"Users of PayPal services are NOT merchants and do not need to comply with PCI standards." Are you serious?! In the context of the conversation, that is *so* wrong. The PCI DSS covers people, process, and technology. So if the entity has individuals accepting cardholder data via telephone, or *any* other workflow that involves CHD, then you have just advised the organization to break the law. Congratulations.
... View more