Do I need to comply with PCI DSS?

Any organisation that accepts credit cards from customers by any means (e.g. over internet, phone or in person at EFTPOS) is required to comply with the standard.

The belief that outsourcing card processing to a PCI compliant Gateway such as Paypal or Eway is incorrect. The organisation in question still needs to be compliant with other relevant areas of the standard.