More germane to my obsession with payments was the announcement that Braintree re-launched Venmo as a cardholder side multi-merchant tokenization system.
Missing from the often-cited standards are specific references to many technologies that the security industry has long been pushing card companies to adopt: EMV (Chip and PIN), End-to-End (E2E) encryption, tokenization and virtualization.
What about requiring every third-party service provider to protect personal customer data through encryption, tokenization or another advanced security technology, through clauses written into and enforced as part of standard service level agreements?