Hacker News new | ask | show | jobs
by lostmypassword2 3779 days ago
What law are you talking about? PCI-DSS is required by the card companies and run an organization called the "Payment Card Industry Security Standards Council". It's self-governed essentially. It's not federal law
1 comments

I had always assumed that it was a matter of law, rather than self governance. I stand corrected.