What to consider when my business is accepting online payments?

What to consider when my business is accepting online payments?

Taking payments online opens up your business, but it also brings legal and security obligations. Handling card and payment data carelessly risks fines, fraud losses and reputational harm. Here is a plain-English guide to the key considerations for businesses in England and Wales.

1. Payment services regulation

If you only accept payments for your own goods/services through a provider, you usually don't need to be authorised yourself. But the Payment Services Regulations 2017 (PSRs) govern the payments industry, and your payment service provider (PSP) operates under them. If your model involves handling other people's money or providing payment services (e.g. a marketplace passing on funds), you may need FCA authorisation or registration, take advice.

2. Strong Customer Authentication (SCA)

Under the PSRs (implementing onshored EU rules), most online card payments require Strong Customer Authentication (SCA), typically two-factor verification (e.g. card details plus a one-time code or app approval). Your checkout and PSP must support SCA (commonly via 3-D Secure), with limited exemptions. This reduces fraud but you must ensure your setup is compliant to avoid declined payments.

3. Card data security: PCI DSS

If you handle card data, you must comply with the Payment Card Industry Data Security Standard (PCI DSS), an industry standard (required by your card acquirer/PSP, and contractually binding) covering how card data is processed, stored and transmitted. The simplest path for small businesses is to use a compliant PSP/hosted checkout so you never store raw card numbers yourself.

4. Data protection (UK GDPR / DPA 2018)

Payment and customer details are personal data, so the UK GDPR / Data Protection Act 2018 applies: have a lawful basis, a clear privacy policy, strong security, and minimise what you store. Be ready to handle data-breach obligations.

5. Consumer rights and refunds

When selling to consumers online, you must:

  • give the required pre-contract information and honour the 14-day right to cancel for most online sales (Consumer Contracts Regulations 2013);
  • meet Consumer Rights Act 2015 standards (and process refunds correctly); and
  • be aware that customers paying by credit card (£100–£30,000) have protection under section 75 of the Consumer Credit Act 1974, and chargeback may apply to debit cards.

6. Fraud, and the new reimbursement rules

Online payments attract fraud. Note that APP fraud reimbursement rules exist (overseen by the Payment Systems Regulator), but the mandatory scheme has limited scope: it applies only in specified circumstances, and eligibility, exclusions, claim limits and customer type all matter. Do not assume that either you or your customers will automatically be reimbursed for APP fraud. Implement fraud-prevention measures and clear refund/dispute processes.

Practical checklist

  • Use a reputable, compliant PSP and a hosted/tokenised checkout (so you avoid storing card data).
  • Ensure SCA / 3-D Secure is enabled.
  • Maintain PCI DSS compliance as required by your acquirer.
  • Have a privacy policy and strong data security (UK GDPR).
  • Display clear terms, pricing, delivery and cancellation information.
  • Put in fraud checks and a clear refunds/chargeback process.

Key takeaways

  • The payments industry is governed by the Payment Services Regulations 2017; you may need FCA authorisation if you handle others' money, otherwise rely on a compliant PSP.
  • Enable Strong Customer Authentication (two-factor) and maintain PCI DSS card-data security (ideally by not storing card data).
  • Comply with the UK GDPR/DPA 2018, and with consumer law (pre-contract info, 14-day cancellation, section 75 card protection).
  • Guard against fraud (including APP-fraud reimbursement rules) with prevention measures and clear dispute handling.

Sources

  • Payment Services Regulations 2017 (PSRs); Strong Customer Authentication requirements; FCA authorisation for payment services
  • PCI DSS (card data security standard); UK GDPR / Data Protection Act 2018
  • Consumer Contracts Regulations 2013 and Consumer Rights Act 2015; Consumer Credit Act 1974, s 75; APP-fraud reimbursement (Payment Systems Regulator)

--- This article is general information about the law of England & Wales as at 2026, not legal advice. For advice on your circumstances, consult a qualified solicitor.

Back to the blog