had the matter been raised before they took the payment, then maybe it could have gone differently. I could, for example, have asked them how many paving stones they would sell to me without triggering this ‘high value’ special process and ordered accordingly.
I’m hoping it can be easily resolved by a quick phone call and, perhaps, a visit to their premises. I suppose I will know soon after they open.
JPJPJP said:
Had the matter been raised before they took the payment, then maybe it could have gone differently. I could, for example, have asked them how many paving stones they would sell to me without triggering this ‘high value’ special process and ordered accordingly.
Because that's certainly not exactly what a scammy scammster would do 
Turn it around, aren't you glad they're checking? If your card had been nicked/cloned, you'd be furious if someone else had spent your money on the stuff. And double furious if the merchant had accepted several small orders, all just under the check threshold...
I have seen a few posts on here with businesses being defrauded by dodgy card payments. As said above, phone orders are a high risk for the businesses taking payment and it's often recommended to check the customer is genuine before proceeding with the order. There may be flaws in how it was presented to you but not unreasonable.
They would probably be more comfortable with chip and pin as well, so if they're local I'd pop in and sort it out.
They would probably be more comfortable with chip and pin as well, so if they're local I'd pop in and sort it out.
rallycross said:
This is a good thing, and has nothing to do with GDPR.
This is your bank/card/lender (you chose) making sure this is a genuine transaction/purchase by you the account holder.
Remote card payments are at the top of the list for these checks, the security models will also pick out unusual transactions and transactions associated with products/sectors that suffer from higher than average credit fraud - eg building trade/materials.
The CRA's will also help with this type of check if the purchase involves credit as the lender will do its first checks with the CRA (credit reference agency).
For example, KBA questions to the account holder (knowledge based answers) helps stop fraudulent credit purchases - ie those questions should in theory only be answered correctly by the account owner, a fraudulent application will not know those exact details, so this = a strong 2nd line of defence against fraud.
Whilst I admire your enthusiasm, the email is from the builder's merchants, not the bank, card or lender. This is your bank/card/lender (you chose) making sure this is a genuine transaction/purchase by you the account holder.
Remote card payments are at the top of the list for these checks, the security models will also pick out unusual transactions and transactions associated with products/sectors that suffer from higher than average credit fraud - eg building trade/materials.
The CRA's will also help with this type of check if the purchase involves credit as the lender will do its first checks with the CRA (credit reference agency).
For example, KBA questions to the account holder (knowledge based answers) helps stop fraudulent credit purchases - ie those questions should in theory only be answered correctly by the account owner, a fraudulent application will not know those exact details, so this = a strong 2nd line of defence against fraud.
A builder's merchants are not going to access your credit file information. Good info, wrong situation though.
Card Not Present fraud is the bane of merchants, card issuers and banks and 3D secure can't be used so ensuring your transaction is legit is a good thing, but they should have told you what their procedure was while you were placing the order, although I think you'd have probably just ordered elsewhere so that 's a bit sneaky.
Did you give them the card CVV? That should never be recorded anywhere such as on an order form, so if they need it they should call you back to take it as they enter your card details again.
Did you give them the card CVV? That should never be recorded anywhere such as on an order form, so if they need it they should call you back to take it as they enter your card details again.
Gassing Station | Speed, Plod & the Law | Top of Page | What's New | My Stuff


