PCI DSS for IATA-accredited travel agencies, the requirements may vary depending on the agreements between the travel agency, the payment processors they use, and any other relevant parties. While IATA itself may not directly enforce PCI DSS compliance, the payment card companies (Visa, MasterCard, etc.) and acquiring banks often require businesses, including travel agencies, to be PCI DSS compliant if they handle credit card transactions. It's important for IATA-accredited travel agencies to be aware of their obligations and responsibilities concerning PCI DSS compliance.