GLOSSARY
Payments
THE SHORT VERSION
PCI DSS applies to every travel business that takes cards, whatever its size, including agents taking card details over the phone. The current version is 4.0.1, published in June 2024, and the PCI Security Standards Council began work on the next version in June 2026.
The Council writes the standard but does not enforce it. The card brands and acquirers decide how each business must show that it complies, and smaller businesses usually complete a self-assessment questionnaire (SAQ). The shortest, SAQ A, is for businesses that take payments online, by post or by phone and have outsourced all card handling to compliant providers.
Keeping card data out of your systems
The simplest way to reduce your PCI DSS work is to set up payments so card numbers never touch your own systems:
use your payment provider’s hosted payment page for online sales and send customers a secure payment link for phone sales, so staff never hear or type card numbers
keep a token from your provider rather than storing card numbers
keep card numbers out of booking notes, emails and call recordings
never keep a card security code after a payment has been authorised
Worth knowing
Outsourcing reduces your scope but not your responsibility. You must still check that your providers are compliant and confirm your own compliance.
Since 31 March 2025, a business using SAQ A whose website embeds a payment form must also confirm that its site is protected from script attacks.
A breach of card data is usually a personal data breach under UK GDPR too.
Sources
The official pages behind this explanation. This is general information, not legal advice, and rules change, so check the latest version.