Card data protection takes priority

CREDIT CARD SALES are crucial to retailers, but having to keep card data is too risky, industry leaders say. /
CREDIT CARD SALES are crucial to retailers, but having to keep card data is too risky, industry leaders say. /

Every night, the owners of Adler’s Hardware carefully lock away the names, numbers and expiration dates on the credit cards used at the Providence store that day – sensitive information they say must be saved in case of fraud, disputed charges or returned merchandise.
In fact, co-owner Harry Adler says his business keeps records of credit card purchases in paper form dating back seven years. That’s more than 200,000 transactions, he estimated.
Although storing the records has become a daily habit, Alder still worries about protecting them from prying eyes.
“We don’t want that information floating around or sitting on a desk,” he said last week. “We’re very concerned about keeping our customers’ credit card information away from the wrong hands.”
So is the National Retail Federation.
The world’s largest retail trade group is urging credit card companies to stop requiring retailers to keep card data for extended periods of time, arguing that it’s creating a security risk.
But MasterCard, the only company that has publicly responded to the federation’s statement, says it does not require that level of record-keeping at all – far more limited data would do.
While Adler’s said it stores information up to seven years, the NRF said most retailers save the information for up to 18 months to help resolve disputed or suspicious transactions or track returned products.
But in a letter to credit card companies last month, the NRF argued that the data would be more secure stored with the credit card companies and the banks that issue the cards instead of with retailers nationwide.
“The bottom line is that it makes more sense for credit card companies to protect their data from thieves by keeping it in a relatively few secure locations than to expect millions of merchants scattered across the nation to lock up their data for them,” wrote David Hogan, chief information officer for the NRF.
Hogan said the credit card companies and banks should give retailers the option of keeping just the authorization code created at the time of sale and a truncated receipt.
MasterCard called Hogan’s letter “inaccurate and unjustified” in a prepared statement.
The company said it has no rules requiring merchants to save transaction data, adding that “a merchant may choose to store no cardholder data at all based on their own risk assessments …”
And an executive from Mercury Payment Systems, a credit card payment processor based in Durango, Colo., agreed that the federation’s letter is wrong, noting there is confusion in the industry about security requirements.
Dan Osby, Mercury’s manager of data security compliance, said truncated credit card numbers should be enough data in situations of chargebacks and disputed purchases.
“Just as long as you can reference that transaction, that’s all that needed,” he said, calling the storing of full credit card information “dangerous.”
The debate over the storage of credit card data follows recent security breaches, including one disclosed by TJX Cos. earlier this year.
In March, the Framingham, Mass.-based retailer acknowledged that millions of credit and debit card numbers had been compromised by hackers who apparently had undetected access to the company’s databases for more than a year, starting in July 2005.
Court filings in a lawsuit against TJX – operator of T.J. Maxx, Marshalls, HomeGoods and Bob’s Stores in the United States — indicate that at least 94 million Visa and MasterCard accounts may have been exposed to fraudsters.
The losses involving Visa cards alone range from $68 million to $83 million, according to documents filed in the lawsuit by several bank associations.
On another front, retailers and the card industry have been squabbling over security requirements known as the Payment Card Industry Data Security Standard.
Only 65 percent of the nation’s largest retailers were compliant with the standard – which calls for the use of firewalls, regular security tests and other safeguards – as of Oct. 24, according to Visa. That’s up from about 44 percent at the end of August.
Among smaller retailers – ones that process between one million and six million Visa transactions a year – the compliance rates were lower, even though Visa has threatened to levy monthly $25,000 fines on merchant banks that work with noncompliant retailers.
Hogan, from the National Retail Federation, said retailers have been forced to “jump through extraordinary hoops” to meet the PCI Standard.
Executives at North Kingstown-based Ocean State Job Lot, which recently became PCI compliant, don’t necessarily agree.
John Conforti, chief financial officer of the 85-store retailer, said last week that it took a year to add the needed security measures, and it did have some costs. But, he added, “I wouldn’t say it was grossly painful.”
And what about the NRF’s push to get credit card firms to store the transaction data? “To us, it’s not unreasonable to hold data and hold data with a sense of security,” Conforti said. •

No posts to display