Where can a Bambu franchisee find the current PCI Data Security Standard?
Bambu Franchise · 2025 FDDAnswer from 2025 FDD Document
The Payment Card Industry ("PCI") requires all companies that process, store, or transmit credit or debit card information to protect the cardholders' information by complying with the PCI Data Security Standard ("PCI DSS").
Therefore, Franchisee shall be PCI compliant by following and adhering to then-current PCI DSS, currently found at www.pcisecuritystandards.org, or any similar or subsequent standard for the protection of cardholder data throughout the term of this Agreement.
Franchisee's Bambū shoppe shall be in compliance with PCI DSS at all times.
Source: Item 23 — Receipts (FDD pages 52–209)
What This Means (2025 FDD)
According to Bambu's 2025 Franchise Disclosure Document, franchisees are required to adhere to the Payment Card Industry (PCI) Data Security Standard (DSS) to protect cardholder information. The document specifies that the current PCI DSS can be found at www.pcisecuritystandards.org. Franchisees must comply with this standard, or any similar updated standard, throughout the entire term of their franchise agreement to ensure their Bambu location is always PCI compliant.
This requirement means that prospective Bambu franchisees need to understand and implement the security protocols outlined in the PCI DSS. This includes measures to secure their point-of-sale (POS) systems and any other systems that process, store, or transmit credit card information. Failure to comply with PCI DSS can result in fines, penalties, and potential legal liabilities for the franchisee.
It is the franchisee's responsibility to stay updated with the latest version of the PCI DSS and to ensure their Bambu shop meets all requirements. This may involve regular security assessments, employee training, and updates to their technology infrastructure. Bambu's requirement for PCI compliance is a standard practice in the franchise industry, particularly for businesses that handle credit card transactions, as it protects both the business and its customers from data breaches and fraud.