Skip to content
Money, records, and accessLesson 8 of 22

Academy/Technology

Online payments

What accepting cards, bank drafts, and automated reminders actually obligates your association to do.

Accepting online payments does not remove your association's legal exposure, it relocates it. Card payments put you inside PCI DSS security rules even when a processor holds the data. Bank drafts must pass a validation step before the first debit. Automated payment reminders need the resident's consent first. Ask any vendor how it handles each.

01

Card payments make you a PCI DSS target, even indirectly

PCI DSS (the Payment Card Industry Data Security Standard) is the security baseline that applies to anyone who touches card data, not just the company that processes the charge. It reaches further than most boards assume.

"Entities that store, process, or transmit cardholder data (CHD) and/or sensitive authentication data (SAD) or could impact the security of the cardholder data environment (CDE)" must comply.

Source: PCI Data Security Standard, PCI Security Standards Council

A "pay now" button linked from your own website can still count as part of that environment, so "our processor handles PCI" is not a full answer. Ask your processor which validation tier applies to your association's volume; that number is set by the processor and your bank, not by PCI DSS itself.

02

Bank drafts have a checkpoint before the first debit

ACH (the Automated Clearing House network) moves many HOA assessment payments straight from an owner's bank account. Nacha, the organization that writes the rules for that network, added a validation step for the first debit of any new account.

"NACHA will enforce a new rule beginning March 2022 that requires that all first-time WEB debits from consumers be validated before submission to the ACH system."

Source: Explanation of Nacha's WEB debit account validation rule, VeriCheck

This is a payments-industry description of Nacha's rule, not the rule text itself. A vendor setting up bank-draft dues collection should be able to describe, in its own words, how it validates a resident's account before that first debit goes through.

03

Automated reminders need consent, not just good intentions

The TCPA (Telephone Consumer Protection Act) restricts autodialed or prerecorded calls and texts to a cell phone. It is not a telemarketing-only rule, and a routine dues reminder can trigger it.

"Any telephone call to any residential telephone line using an artificial or prerecorded voice to deliver a message without the prior express consent of the called party" is restricted, as are automated calls or texts to "any telephone number assigned to a paging service, cellular telephone service... or any service for which the called party is charged for the call."

Source: 47 U.S.C. section 227, Telephone Consumer Protection Act, U.S. Code (Cornell Legal Information Institute)

Treat this as consent-first, not opt-out. Before a vendor turns on automated payment texts or calls, the board should be able to show how and when each resident agreed to receive them.

04

What to ask before you sign with any payment vendor

No independent evaluation of any specific payment product supports naming one here, so ask these questions of any vendor instead: who validates the bank account before the first ACH draft, which PCI validation tier applies to your volume, and who holds admin credentials for the portal where resident payment and personal data live. Who controls those credentials matters beyond convenience: it shapes how fast the association can respond if a breach ever has to be disclosed. Get the vendor's answers in writing before the contract, not after.

Check yourself

Answer before you read the explanation, recalling it is what makes it stick.

The board adds a "Pay Now" button that links out to a third-party processor's hosted page. A director says PCI DSS does not apply since the processor holds all the card data. Is the director right?

A new vendor will set up ACH bank drafts for dues. What should the board confirm the vendor does before the very first debit from a resident's account?

The board wants a system that autodials residents' cell phones with a recorded reminder to pay dues. What does federal law require first?

Technology

See where payments fit into the rest of your systems in the HOA technology stack lesson.

Which PCI validation tier applies to your association, whether your state layers extra consumer-protection rules on top of the federal TCPA baseline, and what your bank or processor requires for ACH setup all vary by processor, transaction volume, and state. Confirm each with your payment processor and, where a state rule may apply, your association's counsel.