top of page

The data security gap hiding in your billing system

Most businesses that collect payments have heard of PCI-DSS. Fewer have thought carefully about what it doesn't cover — and why that gap matters.


The ICO's recent £963,900 fine against South Staffordshire Water is a useful prompt. The penalty notice records that the personal data exfiltrated and published on the dark web included bank account numbers and sort codes for hundreds of thousands of customers. It also records, almost in passing, that payment card data was held outside the compromised IT environment entirely, and was therefore not affected.


What PCI-DSS does — and doesn't — cover

PCI-DSS (the Payment Card Industry Data Security Standard) is a prescriptive, independently audited security framework that applies to any organisation storing, processing or transmitting payment card data. It mandates specific controls: network segmentation, encryption, access management, logging, regular penetration testing. Compliance is verified annually, either by a Qualified Security Assessor or by self-assessment for lower-volume organisations.


For organisations in scope, PCI-DSS creates a rigorous and externally verified control environment. The South Staffordshire findings — 5% monitoring coverage, end-of-life software, no vulnerability scans for approximately 20 months — would very likely have been identified by a PCI-DSS audit before they became an ICO enforcement matter.


But PCI-DSS only covers card data. It has nothing to say about bank account numbers and sort codes used for direct debit payments. And for many businesses, direct debit is the dominant, sometimes the only, payment method. The card data may sit in a tightly controlled, annually audited environment. The direct debit mandate data — the standing instruction from your customer, including their account details, often held for years in a CRM or billing platform — may not be subject to anything like the same level of scrutiny.


The framework that does apply


Bank account data held by a biller falls squarely within UK GDPR. As a data controller, you are required under Article 32(1) to implement "appropriate technical and organisational measures" to ensure security appropriate to the risk. That standard is assessed by the ICO by reference to established guidance (principally from the NCSC) and industry norms, rather than against a prescriptive checklist.


The absence of a checklist is not a comfort. As South Staffordshire discovered, the ICO's view of what "appropriate" looks like is informed by exactly the kind of foundational controls that PCI-DSS mandates as a matter of course: access management, monitoring, patching, vulnerability scanning.


Direct debit originators also operate under Bacs scheme rules, which impose contractual obligations enforced through their sponsoring bank. But those obligations are not a substitute for UK GDPR compliance, and Bacs enforcement operates through the scheme rather than through a regulator with the ICO's penalty-issuing powers.


The fraud risk picture


It is worth being clear about why bank account data warrants serious attention from a security perspective. Card fraud is generally faster to detect, easier to reverse, and the liability framework is well established. A compromised card can be cancelled and reissued. Bank account numbers and sort codes cannot be reissued in the same way — a customer cannot easily change their account details. Direct debit fraud can be harder to identify quickly, and while the Bacs Indemnity Claim process gives customers recourse, the burden of identifying and reporting the fraud sits with them.


The South Staffordshire notice makes this concrete: the November 2022 notifications to over 315,000 customers were triggered specifically by the risk of direct debit fraud arising from the exposure of bank account and sort code data. That is a significant remediation exercise, with reputational, operational and regulatory consequences; all flowing from data that sat outside the scope of any payments industry security standard.


Questions worth asking


If your business collects payment by direct debit, it is worth asking:


  • Where is your direct debit mandate data held, and what is the security posture of those systems?

  • Are those systems subject to the same monitoring, patching and access controls that your card data environment is — or has PCI-DSS scope inadvertently become the ceiling rather than the floor?

  • When did you last review, test or audit the security of the systems holding direct debit data specifically?

  • Do your third-party and outsourcing arrangements, including where direct debit processing is handled by a bureau, include appropriate contractual security obligations covering that data?


The ICO's penalty framework applies to all personal data processed in connection with your business, not just the data that falls within a payments industry standard. PCI-DSS compliance is valuable, but it is not a proxy for UK GDPR compliance in respect of data it

does not cover.


Talking Fox advises businesses on data protection compliance and payments law, including the intersection between the two. If you would like to discuss your approach to payment data security, get in touch at fox@talkingfox.co.uk.

 
 
 

Comments


Talking Fox Limited is incorporated and registered in England and Wales with company ‎number 13394689 whose registered office is at 1 Mill End Cottages, Little Missenden HP7 ‎‎0RG ‎

Get Updates

Thank You!

bottom of page