Skip to main content
Logo GMV

Main navigation

  • Sectors
    • Icono espacio
      Space
    • Icono Aeronáutica
      Aeronautics
    • Icono Defensa y Seguridad
      Defense and Security
    • Icono Sistemas Inteligentes de Transporte
      Intelligent Transportation Systems
    • Icono Automoción
      Automotive
    • Icono Ciberseguridad
      Cybersecurity
    • Icono Servicios públicos Digitales
      Digital Public Services
    • Icono Sanidad
      Healthcare
    • Icono Industria
      Industry
    • Icono Financiero
      Financial
    • Icono Industria
      Services
    • All Sectors

    Highlight

    Slopsquatting
    Slopsquatting: A silent threat born from the hallucinations of LLMs
  • Talent
  • About GMV
    • Get to Know the Company
    • History
    • Management Team
    • Certifications
    • Corporate Social Responsibility
  • Communication
    • News
    • Events
    • Blog
    • Magazine GMV News
    • Press Room
    • Media library
    • Latest from GMV

Secondary navigation

  • Products A-Z
  • GMV Global
    • Global (en)
    • Spain and LATAM (es - ca - en)
    • Germany (de - en)
    • Portugal (pt - en)
    • Poland (pl - en)
    • All branches and all GMV sites
  • Home
Back
New search
Date
Blog
  • Tourism and Smart Destinations

Do I need to comply with PCI DSS and PSD2?

19/08/2022
  • Print
Share
PCI DSS & PSD2

If your business, hotel, OTA, restaurant, travel agency, etc., processes, stores, or transmits critical payment card data, then you need to comply with PCI DSS / PSD2, regardless of the size of your company. If you do not process or store card data, but you use third-party payment gateways, then it is also very likely that you need to comply with this standard.

What is PCI DSS?

PCI DSS stands for Payment Card Industry Data Security Standard, which is the worldwide data protection standard for industries that handle credit or debit card payments. Its primary objective is to ensure that all companies have a minimum level of basic security in place, in order to protect cardholder data.

credit card

The following data is considered as critical to protect: PAN, cardholder’s name, expiration date, service code, data on the magnetic stripe or its equivalent on a chip, CAV2, CVC2, CVV2, CID, personal identification number (PIN) and PIN blocks.

What is PSD2?

The PCI DSS regulations were established in 2006, and although they have now reached version 4 (first quarter of 2022), there was a need to adapt them to new security systems. Because of this, the EU’s Payment Services Directive 2 entered into force in 2019, and it applies to any business that may have interactions with European customers.

PSD2 includes improved guidelines for online payments, and for managing confidential data to reduce the risk of theft, fraud, and security breaches. The main change is the requirement on strong customer authentication (SCA) for online transactions. With SCA, customers need to provide a second authentication factor before they can make a payment. This can be a PIN code or a verification code sent by SMS.

What does PSD2 mean for your hotel business?

It essentially means that any transaction your hotel initiates when a guest is not present is not in compliance with the PSD2 requirements. Guests must be able to complete a two‑factor verification step for each payment, such as when they make a reservation or when they check out. This means that hotels may need to modify or adapt their payment procedures. 

Requirements and Solutions

The PCI DSS standard includes more than 290 controls related to physical, technological, and administrative security. These are organized into 6 goals or objectives, which are in turn subdivided to form 12 requirements, as seen below:

PSD2

Levels

There are also various levels for these requirements, which are based upon a company’s number of annual transactions. These are grouped into four levels:

  • Level 1: more than 6 million annual transactions
  • Level 2: between 1 million and 6 million annual transactions
  • Level 3: between 20,000 and 1 million annual transactions
  • Level 4: fewer than 20,000 annual transactions

For Levels 2, 3, and 4, there is a self-assessment tool: Self-Assessment Questionnaire (SAQ). This is used to evaluate a company’s compliance with the requirements from the PCI DSS standard. However, for Level 1, in addition to completing the SAQ, a "Formal Compliance Audit" is required. This provides more exhaustive evidence for each requirement. GMV is an Approved Scanning Vendor for performing these official evaluations, so feel free to contact us if you need more information.

Author: Joan Antoni Malonda

  • Print
Share

Comments

About text formats

Restricted HTML

  • Allowed HTML tags: <a href hreflang target> <em> <strong> <cite> <blockquote cite> <code> <ul type> <ol start type> <li> <dl> <dt> <dd> <h2 id> <h3 id> <h4 id> <h5 id> <h6 id>
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.
CAPTCHA

Related

No results

Contact

Europaplatz 2
64293 Darmstadt | Deutschland
Tel. +49 6151 3972 970
Fax. +49 6151 8609 415

Zeppelinstraße, 16
82205 Gilching | Deutschland
Tel. +49 (0) 8105 77670 150
Fax. +49 (0) 8105 77670 298

Contact menu

  • Contact
  • GMV around the world

Blog

  • Blog

Sectors

Sectors menu

  • Space
  • Aeronautics
  • Defense and Security
  • Intelligent Transportation Systems
  • Automotive
  • Cybersecurity
  • Digital Public Services
  • Healthcare
  • Industry
  • Financial
  • Services
  • Talent
  • About GMV
  • Shortcut to
    • Press Room
    • News
    • Events
    • Blog
    • Products A-Z
© 2025, GMV Innovating Solutions S.L.

Footer menu

  • Contact
  • Legal Notice
  • Privacy Policy
  • Cookie Policy
  • Impressum

Footer Info

  • Commitment to the Environment
  • Financial Information