Control over Continuous Payment Authorities

I believe the truth is closer to what @anon16223504 said, but @nanos is right about merchants not always storing the details themselves due to the need for PCI compliance requirements.

The business I am involved with uses CPAs, but we don’t store the card details. The card details are stored by our payment processor, and they give us a “token” via which we can request a further payment from the same card details (even though we don’t have them). In this way we don’t need to be PCI compliant because that requirement is for our payment processor to fulfil.

The UK Cards Association website says:

“If you have cancelled a CPA directly with your card issuer and then decide to renew your CPA with the same retailer, you should contact your card issuer first, as it is likely they will otherwise decline the payment.”

Last sentence here: http://www.theukcardsassociation.org.uk/individual/repeat-payments-on-your-card.asp

That would seem to indicate that it is the merchant that is blocked when a customer asks for the CPA to be “cancelled”. Therefore, as I understand it there is nothing on record with your bank that says you have agreed to a CPA.

A bank could provide a facility to block a merchant I guess, and then unblock them at a future date if you wished to do so.

4 Likes