Merchants must be very careful in handling credit card information and data. Sensitive cardholder data must be securely disposed of when no longer needed. All but the last four digits of the account number must be masked when displaying cardholder data. Paper documents containing credit card information must be stored in a locked file with controlled access. Credit card data must not be stored on any of the following: server, laptop, floppy, CD, DVD, or any other electronic manner. Data Security pertains to all transactions, whether they are initiated via the telephone, over the counter, mail order, Internet, etc. If you are not in compliance with any of these requirements, contact the Office of Business Operations for immediately for assistance.
Secure all confidential cardholder numbers and information. Credit card receipts should typically be treated the same as you would treat cash. Departments will be responsible for any losses due to poor internal and inadequate controls.
Credit card numbers must never be transmitted by e-mail, unsecured fax, or through campus mail.
All documentation containing credit card account numbers must be maintained in a secure location that is accessible to only accountable staff members. Secure locations include locked drawers and safes.
Payments should be processed within 24-48 hours of receipt. If payments are stored overnight a Credit Card Storage Log must be maintained.
All documentation containing card account numbers must be destroyed in such a way that they will be deemed unreadable.
The Identity Finder program should be used monthly to scan inboxes, sent folders, and desktops to ensure rouge credit card information is appropriately identified and removed.
Restrict access to credit data and processing to appropriate and authorized
Departments that process credit card transactions are required to monitor all visitors. All personnel need to be able to easily distinguish between employees and visitors. Departments must either maintain a Visitor Log or require all employees to wear a Name Badges.
Background checks must be completed for all New Hires with a credit card processing job responsibility.
Establish segregation of duties between the credit card processing and reconciliation.
An annual review of department policy and procedures must be conducted annually. All changes must be reported to the Office of Business Operations.
To request changes to your Merchant Account the Credit Card Account Change Request form must be submitted. This form can be used for adding new users to the account, deleting users, making a department name change, or modifying account numbers used for deposits and/or fees.
Credit card authorizations must be kept for 18 months for response to charge-backs and other disputes.
Staff members working with credit card data are required to attend annual credit card policy and procedure training.
The Office of Business Operations and/or Internal Audit will conduct periodic reviews of existing credit card accounts regarding the safeguarding and storage of cardholder data.
The Credit Card Account Change Request form should be used to notify the Office of Business Operations of proposed changes.
Report all suspected or known security breaches immediately to the Office of Business Operations and your supervisor.
Examples include: Tampered files/cabinets used to store credit card information, lost/stolen keys, compromised ID & passwords, unusual/unexplained credit card transactions on your account, computer workstation breach, or unsecured credit card data.