Account Data
PCIComplianceHubLast updated
The umbrella term for all data that PCI DSS protects. Account Data comprises Cardholder Data (primary account number, cardholder name, expiration date and service code) and Sensitive Authentication Data (full track data, card verification codes, and PINs or PIN blocks). The split matters: Cardholder Data may be stored where there is a documented business need and it is rendered unreadable, whereas Sensitive Authentication Data must never be retained once authorization completes.
Applies to. Every entity that stores, processes or transmits it, and every system that can affect its security. It is the noun the standard is written around: where account data is, PCI DSS applies.
Example. A PAN with its expiry date on an order record is cardholder data. The three-digit code the customer typed at checkout is sensitive authentication data. Both are account data, and the second must be unrecoverable once the transaction is authorised, even if it was encrypted.
Limits. The two halves are treated differently, and the difference is the point. Cardholder data may be stored where there is a documented business need and it is rendered unreadable (3.5.1). Sensitive authentication data may not be stored after authorisation at all (3.3.1), and while it is held before authorisation it must be encrypted with strong cryptography (3.3.2). Issuers and companies supporting issuing services are the one exception for SAD, with a documented business need.