Cardholder Data
Also: CHD
PCIComplianceHubLast updated
The primary account number together with the cardholder name, expiration date and service code. Abbreviated CHD. The PAN is what defines it: the other three elements are cardholder data when stored, processed or transmitted with a PAN, and a name or expiry date held on its own, with no PAN present anywhere in the environment, does not bring PCI DSS scope with it. Cardholder data is distinct from Sensitive Authentication Data, and the two together are Account Data.
Applies to. Any entity holding a full PAN in any form, with or without the name, expiry date or service code alongside it.
Example. A customer database column holding card numbers is cardholder data and the database is in the CDE. A marketing list holding names and the last four digits of cards, with no full PAN anywhere in the environment, is not.
Limits. The Council's definition starts from the full PAN: name, expiry and service code are cardholder data when they accompany a PAN and not otherwise. That cuts both ways. A name and expiry stored without any PAN bring no scope, and a PAN stored alone is fully in scope. Rendering a stored PAN unreadable (3.5.1) does not take the storing system out of scope; it satisfies a requirement that applies because the system is in scope.