Skip to content
iGaming Times

Independent industry intelligence in your inbox. We will email you a link to confirm your subscription, and every newsletter carries a one-click unsubscribe link.

Compliance

PCI DSS (Payment Card Industry Data Security Standard)

PCI DSS

Definition

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard that applies to any organisation that stores, processes or transmits payment card data, or that could affect the security of the environment where that data is held. It is maintained by the PCI Security Standards Council, founded in 2006 by American Express, Discover, JCB International, Mastercard and Visa, but it is enforced through the card brands and acquirers, which decide who must comply and how compliance is validated.

The current version is PCI DSS v4.0.1, published in June 2024 as a limited revision with no new requirements. Version 4.0, published in March 2022, was retired on 31 December 2024, and the requirements it had marked as future-dated became effective on 31 March 2025. For a gambling operator, PCI DSS covers the cashier, any stored card credentials used for repeat deposits, and suppliers such as gateways and platforms that touch card data.

Key takeaways

  • PCI DSS is the card industry's data security standard for anyone that stores, processes or transmits cardholder data.
  • It is written by the PCI Security Standards Council but enforced contractually through card brands and acquirers, not by a government regulator.
  • PCI DSS v4.0.1 has been the only active version since v4.0 was retired on 31 December 2024; future-dated requirements applied from 31 March 2025.
  • Operators reduce their compliance scope by keeping raw card data off their own systems through hosted payment fields and tokenisation.

Why it matters

Card deposits are still a core funding method in many gambling markets, so most operators fall within PCI DSS in some form. Compliance is a condition of the acquiring agreement: an operator that cannot show it, or that suffers a breach of card data, can face fines passed down from the schemes, forensic investigation costs and, at worst, loss of card acceptance.

The practical goal is to shrink scope. If the cashier captures card numbers in fields hosted by the gateway or PSP, and the operator stores only tokens, far fewer of its systems are in the cardholder data environment and validation is simpler. Version 4.0 and 4.0.1 also put more weight on threats aimed at checkout pages, including requirements for managing scripts that run on payment pages, and on multi-factor authentication for access to the cardholder data environment.

PCI DSS sits alongside, not instead of, other controls. It protects card data at rest and in transit; strong customer authentication and 3-D Secure verify the cardholder at the moment of payment; data protection law such as GDPR governs personal data more broadly. Suppliers matter too: platform providers, CRM tools and outsourced customer service teams that can see card data all need to be assessed. The Fraud and Risk Management course covers how these controls fit together.

PCI DSS (Payment Card Industry Data Security Standard) vs 3-D Secure

PCI DSS (Payment Card Industry Data Security Standard)3-D Secure
A security standard for the systems and processes that store, process or transmit card data, assessed periodically against a set of requirements.An authentication protocol used during an online card payment to confirm that the person paying is the legitimate cardholder, typically through the issuer's app or a one-time code.

PCI DSS protects card data from being stolen from the operator; 3-D Secure makes stolen card data harder to use and can shift fraud liability to the issuer. Operators need both.

The bottom line

PCI DSS is the rulebook for handling card data, set by the card industry and enforced through acquiring contracts. For gambling operators the smart approach is to keep card data out of their own systems wherever possible and validate what remains under v4.0.1, the only active version.

Sources

  1. PCI Data Security Standard (PCI DSS) - PCI Security Standards Council
  2. Just Published: PCI DSS v4.0.1 - PCI Security Standards Council
  3. About Us - PCI Security Standards Council

Frequently asked questions

  • What is PCI DSS?

    PCI DSS stands for Payment Card Industry Data Security Standard. It sets technical and operational requirements for protecting payment card data, covering areas such as network security, encryption, access control, vulnerability management, monitoring and security policies. It applies to merchants, processors, acquirers, issuers and service providers that store, process or transmit cardholder data or can affect its security.

  • What is the current version of PCI DSS?

    The current version is PCI DSS v4.0.1, which the PCI Security Standards Council published in June 2024. It was a limited revision that clarified wording and added no new requirements. PCI DSS v4.0 was retired on 31 December 2024, leaving v4.0.1 as the only active version, and the requirements first introduced as future-dated in v4.0 became mandatory on 31 March 2025.

  • Is PCI DSS a legal requirement?

    PCI DSS is not a law in most countries. It is an industry standard that card brands require through their rules, and acquirers impose it on merchants through contracts. Failing to comply can still have serious consequences, including fines passed on by the acquirer and loss of card acceptance, and a breach of card data may also breach data protection law.

  • Does using a PSP make an operator PCI compliant?

    Not on its own. Using a PSP's hosted payment page or fields can remove most card data from the operator's systems and greatly reduce its scope, but the operator usually still has to validate compliance for what remains, for example through a self-assessment questionnaire, and must check that its PSP and other service providers are themselves compliant.

Cookie Preferences

Choose which cookies you want to accept. Essential cookies are required for the website to function properly.

Required

Necessary for the website to function. Cannot be disabled.

Help us understand how visitors interact with our website.

Used to deliver relevant advertisements and track ad performance.

Remember your preferences and settings for a better experience.