Digital Africa11 min read

PCI DSS compliance and mobile money for merchants in 2026

Mohamed Bah·Fondateur, Kolonell
August 26, 2026
Share:
PCI DSS compliance and mobile money for merchants in 2026

PCI DSS compliance and mobile money for merchants in 2026

Digital Africa

The verdict in three sentences

If your mobile money payment never touches a card, your PCI DSS exposure is low; but as soon as a Stripe card is involved, compliance becomes mandatory. The winning strategy is to never store card data and redirect to the PSP, which places you in SAQ-A, the shortest questionnaire. In Senegal, add law 2008-12 on personal data and GDPR if you serve Europe.

SAQ scope: where do you stand?

Your questionnaire level (SAQ) depends on how card data flows through your system. Redirecting or tokenizing drastically cuts scope and cost.

SAQ typeUse caseScopeIndicative cost 2026
SAQ-AFull PSP redirectMinimalLow (self-assessment)
SAQ-A-EPIframe / hosted fieldReducedModerate
SAQ-D merchantStore / process PANFull500,000-2,000,000 FCFA
Mobile money onlyNo cardOutside card PCI DSSLaw 2008-12 / GDPR

Data you must never store and responsibilities

Some data is forbidden from storage after authorization, full stop. Tokenization replaces the card number with a token useless in case of a leak.

DataStorage allowed?Alternative
PAN (card number)No (only encrypted, heavy scope)PSP token
CVV / CVCNever
Magnetic stripeNever
PINNever
Payment tokenYesrecommended
Mobile money numberYes (law 2008-12)minimize

In case of a leak, the merchant can be held liable: card network penalties, notification to the CDP (data protection authority) in Senegal, and loss of trust. Tokenization and SAQ-A strongly limit this risk.

Need a professional website?

Kolonell builds websites that attract clients, optimized for the Sénégalese market. Free quote in 2 minutes.

Mini case study

Cheikh, a restaurateur in Dakar, wanted to accept international cards in addition to Wave. Tempted to store regulars' cards, he would have shifted to SAQ-D: audit estimated at 1,200,000 FCFA plus heavy obligations. By choosing Stripe redirect (tokenization, SAQ-A) and keeping mobile money for local, he stays in near-free self-assessment, never storing PAN. Estimated first-year saving: over 1,000,000 FCFA and near-zero legal risk.

FAQ

Is mobile money subject to PCI DSS? PCI DSS targets card data. A 100 % mobile money flow without cards falls outside card scope, but remains subject to Senegal's law 2008-12 and GDPR on personal data.

Which SAQ for a small store? If you redirect to the PSP without touching the card, SAQ-A is enough: a short, low-cost self-assessment. Avoid anything that would push you into SAQ-D.

How much does a SAQ-D audit cost? In 2026, expect an order of magnitude of 500,000 to 2,000,000 FCFA depending on size and provider, not counting technical remediation. Hence the value of staying in SAQ-A.

What must never be stored? CVV, PIN and magnetic stripe must never be kept after authorization. The card number is only stored encrypted in a heavy scope; otherwise use a token.

What is my liability in case of a leak? The merchant can face network penalties, a mandatory notification to the CDP and reputation loss. Tokenization and SAQ-A strongly reduce exposure.

Let's talk about your project. We design your payment to stay in SAQ-A, with no card storage, compliant with law 2008-12 and GDPR. WhatsApp +221 77 596 93 33.

Tags:#pci dss#compliance#mobile money#tokenization#gdpr#security#merchant#africa
Share:

Mohamed Bah

Fondateur, Kolonell

Passionate about digital and entrepreneurship in Africa, Mohamed has been helping Sénégalese businesses with their digital transformation since 2020. Founder of Kolonell, he believes every SME deserves a professional and accessible online présence.