We've been asked by one of our clients to complete a SAQ-D. Even though PCI is not a law, we don't want to attest to something that shouldn't apply to us in the first place.
We're not sure compliance is necessary because all credit card transactions are handled on a third party website. The information we have about the customer is nothing more than name, address and a little contact info (phone, email).
The customer logs in, puts products in their cart and clicks to checkout which sends them to a third party site where they put in their credit card information. The only information that comes back to our servers is a transaction code used by our client to reference the payment in their off-site merchant area.
Do we have to do the SAQ-D or should we push back?