PCI Data Migration
In case you are interested in the PCI Data Migration please contact your Customer Success Manager or email our Support Team in the IXOPAY Customer Experience Portal.
The IXOPAY platform allows clients to import sensitive customer data into the IXOPAY platform PCI DSS level 1 compliant vault, as well as to export and transfer clients sensitive customer data to another payment processing provider if they ever need to leave.
- Coming from another payment processor, see Cardholder Data Import section
- Leaving the IXOPAY platform, see Cardholder Data Export section
- Get our public PGP Key for data transfers
Once you are ready, please contact your Customer Success Manager or our Support Team in the IXOPAY Customer Experience Portal with any questions or to schedule your migration.
Cardholder Data Import
We are happy to import your sensitive customer data from any other payment processor. Before initiation the process, you will need to get in touch with your current provider and request a data export to be transferred to IXOPAY via a secure connection.
Kickoff
Your Customer Success Manager will clarify details about the Import with you (Amount of PAN information, expected timeline, supported import procedures, data format and more). Furthermore we need your and your current providers public encryption key as well as contact information of your current provider to provide the encrypted SFTP credentials for the actual data transfer.
Data Transfer and Import
- IXOPAY will send the encrypted SFTP credentials to your current provider for the data upload.
- After you informed us about the successful data upload (encrypted with our public PGP Key), IXOPAY verifies the upload (incl. preliminary checks).
- If the all checks are successful, IXOPAY will perform the data import.
Result
Once the import is successfully completed, IXOPAY will provide you with the result file (newline-delimited JSON) of the import, with each line containing the old and the new reference ID of one card. The result file will remain accessible for 365 days from the date of creation.
Example
Data Format
To ensure a smooth import the data shall be provided in CSV or JSON with UTF-8 encoding. The provided data must follow the following conventions to avoid importing delays.
The encrypted file may not exceed the file size of 25 Megabytes. Please split the file into several chunks if it exceeds the file size limit.
- CSV:
- Text qualifier or encapsulation: none or
" - Delimiter or field separator:
,(comma) or;(semicolon) - A header column which identifies each field must be included.
- Text qualifier or encapsulation: none or
- JSON:
- Newline-delimited JSON (one valid JSON per line) http://jsonlines.org
- The Key of each field shall match the field names of the tables below, we don’t support nested JSON, data must be provided as String types only.
The following data fields can be imported during the data transfer processes. Please include the field name in the data migration file:
Required fields
Optional Fields
Keep in mind that imported tokens might only be useable with a specific mandatory information (Scheme Reference ID, MID, Extra Data) on acquirer side. Furthermore the data export of your current provider might include expired cards (see also Account Updater).
Cardholder Data Export
If you need to move your data to another payment Gateway, you will need to provide us with the attestation of their PCI-DSS compliance (AOC). Once we have that, we will request an encryption Key from the receiving service provider. We will then use the public Key to encrypt the sensitive data and transmit it via SFTP.
It is the responsibility of the receiving provider to protect their private Key file in accordance with PCI-DSS. We will verify the authenticity of the public Key before using it for encryption.
You must export your data from the IXOPAY platform with no more than two exports: one to export the bulk of customers and another to export any new customers created while your processing was switched over. We will not run any periodic exports for backup of failover — you will need to handle this on your side.
Data Format
The export of your Transaction records will be a PGP-encrypted, UTF-8 encoded CSV file.
- Each card will be on its own row, along with the corresponding customer and address information.
- Text qualifier or encapsulation character:
" - Delimiter or field separator:
,(comma). - A header column is included, which identifies each of the following included field names:
Public Encryption Key
When we exchange sensitive customer data, all cardholder data needs to be sent in an encrypted way! Please use the following PGP encryption Key to encrypt all files: https://www.ixopay.com/en/pci-data-migration