logo

PCI DSS Payment Card Data Retention

ID: 2b1d760f-42af-5f9b-8f2b-992159e21fa6

STIX ID: report--2b1d760f-42af-5f9b-8f2b-992159e21fa6

Feed Name: TrustedSec blog

Date Published: 2025-08-06

Date Updated: 2026-05-01

...
...

This guidance explains PCI DSS v4.0.1 requirements for minimizing storage and retention of payment card Account Data, detailing mandatory retention policy elements, quarterly verification of deletions, and secure disposal procedures; it also describes techniques to reduce PCI DSS scope such as separating CHD from PAN, rendering PANs unrecoverable via keyed hashing, truncation, or tokenization, and emphasizes that Sensitive Authentication Data must never be stored after authorization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.