May 27, 2009

Wal-Mart’s Kiosk Trial Raises Serious PCI, Data Ownership Issues

walmart.jpgWal-Mart, E-Play and NCR get called to explain by StorefrontBacktalk and Fred Aun article. Gist is trial of 77 stores running trial of used video buyback kiosks that take card data and drivers license info, and then talk about linking into retailer POS.

Written by Fred J. Aun of StorefrontBacktalk.com

Wal-Mart this month became the latest major retailer to experiment with self-service kiosks, selling space in 77 stores for units that buy back used video games and issue credits directly to various payment cards.

The initial trial is entirely isolated, with the kiosk vendor having access only to its own network and not to Wal-Mart’s. But the $375 billion chain is officially considering having the machines offer in-store credits in the form of gift cards, which would mean allowing the kiosks two-way access to POS and potentially CRM data. That would force some serious strategic debate about how far outside vendor kiosks can—and should—be allowed to play inside a retailer’s databases.

The initial version of the kiosks collect payment card information as well as drivers license data. Even setting aside the potential future POS/CRM access, the payment and highly-sensitive driver’s license data will force some of that debate right away. How secure are the kiosks? Who is ultimately responsible in the event of a security breach, both from a legal and PCI perspective?

Beyond lawyers and assessors, consumers and the dollars they control will likely blame the retailer for any problems that started with a kiosk in or right next to its store. Wal-Mart officials are stressing that the Wal-Mart logo will not be used on any of the trial kiosks, although the Wal-Mart blue and yellow brand colors will absolutely be used. “This is not Wal-Mart’s machine,” said Melissa O’Brien, a spokeswoman for Wal-Mart’s entertainment division. “We are leasing space to them in our store vestibules just like with do with other companies.” And that nuanced distinction will be explained to every Wal-Mart customer how?

The insistence that no brand be used displayed will be a nice point for the lawyers, but it won’t do much for public perception. PCI Safe Harbor and legal indemnification won’t help much if consumers feel betrayed.

Another troubling issue is data ownership. If Wal-Mart gets consumers to come to their stores and asks them to interact with a kiosk in the store, can the kiosk vendor use that information to help other retailers? As a pragmatic matter, how can they not do so?

Rest of article

Posted by staff at May 27, 2009 11:06 AM