What part does California Privacy Notification play in PCI-CISP?
There is no direct relationship between PCI-CISP rules and the California Privacy Notification law (SB1386). The PCI-CISP rules are payment industry and Visa rules required of merchants using their system. You are obligated to follow these rules as a part of your merchant agreement. The California Privacy Notification law affects any merchant selling products in California. If sensitive information, such as credit card numbers, is lost or may have been lost, it requires that you notify anyone who may be affected. There is quite a broad definition of what it means to lose sensitive information, and most companies will begin the notification process on any suspicion that private information may have been compromised.