Check security & privacy obligations: Engage a QSA and Australian privacy adviser for separate written decisions; PCI DSS v4.x is current; acquirer sets validation and evidence rules; Privacy Act 1988 (Cth) applies to businesses over AU$3M turnover or handling health info
Image: Checkout Technology Guide

Fraud Controls

Part of Checkout security and access

Checking current security obligations with qualified specialists

Prepare a checkout data-flow brief and ask the right PCI, payment and Australian privacy specialists for an account-specific decision.

Brief a Qualified Security Assessor (QSA) and an Australian privacy adviser against the checkout the merchant actually operates. Obtain separate written decisions on the PCI validation route and evidence required, and on which Australian privacy obligations apply.

Ask the QSA to identify the PCI DSS version and supporting documents used; PCI SSC identifies PCI DSS v4.x. The acquirer, payment brand or other entity accepting compliance evidence sets the merchant’s validation and submission requirements.

Prepare a factual brief

Give advisers a current map of the buyer path and supporting systems. Show where payment details are entered, who supplies each payment-page element, which scripts and apps affect the page, and where card or personal information travels.

Add log and backup destinations, staff and provider access, payment contracts, existing PCI documents and planned changes.

Mark unknowns. Provider-hosted card fields, for example, do not answer whether the merchant’s surrounding page can affect the payment journey. Do not infer a PCI self-assessment category from “hosted” or “embedded” alone.

Send each adviser the same brief and ask them to identify assumptions, missing facts and the written decision their engagement will provide.

Put each question to the right party

QuestionContact to consider
Which PCI validation route and submission evidence are required?The acquirer or other entity accepting compliance evidence, with a Qualified Security Assessor where appropriate
Which checkout components and provider services are in PCI scope?A payment-security specialist or Qualified Security Assessor using the actual implementation and provider evidence
Does the Privacy Act 1988 (Cth) cover this business and information, and what APP 11 or NDB duties follow?An Australian privacy lawyer or suitably qualified privacy adviser
Does a suspected exposure require assessment or notification?The incident lead with privacy and payment-security advisers using established facts

QSA companies are independent security organisations qualified by the PCI Security Standards Council to perform PCI DSS assessments. QSA employees are employed by a QSA company and must satisfy and continue to satisfy QSA requirements.

Before engaging, check the company on the published QSA list linked from PCI SSC’s Qualified Security Assessors page. The Council says the list is updated frequently but may not always be up to date; contact the QSA about the status of a particular assessor.

Ask the QSA to define which checkout elements, data flows and provider services it will assess, what evidence it needs, and what written findings it will provide. Qualification and re-qualification indicate that the QSA has met PCI SSC requirements to perform assessments; PCI SSC does not endorse the assessor’s business practices.

For privacy advice, consider an Australian privacy lawyer or suitably qualified privacy adviser. Ask the adviser to state relevant qualifications and experience, confirm that the engagement covers the merchant’s Privacy Act 1988 (Cth), APP 11 and Notifiable Data Breaches (NDB) questions, and specify the facts and assumptions their written advice will address.

Ask the entity accepting PCI evidence to confirm in writing whether validation is required, which assessment or SAQ route applies, and what evidence it will accept. The QSA can assess the actual implementation, but the acquirer, payment brand or other compliance-programme entity sets the merchant’s validation and submission requirements.

PCI DSS Validation Routes and Privacy Obligations: Key Differences

  • PCI DSS Validation RouteDetermined by acquirer, payment brand or compliance programme entity; QSA provides assessment but does not set requirements
  • Privacy Act 1988 (Cth) CoverageDepends on business size, type of data handled (e.g. health info), and whether personal information is traded; determined by Australian privacy adviser
  • APP 11 – Security of Personal InformationRequires reasonable steps including technical and organisational measures; includes de-identification or destruction when no longer needed
  • NDB Scheme Notification DutyOnly applies if eligible breach likely to cause serious harm; requires notification to individuals and OAIC

Request a responsibility map

Where a provider performs functions within or related to the cardholder data environment, request evidence describing the service and the PCI requirements it handles. Map which requirements remain with the merchant and which the provider meets, including relevant page changes, access, logs and incident handling.

Under PCI DSS Requirement 12.8, the merchant must oversee provider relationships, identify which requirements apply to each party and monitor provider compliance status at least annually. A provider does not have to be validated as PCI DSS compliant solely to meet Requirement 12.8, but evidence matters when it performs PCI DSS requirements on the merchant’s behalf.

For an embedded provider payment form, ask how the merchant’s page is protected from script attacks. PCI DSS v4.0.1 Self-Assessment Questionnaire (SAQ) A r1 includes the criterion that the merchant has confirmed its site is not susceptible to scripts that could affect its e-commerce systems.

That SAQ A script criterion applies to an e-commerce webpage with an embedded payment page or form, not to a redirect or fully outsourced payment function. PCI FAQ 1588 describes confirmation through techniques such as those in PCI DSS Requirements 6.4.3 and 11.6.1, or confirmation from the compliant provider when its solution is implemented according to its instructions; check the latest SAQ A for all eligibility criteria.

Key Compliance Requirements Summary

PCI DSS v4.x Version in Use
PCI SSC identifies PCI DSS v4.x as current standard
Applicable SAQ for Embedded Forms
SAQ A r1 (with script protection confirmation)
NDB Notification Threshold
Eligible breach likely to cause serious harm

Check Australian privacy coverage separately

The Privacy Act 1988 (Cth) sets out the Australian Privacy Principles (APPs). The Office of the Australian Information Commissioner (OAIC) is Australia’s independent national privacy regulator and publishes APP and NDB guidance.

Ask the adviser to decide in writing whether the Privacy Act covers the business and the personal information it holds, and explain the basis. APP entities generally include private-sector businesses with annual turnover of more than AU$3 million, but some businesses of any size are covered, including businesses that trade in personal information and health service providers that hold health information; turnover alone does not settle coverage.

If APP 11 applies, reasonable steps to protect personal information include technical and organisational measures. The adviser’s decision should also address reasonable steps to destroy or de-identify information when it is no longer needed, except where it is a Commonwealth record or must be retained under Australian law or a court or tribunal order.

Ask whether the NDB scheme applies to the merchant and what assessment or notification duties follow. Covered entities must notify individuals and the Commissioner about eligible breaches likely to cause serious harm; coverage, unauthorised access or disclosure, relevant loss of information, likely serious harm and remedial action affect the decision. An unusual checkout change alone is not an eligible breach.

Keep the advisers’ written scopes, source documents and versions used, findings tied to the merchant’s configuration, and named remediation owners. Set a review trigger for changes to the payment page, apps, provider arrangement or data flow.

More from Fraud Controls

Fraud Controls

Checkout security and access

Map who can change checkout, review staff and app access, keep payment data out of logs and prepare to investigate unexpected changes.