Credit and Debit Card Transaction Procedures. University of Bath

Size: px
Start display at page:

Download "Credit and Debit Card Transaction Procedures. University of Bath"

Transcription

1 Credit and Debit Card Transaction Procedures University of Bath

2 Table of Contents Introduction Ethics and Acceptable Use Policies Credit and Debit Card Transactions Protection of Stored Data Protection of Data in Transit Restriction of Access to Data Physical Security Security Awareness and Procedures Third Parties holding Cardholder Data Security Management / Incident Response Plan - 1 -

3 Introduction The security of information related to credit and debit cards has become increasingly important in recent years. As an organisation which processes card-holder data, the University is now obliged to comply with the Payment Card Industry Data Security Standard (PCI/DSS) In the longer term, the University will be moving towards using web-based processing, where the card-holder information is held only by the payment service providers who have enhanced security in place. In the meantime, it is important that the University does not store this sort of data on electronic systems, which may be vulnerable to hacking and other unauthorised access. For this reason, while transaction processing may be carried out electronically, e.g. on credit card terminals, all procedures detailed below which relate to information storage will be paper-based. These procedures cover the security of credit and debit card-related information and must be distributed to all University employees who deal with credit and debit card transactions. Management will review and update the procedures at least once a year to incorporate relevant security needs that may develop. Each employee involved must read the procedures and verify that they have read and understood them. Ethics and Acceptable Use Policies These procedures are subject to the appropriate University Regulations and Policies. Of particular relevance are :- University Policy 12 Business Ethics and Fraud ( IT Security Policy ( An employee s failure to comply with the procedures set forth in this document may result in disciplinary action up to and including the termination of employment

4 Credit and Debit Card Transactions Credit Card Terminals Departments with access to credit card terminals must use them in accordance with the security measures specified with those terminals. Credit card slips should be retained for at least 6 months, to enable chargebacks. However, they must be held securely. They should in any case not be held for longer than 2 years. Departments without terminals Departments who do not have access to a credit card terminal must use the appropriate University pre-printed Credit and Debit Card Transaction Form. There is one form for sending out to customers for them to complete and return. This form can be obtained from the Downloadable Forms sections of the Finance Office web page ( There is also a pre-numbered form for internal departmental use only. This form is obtainable from the Cashier s Office. On occasion, a Department may wish to combine a course or conference enrolment form with the credit/debit card form. All such forms must be agreed in advance of use with the Cashier s Office. It is prohibited to use any other style of form for credit and debit card transactions. Transaction Form - Customer use This form will typically be used where customers are paying for conference or course fees, etc. When a customer expresses an interest, the department sends out a form for payment. The customer will complete cardholder details and card details. The department will complete the payment details, and send the form to the Cashier s Office for processing. It is prohibited to make a copy of completed forms at any time. Transaction Form - Internal use When a department takes cardholder details directly from a customer, either where the customer is present, or over the telephone, they should use this form. These forms are pre-numbered. It is prohibited to make a copy of this form at any time, either before or after completion

5 Where the credit card security code (the 3 to 4 digit code on the back of the card) has been taken to validate a transaction, it should be recorded on the tear-off strip of the Credit and Debit Card Transaction Form. The strip should be separated from the rest of the form and stored separately. Transaction Form - Combined booking form / credit/debit card details The format and use of all such combined forms must be agreed in advance with the Cashier s Office. A copy may be made of the booking section of the form, but never of the card details. Credit/Debit Card Paying-in Advice Account coding for the transactions should be entered on the paying-in advice, which should be sent to the Cashier s Office together with the Transaction Forms. The use of this advice is similar to that of the advices used for the paying in of cash or cheques Protection of Stored Data All sensitive information must be stored securely and disposed of in a secure manner when no longer required for business reasons. Only paper media should be used to store sensitive information, and it must be protected from unauthorised access. Media no longer needed must be destroyed in a manner to render sensitive data irrecoverable (e.g. shredding, etc). If in doubt, please refer to the guidance contained on the web-site :- Department All sensitive information must be stored securely in a locked cupboard or drawer, with access limited to those properly authorised (see below). Credit and debit card information should never be retained in the department for longer than 24 hours (unless over a weekend or Bank Holiday). The card security code and the rest of the cardholder information should be stored separately from each other. Cashier s Office The Cashier s Office will store cardholder information, in the Cashier s safe or in an alternative secure environment, for up to 2 years to enable refunds to be made. Card security code information must be destroyed as soon as it has been used for a particular transaction - 4 -

6 Credit and Debit Card Information Handling Specifics It is prohibited to store the contents of the card magnetic stripe (track data) on any media whatsoever It is prohibited to store the card security code (last 3 or 4 digit value printed on the signature of the card) on any media whatsoever except the tear-off strip from the pre-numbered Credit and Debit Card Transaction Form It is prohibited to store cardholder information on PCs or any other electronic media. Cardholder information is defined as :- o Card account number o Expiry date o Cardholder name (in conjunction with the above) The card security code must never be stored with the cardholder information Destroy cardholder information by a secure method when no longer needed. Media containing card information must be destroyed by shredding or other means of physical destruction that would render the data irrecoverable Protection of Data in Transit Sensitive information should never be transported electronically. Physical transport should always be via a trusted and secure method. Department Cardholder information and card security code should be taken or sent for processing within 24 hours (or immediately after a weekend or Bank Holiday). Separate envelopes should be used for the two types of information - cardholder data to the Cashier s Office, and the card security code to the Cashier s Office Manager in the Finance Office. Cashier s Office Once the card security code information has been matched with appropriate cardholder information and the transaction has been processed, the card security code must be destroyed. Credit and Debit Card Information Handling Specifics Card account numbers must never be ed Media containing card account numbers must only be given to trusted persons for transport within the University

7 Restriction of Access to Data Access to sensitive information should be restricted to those who have a need to know. No employees should have access to card account numbers unless they have a specific job function that requires such access. Access for each such employee must be authorised by their Head of Department and the Director of Finance or her deputy. A list of these employees will be held centrally in the Finance Office. Before authorising an employee to handle credit and debit card transactions, the Head of Department must be satisfied that the employee has read and understood the procedures, and understands how it affects their job. Physical Security Restrict physical access to sensitive information to protect it from those who do not have a need to access that information. Media containing sensitive information must be securely handled and distributed Media containing stored sensitive information should be properly inventoried and disposed of when no longer needed for business reasons, by shredding, etc In areas that may contain sensitive information, be aware of the need to hold such information securely, especially in relation to visitors and others who should not have access to it Cardholder information will be retained by the Cashier s Office in order to enable later refunds. It should not be retained for longer than necessary for business reasons, and in any case never for longer than 2 years. At the end of the period of retention, it must be physically destroyed by shredding, etc. Security Awareness and Procedures Keeping sensitive information secure requires periodic training of employees and contractors to keep security awareness levels high

8 Third Parties holding Cardholder Data The Treasury Accountant will maintain a central list of service providers who hold cardholder data. All third parties with access to card account numbers are contractually obliged to comply with card association security standards (PCI/DSS) Security Management / Incident Response Plan These procedures are subject to the Financial Regulation G14 Irregularities ( In the event of a compromise of sensitive information, the Internal Auditor will oversee the execution of the incident response plan. Incident Response Plan 1. If a compromise is suspected, alert the Internal Auditor ( [email protected] ) 2. The Internal Auditor will conduct an initial investigation of the suspected compromise. 3. If a compromise of information is confirmed, the Internal Auditor will alert management and begin informing parties that may be affected by the compromise. If the compromise involves card account numbers, the Internal Auditor will perform the following :- Contain and limit the extent of the exposure by shutting down any systems or processes involved in the compromise Alert necessary parties (Merchant Bank, Visa Fraud Control, the police, etc) Provide compromised or potentially compromised card numbers to Visa Fraud Control within 24 hours More information - sp_if_compromised.html - 7 -

University of York Policy on the Management of Debit/ Credit Card Data

University of York Policy on the Management of Debit/ Credit Card Data University of York Policy on the Management of Debit/ Credit Card Data Version 1.0 25th February 2015 Index 1 Introduction and Policy Statement 1.1 The Payment Card Industry Data Security Standard (PCI

More information

ROYAL BOROUGH OF WINDSOR AND MAIDENHEAD SECURITY POLICY. Processing Electronic Card Payments

ROYAL BOROUGH OF WINDSOR AND MAIDENHEAD SECURITY POLICY. Processing Electronic Card Payments ROYAL BOROUGH OF WINDSOR AND MAIDENHEAD SECURITY POLICY Processing Electronic Card Payments Introduction and Policy Aim The Payment Card Industry Data Security Standard (PCI-DSS) is a worldwide information

More information

2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS)

2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS) CSU, Chico Credit Card Handling Security Standard Effective Date: July 28, 2015 1.0 INTRODUCTION This standard provides guidance to ensure that credit card acceptance and ecommerce processes comply with

More information

EAA Policy for Accepting and Handling Credit and Debit Card Payments ( Policy )

EAA Policy for Accepting and Handling Credit and Debit Card Payments ( Policy ) EAA Policy for Accepting and Handling Credit and Debit Card Payments ( Policy ) Background Due to increased threat of identity theft, fraudulent credit card activity and other instances where cardholder

More information

INFORMATION SECURITY POLICY. Policy for Credit Card Acceptance to Conduct College Business

INFORMATION SECURITY POLICY. Policy for Credit Card Acceptance to Conduct College Business DELAWARE COLLEGE OF ART AND DESIGN 600 N MARKET ST WILMINGTON DELAWARE 19801 302.622.8000 INFORMATION SECURITY POLICY including Policy for Credit Card Acceptance to Conduct College Business stuff\policies\security_information_policy_with_credit_card_acceptance.doc

More information

CREDIT CARD PROCESSING POLICY AND PROCEDURES

CREDIT CARD PROCESSING POLICY AND PROCEDURES CREDIT CARD PROCESSING POLICY AND PROCEDURES Note: For purposes of this document, debit cards are treated the same as credit cards. Any reference to credit cards includes credit and debit card transactions.

More information

POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants

POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101 DIVISION: Finance & Administration TITLE: Policy & Procedures for Credit Card Merchants DATE: October 24, 2011 Authorized by: K. Ann Mead, VP for Finance & Administration

More information

Accepting Payment Cards and ecommerce Payments

Accepting Payment Cards and ecommerce Payments Policy V. 4.1.1 Responsible Official: Vice President for Finance and Treasurer Effective Date: September 29, 2010 Accepting Payment Cards and ecommerce Payments Policy Statement The University of Vermont

More information

Cash & Banking Procedures

Cash & Banking Procedures Financial Policies and Procedures Cash & Banking Procedures 1 P a g e Contents 1. Banking Procedures 1.1 Receipt of cash and cheques within a department 1.2 Storage/security of cash and cheques within

More information

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures 1. Introduction 1.1. Purpose and Background 1.2. Central Coordinator Contact 1.3. Payment Card Industry Data Security Standards (PCI-DSS) High Level Overview 2. PCI-DSS Guidelines - Division of Responsibilities

More information

Standards for Business Processes, Paper and Electronic Processing

Standards for Business Processes, Paper and Electronic Processing Payment Card Acceptance Information and Procedure Guide (for publication on the Treasury Webpages) A companion guide to University policy 6120, Payment Card Acceptance Standards for Business Processes,

More information

Credit and Debit Card Handling Policy Updated October 1, 2014

Credit and Debit Card Handling Policy Updated October 1, 2014 Credit and Debit Card Handling Policy Updated October 1, 2014 City of Parkville 8880 Clark Ave. Parkville, MO 64152 Hours: 8:00-5:00 p.m. Monday -Friday Phone Number 816-741-7676 Email: [email protected]

More information

Credit Card Handling Security Standards

Credit Card Handling Security Standards Credit Card Handling Security Standards Overview This document is intended to provide guidance to merchants (colleges, departments, auxiliary organizations or individuals) regarding the processing of charges

More information

This policy applies to all GPC units that process, transmit, or handle cardholder information in a physical or electronic format.

This policy applies to all GPC units that process, transmit, or handle cardholder information in a physical or electronic format. Policy Number: 339 Policy Title: Credit Card Processing Policy, Procedure, & Standards Review Date: 07-23-15 Approval Date: 07-27-15 POLICY: All individuals involved in handling credit and debit card transactions

More information

PCI General Policy. Effective Date: August 2008. Approval: December 17, 2015. Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS:

PCI General Policy. Effective Date: August 2008. Approval: December 17, 2015. Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS: Effective Date: August 2008 Approval: December 17, 2015 PCI General Policy Maintenance of Policy: Office of Student Accounts PURPOSE: To protect against the exposure and possible theft of account and personal

More information

PCI Training for Retail Jamboree Staff Volunteers. Securing Cardholder Data

PCI Training for Retail Jamboree Staff Volunteers. Securing Cardholder Data PCI Training for Retail Jamboree Staff Volunteers Securing Cardholder Data Securing Cardholder Data Introduction This PowerPoint presentation is designed to educate Retail Jamboree Staff volunteers on

More information

Payment Cardholder Data Handling Procedures (required to accept any credit card payments)

Payment Cardholder Data Handling Procedures (required to accept any credit card payments) Payment Cardholder Data Handling Procedures (required to accept any credit card payments) Introduction: The Procedures that follow will allow the University to be in compliance with the Payment Card Industry

More information

CREDIT CARD NUMBER HANDLING PROCEDURES POLICY. 2014 October

CREDIT CARD NUMBER HANDLING PROCEDURES POLICY. 2014 October CREDIT CARD NUMBER HANDLING PROCEDURES POLICY 2014 October Royal Roads University Page 1 of 6 21 October 2014 Table of Contents Policy Statement... 3 Rationale... 3 Applicability of the Policy... 3 Definitions...

More information

TERMINAL CONTROL MEASURES

TERMINAL CONTROL MEASURES UCR Cashiering & Payment Card Services TERMINAL CONTROL MEASURES Instructions: Upon completion, please sign and return to [email protected] when requesting a stand-alone dial up terminal. The University

More information

Clark University's PCI Compliance Policy

Clark University's PCI Compliance Policy ï» Clark University's PCI Compliance Policy Who Should Read this Policy: All persons who have access to credit card information, including: Every employee that accesses handles or maintains credit card

More information

A8.700 TREASURY. This directive applies to all campuses of the University of Hawai i.

A8.700 TREASURY. This directive applies to all campuses of the University of Hawai i. Prepared by Treasury Office. This amends A8.710 dated July 2001. A8.710 April 2005 A8.700 TREASURY P 1 of 5 A8.710 Credit Card Program 1. Purpose To provide uniform procedures for the processing of credit

More information

Information Technology

Information Technology Credit Card Handling Security Standards Overview Information Technology This document is intended to provide guidance to merchants (colleges, departments, organizations or individuals) regarding the processing

More information

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS 1. Introduction Debit and Credit Card Receipt Standards apply to the administration

More information

GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY

GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY PURPOSE The Payment Card Industry Data Security Standard was established by the credit card industry in response to an increase in identify theft

More information

Failure to follow the following procedures may subject the state to significant losses, including:

Failure to follow the following procedures may subject the state to significant losses, including: SUBJECT: Policy and Procedures PAGE: 1 of 5 INTRODUCTION During fiscal year 2014, State of Wisconsin agencies accepted approximately 6 million credit/debit card payments through the following payment channels:

More information

Appendix 1 Payment Card Industry Data Security Standards Program

Appendix 1 Payment Card Industry Data Security Standards Program Appendix 1 Payment Card Industry Data Security Standards Program PCI security standards are technical and operational requirements set by the Payment Card Industry Security Standards Council to protect

More information

University of Sunderland Business Assurance PCI Security Policy

University of Sunderland Business Assurance PCI Security Policy University of Sunderland Business Assurance PCI Security Policy Document Classification: Public Policy Reference Central Register IG008 Policy Reference Faculty / Service IG 008 Policy Owner Chief Financial

More information

CITY OF SAN DIEGO ADMINISTRATIVE REGULATION Number 95.51 PAYMENT CARD INDUSTRY (PCI) COMPLIANCE POLICY. Page 1 of 9.

CITY OF SAN DIEGO ADMINISTRATIVE REGULATION Number 95.51 PAYMENT CARD INDUSTRY (PCI) COMPLIANCE POLICY. Page 1 of 9. 95.5 of 9. PURPOSE.. To establish a policy that outlines the requirements for compliance to the Payment Card Industry Data Security Standards (PCI-DSS). Compliance with this standard is a condition of

More information

The University of Georgia Credit/Debit Card Processing Procedures

The University of Georgia Credit/Debit Card Processing Procedures The University of Georgia Credit/Debit Card Processing Procedures The University of Georgia currently accepts four major credit cards (MasterCard, Visa, Discover and American Express) for payment of services

More information

Payment Card Acceptance Administrative Policy

Payment Card Acceptance Administrative Policy Administrative Procedure Approved By: Brandon Gilliland, Associate Vice President for Finance & Controller Effective Date: October 1, 2014 History: Approval Date: September 25, 2014 Revisions: Type: Administrative

More information

How To Control Credit Card And Debit Card Payments In Wisconsin

How To Control Credit Card And Debit Card Payments In Wisconsin BACKGROUND State of Wisconsin agencies accepted more than 6 million credit/debit card payments annually through the following payment channels: Point of Sale (State agency location) Point of Sale (Retail-agent

More information

CREDIT CARD PROCESSING & SECURITY POLICY

CREDIT CARD PROCESSING & SECURITY POLICY FINANCE AND TREASURY POLICIES AND PROCEDURES E071 CREDIT CARD PROCESSING & SECURITY POLICY PURPOSE The purpose of this policy is to establish guidelines for processing charges/credits on Credit Cards to

More information

6-8065 Payment Card Industry Compliance

6-8065 Payment Card Industry Compliance 0 0 0 Yosemite Community College District Policies and Administrative Procedures No. -0 Policy -0 Payment Card Industry Compliance Yosemite Community College District will comply with the Payment Card

More information

Saint Louis University Merchant Card Processing Policy & Procedures

Saint Louis University Merchant Card Processing Policy & Procedures Saint Louis University Merchant Card Processing Policy & Procedures Overview: Policies and procedures for processing credit card transactions and properly storing credit card data physically and electronically.

More information

LSE PCI-DSS Cardholder Data Environments Information Security Policy

LSE PCI-DSS Cardholder Data Environments Information Security Policy LSE PCI-DSS Cardholder Data Environments Information Security Policy Written By: Jethro Perkins, Information Security Manager Reviewed By: Ali Lindsley, PCI-DSS Project Manager Endorsed By: PCI DSS project

More information

WASHINGTON STATE UNIVERSITY MERCHANT ACCOUNT AGREEMENT FOR UNIVERSITY DEPARTMENTS

WASHINGTON STATE UNIVERSITY MERCHANT ACCOUNT AGREEMENT FOR UNIVERSITY DEPARTMENTS WASHINGTON STATE UNIVERSITY MERCHANT ACCOUNT AGREEMENT FOR UNIVERSITY DEPARTMENTS I. Introduction, Background and Purpose This Merchant Account Agreement (the Merchant Agreement or Agreement ) is entered

More information

Office of Finance and Treasury

Office of Finance and Treasury Office of Finance and Treasury How to Accept & Process Credit and Debit Card Transactions Procedure Related Policy Title Credit Card Processing Policy For University Merchant Locations Responsible Executive

More information

Andrews University Payment Card Acceptance Policies & Procedures. Prepared by Financial Administration

Andrews University Payment Card Acceptance Policies & Procedures. Prepared by Financial Administration Andrews University Payment Card Acceptance Policies & Procedures Prepared by Financial Administration July 12, 2011 Part I: Introduction of Policy and Purpose Formatted: Font: 12 pt In order to protect

More information

PCI Data Security and Classification Standards Summary

PCI Data Security and Classification Standards Summary PCI Data Security and Classification Standards Summary Data security should be a key component of all system policies and practices related to payment acceptance and transaction processing. As customers

More information

This policy shall be reviewed at least annually and updated as needed to reflect changes to business objectives or the risk environment.

This policy shall be reviewed at least annually and updated as needed to reflect changes to business objectives or the risk environment. - 1. Policy Statement All card processing activities and related technologies must comply with the Payment Card Industry Data Security Standard (PCI-DSS) in its entirety. Card processing activities must

More information

UTAH STATE UNIVERSITY POLICIES AND PROCEDURES MANUAL

UTAH STATE UNIVERSITY POLICIES AND PROCEDURES MANUAL UTAH STATE UNIVERSITY POLICIES AND PROCEDURES MANUAL Title: Credit Card Handling and Acceptance Policy Policy Number: C3875 Effective Date: November 8, 2006 Issuing Authority: Office of VP Business and

More information

UNL PAYMENT CARD POLICY AND PROCEDURES. Table of Contents

UNL PAYMENT CARD POLICY AND PROCEDURES. Table of Contents UNL PAYMENT CARD POLICY AND PROCEDURES Table of Contents Payment Card Merchant Security Standards Policy and Procedures... 2 Introduction... 4 Payment Card Industry Data Security Standard... 4 Definitions...

More information

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011 CREDIT CARD MERCHANT PROCEDURES MANUAL Effective Date: 5/25/2011 Updated: May 25, 2011 TABLE OF CONTENTS Introduction... 1 Third-Party Vendors... 1 Merchant Account Set-up... 2 Personnel Requirements...

More information

ACCEPTING CREDIT CARDS AND ELECTRONIC CHECKS TO CONDUCT UNIVERSITY BUSINESS

ACCEPTING CREDIT CARDS AND ELECTRONIC CHECKS TO CONDUCT UNIVERSITY BUSINESS UNIVERSITY OF NORTH DAKOTA FINANCE & OPERATIONS POLICY LIBRARY ACCEPTING CREDIT CARDS AND ELECTRONIC CHECKS TO CONDUCT UNIVERSITY BUSINESS Policy 2.3, Accepting Credit Cards and Electronic Checks to Conduct

More information

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 Effective Date of this Policy: August 1, 2008 Last Revision: September 1, 2009 Contact for More Information: UDit Internal Auditor

More information

COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL

COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL PAYMENT CARD INDUSTRY COMPLIANCE (PCI) Effective June 1, 2011 Page 1 of 6 (1) Definitions a. Payment Card Industry Data Security Standards (PCI-DSS): A set of standards established by the Payment Card

More information

How To Complete A Pci Ds Self Assessment Questionnaire

How To Complete A Pci Ds Self Assessment Questionnaire Department PCI Self-Assessment Questionnaire Version 1.1 2009 Attestation of Compliance Instructions for Submission This Department PCI Self-Assessment Questionnaire has been developed as an assessment

More information

Approved and commenced March 2015 Review by March, 2017 CONTENTS

Approved and commenced March 2015 Review by March, 2017 CONTENTS Related Policy Responsible Officer Approved by Approved and commenced March 2015 Review by March, 2017 Responsible Organisational Unit CONTENTS Cashiering and Revenue Collection Procedure Invoicing & Receivables

More information

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Mission Statement Dartmouth College requires all departments that process, store or transmit credit card data remain in compliance

More information

University of Liverpool

University of Liverpool University of Liverpool Card Payment Policy Reference Number Title Version Number 1.0 Document Status Document Classification FIN-001 Card Payment Policy Active Public Effective Date 03 June 2014 Review

More information

New York University University Policies

New York University University Policies New York University University Policies Title: Payment Card Industry Data Security Standard Policy Effective Date: April 11, 2012 Supersedes: N/A Issuing Authority: Executive Vice President for Finance

More information

Cashier s Office. Income Procedure Guidance

Cashier s Office. Income Procedure Guidance Cashier s Office Income Procedure Guidance Accounts Receivable Revised May 2013 Contents Introduction 1 Key Financial Regulations 2 Paying-In at the Cashier s Office 3 Paying-In Advice Income Miscellaneous

More information

Business Debit Card. Cardholder Terms. HB00520_BusDebitCard_TC-12pp.indd 1 01/08/2012 15:07

Business Debit Card. Cardholder Terms. HB00520_BusDebitCard_TC-12pp.indd 1 01/08/2012 15:07 Business Debit Card Cardholder Terms HB00520_BusDebitCard_TC-12pp.indd 1 01/08/2012 15:07 2 Cardholder Terms These Business Debit Card Cardholder Terms (these Cardholder Terms ) apply to the use of the

More information

Merchant Payment Card Processing Guidelines

Merchant Payment Card Processing Guidelines Merchant Payment Card Processing Guidelines The following is intended to provide guidance that departments or units can use to help develop specific procedures for their department or unit. If you have

More information

The Online Payment Process

The Online Payment Process Bank of Valletta Insert Title of Presentation The Online Payment Process Ray Bezzina Agenda Is there the need for me to go online? What do I stand to gain if I go online? What do I stand to lose if I do

More information

Date Adopted: 05-18-11

Date Adopted: 05-18-11 Page 1 of 9 I. PURPOSE: The Oakland County Parks and Recreation Cash and Payment Card Industry (PCI) outlines procedures for the safe handling of funds managed on behalf of Oakland County as well as PCI

More information

Dartmouth College Merchant Credit Card Policy for Processors

Dartmouth College Merchant Credit Card Policy for Processors Mission Statement Dartmouth College Merchant Credit Card Policy for Processors Dartmouth College requires all departments that process, store or transmit credit card data remain in compliance with the

More information

Banking terms and conditions

Banking terms and conditions M&S PREMIUM CURRENT ACCOUNT, M&S PREMIUM CURRENT ACCOUNT WITH INSURANCE AND M&S MONTHLY SAVER Banking terms and conditions EFFECTIVE FROM 17 FEBRUARY 2015 NEW FASHIONED BANKING Contents Page Page Section

More information

General Terms and Conditions Current Accounts Terms and Conditions Savings Accounts Terms and Conditions

General Terms and Conditions Current Accounts Terms and Conditions Savings Accounts Terms and Conditions 1 General Terms and Conditions Current Accounts Terms and Conditions Savings Accounts Terms and Conditions Effective from 1 April 2012 (for new customers) 2 General Terms and Conditions Your agreement

More information

An introduction to CashFlows and the provision of on-line card acceptance services we provide to Young Enterprise companies

An introduction to CashFlows and the provision of on-line card acceptance services we provide to Young Enterprise companies An introduction to CashFlows and the provision of on-line card acceptance services we provide to Young Enterprise companies Q. What is CashFlows? A. CashFlows is a Financial Services company that provides

More information

Welcome to the Duke Medicine Credit Card PCI Education session.

Welcome to the Duke Medicine Credit Card PCI Education session. Welcome to the Duke Medicine Credit Card PCI Education session. During this session, we will explain the Duke Medicine Credit Card PCI Policy and Procedure that has been implemented to ensure we are in

More information

POLICY SECTION 509: Electronic Financial Transaction Procedures

POLICY SECTION 509: Electronic Financial Transaction Procedures Page 1 POLICY SECTION 509: Electronic Financial Transaction Procedures Source: NDSU President NDSU VP for Finance and Administration NDSU VP for Information Technology A. Purpose / Rationale Many NDSU

More information

CAL POLY POMONA FOUNDATION. Policy for Accepting Payment (Credit) Card and Ecommerce Payments

CAL POLY POMONA FOUNDATION. Policy for Accepting Payment (Credit) Card and Ecommerce Payments CAL POLY POMONA FOUNDATION Policy for Accepting Payment (Credit) Card and Ecommerce Payments 1 PURPOSE The purpose of this policy is to establish business processes and procedures for accepting payment

More information

A Rackspace White Paper Spring 2010

A Rackspace White Paper Spring 2010 Achieving PCI DSS Compliance with A White Paper Spring 2010 Summary The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard defined by the Payment Card Industry

More information

University of St Andrews. Unit Income and Cash Handling Policy

University of St Andrews. Unit Income and Cash Handling Policy University of St Andrews Unit Income and Cash Handling Policy Last reviewed 17 September 2014 CONTENTS page 1 Introduction and Policy Statement 3 2 Cash Free Units 3 3 Securing Cash 3 4 Receipting Cash

More information

University of Virginia Credit Card Requirements

University of Virginia Credit Card Requirements University of Virginia Credit Card Requirements The University of Virginia recognizes that e-commerce is critical for the efficient operation of the University, and in particular for collecting revenue.

More information

Merchant Card Processing Best Practices

Merchant Card Processing Best Practices Merchant Card Processing Best Practices Background: The major credit card companies (VISA, MasterCard, Discover, and American Express) have published a uniform set of data security standards that ALL merchants

More information

CREDIT CARD SECURITY POLICY PCI DSS 2.0

CREDIT CARD SECURITY POLICY PCI DSS 2.0 Responsible University Official: University Compliance Officer Responsible Office: Business Office Reviewed Date: 10/29/2012 CREDIT CARD SECURITY POLICY PCI DSS 2.0 Introduction and Scope Introduction

More information

Policies and Procedures. Merchant Card Services Office of Treasury Operations

Policies and Procedures. Merchant Card Services Office of Treasury Operations Policies and Procedures Merchant Card Services Office of Treasury Operations 1 Welcome! Table of Contents: Introduction Establishing Payment Card Services Payment Card Acceptance Procedures Payment Card

More information

SWEDBANK AS TERMS AND CONDITIONS FOR PAYMENT CARDS SERVICING Valid from 01.12.2014

SWEDBANK AS TERMS AND CONDITIONS FOR PAYMENT CARDS SERVICING Valid from 01.12.2014 SWEDBANK AS TERMS AND CONDITIONS FOR PAYMENT CARDS SERVICING Valid from 01.12.2014 1. TERMS AND DEFINITIONS 1.1 Account is a current account of the Merchant specified in the Agreement. 1.2 Agreement is

More information

Policy for Protecting Customer Data

Policy for Protecting Customer Data Policy for Protecting Customer Data Store Name Store Owner/Manager Protecting our customer and employee information is very important to our store image and on-going business. We believe all of our employees

More information

EFTPOS Merchant Facilities Quick Reference Guide

EFTPOS Merchant Facilities Quick Reference Guide EFTPOS Merchant Facilities Quick Reference Guide How to Use this Guide This handy Quick Reference Guide has been designed to give you step-by-step, easy-to-follow instructions on how to correctly use your

More information

Information Security

Information Security Information Security A staff guide to the University's Information Systems Security Policy Issued by the IT Security Group on behalf of the University. Information Systems Security Guidelines for Staff

More information

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 I. PURPOSE The purpose of this policy is to establish guidelines for processing charges on Payment Cards to protect

More information

General Terms and Conditions Current Accounts Terms and Conditions Savings Accounts Terms and Conditions

General Terms and Conditions Current Accounts Terms and Conditions Savings Accounts Terms and Conditions General Terms and Conditions Current Accounts Terms and Conditions Savings Accounts Terms and Conditions Effective from 10 November 2014 2 Contents Section/Clause Page Contact Information 3 Section 1 Payment

More information

Newcastle University Information Security Procedures Version 3

Newcastle University Information Security Procedures Version 3 Newcastle University Information Security Procedures Version 3 A Information Security Procedures 2 B Business Continuity 3 C Compliance 4 D Outsourcing and Third Party Access 5 E Personnel 6 F Operations

More information

credit card Conditions of Use

credit card Conditions of Use VISA credit card Conditions of Use EFFECTIVE FROM 20 MARCH 2013 a refreshing attitude to banking QUEENSLAND COUNTRY CREDIT UNION VISA CREDIT CARD 1 Contents 1. Introduction 3 2. Additional Cards 3 3. Application

More information

Controls should be appropriate to the scale of the assets at risk and the potential loss to the University.

Controls should be appropriate to the scale of the assets at risk and the potential loss to the University. POLICY SUPPORT PAPER MANAGING THE RISK OF FRAUD Risk and Controls in Specific Systems Purpose of the Paper The purpose of this paper is to provide guidance to managers and supervisors on controls that

More information