PCI DSS
The Payment Card Industry Data Security Standard — security requirements for any business or system that stores, processes, or transmits cardholder data, enforced contractually rather than by law.
The current version, PCI DSS 4.0.1 (June 2024), is organized around six goals: a secure network, protected account data, vulnerability management, strong access control, ongoing monitoring, and a written security policy. It doesn't apply based on business size — it applies based on whether a card number ever touches a system a business operates.
A pizzeria's counter terminal already encrypts a card the instant it's tapped, so the owner fills out the shortest self-assessment questionnaire each year. The following spring the same pizzeria wires up a plain web form for phone orders — its card volume hasn't changed, but its PCI scope has grown considerably, because a card number now briefly exists on a system it built and has to secure itself.
The most common mistake is treating “PCI compliant” as one fact true of an entire company, rather than a scope question answered separately for each system. It's also a contractual standard, not a government regulation — the consequences of falling short are fines and higher fees, not a criminal matter.
Dohos's own systems — the conversation, the transcript, the order record — sit structurally outside a restaurant's cardholder data environment, without claiming any specific compliance level, covered on PCI DSS at Dohos.
BACK TO THE FULL GLOSSARY · OR THE WORKED GUIDES
Open the line.
Tell us about your restaurant. We load your menu, you place a call, and you hear it answered yourself.