Cardholder

PCIComplianceHubLast updated

The customer a payment card is issued to, or anyone authorised to use it. The cardholder is the person whose data PCI DSS protects, and is distinct from the merchant's personnel and from visitors to the merchant's premises.

Applies to. Everywhere account data appears. The term matters most in Requirement 9, where the standard is careful that a customer at a till is neither personnel nor a visitor.
Example. A shopper paying at a checkout is a cardholder, not a visitor: they need no badge or escort (9.3.2 governs visitors, who are people such as vendors and guests). The same person's card number in the merchant's database is cardholder data, governed by Requirement 3.
Limits. The cardholder is not a party to the merchant's compliance and has no obligations under the standard; the merchant's obligations run to the payment brands and the acquirer. What the cardholder is owed is that their PAN is masked on the receipt (3.4.1), their card verification code is never stored (3.3.1), and the page they type into is watched (11.6.1).