: Is an SSL certificate required by law on an e-commerce site? I've inherited a site which sells digital products (videos) using paypal. The cart and checkout pages are not currently served over
I've inherited a site which sells digital products (videos) using paypal. The cart and checkout pages are not currently served over SSL. The business is UK based but the servers are in the US.
Aside from security concerns (I realise these pages should be served over https), is this actually a legal requirement in the UK and / or USA?
More posts by @Rivera981
1 Comments
Sorted by latest first Latest Oldest Best
If the payments are totally handled by paypal then they are taking care of this for you. See this info on PCI DSS compliance
www.paypal.com/uk/webapps/mpp/pci
However if you are additionally taking and storing customer details you have additional obligations under the data protection act.
Here is a good roundup...
www.amitywebsolutions.co.uk/blog/website-legal-requirements-3-the-data-protection-act
Terms of Use Create Support ticket Your support tickets Stock Market News! © vmapp.org2024 All Rights reserved.