What is the Data Security Operating Policy?
The Data Security Operating Policy is an American Express policy, with which all Merchants, Processors, and Service Providers that store, process or transmit American Express® Cardmember information must comply. This policy has been strengthened to reflect current business conditions, provides additional requirements to help safeguard Cardmember information, and aligns with the Payment Card Industry Data Security Standard (PCI Standard). The PCI Data Security Standard sets out a common set of technical requirements for safeguarding sensitive payment data which are applicable across the industry.
The Data Security Operating Policy is an American Express policy, first implemented in 2002, with which all merchants, processors, and service providers that store, process or transmit American Express® Cardmember information must comply. The latest version of this policy has been strengthened to reflect current business conditions, provides additional requirements to help safeguard Cardmember information, and aligns with the Payment Card Industry Data Security Standard (PCI Standard). The PCI Data Security Standard sets out a common set of technical requirements for safeguarding sensitive payment data applicable across the industry.