For fundraisers in the UK charity sector, managing donations securely is not just about meeting regulatory standards—it’s about building and maintaining the trust of their donors.
As cheque donations are slowly declining, processing card payments safely and efficiently has become an even more critical part of delivering excellent donor experiences. This is where PCI DSS (Payment Card Industry Data Security Standard) becomes a key factor, especially Level 1 compliance.
While many service providers might talk about PCI compliance only those that are compliant to Level 1 will have undergone an independent external assessment.
IT Governance.co.uk state that "According to UK Finance’s Fraud the Facts 2019 report, unauthorised financial fraud losses totalled £844.8 million in 2018, a year-on-year increase of 16%."
PCI DSS is a global security standard created to ensure all organisations that store, process or transmit credit or debit card information do so securely. Compliance with PCI DSS is mandatory for any service provider involved with storing, processing, or transmitting cardholder data, but it is also mandatory for those service providers that could affect the security of card holder data.
PCI DSS V4.0 for Service Providers contains over 260 questions detailing the associated controls that need to be implemented, maintained, monitored, reviewed, and verified. Those controls need to be applied to all applicable components within scope of the Cardholder Data Environment (CDE); and as mentioned this is not just those components that store, process, or transmit cardholder data but those that affect the security of cardholder data (this latter point is often overlooked when organisations consider what is and isn’t in scope of PCI DSS, or often they do not implement segmentation appropriately resulting in devices being accidently brought into scope but not having the appropriate controls and measured implemented).
PCI DSS also requires certain tasks and activities to be performed consistently via a regularly scheduled and repeatable process, and in some cases at specific time intervals, e.g. external scans must be conducted by an Approved Scanning Vendor (ASV) every 3 months. Failure to do so would result in non-compliance.
It is mandatory for service providers processing over 300,000 transactions (per payments brand) to achieve PCI DSS Level 1 compliance. This requires the organisation to be independently assessed by a QSA every year.
A Report on Compliance (RoC) will be completed by the QSA and an Attestation of Compliance (AoC) will be completed and signed by the QSA company and the Service Provider.
Some Service Providers choose to achieve Level 1 compliance even though the number of transactions they process per payment brand equate them to a Level 2. Woods Valldata is one of those providers because it knows partner charities’ donor data and reputations require the highest level of compliance.
Self-assessment applies to any service provider that processes fewer than 300,000 card payments for a single payment brand such as Visa, Mastercard, American Express etc.
So in reality a service provider could be processing a lot more than 300,000 card payments in total but because they do not exceed the 300,000 for a single payment brand they are permitted to self-assess their compliance status by completing a Self-Assessment Questionnaire and a Attestation of Compliance (AoC) annually.
It’s worth noting then that a service provider could be processing in excess of 500,000 card payments and they could still self-assess!
Ultimately, achieving PCI DSS compliance requires a Provider to meet the most stringent standards, ensuring comprehensive and robust protection of cardholder data.
Only those that achieve level 1 compliance have had the following externally validated against PCI DSS requirements:
Therefore, for charities relying on outsourced payment processing, understanding the provider’s PCI DSS level matters.
At Woods Valldata, we understand the unique needs of UK charities and are committed to providing the best-in-class solutions for their fundraising activities. We know that when you outsource, you're outsourcing your charity's reputation. We’re in it with you to deliver the best possible experience for your supporters and the highest possible return for your fundraising spend. Here’s why we stand out:
PCI DSS Level 1 compliance: We’re externally validated to meet the highest standard in payment security, meaning you can be certain your donors’ card data is handled with maximum protection.
Expertise in charity fundraising: With decades of experience, we’ve developed services tailored specifically to the charitable sector, including raffles, lotteries, response handling across platforms, fulfilment and data strategy.
End-to-end support: Our solutions go beyond compliance to include ongoing operational support, insightful reporting, and optimisation to enhance your fundraising success.
Reputation for excellence: Trusted by leading UK charities, our proven track record demonstrates that partnering with us delivers tangible benefits.
Partnering with a provider like Woods Valldata not only ensures compliance with the highest standards but also demonstrates your commitment to protecting your supporters’ sensitive information.
By outsourcing your card payment processing to Woods Valldata, you can safeguard your organisation’s reputation, grow your donor base, and focus on what truly matters—delivering impact through your charitable mission.
Let’s discuss how we can help you take your fundraising to the next level with secure and efficient payment processing solutions. Get in touch with Woods Valldata today.