The SVIC DSS will address how to best secure data on closed-loop programs: card numbers, data concerning purchasing habits, loyalty point information, as well as other consumer-specific demographic data (birthdays, anniversaries, even shoe sizes) unique to stored-value transaction processing.
According to Vaden Landers, Chief Executive Officer at ProfitPoint, the initiative was borne out of a need recognized by Landers and SparkBase CEO Doug Hardman for the stored-value industry to stay ahead of data security issues that may arise. They wanted to "work to limit the potential for any horror stories popping up in the news that would create growth barriers for closed-loop players," he said.
Landers was not aware of any data security breaches having occurred on stored-value networks. But once fraudsters recognize the detailed information available on stored-value, closed-loop networks, and what they can do with that data, their level of interest in the stored-value industry will undoubtedly increase. And as their interest increases, the threat level increases proportionately.
Currently, there is no mechanism in place to track fraud on stored-value networks, Landers said. However, he noted that fraud on stored-value cards is of a different variety than fraud that occurs on the credit and debit card side.
"Anyone who could hack into a system and steal credit card information could get much more personal data from a stored-value network, whether at the merchant or the processor level," he said. "The potential for something really bad to happen that would give the industry a black eye is there, so we feel responsible for addressing it given that we are leaders in the space."
Landers said the standard will be based on the best practices already in place at ProfitPoint and SparkBase. "We are starting with our networks because it is our experience that offers the ability to capture and retain the most robust set of cardholder data of any other network in the industry," he added. "We felt that if we could secure our platform first, with its comprehensive toolset, other platforms would be simpler to certify."
The Payment Card Industry (PCI) Data Security Standard (DSS) will be useful in setting up a similar structure for the SVIC DSS, Landers noted. He expects ProfitPoint, SparkBase and Valutec Card Solutions (also involved in developing best practices) to collaborate with other leading players in the space on security protocols, much as the PCI Security Standards Council has done for the PCI DSS.
Notice to readers: These are archived articles. Contact names or information may be out of date. We regret any inconvenience.Prev Next