The Payment Gateway
Setting up online card payments looks simple from the customer’s side: type in a card number, click pay, done. From the business side, three separate systems are working together, and getting any one of them wrong either costs you sales or puts you on the wrong side of card scheme rules. The first is the payment gateway, the software that captures the card details and passes them securely to your acquirer. Stripe, Opayo, Square and PayPal are the common UK choices. Most small UK businesses use a hosted checkout page from one of these providers, meaning the card number never actually touches your own website or servers, it goes straight to the gateway. That single decision has a large knock-on effect on your compliance obligations, covered next.
PCI DSS: What It Actually Requires
The second is PCI DSS, the Payment Card Industry Data Security Standard. It isn’t UK law, it’s a contractual requirement written into the agreement every business signs with its acquirer, but the penalties are real: non-compliance fines typically run from around £4,000 to £80,000 a month depending on business size and severity, and can escalate to the acquirer closing the merchant account entirely. Your obligations depend on your merchant level, set by transaction volume. Level 4 covers any UK business processing fewer than 20,000 card-not-present transactions a year, which is nearly every small business trading online, and at that level you’re generally completing a short annual Self-Assessment Questionnaire rather than a full audit. If you use a hosted checkout from Stripe, Square or similar, you likely qualify for the simplest version, SAQ A, because card data never reaches your own systems. That doesn’t remove your obligations entirely though: your acquirer still expects you to know where card data could touch your business, a saved card number sitting in an email thread, a phone order jotted on a notepad, and to control staff access accordingly.
Strong Customer Authentication
The third is Strong Customer Authentication, the rule requiring two-factor verification on most online card payments, usually the 3D Secure prompt where a customer confirms via their banking app. On a hosted gateway this is typically built in and managed for you, but it’s worth knowing it exists, because a customer abandoning checkout at the verification step is a common, fixable source of lost sales, not a sign that something is broken.
The Surcharge Ban You Need To Know About
One legal point that catches out new online sellers: since January 2018, UK businesses cannot add a surcharge for a customer choosing to pay by consumer debit or credit card. If you want to recover your card processing costs, they need to be built into your displayed price, not added at checkout. A genuine booking or delivery fee, applied regardless of payment method, is still fine, but a standalone card handling fee is not.
The Realistic Setup For Most UK Businesses
Put together, the realistic path for most small UK businesses selling online is a hosted gateway to keep PCI scope small, an annual SAQ A to keep the compliance workload light, and prices that already include card costs to stay on the right side of the surcharge ban. None of that needs deep technical knowledge. It needs the right building blocks chosen up front.
Selling online and not sure your rate reflects that? Compare your fees free, results back the same working day.