Protect account data

Requirement 3: Protect stored account data

If you store account data, it must be rendered unreadable, and sensitive authentication data must never be stored after authorisation.

SCOPEEVIDENCERISKEVIDENCETESTEVIDENCEREPORTEVIDENCEAUDIT TRAILPCI Req 3 EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

Sub-requirements

Tips

  • The cheapest way to comply is to not store cardholder data at all, use a tokenising provider.
  • Run a discovery scan to find PAN that has leaked into logs, backups, or spreadsheets.

Evidence to keep

  • Data-retention policy
  • Encryption/tokenisation design
  • Key-management procedures
  • PAN discovery scan results

Example

A merchant tokenises cards at the gateway, stores only tokens and last-four, masks PAN on all screens, and never logs full PANs.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map