Who asks for compliance
No Canadian law requires PCI DSS. The obligation comes from the merchant agreement with an acquirer or payment processor, which passes on card brand rules. The acquirer decides which SAQ or report it needs, how often, and in what format. Many acquirers and processors use an online portal where merchants complete the SAQ each year and upload ASV scan results when required.
Contracts often allow the acquirer to charge fees or pass on brand penalties when a merchant doesn't validate, and to hold the merchant responsible for costs after a card data breach. Read the agreement's security section. Small merchants often discover these terms only after an incident.
Interac is separate
Interac Debit is Canada's domestic debit network. Interac is not one of the payment brands that founded or govern the PCI Security Standards Council, so PCI DSS is not the instrument that sets its rules. Interac sets its own operating rules, which reach merchants through their acquirer, and these cover matters such as how PIN entry must be protected.
In practice, the same terminal and the same network often handle both Interac and credit card transactions, so the security work overlaps. Co-badged debit cards that carry a Visa or Mastercard logo are covered by those brands' rules when used on their networks.
Card brand programs in Canada
Visa runs its Account Information Security program in Canada, which requires merchants and service providers that handle Visa account data to protect it properly, with PCI DSS as the baseline. Visa Canada's merchant security page also points to related programs. These include expanded use of card verification values and the end of fallback to magnetic stripe. Other brands run comparable programs through acquirers.
Payment service providers and the RPAA
Canadian payment service providers, such as payment facilitators, wallets, and some processors, may also be covered by the Retail Payment Activities Act. Registration with the Bank comes first. Since September 8, 2025, they must have risk management and funds safeguarding frameworks in place, and they file annual reports. PCI DSS work can feed into the operational risk part of that framework, but RPAA compliance is a separate obligation supervised by the Bank of Canada.
Privacy law overlap
Card data is personal information. A breach can trigger PCI forensic investigation and acquirer reporting, and can also trigger breach reporting under federal or provincial privacy law. Depending on the law that applies, the Office of the Privacy Commissioner of Canada or a provincial commissioner may need to be notified. Plan both tracks in the incident response plan.
Practical steps for a Canadian merchant
Service providers should expect merchants and banks to ask for a current Attestation of Compliance during procurement and each year after.
- Ask your acquirer or processor which validation it requires and by when
- Map every way you accept cards: terminals, phone, online, and mobile
- Use validated point-to-point encryption terminals or hosted payment pages to reduce scope
- Confirm your SAQ with your acquirer and your payment provider
- Book quarterly ASV scans if your SAQ requires them
- Keep your Attestation of Compliance and evidence for at least the next cycle
Resources
- PCI Data Security Standard (PCI DSS), PCI Security Standards Council
- Document Library (standard, SAQs, and guidance), PCI Security Standards Council
- Merchant Resources, PCI Security Standards Council
- Qualified Security Assessors list, PCI Security Standards Council
- Approved Scanning Vendors list, PCI Security Standards Council
References
- Merchant Resources, PCI Security Standards Council
- Merchant security, Visa Canada
- Retail payments supervision, Bank of Canada
General information, reviewed 2026-10-11. Not legal advice.