What information is cardholder data?

What information is cardholder data?

Cardholder data refers to any information contained on a customer’s payment card. The data is printed on either side of the card and is contained in digital format on the magnetic stripe embedded in the backside of the card. Some payment cards store data in chips embedded on the front side.

What contains sensitive cardholder data?

Sensitive Authentication Data: Security-related information including, but not limited to, card validation codes/values (e.g., three- digit or four-digit value printed on the front or back of a payment card, such as CVV2 and CVC2 data), full magnetic-stripe data, PINs, and PIN blocks) used to authenticate cardholders …

Which is not considered as cardholder data?

Cardholder data, aka CHD, comes from credit, debit, and prepaid cards bearing the logo of one of the PCI founding card brands. For clarity, sensitive authentication data has additional restrictions. Truncated cardholder data is not considered cardholder data. For more see the official PCI Compliance glossary.

Why is it important to protect cardholder data?

Providing customers with secure payment options is good for your brand and your bottom line. A data breach could result in fines from the payment card brands and remediation costs in the event of cardholder data loss – this is in addition to loss of business and your brand reputation.

What is full track data?

Magnetic Stripe Data – Also referred to as “full track data” or “track data.” Data encoded in the magnetic stripe or chip used for authentication and/or authorization during payment transactions. This can be the magnetic-stripe image on a chip or the data on the track 1 and/or track 2 portion of the magnetic stripe.

What type of cardholder data must be protected when stored?

If required for business purposes, the cardholder’s name, PAN, expiration date, and service code may be stored as long as they are protected in accordance with PCI DSS requirements.

What are the different types of cardholder data?

Cardholder data includes the primary account number (PAN) along with any of the following data types: cardholder name, expiration date or service code.

What is the definition of cardholder data in PCI?

Q16: What is defined as ‘cardholder data’? A: The PCI Security Standards Council (SSC) defines ‘cardholder data’ as the full Primary Account Number (PAN) or the full PAN along with any of the following elements: Cardholder name; Expiration date; Service code

What is the payment card industry data security standard?

Skip to content Skip to content. A: The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.

What is the scope of the cardholder data environment?

These are not just the systems that are known to be storing cardholder data. Neither is the CDE just the virtual local area network (LAN), where all the systems that store, process, and transmit cardholder data are physically placed. It is all that but much more.