Legal Exception
PCIComplianceHubLast updated
A situation where meeting a PCI DSS requirement would break a local or regional law or regulation. It is the one ground on which a requirement can be reported as not met without a finding, and it is narrow: a contract, a policy or a lawyer's advice is not a legal restriction.
Applies to. Any entity subject to a law that conflicts with a requirement. The Council's examples are laws on data retention, on cross-border transfer, and on monitoring of personnel.
Example. A retention law requires an entity to keep a category of records that includes account data for longer than its own retention policy under 3.2.1 would allow. The entity keeps the data as the law requires and reports the legal exception, with the law cited, in its ROC or SAQ.
Limits. The exception is reported, not silently applied: the ROC template and each SAQ and its Attestation of Compliance have a place for it, and the assessor documents the restriction. It covers only the part of the requirement the law prevents, and the entity is expected to meet the rest and to mitigate the risk the gap creates. A commercial contract that forbids a control, however binding, is an obligation the entity took on and not a legal exception.