PCI DSS
-
Overview
What Counts as Cardholder Data in PCI DSS?
Cardholder data includes PAN, name, expiration, and service code; sensitive data like CVV and PIN.
What Counts as Cardholder Data in PCI DSS?
Understanding precisely what qualifies as cardholder data is essential for defining the scope of your PCI DSS compliance program.
PCI DSS defines cardholder data as:
Primary Account Number (PAN) → the unique number identifying the cardholder account
Cardholder Name
Expiration Date
Service Code
Additionally, Sensitive Authentication Data—which must never be stored after authorization—includes:
Full magnetic stripe data
CAV2, CVC2, CVV2, CID codes
PIN/PIN Block data
Any system, process, or person that stores, processes, or transmits cardholder data or sensitive authentication data falls within the scope of PCI DSS compliance.
Proper data discovery and classification is key—helping organizations define scope, implement controls, and ensure that data protection efforts align with PCI DSS requirements.