Kiosk security and maintenance best practice: Identify kiosk owner, software and payment terminal before installation.; Use Microsoft Assigned Access and low-privilege accounts for restricted kiosk mode.; Check for customer data leaks and ensure PCI DSS compliance on card terminals.
Image: Retail Technology Guide

Self-service Devices

Part of Retail kiosks and self-service devices

Reviewing kiosk access and maintenance controls

Check the public session, staff access, payment terminal and upkeep responsibilities for a retail kiosk.

Treat a retail kiosk as a public device with private administration. Shoppers should reach the intended task; authorised staff need controlled access to inspect, update and restore it. Before installation, identify the owner of the kiosk, its software, any payment terminal and every route into its settings.

Check the public session boundary

Try to leave the intended task through home controls, browser menus, downloads, print dialogue boxes, error screens, keyboard shortcuts and restart. Check whether one shopper can see the previous shopper’s information, including printed output. An idle timer alone does not prove that every application record is cleared.

If the kiosk collects personal information, assess collection notice, security and retention under the Australian Privacy Principles where they apply to the organisation.

Microsoft documents Assigned Access for a restricted kiosk experience and recommends a low-privilege account on public devices. Microsoft Edge kiosk mode lists 'Reset on inactivity' as a supported feature.

Key Compliance and Security Metrics

APPLY - Public Session Boundary Check
Test for escape via keyboard shortcuts, browser menus, print dialogs, error screens
APPLY - Data Clearing on Inactivity
Idle timer alone is insufficient; verify application data is cleared
APPLY - Personal Information Collection Notice
Required under Australian Privacy Principle 1 (APP 1)
APPLY - Security of Personal Information
Required under APP 11 (Security of Personal Information)
APPLY - Payment Terminal Compliance
Must meet PCI PTS POI standard for unattended terminals

Pros and Cons of Assigned Access vs. Full Admin Access

  • Pros of Assigned Access (Low-Privilege Account)Reduces risk of accidental or malicious changes; aligns with Microsoft recommendations for kiosk devices
  • Cons of Assigned AccessMay limit diagnostic capabilities for staff; requires careful configuration to avoid lockout
  • Pros of Full Admin AccessAllows full system control for troubleshooting and updates
  • Cons of Full Admin AccessIncreases risk of data exposure, misconfiguration and unauthorised changes

Control service access

List staff and suppliers who may unlock the enclosure, change settings, install software or provide remote support. Define how access is granted, recorded and removed. Keep public and maintenance access separate, and check whether servicing the device could expose customer records in the shop.

If the kiosk accepts cards, review the payment terminal separately. The PCI Security Standards Council includes unattended payment terminals in its Point of Interaction standard. Its merchant guidance recommends keeping a list of payment terminals, checking them for tampering and allowing repairs only by authorised repair personnel. According to the standards body, questions about which entities need to validate compliance should be referred to the payment brands.

Make upkeep visible

Assign an owner and schedule for screen and scanner checks, consumables, software updates, payment-terminal inspection and recovery after an outage. Microsoft recommends configuring kiosk devices so they are always up to date without disrupting the user experience; for other platforms, ask the supplier to show how updates and restarts are managed.

A maintenance record can identify the device, software version, last check, fault, action, owner and outcome. Retain access logs and customer information under the retailer's approved policy.

More from Self-service Devices