Emailing Credit Card Forms is a Risk to Your Business
Emailing Credit Card Forms isn’t “simple”; it’s a Risk with Big Consequences
You send a form. The customer fills out their credit card number, expiration date, billing ZIP, even the security code on the back. Then they’re told: “Just scan it and email it back.”
So many businesses still do this. It feels harmless. It feels old-school. It feels easier than setting up a payment portal!
But there’s a major security risk: When that form is emailed, your inbox is a storage location for credit card data. So is your laptop or maybe even an employee’s laptop, phone, or a random Downloads folder. Possibly a printer, scanner, or cloud backup. It’s not nefarious, just the nature of workflows…
But it also is NOT a process. It’s a data security problem and it creates serious compliance issues with the Payment Card Industry Data Security Standards (PCI DSS).
PCI DSS applies to organizations that store, process, or transmit cardholder data, and the financial institutions (think Visa/Mastercard) will levy heavy fines and penalties against businesses who break these regulations. https://usa.visa.com/dam/VCOM/download/about-visa/visa-rules-public.pdf
And, while the fines will hurt financially, penalties can include major rate increases, suspensions, or even termination. That means no more processing credit cards, and that can mean lights out.
Paper Doesn’t Make It Safe
Some owners assume paper is somehow outside cybersecurity. It isn’t.
The PCI Security Standards Council specifically says PCI DSS applies when a Primary Account Number, or PAN, is stored, processed, or transmitted “on or by any media,” including paper records. It also notes that PCI DSS Requirement 9 addresses safeguarding physical media, including paper records containing cardholder data. (PCI Security Standards Council)
A paper credit card form is a record containing payment card data. If it sits on a desk, gets tossed into an unlocked drawer, is scanned to email, printed, downloaded, or saved in a folder called “Customer Forms,” it’s part of your cardholder data environment.
And now you now have to answer harder questions:
- Who can access it?
- Where is it stored?
- How long is it kept?
- Is it encrypted?
- Can employees forward it?
- Is it backed up?
- Was it deleted securely?
- Was the CVV stored after the transaction?
- Could someone steal it from email, paper files, or a shared drive?
Most businesses owners won’t have good answers to those questions.
Email Is the Real Problem
Email was not built to be your payment vault.
The PCI Security Standards Council is direct on this: unencrypted PANs cannot be sent over email, instant messaging, SMS, or chat. PCI DSS Requirement 4.2.2 prohibits sending unprotected primary account numbers through end-user messaging technologies, and PCI DSS Requirement 4.2.1 requires strong cryptography and security protocols when cardholder data is sent over open, public networks. (PCI Security Standards Council)
There’s an important nuance here. PCI DSS does not say a business can never request cardholder data through email or other messaging tools. But if a business uses that channel to receive or send PAN, then that channel has to be protected under applicable PCI DSS requirements, and related systems, such as email servers, can come into PCI scope. (PCI Security Standards Council)
That’s where small businesses get trapped. They think they’re using a simple shortcut. In reality, they may be expanding their compliance footprint from “we use a payment processor” to “our email, employee laptops, phones, scanners, file storage, backups, and retention practices may all be involved in handling credit card data.”
That’s a very different world.
The Security Code Is Even More Dangerous
The CVV or CVC code — the three or four digits on the card — deserves special attention.
PCI DSS does not prohibit collecting that code before authorization for a specific transaction. But once the transaction is authorized, the code cannot be retained. PCI SSC is clear that storing card verification codes after authorization is prohibited, even if the customer gave permission. (PCI Security Standards Council)
So if your paper form asks for the security code, and that form gets emailed, saved, printed, or filed after the payment is run, you may have created a serious compliance issue.
The Data Spreads Fast
The biggest danger with emailed credit card forms is that the data doesn’t stay in one place. It spreads quickly, increases your attack surface, and creates huge liability. Consider this:
A customer emails the form >> Your office manager downloads it >> Someone prints it >> Someone forwards it to billing >> The attachment stays in Gmail or Outlook >> The file syncs to OneDrive, Google Drive, Dropbox, or a local desktop >> The scanner saves a copy >> The email backup keeps another copy >> The paper version sits in a folder >> The trash copy sits in the recycling bin >>>>
Now imagine there’s a breach. You don’t just have to say, “Someone got into our email.” You may have to say, “We had customer credit card information stored in email, attachments, downloads, paper files, and backups, and we’re not sure how long it was there or who accessed it.”
That’s the part most owners don’t see until after something goes wrong.
What Small Businesses Should Do Instead
Stop asking customers to email credit card forms! Use a payment link, hosted payment page, secure invoice, card-on-file feature, or customer portal through a reputable payment processor.
The goal is simple: let the processor collect and protect the card data, not your inbox.
You can still get written authorization from the customer. You can still have terms. You can still document what they agreed to pay. But the actual card number should go through a secure payment workflow — not a PDF, photo, scan, or email attachment.
Also, train your team on what to do when a customer emails card data anyway. PCI SSC says when cardholder data is accidentally received through an unintended insecure channel, the merchant should either bring that channel into the cardholder data environment and secure it, or implement measures to prevent that channel from being used for cardholder data. It also says the business should avoid further unsecured transmissions, remove or secure the data, and communicate secure payment methods to customers (PCI Security Standards Council), but in plain English:
Don’t reply with the card number still in the thread
Don’t forward it around the office
Don’t save it “just in case"
Don’t print it and leave it on a desk
Don’t keep the CVV after the transaction
Do move the customer to a secure payment method
Convenience Is Not a Security Strategy
Small businesses use paper and email because it feels easy. But easy can get expensive.
A paper credit card form emailed back to your office may create more risk than the owner realizes. It can pull email into PCI scope. It can leave card data scattered across devices and backups. It can expose customers. It can create hard questions after a breach. And if CVV codes are stored after authorization, that’s a problem no small business wants to explain.
The better move isn't complicated:
- Use a secure payment link
- Use a trusted processor
- Keep credit card information out of email
- Limit who can access payment information
- Destroy old paper records
- Train your people
Know your risk. Protect what you’ve built. Convenience should never turn your inbox into a credit card vault, and if we can be a resource to help you get that done just fill out the form below.
Need a better way?
