- Home
- Regulations and compliance
The rules that apply when you hold customer data.
Wallet sits across payments, messaging and customer records, so a long list of privacy, accessibility, messaging, security and accounting standards bears on how the platform is built and operated. This page explains what each of them is and why it matters here.
For our current attested status against these standards, rather than a description of them, use the Trust Portal.
Who may hold personal data, and what a person can demand back.
GDPR
The GDPR is a landmark personal data protection law for all European Union residents. It holds organizations that handle customer data accountable and grants EU residents control over their data. Under GDPR, EU residents can view their data, erase it, object to its processing, or export it.
It applies to any organization handling the personal data of EU residents, regardless of where that business operates from. Organizations that breach it are subject to significant disciplinary action.
CCPA
The California Consumer Privacy Act is a state statute that enhances data protection and consumer privacy for California residents. Under CCPA, a California resident has the right to know what personal information a business collects about them, to delete it, to opt out of its sale, and not to be discriminated against for exercising those rights.
23 NYCRR 500
The New York State Department of Financial Services used its authority under state law to create cybersecurity regulations protecting consumers and ensuring the soundness of the institutions serving them. These apply to registered entities providing financial services, including insurers, banks and financial services institutions.
In short, 23 NYCRR 500 requires supervised entities to assess their cybersecurity risk profile and implement a plan that recognizes and mitigates that risk.
Whether everyone can actually use what you built.
ADA
The Americans with Disabilities Act requires that websites are built to a standard that supports screen-reading devices for the visually impaired, among many other requirements.
WCAG
The Web Content Accessibility Guidelines are part of a series of accessibility guidelines published by the Web Accessibility Initiative of the World Wide Web Consortium, the main international standards organization for the internet.
What you may send, to whom, and how they opt out.
TCPA
The Telephone Consumer Protection Act regulates telemarketing calls, autodialed calls, prerecorded calls, text messages and unsolicited faxes. The national do-not-call list was created under the TCPA, and the Federal Communications Commission is empowered to issue rules implementing it.
CTIA
The Messaging Principles and Best Practices are a set of voluntary best practices developed by CTIA member companies across the wireless messaging ecosystem. They set out how consumer (person-to-person) and non-consumer (application-to-person) messages are exchanged over wireless provider networks while protecting consumers from unwanted messages.
CAN-SPAM
The Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003 established the first national standards in the United States for sending commercial email. The law requires the Federal Trade Commission to enforce its provisions.
How card data and customer records are meant to be handled.
PCI DSS
The Payment Card Industry Data Security Standard is a set of security protocols for companies involved in accepting, transferring or storing card information. It exists to ensure such companies operate in a safe and secure environment.
It applies regardless of where a company operates, which payment methods it processes, or how many transactions it handles.
ISO/IEC 27001
The International Organization for Standardization publishes a family of regulations for information security management systems, providing a framework that identifies, analyzes and mitigates security risk. ISO 27001 acts as a guideline for managing risk assessment and security measures.
In ISO's own words, it "enables organizations of any kind to manage the security of assets such as financial information, intellectual property, employee details or information entrusted by third parties".
SOC 2
Developed by the American Institute of CPAs, Security Organization Control 2 is a voluntary standard for service organizations that defines criteria for managing customer information.
Its guidelines are reflected in the everyday handling of customer data, so a SOC 2 attestation means a business has established information security processes with oversight across the organization.
How revenue is recognized and reported.
GAAP
Set by the Financial Accounting Standards Board, Generally Accepted Accounting Principles are a collection of commonly followed accounting rules and practices covering the details of business and corporate accounting. US law requires companies releasing public financial statements, or publicly traded on the stock exchange, to follow GAAP.
GAAP ensures a company's financial reporting is transparent and uses standard terminology and methods.
ASC 606
Jointly developed by the Financial Accounting Standards Board and the International Accounting Standards Board, ASC 606 provides a five-step process for recognizing revenue, flexible enough to cover the revenue scenarios a SaaS business typically encounters.
It accounts for the costs incurred by customers at every stage of their lifecycle and gives businesses a guideline for recognizing recurring revenue, expansion revenue and consulting services alike.
IFRS
International Financial Reporting Standards are a set of globally accepted accounting rules for the financial statements of public companies, intended to keep reporting transparent, consistent and comparable worldwide.
IFRS is required in more than 140 jurisdictions and permitted in many others, including South Korea, Brazil, India and the European Union.
Descriptions are not evidence. The portal is.
Everything above explains what a standard is. If what you need is our actual position against it, our Trust Portal is where that lives, provided by TrustShare.
The Wallet Inc Trust Portal
Documentation, policies and current status, in one place, kept up to date independently of this page.
Open the Trust Portal