Mail Order Co. Storing Credit Card Details
Mail Order Co. Storing Credit Card Details
Author
Discussion

sam_r

Original Poster:

2,379 posts

251 months

Friday 14th July 2006
quotequote all
If you take peoples credit cards details over the phone to be used on a pdq machine (customer not present) What do you do with the details after?

I mean, what if you have customers that order every week. Are you allowed to store the details or is it illegal??

magic torch

5,781 posts

245 months

Friday 14th July 2006
quotequote all
Normally the PDQ suppliers have guidelines.

A nice man from Nigeria used to look after mine.

slapmatt

1,132 posts

245 months

Friday 14th July 2006
quotequote all
My understanding of the Data Protection Act is that you are allowed to hold customer data, but you must inform them of what data you are holding, name, address, credit card etc.

Also, you are only allowed to hold data for a "reasonable" amount of time, say 2 years, after which you must get the customers permission to continue to hold the data (not really practical) or you must destroy it.

Undoubtedly, there are alot of companies who hold the data of every customer they have every had, but, AFAIK this is technically illegal.

Other than the DPA, there is of course the security implications of holding customers credit card details.

sam_r

Original Poster:

2,379 posts

251 months

Friday 14th July 2006
quotequote all
Cool - i thought it wasnt illegal to hold the information. Where can it be stored? On a PC?

slapmatt

1,132 posts

245 months

Friday 14th July 2006
quotequote all
You can hold it electronically if you have the customer's permission.

sam_r

Original Poster:

2,379 posts

251 months

Friday 14th July 2006
quotequote all
Thanks Matt