How to | Complete PCI Compliance for GB Members CRM

12 min. readlast update: 08.04.2026

This help article answers frequently asked questions about PCI DSS compliance related to GB Members CRM and our payment processing through Bambora/Worldline. These answers ensure that all stakeholders, including school owners and staff, understand how we maintain a secure and compliant payment environment.

NOTE: This document is intended for informational purposes only and does not replace formal PCI DSS compliance validation with your payment provider.


Related Articles


PCI Compliance Resources by Country

🇨🇦 Canada (Payment Guard Portal)

Merchants in Canada complete their PCI screening through Payment Guard.
If you need help completing your PCI questionnaire:


🇺🇸 United States (PCI Apply Portal)

Merchants in the U.S. complete their PCI screening through PCI Apply.
If you need help completing your PCI questionnaire:

💡 Tip: The correct questionnaire for GB Members CRM integration with Worldline is typically SAQ Type A. If you are unsure, the PCI Help Desk can confirm which version applies to your setup.


1. Is your Pay By Link solution provider PCI DSS compliant for the services they provide to you?

Yes, our billing provider, Bambora/Worldline, is PCI DSS compliant for their services, including secure payment processing. We review their Attestation of Compliance (AoC) regularly to ensure ongoing compliance with industry standards.

NOTE: This is only applicable if you have the self-sign-up registration configured. 


2. Is Pay by Link the only method that your customers can use to pay by card?

No, Pay by Link is not the only available method. Customers can enroll in memberships and make payments through our self-enrollment widget in GB Members CRM, which is securely integrated with Bambora/Worldline. Additionally, GB North America manages billing directly within the CRM.


3. Please list all of your organization’s e-commerce URLs and/or domain names.

Our primary e-commerce domain for membership enrollment and payments is:

  • https://services.gbmembers.net/gbcalendar-2.0/calendar.htm?space=schoolname – Self-enrollment and payment processing via GB Members CRM, integrated with Bambora/Worldline.

  • You must replace ‘schoolname’ in the iframe src attribute with your school's specific URL name for a personalized experience. Your School Name is in your GB Members URL for your software: schoolname.gbmembers.net (i.e., arcadia.gbmembers.net) 

We do not operate a standalone e-commerce store for memberships beyond this widget.


4. Is your entire online payments e-commerce website fully managed, operated, and maintained by a third party?

Yes, for our schools, the payment infrastructure is fully managed by Bambora/Worldline.

  • GB North America oversees the GB Members CRM integration with Bambora/Worldline.

  • Individual schools do not directly manage or operate the payment infrastructure.

  • All transactions are processed securely through Bambora/Worldline, ensuring PCI DSS compliance.


5. Is your outsourced e-commerce service provider PCI DSS compliant for the services they provide to you?

Yes, Bambora/Worldline is PCI DSS compliant for all payment processing services they provide to us. Their Attestation of Compliance (AoC) verifies adherence to PCI DSS security requirements.


6. Can you verify or provide proof that your e-commerce package provider performs vulnerability scanning on your website on at least a quarterly basis?

Yes, Bambora/Worldline performs PCI DSS-required vulnerability scans as part of their compliance program.

  • These scans follow Approved Scanning Vendor (ASV) guidelines.

  • We can request documentation from Bambora/Worldline to confirm these security measures upon request.


7. Can you verify or provide proof that your payment gateway/processor is PCI DSS compliant for the services they provide to you?

Yes, Bambora/Worldline is PCI DSS compliant.

  • Their Attestation of Compliance (AoC) is reviewed periodically to ensure continued adherence to PCI DSS standards.

  • All payment transactions through GB Members CRM are securely processed by Bambora/Worldline in compliance with PCI DSS guidelines.


8. Does anyone in your company, or any third party, require remote access to your point-of-sale devices, payment application, or other network components?

No, remote access to point-of-sale devices or payment applications is not required or permitted.

  • GB North America oversees the GB Members CRM, but no third parties access or manage payment processing remotely.

  • All payment card transactions are handled directly by Bambora/Worldline without remote intervention.


9. Do you print, receive, or have access to paper receipts or reports that contain the full payment card number?

No, we do not print, receive, or have access to paper receipts or reports containing full payment card numbers.

  • All cardholder data is securely processed by Bambora/Worldline.

  • Reports only display truncated or tokenized payment information for security.


10. Do you have an Information Security Policy (ISP) in place for your organization, as required by PCI DSS?

Yes, GB North America has an Information Security Policy (ISP) in place to ensure compliance with PCI DSS.

  • The ISP is centrally maintained by GB North America and applies to all schools using the GB Members CRM.

  • It includes security guidelines, access controls, incident response plans, and PCI DSS compliance measures.

  • The policy is reviewed annually and stored on GB Connect for reference.


11. Are you validating your compliance through an Internal Security Assessor (ISA) who is certified by the PCI Security Standards Council (PCI SSC)?

No, we are not using an Internal Security Assessor (ISA).

  • Instead, we ensure compliance through Bambora/Worldline’s PCI DSS certification and internal compliance reviews.

  • Our systems and processes align with PCI DSS guidelines to maintain a secure payment environment.


12. Have you appointed a Qualified Security Assessor (QSA) to assist you in achieving, assessing, and/or maintaining PCI DSS compliance?

No, we have not appointed a Qualified Security Assessor (QSA).

  • We rely on Bambora/Worldline’s PCI DSS compliance and their Attestation of Compliance (AoC).

  • Our internal compliance team ensures that all required security measures are met for our operations.


13. Do you have relationships with one or more third-party service providers that manage system components included in the scope of this assessment, for example, via network security control services, anti-malware services, security incident and event management (SIEM), contact and call centers, web-hosting services, and IaaS, PaaS, SaaS, and FaaS cloud provider?

Yes, our school relies on Gracie Barra North America’s GB Members CRM, which is hosted and managed by third-party providers, including Bambora/Worldline for payment processing. However, our school does not have direct relationships with external IT security or hosting vendors, as our internet and local networks are managed independently.


14. Do you have relationships with one or more third-party service providers that could impact the security of your company's cardholder data environment (CDE)? For example, vendors providing support via remote access, and/or bespoke software developers.

Yes, because our school creates an account with Bambora/Worldline to process payments. However, we do not manage payment security directly—Gracie Barra North America (GBNA) integrates our Bambora account with the GB Members CRM and oversees security measures to ensure PCI compliance


15. List your business premises type(s) and a summary of locations that are relevant to your PCI DSS assessment (eg, retail outlets, corporate offices, data centres, call centres etc..)

Our business operates as a franchise location under Gracie Barra North America. Payments are processed through the GB Members CRM, which integrates with Bambora/Worldline for secure transactions. Our school does not store or transmit cardholder data directly. Below are the relevant premises:"

Gracie Barra [School Name] – [Insert School Address] (Franchise Location)

Gracie Barra North America – 3030 W Deer Valley Rd, Phoenix, AZ 85027 (Corporate Office)

Bambora/Worldline – 1515 Douglas St, Suite 410, Victoria, BC, Canada V8W 2G4 (PCI-Compliant Payment Processor)


16. How and in what capacity does your business store, process, and/or transmit cardholder data?

Our school does not store or transmit cardholder data. All transactions are processed through GB Members CRM, which is securely integrated with PCI DSS-compliant payment processor Bambora/Worldline. Payments are entered by staff within the CRM or through student self-enrollment online. Our school does not store or manage full cardholder data—Bambora/Worldline handles this.


17. Provide a high level description of your overall business environment, applicable to your PCI DSS assessment. For example describe the type of equipment you use for card processing, storage and transmission; such as POS devices any databases and webservers, include a description as to how they connect both externally and any internal connections.

Our school operates as a franchise under Gracie Barra North America. We process payments through the GB Members CRM, which securely integrates with PCI DSS-compliant payment processor Bambora/Worldline. Payments occur via online self-enrollment or manual entry within the CRM—no POS terminals or local storage of cardholder data are used. All payment data is securely transmitted from the CRM to Bambora/Worldline via encrypted API connections. Our school does not maintain internal databases or web servers for processing or storing cardholder data.


18. Outbound traffic from the CDE is restricted as follows:

To only traffic that is necessary.

All other traffic is specifically denied.

Select N/A

Our school does not maintain a Cardholder Data Environment (CDE) on-premises. All payment processing occurs through the GB Members CRM, which securely integrates with Bambora/Worldline, a PCI DSS-compliant payment processor. Outbound traffic restrictions from the CDE are enforced by Bambora/Worldline, not at the school level.


19. Confirm the Wireless Traffic and Network Configuration.

Select N/A

Our school does not maintain a Cardholder Data Environment (CDE) on-premises. All payment transactions occur through the GB Members CRM, which integrates with PCI DSS-compliant payment processor Bambora/Worldline. Network Security Controls (NSCs) for wireless traffic are managed at the payment processor level, making this requirement not applicable at the school level.


20. How are security controls implemented on devices?

Select N/A 

Our school does not maintain a Cardholder Data Environment (CDE), nor do we store, process, or transmit cardholder data locally. All payment processing occurs through GB Members CRM, which integrates with PCI DSS-compliant payment processor Bambora/Worldline. As a result, security controls on local computing devices are not applicable.


21. How are security policies and procedures identified?

N/A

Our school does not maintain independent security policies for PCI DSS compliance, as all payment processing is managed through GB Members CRM, which integrates with PCI DSS-compliant payment processor Bambora/Worldline. Security policies and operational procedures related to cardholder data are maintained at the GB North America level.


22. System security parameters are configured to prevent misuse.

N/A - Our school does not configure or manage system security parameters related to payment processing. These security measures are managed at the GB North America level and enforced through our PCI DSS-compliant payment processor, Bambora/Worldline.


23. For wireless environments connected to the CDE or transmitting account data, wireless encryption keys are changed as follows:

Whenever personnel with knowledge of the key leave the company or the role for which the knowledge was necessary.

Whenever a key is suspected of or known to be compromised.

N/A - Our school does not have a wireless network connected to a Cardholder Data Environment (CDE) or transmit account data over Wi-Fi. All payments are processed through a PCI DSS-compliant third-party provider (Bambora/Worldline), and no sensitive payment data is stored or transmitted via our local network.


24. Account data storage is kept to a minimum through implementation of data retention and disposal policies, procedures, and processes that include at least the following:

Coverage for all locations of stored account data.

Coverage for any sensitive authentication data (SAD) stored prior to completion of authorization. This bullet is a best practice until its effective date; refer to Applicability Notes below for details.

Limiting data storage amount and retention time to that which is required for legal or regulatory, and/or business requirements.

Specific retention requirements for stored account data that defines length of retention period and includes a documented business justification.

Processes for secure deletion or rendering account data unrecoverable when no longer needed per the retention policy.

A process for verifying, at least once every three months, that stored account data exceeding the defined retention period has been securely deleted or rendered unrecoverable.

N/A - Our school does not store, retain, or manage account data. All payments are processed through GB Members CRM, which integrates with Bambora/Worldline, a PCI DSS-compliant payment provider. Data retention and disposal policies are handled by the payment processor, ensuring compliance with PCI DSS standards.


25. SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process.

Yes - Our school does not store any Sensitive Authentication Data (SAD) after authorization. All payment transactions are processed through GB Members CRM, which integrates with Bambora/Worldline, a PCI DSS-compliant payment provider. The payment processor ensures all SAD is rendered unrecoverable upon authorization completion, aligning with PCI DSS requirements.


26. Wireless networks transmitting PAN or connected to the CDE use industry best practices to implement strong cryptography for authentication and transmission.

Our school ensures that any wireless networks transmitting PAN or connected to the Cardholder Data Environment (CDE) use industry-standard encryption methods, including WPA2/WPA3. Payment processing is handled through GB Members CRM, which integrates with Bambora/Worldline, a PCI DSS-compliant provider. Wireless security settings are configured to meet PCI DSS standards, ensuring strong cryptographic protection for authentication and transmission.


27. All security policies and operational procedures that are identified in Requirement 8 are: Documented. Kept up to date. In use. Known to all affected parties.

Select "Yes" if:

  • The school has written policies related to user authentication, password security, and access control for systems handling cardholder data.

  • Policies are regularly reviewed and updated as needed.

  • The policies are actively enforced and followed by all employees handling payments.

  • All relevant staff are aware of and trained on these security policies.


28. Addition, deletion, and modification of user IDs, authentication factors, and other identifier objects are managed as follows:

Authorized with the appropriate approval.

Implemented with only the privileges specified on the documented approval.

Select "Yes" if:

  • Adding, deleting, or modifying user accounts requires formal approval from a manager or administrator.

  • Changes to access privileges are strictly limited to what is specified in the approval process.

  • The school has a process in place to control who can access payment systems and cardholder data.


29. Offline media backups with cardholder data are stored in a secure location.

N/A - Our school does not store or retain offline backups containing cardholder data. All payments are processed through the GB Members CRM, which integrates with PCI DSS-compliant payment processor Bambora/Worldline. As a result, offline media storage of cardholder data is not applicable at the school level.


Need More Information?

If you have additional questions about PCI DSS compliance, please contact software@graciebarra.com and we will try to assist you to the best of our ability.

For Bambora/Worldline’s PCI DSS documentation, you can request their latest Attestation of Compliance (AoC) through their customer support.


Related Articles


Need Assistance?

For further assistance or clarifications, please contact northamerica@graciebarra.com

You can also schedule a 1-1 consultation: https://graciebarra.link/gbmembers-consultation

 

Was this article helpful?