PCI DSS and card data on your site: what you actually must do
What PCI DSS and GDPR really require when you take card payments online, and the simplest way to stay safe: never touch the card data yourself.
If you want to accept card payments on your website, you have probably heard of PCI DSS and felt a little overwhelmed. The good news: for most small businesses, the real obligations are far simpler than they sound, as long as you build the site the right way from the start.
It all comes down to one idea: the safest card is the one you never touch. If card details never pass through your server, most of the PCI DSS burden disappears and your data-protection risk drops sharply. In this article I explain what PCI DSS actually is, how it connects to GDPR in Europe, and what you concretely need to do as a business owner, without the jargon.
What PCI DSS is (and what it isn't)
PCI DSS stands for Payment Card Industry Data Security Standard. It is not a national or EU law, but a security standard imposed by the card networks (Visa, Mastercard and the rest). It applies to anyone who stores, processes or transmits card data.
Many owners assume they need an expensive, complicated certification. In reality, the level of obligation depends on how much you "touch" the card data:
- if card data passes through your own server, your obligations are serious and costly;
- if you use a payment processor that handles the card entirely (redirect or hosted fields), your obligations shrink to a simple self-assessment questionnaire called SAQ A.
For a typical shop, SAQ A is the right path. Not a heavy certificate, just smart architecture.
The practical solution: never store card data
The golden rule for any site is to let a specialised processor handle the card. In practice that means integrating a provider such as Stripe, PayPal or a local acquirer, which captures the card details directly on its own certified infrastructure.
The customer enters the card either on a secure page hosted by the processor, or in a hosted field (iframe) that never touches your server. You only receive the payment confirmation and a transaction identifier.
Things you must never do:
- store the full card number in your database;
- save the CVV (the three digits) — this is never stored by anyone;
- receive card numbers by email, WhatsApp or a plain form.
Stick to this and you stay in the safe zone while making your life far simpler.
Where GDPR sits on top of PCI DSS
PCI DSS covers the security of card data. GDPR (Regulation 2016/679) covers all your customers' personal data — name, address, email, order history and, by extension, payment-related data.
The two overlap but are not the same. Even if the processor handles the card, you remain responsible for everything else. Concretely, you need:
- a clear privacy policy that says what data you collect and why;
- a lawful basis for processing (usually performance of the contract — the order);
- HTTPS across the whole site, mandatory, not optional;
- to collect only the data you actually need, nothing extra.
The payment processor is a "processor" in GDPR terms, and that relationship should be governed by a data processing agreement.
A concrete checklist for the business owner
Whether you set up the site yourself or check what someone built for you, here is the short list that matters:
- use a recognised payment processor and let it touch the card;
- confirm HTTPS is active on every page, including checkout;
- never store card numbers or CVV, anywhere;
- complete the SAQ A questionnaire your processor asks for (usually simple and annual);
- have a privacy policy and a cookie policy fitted to your business;
- sign a data processing agreement with the processor and with whoever manages your site;
- keep your plugins and platform up to date so vulnerabilities don't appear.
It is not an intimidating list. It is technical common sense, put in order.
How we handle payments at MPO Web Studio
We build sites that, by design, never touch card data. We integrate the right processor for your business, with HTTPS by default and a clean checkout, so you stay in the SAQ A zone and carry no unnecessary technical worry.
We work remotely nationwide, with transparent pricing, and before you pay anything we can prepare a ready-built demo of your site so you see exactly how it looks, payment flow included.
We are not lawyers and we don't give legal advice; for the GDPR documents it is wise to also work with a specialist. But the technical part — the architecture that keeps you safe — we get right.
If you'd like to talk it through for your own business, send us a message on WhatsApp and we'll reply plainly, no jargon.
Frequently asked questions
Do I need an expensive PCI DSS certification for my online shop?+
Most likely not. If you use a processor that handles the card entirely (redirect or hosted fields), your obligation usually reduces to the SAQ A self-assessment questionnaire, which is simple and completed annually. Heavy certifications are for those who process cards directly on their own server.
Can I save my customers' cards so they pay faster next time?+
Yes, but not on your server. Processors offer "tokenisation": they keep the card safely and hand you a token you can reuse. You never store the real card number or the CVV. That gives fast repeat payments without you taking on the risk.
Do I need HTTPS even if I don't sell directly on the site?+
Yes. HTTPS is the minimum standard today for any site, and for any page collecting personal data (contact form, order, account) it is effectively mandatory under GDPR practice. Browsers also flag non-HTTPS sites as not secure.
Who is responsible if something goes wrong with payment data — me or the processor?+
It depends where the problem arises. The processor is responsible for the card security itself, provided you never touched the data. For the personal data you manage (name, email, orders) you remain responsible under GDPR. That's why both correct architecture and the processing agreements matter.
7 mistakes that drive clients away from your website
Leave your email and get the guide right here, instantly. No spam.
Want to see what your business's website could look like?
Message us on WhatsApp and we'll build you a free demo website with your business name on it. See it first, then decide — no strings attached.