Operation: Acceptance of credit card registration
Want to promote credit card charging...If I could charge to "credit cards" according to the service usage record automatically, very smooth settlement would be possible. If I could digitize "bill issuance", I would drastically reduce cost on payment collection.
I would like to prepare a "card payment system" like an electric company, gas company, or mobile phone company.
Challenge: Risk of credit card information data breach
However, as security requirements become more stringent, "holding a credit card number" seems to be a big risk.Our company is not a power company nor, a big company such as Google or Facebook. In other words, it seems that we unlikely could comply the requirement that "PCI DSS" says. "What important is," the credit companies (Acquirer) say, "not to possess cardholder's info".
Alright, I'm going to leave cardholder's info such as PAN, PIN, CVC, to "Payment agencies", as it is advocated in a document by the Japanese government that "we aim for non-retention by March 2018". (But how?)
- PAN:Primary Account Number (card number)
- PIN:Personal Identification Number
- CVC: Card Verification Code/Value (3 digit number. Formally CVC2, aka CID)
DATA SECURITY STANDARD) Ver.3.2 2016-04
* Reference: Payment services (PSD 2) - Directive (EU) 2015/2366
[Credit Card Info Reception]