Are your shopping carts up to date?
Posted: Thur 2 Apr 2009
With a new VISA mandate coming into effect from 1st June 2009 that requires that the CSC* be provided with all Visa eCommerce transactions (online only), it's time to make sure your e-commerce is up to date and coplies with any legal requirements. By doing this you will enhance security to your customers and reduce the risk of being fined.
*CSC - Card security code, also referred to as CV2, CVV and CAVV - these are the three digits on the rear of the card (four digits if Amex)
There are a number of exemptions to the new VISA mandate, these are listed below:
- - Recurring and Instalment Payments (scheduled transactions)
- - Hotels/Lodging
- - Car Hire
- - Delayed or Amended T&E Charges
- - Travel and Entertainment deferred or amended charges
- - Health Care Incidental Expenses
- - Account on file CNP transactions (repeat transactions)
- - Split Sales
- - Business Travel Agents
- - Mail Order Transactions
In addition to this mandate, some acquiring banks are also specifying that the CSC be provided with all eCommerce transactions.
What you or your site developers need to do
A CV2 field needs to be incorporated on your payment page prior to the enforcement of this as a mandatory field. If you are unsure whether your site has this already, checkout your payment provider site where you login and see transactions processed, along with each transaction you should be able to determine whether the CV2 matching is in place.
The UK's E-commerce Regulations
Excerpt from Out-law.com
Whether your business is trading online or not, it is almost certainly affected by the E-commerce Regulations which came into force on the 21st August 2002. The Regulations (Electronic Commerce (EC Directive) Regulations 2002) implement the EU's E-Commerce Directive into UK law. The Directive was introduced to clarify and harmonise the rules of on-line business throughout Europe with the aim of boosting consumer confidence. The Directive was passed in June 2000. The UK missed its implementation deadline by over eight months.
Continue reading article at http://www.out-law.com/page-431
What to do?, where to start?
If you need any advice on your shopping carts legal requirements, feel free to drop us an enquiry or there are a number of sites that are available to help you. We have listed a few below to give you a starting point:
- UK Business Forums
Small business and startup help and advice for owners, managers and entrepeneurs.
- Out-Law
Out-Law.com is part of international law firm Pinset Masons and provides free legal news and guidance, mostly on IT and e-commerce issues.
- UK Business Labs
The forum based site is aimed to bring together business people from the UK

This information is provided with the assumption that you use a third-party payment provider (or direct with your bank) for your payments. X:drive do NOT recommend that you collect payment details and process them offline, by hand or by any other means. If you are in this position you need to consider the security of your online store.
COMMENTS