PCI Compliance28 July 20267 min read

PCI Compliance UK: Who Enforces It & What It Costs

PCI DSS isn't UK law — but your acquirer enforces it like it is. Who actually checks, which SAQ you need, and the monthly fees that hit your merchant statement when you lapse.

PCI Compliance UK: Who Enforces It & What It Costs

If you take card payments in Britain, you've almost certainly been told you need to be "PCI compliant." What nobody explains is who's actually checking, what they can do about it, and how much it costs when you get it wrong. Most guides answer the global question and stop. This one is about the UK — your acquirer, your self-assessment, and the fees that quietly appear on your merchant statement.

Let's clear up the biggest myth first.

Is PCI compliance a UK law?#

No. PCI DSS — the Payment Card Industry Data Security Standard — isn't an Act of Parliament. You won't find it in UK statute, and the FCA doesn't police it. It's a standard written and maintained by the PCI Security Standards Council, a body set up by the major card schemes.

So why does everyone treat it like law? Because it's enforced by contract instead of by legislation, and in practice that's just as binding. When you signed up with your payment provider, you agreed to meet PCI DSS. That agreement is real, it's enforceable, and breaking it has consequences — as we'll get to.

There's a second reason it matters here. UK data-protection law does apply to card data. If you leak customers' card details, the ICO can act under the Data Protection Act 2018 and UK GDPR, entirely separately from anything the card schemes do. So "it's not the law" doesn't mean "it doesn't matter." It means the pressure comes from two directions at once. If you want the full standard from the ground up, start with what PCI DSS actually is.

Who actually enforces PCI DSS in the UK#

Here's the chain, because understanding it tells you exactly who'll be knocking.

At the top sit the card schemes — Visa, Mastercard and the rest — through the PCI Security Standards Council. They write the standard. They don't bill you directly.

Below them are the acquiring banks — your merchant acquirer, the organisation that settles card payments into your bank account. This is who enforces PCI on you. Your acquirer is contractually obliged to make sure their merchants meet PCI DSS, and they pass that obligation straight down to you.

So when we talk about "enforcement" in the UK, we mean your acquirer. They set your deadlines. They decide which self-assessment you complete. They apply the fees if you slip. If you've ever had a chaser email demanding you renew your PCI status, it came from them or from a compliance service acting on their behalf.

The ICO sits outside this chain but overlaps with it. They don't check your PCI paperwork. They turn up after a breach.

What your acquirer requires from you#

Two colleagues working through compliance paperwork at an office desk, the evidence-gathering stage of a PCI self-assessment

Every acquirer wants proof you're handling card data properly. What that proof looks like depends on how many card transactions you process a year and how you take them.

The card schemes split merchants into levels. Level 1 is the largest — typically over six million transactions a year — and demands an external audit by a Qualified Security Assessor plus regular network scans. Most UK small and mid-sized businesses fall into Levels 2 to 4, where you can prove compliance yourself with a Self-Assessment Questionnaire, or SAQ.

Your acquirer will usually ask for three things: a completed SAQ, evidence of any required vulnerability scans, and an annual renewal. Miss the renewal and you're marked non-compliant, even if nothing about your setup has actually changed. That's a common trap — plenty of merchants are technically secure but administratively lapsed, and they still get charged for it.

If you take payments over the phone, there's an extra layer worth reading up on separately in our guide to the UK rules for taking card payments by phone, because phone payments are where scope tends to balloon.

The SAQ process, and how to land on the shortest one#

The SAQ is where PCI gets real for most UK businesses. There are several versions, and which one you complete depends entirely on how card data flows through your business. This is the single most important thing to understand, because the wrong setup can put you on a questionnaire with hundreds of controls when you could be on one with a handful.

SAQ A is the short one. It applies when you've fully outsourced card handling and no cardholder data ever touches your systems. Fewer questions, less evidence, far less that can go wrong at audit time.

At the other end, SAQ D is the long one — the setup that applies when card data passes through your environment. For a contact centre, that's the default nightmare. The moment an agent hears a card number read aloud, or it's typed into a screen on your network, or it sits in a call recording, your systems are "in scope." Everything that touches that data has to meet PCI DSS. That's servers, phones, recordings, the lot.

The whole game, then, is descoping — arranging things so card data never enters your environment in the first place. Do that, and you drop from the long questionnaire to the short one. We'll come back to how that works for phone payments, because it's what we do.

What non-compliance costs — the fees on your merchant statement#

A contactless card payment at a terminal — every UK card transaction runs under an acquirer agreement that requires PCI DSS compliance

This is the part nobody's straight with you about. Non-compliance isn't a hypothetical. It's a line item.

Most UK acquirers apply a monthly non-compliance fee to merchants who haven't got a valid SAQ on file. It's typically a recurring charge — often somewhere in the region of £30 to £50 a month, sometimes bundled as a "PCI DSS non-compliance" or "PCI management" fee — and it keeps applying every month you stay lapsed. Look closely at your merchant statement and you may find you're already paying it without realising. The exact amount varies by acquirer, so check yours, but the principle is universal: no valid self-assessment, extra charge.

That's the quiet cost. The loud cost comes after a breach.

If card data is stolen from your environment, you can face scheme fines passed down through your acquirer, forensic investigation costs, the expense of reissuing compromised cards, and potentially higher processing rates afterwards. On top of that, the ICO can act under UK data-protection law if customers' personal data was exposed. Two separate bodies, two separate bills, one incident.

We've written more on the full cost of PCI compliance — including the cost of doing it properly versus the cost of getting caught out. The short version: the non-compliance fee is annoying, but it's cheap compared to a breach.

Where UK data-protection law fits in#

Worth being precise here, because merchants conflate the two. PCI DSS protects card data on behalf of the card schemes. UK GDPR and the Data Protection Act 2018 protect personal data on behalf of individuals, and they're enforced by the ICO.

A card number sitting in an unsecured call recording is both a PCI problem and a data-protection problem. Your acquirer cares about the first. The ICO cares about the second. Being PCI compliant makes an ICO problem far less likely, but the two are governed separately, and you're answerable to both. That's exactly why "PCI isn't law" is a dangerous half-truth to build a policy on.

How we cut phone payments down to SAQ A#

Phone payments are the hardest place to stay compliant, because a spoken card number is naturally in scope. So we take it out of scope.

We've been a PCI DSS Level 1 certified service provider since 2016 — the top certification tier, independently audited every year. When your customer types their card number on their phone keypad during a call, our DTMF masking converts those tones so your agent never hears the digits and the numbers never reach your systems, your screens, or your call recordings. The card data goes straight to us and on to the payment processor. It doesn't enter your environment at all.

That's what moves you to SAQ A — the shortest self-assessment. Instead of proving that every server, phone and recording meets hundreds of controls, you're proving you've outsourced card handling to someone who has. You can read the detail of our PCI DSS Level 1 certification on our compliance page.

And because staying compliant is more than one questionnaire, we built Paytia Comply — a free app that covers all 966 PCI DSS v4.0.1 requirements, so you can track where you stand across the whole standard rather than guessing at renewal time.

Get out of scope, not just compliant#

Being PCI compliant is the floor. The smarter move is to arrange things so card data never touches your business at all — because you can't lose what you never hold. That's what takes a contact centre from the long questionnaire to the short one, and it's what keeps you off both your acquirer's fee list and the ICO's radar.

We can take your phone payments out of scope and drop you to SAQ A, and Paytia Comply will help you keep the rest of the standard in order for free. Talk to us about descoping your card payments — we'll show you exactly what changes and what it saves you.

The Paytia solution

If you're reading this, here are the Paytia solutions that solve it.

Related Articles

Ready to take secure payments?

Book a demo with our team. We'll show you DTMF masking live, talk through PCI DSS scope reduction, and put together pricing based on your call volume.

PCI DSS Level 1
Cyber Essentials Plus

Trusted by law firms, insurers, healthcare providers and regulated businesses worldwide. Learn more about Paytia