An “SEC violation” tied to a credit card almost never involves the Securities and Exchange Commission. In everyday use, the phrase is shorthand for a security or compliance violation in how a merchant handled card data or ran a transaction, most often a failure under the Payment Card Industry Data Security Standard (PCI DSS), a consumer protection breach, or an infraction of the card networks’ own rules. There is one real Securities and Exchange Commission angle, but it only applies to publicly traded companies and their disclosures about cyber incidents.
So if you’ve seen the term on a statement notice, in a chargeback message, or in a story about a retailer, the first question to ask is which of these it actually refers to.
The Most Common Meaning: A PCI DSS Security Violation
Every business that processes, stores, or transmits card data must follow PCI DSS. The current version is PCI DSS v4.0.1, which became the only active version after v4.0 retired at the end of 2024, with new requirements mandatory as of March 31, 2025. The standard covers network security, encryption, vulnerability management, access controls, and monitoring.
The violations that catch merchants out are often basic. Storing sensitive authentication data after a transaction has been authorized (for example, the three-digit code on the back of a card) is flatly prohibited. Sending cardholder data over unencrypted connections, leaving default passwords on payment systems, skipping required vulnerability scans, or giving employees access to card data they don’t need for their job are all common findings.
PCI DSS is not a government law. The card brands (Visa, Mastercard, American Express, Discover) enforce it, and fines flow through the acquiring bank that handles the merchant’s transactions. Early non-compliance fines often start around $5,000 to $10,000 per month and escalate the longer the gap persists. If a data breach happens while a merchant is out of compliance, breach-related penalties can reach $500,000 per incident, on top of forensic investigation, card reissuance, and customer notification costs.
Consumer Protection Violations
Federal consumer protection law sets a floor for every merchant. Section 5 of the Federal Trade Commission Act makes “unfair or deceptive acts or practices in or affecting commerce” unlawful.1Federal Trade Commission. A Brief Overview of the Federal Trade Commissions Investigative and Law Enforcement Authority In the card-processing world, that captures hidden fees not disclosed before checkout, charges above the amount the customer agreed to, subscription terms designed to make cancellation hard, and refunds that never arrive.
The FTC also expects reasonable data security. When a company makes a privacy promise (directly or by implication) and doesn’t keep it, that’s a deceptive practice even without a breach. A site that says it encrypts all payment data but actually stores card numbers in plain text is already in violation.2Federal Trade Commission. Privacy and Security
Unauthorized Charges
Charging a card without the cardholder’s consent sits at the intersection of consumer protection and federal law. Under the Truth in Lending Act, a cardholder’s liability for unauthorized use of a credit card is capped at $50, and that cap only applies when the issuer has met several conditions, including notifying the cardholder of potential liability and providing a way to report unauthorized use.3Office of the Law Revision Counsel. 15 US Code 1643 – Liability of Holder of Credit Card Most major issuers waive that $50 as a matter of policy.
Recurring billing is a frequent trouble spot. If a customer cancels a subscription and the merchant keeps charging, each new charge is unauthorized regardless of what the original auto-renewal terms said.
Card Network Rule Violations
Visa, Mastercard, American Express, and Discover each publish detailed operating rules that merchants agree to follow when they accept cards. These are private contractual rules, not government law, but the networks enforce them through fines and account restrictions. They also go further than most merchants expect.
Surcharging
Merchants can add a surcharge to credit card transactions to offset processing costs, but the rules are tight. Visa caps surcharges at 3% of the transaction amount and Mastercard at 4%. Several states prohibit surcharging entirely. Surcharging a debit card transaction, failing to disclose the surcharge before the sale, or exceeding the cap all count as violations.
Minimum Purchase Amounts
Federal law lets a merchant require a minimum purchase for credit card transactions, but the minimum cannot exceed $10 and must apply equally across all card brands.4Office of the Law Revision Counsel. 15 US Code 1693o-2 – Reasonable Fees and Rules for Payment Card Transactions A store that sets a $15 minimum for Visa, or imposes any minimum on debit cards, is breaking both federal law and network rules. This provision comes from the Dodd-Frank Act and applies nationwide.
Chargeback Handling
When a cardholder disputes a transaction, the networks have specific procedures. Missing response deadlines, submitting incomplete documentation, or attempting to re-charge a customer for a transaction that was already resolved through a chargeback all violate network rules. Merchants whose chargeback ratios climb above roughly 1% of transactions are flagged for monitoring and face escalating penalties.
When It Actually Is the SEC
The Securities and Exchange Commission does not regulate credit card processing. But it does regulate what publicly traded companies tell their investors, and that’s where a real SEC violation can enter a card-related story. A public company that suffers a significant breach of cardholder data and fails to disclose it properly has committed a genuine SEC violation.
Under rules adopted in 2023, public companies must file a Form 8-K within four business days of determining that a cybersecurity incident is material. The filing has to describe the nature, scope, and timing of the incident and its actual or reasonably likely impact on the company’s financial condition.5U.S. Securities and Exchange Commission. Public Company Cybersecurity Disclosures Final Rules The only exception is narrow: disclosure can be delayed if the U.S. Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety.
Beyond incident reporting, Regulation S-K Item 106 requires annual disclosures about the company’s cybersecurity risk management, whether management has relevant expertise, and how the board oversees cybersecurity risk.6eCFR. 17 CFR 229.106 (Item 106) Cybersecurity For a retailer or payment processor handling millions of card transactions, those disclosures carry real weight, and the SEC has pursued companies that downplayed cybersecurity vulnerabilities.
Two things worth keeping straight. First, this only applies to publicly traded companies; a private business cannot commit this kind of SEC violation no matter how badly it handles a breach. Second, the SEC angle sits on top of the other violations already discussed. A public retailer breached because it ignored PCI DSS could face card-brand fines, FTC action, state attorney general suits, and an SEC enforcement action for the disclosure failure, all from the same incident.
Data Breach Notification
When cardholder data is exposed, a separate layer of legal obligations kicks in. All 50 states, the District of Columbia, and U.S. territories have breach notification laws requiring businesses to inform affected individuals when their personal information has been compromised. Deadlines vary. All states require notice “without unreasonable delay,” and many set specific timeframes, commonly 30, 45, or 60 days after discovery.7National Conference of State Legislatures. Security Breach Notification Laws A business that processes cards in multiple states has to comply with every state law that covers affected residents.
How the Penalties Add Up
The consequences stack from several directions at once, which is why merchants who focus only on card-brand fines get surprised.
Card-brand penalties for PCI DSS non-compliance can climb to $100,000 per month for prolonged failures, with breach-related penalties up to $500,000 per incident, plus liability for card reissuance and forensic costs. These are passed through the acquiring bank, which may also terminate the processing relationship.
The FTC can pursue much larger amounts for deceptive practices or data security failures, with settlements reaching tens of millions of dollars in large cases.1Federal Trade Commission. A Brief Overview of the Federal Trade Commissions Investigative and Law Enforcement Authority State attorneys general can bring parallel actions under state consumer protection and breach notification laws. For public companies, the SEC adds its own enforcement track for disclosure failures. And affected consumers and banks can sue directly; several state breach statutes give individuals a private right of action, meaning they don’t have to wait for a government agency.
If you’re trying to decode a specific reference to an “SEC violation” on a credit card, start by asking which of these is actually in play. In most day-to-day contexts it’s a PCI or consumer protection issue wearing the wrong initials. When it really is the Securities and Exchange Commission, the company involved is public and the underlying issue is disclosure to investors, not the card transaction itself.