Hacker News new | ask | show | jobs
by cesther 4399 days ago
PCI DSS is not voluntary if you transmit, store or process credit cards.

It is enforced through contract, typically for a merchant through their relationship with their bank, for service providers via the contract with the merchant.