"I WOULD HATE TO GO BACK TO THE OLD PAPER BASED PROCESS, ESPECIALLY IN LIGHT OF PCI DSS"
Sally Salter, Income Office Manager, University of Sheffield
Follow the autonomy of a transaction from payment by the customer through to receiving the funds in your account.
To learn more click here
WPM Education is fully PSP independent allowing you to use any PSP and select the rates and model that best suit your institution.
Click to view a list of PSPs we have interfaced with
We have put together a list of some of our most frequently asked questions. If your question isn’t there we’ll happily answer it for you.
Click here to view FAQsPCI DSS FOR UNIVERSITIES AND COLLEGES
The Payment Card Industry Data Security Standard (PCI DSS) is a global standard covering the way in which card holder data should be handled.
Therefore, if your university or college is not transferring or storing data in a secure way that is compliant with the PCI DSS standard you are at risk of a non-compliance penalty.
PCI DSS AND THE EDUCATION SECTOR
Often at busy times in the academic calendar a large amount of transactions are being processed over a matter of weeks. Therefore, security solutions must be sustainable throughout these high risk times.
If your university or college uses remote interfaces or handles card details internally you will need to become PCI DSS compliant. This may require additional IT resources, software and hardware. Depending on the size of your university or college once processes are in place a security standards council qualified security assessor may need to visit on an annual basis to grant a compliant class.
HOW WPM EDUCATION CAN HELP YOU BECOME PCI DSS COMPLIANT
WPM Education is classed as a level 1 service provider under the standard and, as such, has an annual independent audit carried out to certify this compliance. WPM has been certified as compliant since March 2008 and is one of the first UK organisations providing managed services to do so.
WPM Education solutions prevent card payment data from entering a university or college environment by processing the payment data on its own fully PCI DSS compliant servers, transferring only fully encrypted data back and forth to the university or college. This removes the risk from the university or college as no card payment data is present on the university or college servers to be stolen.
Therefore, clients using WPM Education services that do not handle the card details themselves are covered by WPM Education's compliance.
HOW IT WORKS
- Payee visits institution's website and selects to pay a fee, set up recurring billing/ payment plan or add a product or service to the institution's shopping basket.
- Customer is seamlessly redirected to WPM Education's Secure Payment Pages.
- The payee enters their payment details into the system. The PCI DSS risk is completely removed from the institution as no card details are submitted or stored within the institution's network.
- WPM Education transfers the data to the credit card network and completes the transaction.
- Result of payment is displayed to the customer.
BENEFITS:
- Increased payment data security: No cardholder data is present in the university or college server environment.
- Increased customer satisfaction: Students, parents and payers will be seamlessly transferred to WPM Education's payment pages that are branded as the university or college's main website. This increases trust in the website and provides a consistent and straightforward payee experience.
- Secure data integration with all university or college systems: WPM can securely pass data to any finance, student records, accommodation or any internal system.
HOW DO YOU BECOME PCI DSS COMPLIANT?
Many universities and colleges are becoming wiser to the risk of PCI DSS non-compliance and are undertaking procedures to ensure that all payment data collected, be it from a face to face transaction, payment over the telephone or payment submitted online, is processed and stored in a fully secure manner.
Find out more about how you can become PCI DSS compliant by visiting the Payment Card Industry Standards Council or read more about the core requirements for becoming PCI DSS compliant.
