The average data breach now costs $4.45 million. For a payments business, that number isn’t abstract — it’s exactly what’s at stake when payments compliance gets treated as an afterthought. Payments compliance is adherence to the laws, standards, and best practices that govern how customer payment data is collected, stored, processed, and protected. Get it wrong badly enough, and it’s not just a fine on the table: processing agreements can be terminated, and banks can revoke a merchant’s ability to accept credit cards altogether. This guide covers what payments compliance actually involves, which regulations apply where, and how to build embedded compliance into the way you operate rather than bolting it on after the fact.
What Is Payments Compliance?
Payments compliance is the umbrella term for everything a business must do to handle payment data legally and safely. It covers four distinct layers, and most compliance failures happen because a business has one layer covered and assumes that’s the whole picture:
- Data security standards — PCI DSS and similar frameworks
- Regulatory frameworks — PSD2, GDPR, and their regional equivalents
- Financial crime prevention — AML and KYC obligations
- Payment network rules — requirements set directly by Visa, Mastercard, and other schemes
Compliance frameworks typically include security protocols like encryption and access controls, alongside data privacy rules that dictate exactly how consumer data can be collected and handled in the first place. On top of that sits network-level compliance — the operating rules that Visa, Mastercard, and other card schemes set independently of any government regulator, covering everything from chargeback handling to merchant category restrictions.
It’s worth reframing this: global payments compliance isn’t purely a legal cost center. Done well, it reduces disputes and chargebacks and makes operations genuinely more efficient — fewer disputes means less time spent fighting them after the fact, and cleaner data handling tends to mean fewer processing errors overall.
Key Payment Compliance Regulations
Five frameworks come up constantly in payments compliance conversations. Here’s what each one actually requires:
- PCI DSS — introduced in 2004 by the major card brands, this applies to any business processing cardholder data, regardless of size or transaction volume. It sets specific requirements for secure data storage and encryption, along with regular vulnerability scans and access controls. Non-compliance doesn’t just mean a one-time fine — it typically means increased processing fees on every transaction going forward, which compounds fast for high-volume merchants.
- PSD2 — adopted in 2015 and enforced from 2019 in Europe, PSD2 mandates Strong Customer Authentication (SCA) for online transactions. SCA requires two independent authentication factors — something the customer knows, has, or is — before a payment can go through, which is why so many European checkouts now include a bank-app confirmation step.
- GDPR — Europe’s core data privacy law, governing how personal data is handled from collection through deletion. GDPR and CCPA (its US counterpart in California) both dictate how consumer data must be collected, stored, and processed, and both give individuals enforceable rights over their own data — including the right to have it deleted.
- AML regulations — require ongoing monitoring of transactions to catch financial crime before it happens, not after. In the US, that means following frameworks like the Bank Secrecy Act, which sets reporting thresholds and recordkeeping obligations that apply directly to payment processors.
- KYC — the process of verifying customer identities to reduce fraud risk before a relationship even begins. It’s usually treated as a core component sitting inside the broader AML framework rather than a separate obligation, but it has its own documentation and verification standards that need to be met independently.
None of this is static. PSD3 is already in development in Europe, building on lessons learned from PSD2’s rollout, and compliance strategies that don’t build in room to adapt will fall behind fast — what’s fully compliant today can become a gap within a single regulatory cycle.
One question worth answering directly: does ACH fall under PCI compliance? Generally, no — ACH transactions don’t involve cardholder data the way card payments do, so they sit outside PCI DSS scope. That doesn’t mean ACH is unregulated, though; it’s still governed by NACHA rules and standard AML requirements.
Ready to upgrade your payment infrastructure?
Stop struggling with fragmented payment flows. Access dedicated IBANs, SEPA Instant, and seamless API integrations – all from a single, unified platform.
The 5 Key Areas of Payments Compliance
Zooming out from individual regulations, payments compliance really comes down to five operational areas. Think of these less as separate checklists and more as five muscles that all need to stay in shape at once.
- Data security — PCI DSS compliance is mandatory for any business handling cardholder data, and encryption is the baseline protection against breaches. This also covers network segmentation and access logging — knowing exactly who touched sensitive data, and when.
- Authentication and fraud prevention — Strong Customer Authentication is a PSD2 requirement for online transactions in Europe, and multi-factor authentication is now standard practice for fraud prevention more broadly, even outside jurisdictions where it’s technically mandated.
- AML and transaction monitoring — ongoing monitoring is what catches suspicious activity in real time, before it becomes a much bigger problem. This includes screening against sanctions lists and flagging transaction patterns that don’t match a customer’s expected behavior.
- KYC and identity verification — essential not just for consumers but for onboarding business clients too, and it’s an ongoing obligation rather than a one-time check performed at signup and forgotten.
- Data privacy — GDPR and CCPA set the rules for how consumer data gets collected and used, and both carry real enforcement teeth, including fines that scale with global revenue rather than a fixed cap.
Fraud and financial crime specifically deserve their own deep dive — this piece on money muling covers one of the areas AML monitoring is designed to catch.
Consequences of Payments Non-Compliance
The costs of getting this wrong fall into four categories:
- Financial penalties. PCI DSS non-compliance triggers fines and increased processing fees — and that’s before factoring in breach costs, which averaged $4.45 million in 2023.
- Loss of processing ability. Banks can revoke a merchant’s ability to accept credit cards entirely, and processing agreements can be terminated outright for serious violations.
- Reputational damage. Compliance failures erode customer trust in ways that outlast the incident itself — a clean compliance record is part of what keeps customers coming back, and a public failure changes purchasing behavior long after the headlines fade.
- Operational disruption. Compliance monitoring has to be continuous and structured. Gaps don’t just sit there quietly — they create exposure that eventually surfaces as enforcement action, often at the worst possible time, like during a busy sales period when a review or audit forces attention away from the business itself.
For a broader view of what “getting compliance right” actually looks like day to day, this guide to financial service compliance is a good next step.
Global Payments Compliance: Key Regional Differences
Payments compliance doesn’t look the same everywhere, and that’s the single biggest headache for businesses operating across borders.
Europe runs on PSD2 (with PSD3 in development), GDPR, and AML directives including 6AMLD. Strong Customer Authentication is mandatory for online transactions, and open banking itself is regulated directly under PSD2.
The United States takes a more fragmented approach. PCI DSS applies universally to card payments, the Bank Secrecy Act governs AML, FinCEN sets KYC requirements, NACHA governs ACH payments specifically, and CCPA covers data privacy — but only in California, which creates its own patchwork across states.
Globally, Visa and Mastercard network rules apply regardless of jurisdiction, layered on top of whatever local law already requires. FATF sets international AML standards that most countries align with in some form, even where local implementation and enforcement intensity varies significantly from one market to the next.
Inconsistent requirements across jurisdictions make global payments compliance genuinely difficult to manage in-house. A business expanding from Europe into the US, for example, doesn’t just need to add new rules — it needs to reconcile PSD2’s authentication mandate with a US market that has no equivalent SCA requirement, while still meeting PCI DSS on both sides of the Atlantic. That’s usually the point where businesses operating in multiple markets need either a dedicated compliance team or an infrastructure provider with compliance already built in. PSD2 and open banking specifically are worth understanding in more depth if Europe is a core market.
Payments Compliance Best Practices
Here’s what actually holds up in practice, not just on paper. None of these are one-time projects — they’re standing operational habits, which is exactly what most businesses underestimate when they first set up a compliance program.
- Run regular audits and training. PCI DSS specifically requires ongoing audits, not a one-time certification.
- Implement continuous transaction monitoring. Real-time detection is what catches suspicious activity before it compounds.
- Apply Strong Customer Authentication everywhere PSD2 applies. Don’t treat SCA as optional for any EU-facing transaction.
- Keep KYC records current. Identity verification isn’t a one-time onboarding step — it needs regular updates.
- Use encryption and access controls consistently. These are the baseline security protocols every compliance framework assumes are already in place.
- Choose infrastructure with compliance embedded, not bolted on. Businesses relying on providers that build AML, KYC, PSD2, and GDPR obligations into the platform itself carry significantly less operational exposure than those managing it all separately.
- Build in room to adapt. Compliance strategies that assume today’s rules are permanent get caught out — regulatory change is a constant, not an exception.
ConnectPay handles that sixth point directly: AML, KYC, PSD2, and GDPR obligations sit inside the platform infrastructure itself, which is a fundamentally different starting point than managing compliance as a bolt-on service layered over a generic payment stack. You can see the full ConnectPay platform for how that plays out end to end.
What Is a Payments Compliance Notice?
A payments compliance notice is a formal communication — usually from a payment network, a regulator, or an acquiring bank — informing a merchant or financial institution that they’ve failed to meet a specific compliance requirement.
A few things typically trigger one: PCI DSS non-compliance, an unusually high chargeback rate, gaps in AML monitoring, or exposure from a data breach. None of these have to happen simultaneously — a single unresolved audit finding is often enough on its own to trigger a notice, especially if it follows an earlier warning that went unaddressed.
Receiving a notice isn’t automatically catastrophic, but it usually kicks off a review period, and it can mean increased fees or, in more serious cases, termination of processing agreements.
If a notice does land, the right move is to respond promptly and bring in a compliance specialist — or an infrastructure provider with embedded fraud prevention capabilities — rather than trying to resolve it internally from scratch.









