Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

PCI is not a law, it's an industry standard. Only a couple of states legally mandate compliance to PCI DSS.

I agree OP should report them, though.



This is true, but if the competitor is advertising PCI compliance and is not providing that, their consumers have a right to know that they are not getting what they paid for.


He would lose his ability to process credit cards, possibly having bank accounts closed etc.


Immediately? Wouldn't they give them a "second chance" to implement the necessary changes?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: