This survey is being run in conjunction with WPM Education in the run up to their Payment Security Summit.  Your answers will remain anonymous, and will be used to collate an aggregated and anonymised report detailing the results of this survey.

You will be aware of your institution’s responsibility to protect cardholder data under the Payment Card Industry Data Security Standards (PCI DSS).  But are you aware of the consequences of a data breach with respect to the security requirements of the GDPRs and the Data Protection Act 2018? 

If your institution should suffer a breach because of failure to fully comply with the PCI DSS, the Information Commissioners Office (ICO), in its enforcement activities, will take this into account.  There is therefore an urgent need for protection of payment data to be considered as part of the overall data protection strategy for the institution.     

We’d appreciate you taking the time to respond to a short survey about how your institution is tackling payment security.

Question Title

* 1. Where does responsibility for PCI DSS compliance sit within your institution?

Question Title

* 2. Is your institution PCI DSS compliant?

Question Title

* 3. What do you understand to be the implications of non-compliance with PCI DSS?

Question Title

* 4. Is your institutions Data Protection Officer (DPO) involved with/ aware of PCI DSS?

Question Title

* 5. Does your institution have a data protection strategy that you are aware of?

Question Title

* 6. If yes, who in the institution is responsible for your data protection strategy?

Question Title

* 7. Is protecting payment data looked at as part of that strategy?

Question Title

* 8. Are you aware of your legal obligations to protect payment data, as defined by the UK’s Data Protection Act (DPA) 2018?

Question Title

* 9. What do you understand to be the implications of non-compliance with the Data Protection Act 2018?

Question Title

* 10. What are your key challenges in ensuring that payment data is secure all the time?

Question Title

* 11. Do you feel that your institution has a strong information security culture?

Question Title

* 12. So we can share a copy of the survey results with you, what is your email address? Note you do not have to provide this if you do not want to.

T