Articles and Commentary

Your representation agreement likely violates PCI. Now what?

| Charles D. Hatley

This article was originally posted on Virginia Lawyers Weekly by Charles D. Hatley, CEO of Melone Hatley, P.C. VLW has provided permission to fully repost the commentary provided by Charles on this page.

Look at your firm’s representation agreement or engagement letter template. If there’s a field on it for a client’s credit card number, expiration date or CVV, sitting right there on the same document they sign to retain you, your firm is very likely out of payment card industry (PCI) compliance.

Not at risk of it someday. Right now.

This isn’t a hypothetical. It’s how most firms built their intake process, and plenty of attorneys have recently had to learn that the hard way. A prospective client signs the agreement, authorizes payment in the same packet and the firm opens the file. It’s efficient, it’s familiar, and for years, almost nobody asked whether it was allowed.

The wake-up call

Many companies received a wake-up call from PandaDoc. An audit related to PCI standards revealed that the platform wasn’t compliant with how many firms were using it, and PandaDoc informed users they needed to stop collecting card data within document fields and move that step to a separate, tokenized payment system.

For firms that had depended on a single signing packet for years, this changed their entire intake process.

It’s tempting to see this as a PandaDoc issue. It isn’t. Any e-signature platform that allows you to create custom fields (like Docusign, Adobe Sign, PandaDoc or whatever your firm uses) will let you add a field for a card number if you request it. The software doesn’t determine whether the data passing through that field is regulated differently from a name or a date; that’s your responsibility.

PandaDoc’s audit simply happened to be the first to catch it. Future audits may uncover issues across different platforms, but the core problem remains the same: a full credit card number embedded directly on the face of a legal document.

‘Secure’ doesn’t mean ‘compliant’

Firms trust their document platforms because those platforms have earned it through encryption, access controls, audit logs, secure cloud storage and multi-factor authentication.

Cardholder data follows a separate set of rules. PCI Data Security Standard is a global standard that specifically governs how credit card numbers are collected, transmitted, processed and stored, regardless of how secure the surrounding document is. A platform can be highly effective at protecting confidential client information overall and still place your firm within PCI scope if a card number appears in a field outside of a certified, tokenized payment flow.

Once this occurs, the responsibility for compliance shifts to the firm, not the vendor, and most small and midsize firms have never evaluated their compliance because they were never pressured to do so.

How the problem happens

Retainer-based practices collect payment when the agreement is signed, so combining the engagement letter and the payment authorization into one package was an easy decision years ago. It eliminated a step in onboarding. The platform allowed it, someone created the template, and every attorney and staff member since has inherited it without questioning why it was created that way or whether it still works.

That’s the real issue worth noticing. This isn’t really about PandaDoc changing its policy but about a practice that has simplified workflows for years now. A template gets updated, a payment field is added because it’s convenient, and years later, the firm ends up holding cardholder data directly in a signed agreement without anyone deliberately choosing that as the right way.

This pattern is exactly what the recent enforcement wave is uncovering, one firm at a time.

The document fix

Payment authorization should be removed from the face of the agreement and processed through a properly PCI-compliant, tokenized payment system such as Clio Payments, LawPay, Stripe or whatever your practice management system supports.

Typically, the client signs the agreement and then completes payment via a separate portal or payment link. This adds an extra step for the client and addresses a genuine compliance gap. If your template currently includes a card field directly in the document, that field must be removed entirely: no rewording or optional adjustments, just outright removal.

Fix can’t stop at template

The representation agreement is only the most visible place card data can end up. It’s worth auditing the rest of intake with the same scrutiny:

  • Do prospective clients email card numbers to your staff?
  • Do intake forms collect payment before a client ever signs an agreement?
  • Does someone take a card number over the phone and key it in later?
  • Is your practice management system routing payments through its certified integration, or through something the firm built on top of it?
  • Are recurring payment authorizations stored in a properly tokenized vault or in a less secure location?

Each of those looked reasonable on its own when it was created. Together, they can tell a very different story about how much unprotected cardholder data is really moving through a firm.

The broader habit this points to: 2026 marks the first complete enforcement cycle under PCI DSS v4.0.1, which includes numerous new mandatory requirements originally introduced in v4.0 and phased in since 2022.

Audits like PandaDoc’s are only going to become more common as vendors reassess how their tools are actually being used in the field, and the firms caught are rarely outliers; they are simply the ones an audit happened to reach first.

But the real lesson isn’t about the compliance calendar. It’s this: Software can allow a process, and thousands of firms can adopt it without that process ever being checked against the regulations that truly govern it. A field on a document doesn’t know it’s noncompliant. It just sits there, working fine until an audit (yours or a vendor’s) finds it.

So don’t wait for your own PandaDoc moment. Open your representation agreement now. If there’s a spot for a client’s card number, you already know the answer. Remove it from the document, process it through a compliant payment system and then expand the review to the rest of the intake. The agreement was never the only place this occurred; it was just the easiest one to spot.

Charles D. Hatley is CEO of Melone Hatley, where he focuses on building systems-driven, client-centered family law and estate planning practices. Melone Hatley has offices in Virginia, South Carolina, Texas, and Florida.

Have Questions?

We’re Here to Help.