Who enforces the PCI-DSS?
PCI-DSS is not included in state or federal laws, but is a set of security standards developed by the PCI-SSC to guide Merchants who are storing, transmitting, or processing cardholder data. All Merchants must sign agreements with their Acquiring Banks in order to accept credit cards. The agreement with the Acquiring Bank does hold the Merchant liable to comply with the PCI-DSS and addresses the penalties and fines that ensue if the Merchant is found not to be compliant.