Is my website PCI-DSS compliant?
PCI-DSS are standards developed to enhance the security of payment card data. As we do not store any credit card data in the content management systems we are not directly required to be PCI-DSS compliant. The providers we integrate with for processing credit card payments (eWAY and PayPal) are PCI-DSS compliant.
The eWAY solution in particular requires users to enter their credit card information in the checkout page created by us. This is securely transmitted to eWAY with SSL encryption. This information is not saved or stored anywhere in the system - even temporarily.
For more information visit:
http://www.eway.com.au/company/pci-dss-compliance
https://www.paypal.com/au/cgi-bin/webscr?cmd=xpt/Marketing/merchant/PCIComplianceDSS-outside