Issuing Services
PCIComplianceHubLast updated
Services performed on behalf of a card issuer: authorising transactions, personalising cards, and the like. An entity that provides them handles sensitive authentication data for a business reason no merchant has, and the standard makes one exception for it.
Applies to. Issuers and companies that support issuing services and store sensitive authentication data.
Example. A card personalisation bureau holds PIN data to encode cards for a bank. It may store that SAD under 3.3.3, limited to what a legitimate issuing business need requires, and secured.
Limits. 3.3.3 is the only exception to the prohibition on storing SAD after authorisation, and it does not apply to a merchant, a processor or a gateway however large. An issuer that also acquires or hosts merchants is a service provider for those functions and gets no exception there. The business need has to be documented; 'we have always kept it' is not one.
In PCI DSS v4.0.1. 3.3.3