PCI DSS and Payment Card Compliance Policy

    Hosting UK's approach to PCI DSS, ecommerce hosting and payment card security responsibilities.

    Version 1.0 · Policy · Applies to all customers processing payment cards

    If your website accepts, processes, stores or transmits payment card information, you may be subject to the Payment Card Industry Data Security Standard ("PCI DSS").

    Hosting UK may provide reasonable assistance and guidance in relation to PCI DSS requirements where they relate to the services we provide. However, responsibility for achieving and maintaining PCI DSS compliance remains with the customer unless expressly agreed otherwise in writing.

    1. Hosting UK's role

    1.1Hosting UK may provide hosting and infrastructure services purchased by the Customer.

    1.2Hosting UK may provide reasonable guidance regarding PCI DSS requirements affecting our Services.

    1.3Hosting UK may assist with implementing security measures that fall within the scope of our Services.

    1.4Hosting UK may provide information reasonably required during Customer compliance assessments.

    1.5Any assistance provided by Hosting UK is provided on a reasonable endeavours basis only.

    2. Services not included

    2.1Unless expressly agreed in writing, Hosting UK does not provide PCI DSS compliant hosting services.

    2.2Hosting UK does not provide PCI DSS certification services.

    2.3Hosting UK does not provide Qualified Security Assessor (QSA) services.

    2.4Hosting UK does not provide PCI compliance consultancy.

    2.5Hosting UK does not provide PCI remediation services.

    2.6Hosting UK does not provide Approved Scanning Vendor (ASV) scanning services.

    2.7Hosting UK does not provide PCI DSS documentation preparation services.

    2.8Hosting UK does not provide penetration testing services.

    2.9Hosting UK does not manage Customer PCI compliance programmes.

    3. Customer responsibilities

    3.1The Customer is solely responsible for determining whether PCI DSS applies to their business.

    3.2The Customer is responsible for understanding and maintaining their PCI DSS obligations.

    3.3The Customer is responsible for securing their applications and business processes.

    3.4The Customer is responsible for managing third-party suppliers.

    3.5The Customer is responsible for completing any required assessments or certifications.

    3.6The Customer is responsible for implementing appropriate security controls.

    3.7The Customer is responsible for ensuring the lawful handling of payment card data.

    4. Ecommerce applications and payment gateways

    4.1The installation, configuration or support of ecommerce software, shopping cart applications, payment gateways, SSL certificates, firewalls, security plugins or server software does not constitute a representation, warranty or certification that a Customer's environment is PCI DSS compliant.

    5. Scope of responsibility

    5.1Hosting UK is only responsible for the Services expressly purchased by the Customer.

    5.2Hosting UK is not responsible for Customer applications, custom code, third-party software, business processes, internal procedures, Customer devices or networks, or any systems outside the scope of the purchased Services.

    6. Limitation of liability

    6.1Hosting UK shall not be liable for PCI DSS non-compliance, payment card data breaches, regulatory fines or penalties, chargebacks, forensic investigation costs, or costs associated with obtaining or maintaining PCI DSS certification, except to the extent directly caused by Hosting UK's negligence in providing the specific Services purchased by the Customer.

    7. Future services

    7.1Hosting UK may introduce dedicated PCI DSS compliant hosting services or managed compliance services in the future.

    7.2Any such services will be subject to separate specifications, pricing and terms and conditions.

    Related documents

    © Hosting UK. This content is provided as structured legal website copy. Please contact us if you need a signed copy or have questions.