General Description
Policy Summary:
Trinity University is committed to compliance with applicable laws, regulations, and standards related to accepting payment cards on campus. This Policy provides standards for the University to accept and process payments from third parties by credit card, debit card, or any card or device other than cash or check (collectively, “Payment Cards”).
Purpose:
Trinity University is subject to certain Federal, State, and industry rules, regulations, and contractual provisions regarding the processing and handling of Payment Cards and the data associated with those Payment Cards. The goal of this Policy is compliance with laws, rules, regulations and contractual provisions, maintenance of a secure Payment Card processing environment and security of Payment Card data.
Scope:
All Trinity individuals that process Payment Card transactions on behalf of the University and third parties, vendors, and contractors involved in accepting card payments for or on behalf of Trinity University and/or supporting that activity are responsible for compliance with this Policy and familiarizing themselves with its contents.
Exceptions:
None
Policy Content
Performance Evaluation
Consequences of Policy Violation:
The University may be assessed non-compliance penalties by the Acquiring Bank. Any non-compliance fees may be the responsibility of the Merchant Department. Failure to comply with this Policy may result in disciplinary action up to and including termination.
Terms & Definitions
Terms and Definitions:
Term: |
Definition: |
---|---|
Acquiring Bank | A financial institution that maintains the University’s bank account and is contracted to process credit and debit card transactions. |
Cardholder Data |
The Primary Account Number (PAN) alone or the PAN plus any of the following: full magnetic strip information, cardholder name, expiration date, or security code. |
Merchant Account |
Account number assigned by the Business Office to a Merchant Department for the purpose of processing Payment Card transactions. |
Merchant Department | A University Department that is approved by the Business Office and ITS to accept Payment Cards on behalf of the University as payment for goods and/or services. |
Payment Card |
Refers to credit cards, debit cards or any other card or device other than cash or check. |
Payment Card Equipment | Payment Card terminal or machine used to process Payment Card transactions. |
Payment Card Industry Data Security Standard (PCI DSS) |
A set of comprehensive requirements for Payment Card data security established by the PCI Security Standards Council. Compliance with the PCI DSS helps to mitigate vulnerabilities that put Cardholder Data at risk. The PCI DSS standards must be adopted by all merchants, organizations, and entities that accept and process Payment Cards. |
Service Provider |
Any company that stores, processes or transmits Cardholder Data on behalf of another entity. Includes Third Party Payment Processors/Payment Gateway companies. |
Third Parties | Refers to individuals, companies, merchants, vendors, contractors or other parties that are not Merchant Departments and either pay the University for goods or services or request to conduct Payment Card transactions on the Trinity campus. |
Third Party Payment Processor or Payment Gateway | A company that offers Payment Card processing software and/or gateway services. |
Related Documents
Related Content:
Revision Management
Revision History Log:
Revision #: |
Date: |
Recorded By: |
---|---|---|
v1.0 | 2/20/2024 11:46 AM | Jennifer Gilmore Adamo |
Vice President Approval:
Name: |
Title: |
---|---|
Gary Logan | Vice President for Finance & Administration |