/

PCI DSS

GLOSSARY

Payments

PCI DSS

PCI DSS

PCI DSS

THE SHORT VERSION

PCI DSS, the Payment Card Industry Data Security Standard, is the security standard every business that stores, processes or transmits card data must meet under its card acceptance agreements. It is an industry standard rather than UK law.

PCI DSS, the Payment Card Industry Data Security Standard, is the security standard every business that stores, processes or transmits card data must meet under its card acceptance agreements. It is an industry standard rather than UK law.

PCI DSS applies to every travel business that takes cards, whatever its size, including agents taking card details over the phone. The current version is 4.0.1, published in June 2024, and the PCI Security Standards Council began work on the next version in June 2026.

The Council writes the standard but does not enforce it. The card brands and acquirers decide how each business must show that it complies, and smaller businesses usually complete a self-assessment questionnaire (SAQ). The shortest, SAQ A, is for businesses that take payments online, by post or by phone and have outsourced all card handling to compliant providers.

Keeping card data out of your systems

The simplest way to reduce your PCI DSS work is to set up payments so card numbers never touch your own systems:

  • use your payment provider’s hosted payment page for online sales and send customers a secure payment link for phone sales, so staff never hear or type card numbers

  • keep a token from your provider rather than storing card numbers

  • keep card numbers out of booking notes, emails and call recordings

  • never keep a card security code after a payment has been authorised

Worth knowing

  • Outsourcing reduces your scope but not your responsibility. You must still check that your providers are compliant and confirm your own compliance.

  • Since 31 March 2025, a business using SAQ A whose website embeds a payment form must also confirm that its site is protected from script attacks.

  • A breach of card data is usually a personal data breach under UK GDPR too.

Sources

The official pages behind this explanation. This is general information, not legal advice, and rules change, so check the latest version.