A merchant based in the U.S. processes credit card transactions for customers in the EU and stores cardholder data. Which two frameworks are most directly relevant to its compliance obligations?
-
A
NACHA Operating Rules and Regulation CC
-
B
PCI DSS and GDPR
-
C
BSA/AML and Regulation E
-
D
FFIEC guidance and the RFPA