
Strengthening our commitment to payment data security
Baker Tilly Spain has successfully renewed its PCI DSS certification, the international standard that ensures the proper protection of payment card data. This renewal confirms that our systems and procedures meet the most stringent requirements for information security and regulatory compliance.
This year’s assessment, conducted against version 4.0.1 of the standard, has been particularly thorough. Although our management system remains essentially unchanged from previous years, the audit process required us to submit nearly 400 pieces of documentary evidence, reflecting the sector’s increasingly stringent requirements.
What is PCI DSS certification and why is it relevant?
PCI DSS (Payment Card Industry Data Security Standard) is the globally recognised security standard for any organisation that stores, processes or transmits payment card information. Obtaining and maintaining this certification requires organisations to meet strict controls in areas such as data encryption, access control, continuous system monitoring and the secure management of sensitive information.
As a result of this process, we have obtained two key documents:
- Attestation of Compliance (AOC): the official document confirming that we have successfully completed the audit, which we can provide to clients upon request.
- Self-Assessment Questionnaire (SAQ): the report detailing our level of compliance with the PCI DSS standard.
Added value for our business relationships
For clients who provide us with access to financial databases, payment information or data relating to their own end users, this renewal provides an additional level of assurance, confirming that we operate in accordance with rigorous, independently audited security protocols.
Maintaining this certification on an ongoing basis reinforces the trust that our clients and business partners place in us and demonstrates our continued commitment to the protection of the information we manage in the delivery of our services.