Whose Responsibility Should it be to Protect Sensitive Payment Card Data?

The payment card ecosystem is a very complex, involving multiple interconnected service providers. It has been built over the last several decades. When it was originally put together, protection of card data wasn’t the primary concern, since payment cards could only be used in face-to-face / ATM transactions and risks were manageable with original technologies and processes (mainly relying on visual cardholder signature checking and cardholder PIN verification). If the card data got stolen eventually, it could have been used only for producing counterfeit cards. That’s how EMV standard came about, with its primary goal being efficient protection from card cloning and counterfeiting. But unfortunately EMV standard did nothing (although it could) to protect sensitive card data from POS a ...

