Earlier quoted context omitted.
Yeah, you don't need to be a lawyer to implement PCI-DSS. You are entirely missing the following dot point: "Processes for secure deletion of data when no longer needed" Those dot points aren't using a disjunction, they must ALL be followed. The standard is very, very clear on that point: once you don't need the data, you securely delete it. That makes sense, incidentally. If you no longer have the data anywhere, the…
I'm not entirely missing the point, but I don't know enough about the PCI-DSS to be too much of a contrarian here :) Processes for secure deletion of data when no longer needed Is "needed" defined anywhere? As far as I can tell this requires companies to create a plan – that plan could be very different between companies. I highly doubt Homejoy/Fly Maids is maintaining the data themselves, it's probably stored in Str…
Speechless!
I highly doubt Homejoy/Fly Maids is maintaining the data themselves, it's probably stored in Stripe, so unless they are actually storing credit card data in a non PCI compliant way, they are probably fine, right?
No, Stripe would then be violating PCI-DSS themselves.