Financial Policies

FN07 Electronic Payments: Credit Cards

Policy Status
Active
Subject Matter Expert
Karen Hughes, 814-863-4012, klh39@psu.edu
Policy Steward
Associate Vice President for Budget and Finance

Table of Contents


Definitions

Account Data
Account data consists of cardholder data and/or sensitive authentication data. See Cardholder Data and Sensitive Authentication Data.
Cardholder Data (CHD)
At a minimum, cardholder data consists of the full Primary Account Number (PAN) . Cardholder data may also appear in the form of the full PAN plus any of the following: cardholder name, expiration date, and/or service code.
End-User Technologies
Remote access and wireless technologies, laptops, tablets, mobile phones, and removable electronic media, email usage, and internet usage.
Primary Account Number (PAN)
the main credit or debit card number printed on the front of a payment card. It is typically 15 or 16 digits long (depending on the card brand) and uniquely identifies the cardholder’s account with the issuing bank.
Self-Assessment Questionnaire (SAQ)
a tool that allows merchants that fall under the purview of PCI DSS to self-evaluate their compliance with the standards.
Sensitive Authentication Data (SAD)
Security-related information used to authenticate cardholders and/or authorize payment card transactions. This information includes, but is not limited to, card verification codes, full track data (from magnetic stripe or equivalent on a chip), Personal Identification Number (PINs), and PIN block.

Purpose

This policy establishes the requirements governing the acceptance of electronic payments—specifically credit-card-branded credit, debit, and check cards—by The Pennsylvania State University (“University”). The University must ensure the secure, compliant, and efficient processing of electronic payments, in accordance with Payment Card Industry Data Security Standards (PCI DSS), additional card brand compliance rules, and contractual merchant agreements.

This policy also establishes responsibilities for oversight, risk management, and protection of cardholder data, including mandatory PCI DSS training, annual merchant validation, third-party service provider management, and incident response protocols that assist in assurance of PCI DSS compliance.

Scope

This policy applies to all entities that store, process, or transmit cardholder data (CHD) and/or sensitive authentication data (SAD) or could impact the security of the cardholder data environment (CDE). The Cardholder Data Environment is comprised of:

  • System components, people, and processes that store, process, and transmit cardholder data and/or sensitive authentication data. and,
  • System components that may not store, process, or transmit CHD/SAD but have unrestricted connectivity to system components that store, process, or transmit CHD/SAD, and
  • System components, people, and processes that could impact the security of the CDE.

Policy

All electronic payment activities must be conducted using University-approved merchant accounts and validated, compliant payment systems.

Units must not independently establish processing relationships or use third-party payment platforms without approval from the Treasury/Accounts Receivable Shared Services team and review by the Office of Information Security (OIS).

Account data must never be stored, transmitted, or processed outside secure University-approved systems and must never be transmitted\stored using end user technologies shared drives, or shadow systems.

All University merchant operations must comply with PCI DSS, card brand requirements, and University security standards.

The University must maintain a formal PCI DSS compliance program, including annual merchant attestation, training, system review, and reporting.

Roles & Responsibilities

Merchant Services

Merchant Services, a division of the Treasury/Accounts Receivable shared services team, serves as the central PCI DSS authority and merchant program owner.

Merchant Services:

  • Maintains and disseminates this policy
  • Oversees all required training
  • Approves creation, modification, or removal of merchant accounts and Terminal IDs.
  • Maintains the University’s enterprise acquiring relationship.
  • Documents, maintains, and coordinates PCI DSS compliance validation across all merchants.
  • Maintains and tests the PCI DSS incident response plan.

Office of Information Security

  • Evaluates technical security of payment platforms and integrations.
  • Approves payment technologies, encrypted card readers, e-commerce gateways, and network segmentation.
  • Conducts/coordinates PCI DSS assessments and vulnerability testing.
  • Oversees third-party service provider security reviews.

Units/Merchants

  • Must follow all PCI DSS requirements, University policies, and training.
  • Must only use PCI SSC defined payment channels.
  • Must participate in annual Self-Assessment Questionnaire (SAQ) completion and system review.
  • Must report payment-related security incidents immediately.
  • Must maintain documented procedures for handling refunds, disputes, and physical device security.

Third-Party Service Providers

University units must not enter agreements with payment processors, websites, fundraising platforms, mobile apps, point-of-sale systems, or software that handles payments unless:

  1. The vendor undergoes a security and contract review by OIS, Merchant Services, and the Central Procurement Contract Review Team.
  2. The vendor provides a current Attestation of Compliance (AOC) or Report of Compliance (ROC) .
  3. The vendor is listed on and monitored through the University's Service Provider documentation.
  4. The vendor is required contractually to meet PCI DSS requirements, provide breach notifications, and support incident response.

Unauthorized third-party service providers are prohibited.

Merchant Accounts Management

Units must submit a Merchant Account Request. Approval requires:

  • Budget Executive authorization
  • PCI DSS training for staff
  • Technology review by OIS
  • Completion of merchant onboarding documentation
  • Identification of the merchant's responsible Strategic Finance Partner

Merchant accounts must be reviewed annually for:

  • Continued business need.
  • Updated staff lists and training confirmation.
  • SAQ completion and technical validation

PCI DSS Training & Annual Compliance

All employees and contractors with access to payment systems must:

  • Complete PCI DSS security training before assuming duties.
  • Renew PCI DSS training annually.
  • Participate in the annual PCI DSS SAQ review
  • Maintain system configuration accuracy in University records.

Assignment and verification of PCI-DSS training are initiated and monitored by the units.

Failure may result in suspension of merchant processing privileges.

Account Data Security

Sensitive Authentication Data must not be stored after authorization:

  • Full card numbers
  • CVC/CVV/CID security codes
  • Magnetic stripe data
  • PIN/PIN block

Cardholder Data Storage (only if approved):

  • Last four digits of card number
  • Card type
  • Expiration date

Account data must:

  • Be transmitted, process stored only in compliant cardholder data environments
  • Never be transmitted via end-user technologies
  • Be protected by adequate encryption including physical and logical access controls.
  • Be retained only per University retention schedules.

Refunds, Disputes, and Chargebacks

  • Refunds must be processed to the original card used for payment.
  • Units must maintain documentation for disputes.
  • Chargebacks must be resolved promptly; repeated failure may require retraining or corrective action.

Incident Response

All suspected or actual data breaches involving cardholder information must be immediately reported to:

  • Office of Information Security
  • Merchant Services
  • Unit leadership

The University will activate its PCI DSS Incident Response Plan, including containment, forensic investigation, and notification.

Sanctions

Noncompliance may result in:

  • Suspension of merchant accounts
  • Removal of payment terminals
  • Mandatory retraining
  • Financial liability for fines or penalties
  • Disciplinary action under University policy

Violations

Violations of University policy should be reported to the appropriate supervisor, unit manager, Human Resources representative, or the office responsible for the relevant policy or procedure. If these channels are insufficient or unavailable, individuals may submit an anonymous report through the Penn State University Hotline, accessible via the Reporting at Penn State website.

Further Information

For questions, additional detail, or to request changes to this policy, please contact the Merchant Management team.

Cross References


Policy Status

Most Recent Changes

  • March 16, 2026 – Policy rewritten to define Finance Shared Services business model, including:
    • Modernize and clarify requirements for accepting electronic payments.
    • Incorporate updated PCI DSS 4.0 standards.
    • Address gaps identified during benchmarking against Big Ten institutions.
    • Establish stronger University-wide governance over merchants, payment platforms, and third-party service providers.
    • Reduce risk of cardholder data exposure and financial/brand penalties.
    • Standardize responsibilities between the Office of Budget & Finance, the Office of Information Security, and unit-level merchants.
    • Temporary statement regarding the new finance shared services business model impacting policy revisions removed

Revision History

  • February 24, 2026 – Editorial changes:
    • Temporary statement regarding the new finance shared services business model impacting policy revisions added
    • Financial Officer references changed to Strategic Finance Partner teams
    • March 11, 2025 - Editorial changes - website source code changes - definition tag formatting added and all links reviewed and/or updated.
    • February 1, 2023 - Editorial Changes. Changed all references to the Associate Vice President for Finance to the Associate Vice President for Budget and Finance, per the directive of the Senior Vice President for Finance and Business.
    • January 5, 2023 - Editorial Changes. Changed all references to the Office of the Corporate Controller to the Office of Budget and Finance, per the directive of the Associate Vice President for Finance.
    • October 25, 2022 - Policy rewritten to document SIMBA and LionPATH processes
    • November 8, 2018 - Subject Matter Expert added.
    • September 10, 2018 - Editorial changes to correct hyperlinks and remove redundant Date Approved, Date Published, and Effective date.
    • September 25, 2013 - Editorial changes. Addition of policy steward information, in the event that there are questions or requests for changes to the policy.
    • September 21, 2011 - Editorial change in PURPOSE section, second paragraph, to clarify approval requirements for other forms of electronic payments, such as wires, EFTs and ACHs.
    • November 30, 2010 - Significant changes have been made to bring this policy in line with current University and industry practices.
    • March 30, 2004:
      • Significant changes have been made to bring this policy in line with current University and industry practices.
      • The Corporate Controller's Office and Administrative Information Services (AIS) administer the only resources authorized for establishing merchant accounts and processing credit card payments at Penn State. Individuals and areas are not permitted to make alternative arrangements.
      • Added Financial Officers to approval process for allowing areas to accept credit cards.
      • Use of the AIS eCommerce system was added.
      • Now allows surcharges to be added for credit card payments but under eLion only.
      • "Office of Administrative Systems" changed to "Administrative Information Services" and the "Associate Treasurer" to "Corporate Controller's Office."
      • The DEPOSIT section was deleted since paper credit card slips are no longer used with the advent of electronic processing.
      • Editorial changes for clarity.
    • January 24, 2000 - The section INTERNET/INTRANET SALES was added.
    • September 16, 1992 - Added the section LIMITATIONS, and revised wording regarding the Report of Cash Receipts.
    • March 27, 1991 - Limited holding of credit card slips to no more than three days.
    • May 31, 1989 - Changed "Assistant Treasurer" to "Associate Treasurer."
    • January 22, 1988 - Under the section CONTROL AND REPORTING, added provisions for the Integrated Student Information System. Under the DEPOSIT section, added provision for electronic data capture.
    • November 21, 1986 - Changed " Director of Financial Management" to "Assistant Treasurer." Expanded charges to be absorbed by department to include any bank charges. Other editorial changes for clarity.
    • August 15, 1986 - Minor editorial changes for clarity.
    • July 25, 1983 - Redesignated from CS07 to FN07.
    • September 3, 1980 - New Policy.
Date Approved
Date Published
Effective Date