The right of storing client information
I have a selling website, and I'm wondering if I can store my clients information in the databases like credit card nu开发者_StackOverflow中文版mber and expiration date... and transactions history, etc.
Is it legal? If yes, in which countries?
Legal or not it would be extremely dangerous for you. In most places if the credit card info is stolen from your database then you would be liable. Unless you are supremely confident in your ability to safeguard the data you should not even consider it.
Look at Amazon.com or any other e-Commerce site. They do store client information like credit cards, names, transaction history, etc. Now, the legal requirements (record management, retention, privacy) of doing this may vary form jurisdiction to jurisdiction, and you have to wonder if storing that information would negatively impact perception of your site, but it is legal and done very often in North America.
I'd definitely talk to a lawyer about any regulatory requirements you may need to fulfill or any liabilities you may be opening yourself up to.
The issue here is not really the law - rather the requirements that credit card companies require to allow you to store such information. Go read the PCI DSS standard and see for yourself if you really want all that hassle.
精彩评论