In this example an ADC occurred involving a non compliant customer where 4,000 Visa cards were deemed at risk and less than 30,000 Mastercard cards were deemed at risk. For the purposes of this example PAN and CVV were located.
Grand Total £25,630*
*Any ADC fees are correct at the time and date of release and are subject to change and will be allocated on a case by case basis. Mastercard is a registered trademark of Mastercard International Incorporated. What to do if card data has been lost or stolen
What other costs might you face?
As well as paying card scheme ADC fees, you also need to take steps to make sure a breach doesn’t happen again. Following an ADC event, you will need to validate as a PCI Level 1 merchant for a year. This means you will need to engage with a Qualified Security Assessor to do this. Engaging a Qualified Security Assessor (QSA) for a full report on compliance (level 1 certification) could cost up to £50,000, depending on the complexity of systems and the amount of remediation work required.
But you could face a number of unknown additional costs such as:
- Migration to an outsourced solution
- Website re-development
- Compressing an existing compliance programme into 90 days
- Cost of reputational risk
The costs outlined are only the ADC fees from card schemes. These are separate from the significant Data Protection fines that can be levied by Data Protection Authorities under the General Data Protection Regulation (GDPR). This is the regulation that was introduced in May 2018 which comes to govern personal data including adequate security around payment card data. Companies may be subject to fines of up to 4% of their global annual turnover or €20million (or whichever is the greater) if they do not put in adequate security controls such as PCI DSS.
Recent precedent has shown that even high profile companies that have taken steps to protect data have been subject to fines up to 4% of their global annual turnover.
Elavon is here to support you
By working with one of the world’s largest acquirers, you’ll benefit from our leading expertise within the payments industry.
We can support our customers through every stage of the ADC process:
- Helping you to engage with third parties
- Providing impartial advice and guidance on remediation
- Working with you towards minimising costs
For more details
Elavon can help you to secure your payment channels and reduce the risk of an ADC event and the costly aftermath. We can offer you complimentary consultancy with trusted partners and the reassurance you need. For more information speak to your Elavon Relationship Manager or contact the Elavon Account Data Compromise team.