Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Map your card data flow
- 2. Design out unnecessary handling of card data
- 3. Review your contracts and supplier promises
- 4. Align PCI work with privacy and data protection
- 5. Train staff on the real-world failure points
- 6. Keep records and validation up to date
- Common mistakes UK businesses make
- How PCI fits into wider business set-up
FAQs
- Is PCI DSS a legal requirement in the UK?
- Does a small business need to comply with PCI DSS?
- If we use Stripe, Shopify, or another payment platform, are we covered?
- Can staff take card details over email or write them down temporarily?
- What should we review before signing with a payment or software provider?
- Key Takeaways
If your business takes card payments, the main risk is assuming PCI DSS is just an IT issue for your payment provider. That mistake catches a lot of UK founders out. Common problems include storing card details in places you should not, relying on a third party without checking your own responsibilities, and treating PCI paperwork as a one-off exercise instead of an ongoing compliance job.
PCI DSS can affect a small online retailer, a subscription software business, a hospitality venue, or a professional services firm taking deposits over the phone. It sits alongside your privacy obligations, your contracts with banks and payment providers, and your wider cyber risk management.
This guide explains what PCI data security requirements mean in practice for UK businesses, when the issue usually comes up, the legal and commercial risks of getting it wrong, and the practical steps to sort out before you take orders, sign with a payment provider, or spend money on setup.
Overview
PCI DSS is a security standard for businesses that store, process or transmit payment card data. It is not the same as a statute passed by Parliament, but it can still have serious legal and commercial consequences because it is built into payment industry rules, contracts, and your wider data protection and security responsibilities.
For most UK businesses, the real question is not whether PCI DSS matters, but what level of compliance applies to your payment set-up and what you must stop doing immediately if card data touches your systems.
- Work out whether your business stores, processes or transmits cardholder data at all.
- Check whether your payment flow keeps card details off your systems, or whether your website, staff, software or devices bring you into scope.
- Identify which PCI DSS validation route applies, including whether you need a self-assessment questionnaire, scans, or a higher level of review.
- Review contracts with payment service providers, merchant acquirers, web developers and IT suppliers.
- Line up PCI work with UK GDPR duties, privacy notices, internal policies, and incident response planning.
- Train staff not to record card details in emails, notes, spreadsheets, chat tools or call recordings.
- Check what happens before you sign for new ecommerce tools, booking systems, or recurring billing software.
What PCI Data Security Requirements Means For UK Businesses
PCI DSS sets security rules for card payments, and if your business touches card data, those rules may apply even if you are small.
PCI DSS stands for the Payment Card Industry Data Security Standard. It was developed by the major card schemes to reduce payment fraud and improve the security of cardholder data. It is usually enforced through the contractual chain around card payments, including your merchant acquirer, payment processor, gateway provider, or platform terms.
That means many SMEs first hear about PCI DSS when a provider sends a compliance questionnaire, asks for evidence of security controls, or warns about charges for non-compliance. Founders sometimes assume this is optional admin. Usually, it is not.
It is not just for large retailers
A common misunderstanding is that PCI data security requirements only matter if you are a big ecommerce brand. In reality, a very small business can be in scope if it:
- takes payments through its own website checkout
- keys card details into a virtual terminal
- accepts payments over the phone
- stores card details for repeat billing
- uses booking, subscription or CRM tools that expose card information to staff
- runs card payments through office networks, laptops or point of sale systems
A business can also create avoidable risk simply by handling card data badly for a short period. For example, if staff ask customers to email card numbers, write them in a notebook, or save them in a shared spreadsheet, that can create a significant PCI issue very quickly.
PCI DSS is different from UK GDPR, but the two overlap
PCI DSS is not the same thing as UK data protection law. Card details and related payment information may also be personal data, so UK GDPR and the Data Protection Act 2018 may apply alongside PCI rules. The standards overlap because both expect proper security, controlled access, limited retention, and a sensible response to breaches.
If cardholder information is compromised, the consequences may spread across several areas at once:
- contractual action by your acquirer or payment provider
- fines, penalties or increased charges within the card payment ecosystem
- forensic investigation costs
- obligations to investigate and report a personal data breach where relevant
- customer claims, complaints or reputational damage
- business interruption and the cost of reworking systems
Compliance depends on how your payment set-up works
The scope of PCI data security requirements depends heavily on your technical and operational set-up. This is where founders often get caught. Two businesses selling the same product can have very different compliance burdens depending on how payment data flows.
For example, a merchant using a fully hosted payment page where card details go straight to a specialist payment provider may have a narrower PCI scope. A merchant with a custom checkout, integrated plugins, or staff who manually handle card details may have wider obligations.
The key practical point is this: the less card data your systems and staff touch, the easier compliance usually becomes.
Contract terms matter as much as the standard itself
Most UK businesses do not sign a contract called a PCI agreement. Instead, PCI obligations are buried inside merchant acquiring terms, payment platform terms, software agreements, website development arrangements, and outsourced IT contracts.
Before you sign a contract, check who is responsible for:
- maintaining PCI compliant systems
- security testing and vulnerability scanning
- patching ecommerce plugins and integrations
- segregating access rights for staff and contractors
- incident detection, reporting and support
- handling customer payment data in support channels or call centres
- indemnities, liability caps and exclusions if a payment data incident occurs
If those responsibilities are vague, the commercial risk often lands back on the merchant.
When This Issue Comes Up
PCI questions usually appear when a business changes how it takes money, not when the founder is thinking about legal compliance in the abstract.
That is why it helps to spot the trigger points early, especially before you spend money on setup or commit to a platform that creates unnecessary exposure.
Launching online sales
If you are about to sell online in the UK, PCI DSS should be part of your website planning. It sits alongside privacy, customer terms, cookies, and supplier contracts. A developer may tell you the checkout is secure, but that does not answer whether card data passes through your site, server, plugins or admin tools.
This matters for startups choosing between hosted checkout pages, embedded payment fields, marketplace platforms, and custom ecommerce builds.
Taking payments over the phone
Telephone payments are a classic problem area for SMEs. A business may think it is low risk because a staff member simply types details into a payment portal. In practice, the risks expand if calls are recorded, details are written down, emails confirm full card numbers, or teams use shared devices and weak access controls.
Professional services firms, clinics, event businesses and B2B suppliers often run into PCI issues here.
Using recurring billing or stored card details
Subscription businesses, gyms, training providers, software companies and hospitality businesses often want easy repeat payments. The legal and compliance question is whether your business is actually storing the card data, tokenising it through a provider, or exposing payment details through an internal system.
Many businesses discover too late that a convenient manual process has created a much bigger compliance footprint.
Changing payment providers or signing merchant terms
PCI obligations often become visible when a bank, acquirer or processor asks you to complete onboarding forms or annual validation. That is the moment to review the legal terms carefully, not after a security incident or chargeback problem.
Founders sometimes focus on transaction fees and settlement times, but ignore clauses dealing with security standards, breach reporting, audit rights and the provider's ability to pass on scheme penalties.
Buying software or outsourcing support
PCI issues also arise when you use third party booking systems, ecommerce plugins, CRM tools, customer support platforms, call handling services, or outsourced IT. A supplier may say its product is suitable for payments, but your business still needs to understand what data is collected, where it goes, who can access it, and what your contract says if something goes wrong.
This is especially relevant before you sign a contract for:
- a custom website build
- a point of sale system
- a booking platform for hospitality or healthcare
- a virtual terminal set-up for telephone orders
- a subscription billing platform
- a call centre or outsourced customer service arrangement
Expanding teams and internal access
A business that started with one founder can quietly drift into non-compliance as it grows. New hires get admin access, laptops are shared, permissions are not reviewed, and internal workarounds become normal. PCI DSS often becomes a live issue when a business scales faster than its internal controls.
This is also where PCI touches employment contracts, IT policies, confidentiality obligations and staff training.
Practical Steps And Common Mistakes
The best PCI strategy for most SMEs is to reduce your exposure first, then document and support the set-up you actually use.
Many businesses start in the wrong place. They look for a form to complete before they have mapped how card data moves through the business. That approach leads to inaccurate declarations and missed risks.
1. Map your card data flow
You need a clear picture of where card data enters, passes through, and could be stored. That includes websites, payment pages, devices, phone lines, email accounts, chat tools, support tickets, call recordings, spreadsheets and third party apps.
Ask practical questions such as:
- Do customers ever give card details directly to staff?
- Do we receive card numbers by email, web form or message?
- Does our website host payment fields, or does the provider handle them externally?
- Are any full card numbers stored anywhere in our systems or documents?
- Can staff replay recordings that contain payment details?
- Do contractors or developers have access to payment environments?
Without this map, it is hard to know what standard applies or what needs fixing first.
2. Design out unnecessary handling of card data
The simplest way to lower PCI risk is to stop card data touching your environment where possible. Many SMEs can use payment models that redirect customers to a specialist hosted page or use tokenised recurring billing rather than storing details themselves.
This is often a better decision before you launch online than trying to patch up a custom build later.
3. Review your contracts and supplier promises
Do not rely on marketing statements like “PCI compliant solution” without checking the contract and the actual implementation. A provider can offer PCI capable software while leaving major security responsibilities with you.
Look closely at:
- the service description and exclusions
- security commitments and technical requirements
- who manages updates and plugin maintenance
- incident notification timeframes
- subcontracting and hosting arrangements
- liability limits if a breach stems from the supplier's failings
- termination rights if the service creates compliance issues
4. Align PCI work with privacy and data protection
If payment information links to identifiable customers, UK GDPR may also be in play. Your privacy notice and privacy policy should describe relevant processing clearly and accurately. Internal retention practices should make sense. Access controls should be limited to people who genuinely need access.
If there is a security incident involving personal data, the business may also need to assess whether notification obligations arise. PCI and privacy compliance should be treated as connected workstreams, not separate boxes.
5. Train staff on the real-world failure points
Most PCI failures in SMEs are not dramatic hacks. They are everyday habits. A staff member takes a card number in a rush, writes it on paper, asks for it by email, or leaves it in a ticketing system because “we only do that sometimes”.
Training should be short, practical and role-based. Staff need clear rules on what they must never do, what approved payment methods they should use, and who to escalate to if a customer sends payment details through the wrong channel.
6. Keep records and validation up to date
PCI DSS is not just about security controls. It also involves proving your status through the right validation route. Depending on your set-up, that may include self-assessment questionnaires, scans or additional review steps requested by your acquirer or provider.
Founders often make the mistake of completing a questionnaire once and forgetting it. System changes, new plugins, acquisitions, staff growth or new sales channels can all change your scope.
Common mistakes UK businesses make
Most legal and compliance trouble comes from a handful of repeat errors.
- Assuming the payment provider takes full responsibility for PCI DSS.
- Letting customers send card details by email or web form.
- Recording payment calls without a secure process.
- Storing card details for convenience rather than using tokenised solutions.
- Using a developer-built checkout without checking how card data is handled.
- Signing supplier terms that shift security risk back to the merchant.
- Treating PCI as separate from privacy, contracts and internal staff controls.
- Failing to revisit compliance after changing systems or sales channels.
How PCI fits into wider business set-up
If you are a startup or growing SME, PCI compliance should be considered alongside the rest of your legal set-up. That can include your business structure, customer terms, supplier contracts, privacy notice, cyber policies, employment contracts and trade mark strategy.
For example, if you start a business in the UK selling online, your legal requirements are not only about company setup, registration and contracts. The payment journey, privacy information and allocation of risk with technology suppliers can also shape your exposure. Founders often spend money on branding, a business name, and website design first, then realise later that the checkout flow, support process and internal permissions need to be redesigned.
Sorting this early is usually cheaper than dealing with a failed compliance assessment or payment data incident after launch.
FAQs
Is PCI DSS a legal requirement in the UK?
PCI DSS is generally not a UK statute in the same way as an Act of Parliament, but it can still be effectively mandatory through your contracts with payment providers, acquirers and card scheme rules. UK data protection law may also apply to related personal data and security measures.
Does a small business need to comply with PCI DSS?
Yes, if the business stores, processes or transmits cardholder data, even a small business may have PCI responsibilities. The exact compliance burden depends on how payments are taken and how much card data touches your systems.
If we use Stripe, Shopify, or another payment platform, are we covered?
Using a well-known platform may reduce your PCI scope, but it does not automatically remove all responsibility. Your website configuration, plugins, staff processes, contracts and any direct handling of card data still matter.
Can staff take card details over email or write them down temporarily?
That is usually a bad idea and can create serious PCI and security problems. Businesses should use approved payment channels and train staff to avoid collecting or storing card details in informal ways.
What should we review before signing with a payment or software provider?
Check the payment flow, security responsibilities, incident reporting terms, liability provisions, update and maintenance obligations, and whether the service keeps card data outside your environment where possible.
Key Takeaways
- PCI data security requirements matter to many UK startups and SMEs, not just large retailers.
- Your responsibilities depend on whether your business stores, processes or transmits cardholder data, and on how your payment set-up actually works.
- PCI DSS is not the same as UK GDPR, but payment security and data protection issues often overlap.
- The biggest practical win is usually reducing or removing direct handling of card data by your staff, website and internal systems.
- Contracts with payment providers, developers, software vendors and IT suppliers should clearly allocate security responsibilities and incident risk.
- Telephone payments, stored card details, custom checkouts and informal staff workarounds are common danger areas.
- PCI compliance needs periodic review, especially when you change systems, channels, suppliers or team access.
If your business is dealing with PCI data security requirements and wants help with supplier contracts, privacy compliance, website terms, and incident response planning, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.





