Visa and Mastercard brought-in PCI DSS Payment Card Industry Data Security Standard a couple of years ago as an anti- credit card fraud measure.
It details all sorts of security measures anyone handling credit card numbers has to take, from shredding paper order forms which have card numbers on them, to destroying the 'your calls may be recorded' tapes if they have card numbers on them, to encrypting card numbers in their computer systems before they charge your card and then deleting the card numbers afterwards, to doing criminal records checks on staff who can access card details, to website firewalls and anti-virus, etc, etc.
They're forcing retail merchants to apply these rules, with (very expensive) audits from outside data-security consultants to give sign-off's, major fines for non-compliance and really humungous fines if there is some data breach by hackers, etc.
As much of a risk is data processing by the banks of the card transactions - there have been several reported instances of outsourced data centres in India providing card details, even for cards which haven't actually been received through the post by the cardholders yet !
There are a few people advocating using PayPal rather than their card when buying online, but personally I'm not keen at all on using PayPal at all, unless I'm forced to by buying on
eBay.
- what makes you think PayPal is secure ?
- if anything goes wrong, have you ever tried to get your money back from PayPal ?
Do be aware that if you buy something over £100 on your credit card then the card issuer has Section 75 liability, meaning that they are also liable if the company supplying the goods goes bust
- and if you get into a dispute for non-delivery, or the quality of the goods, etc then you can take it up with your credit card company
http://www.prudentminds.com/section-75.html
You
won't get Section 75 from your card issuer if you buy something via PayPal - you paid PayPal, PayPal paid the seller...
http://www.wider-implications.info/case_studies/wi_03.html
I've heard enough horror stories about Paypal dispute resolution on eBay to not want to have to go through them...