PCI Assessments Center
Loading your workspace…
Requirement 3.2.1 keeps account data storage to the minimum. Sensitive authentication data (full track data, card verification codes, PINs and PIN blocks) must not be retained after authorisation, even when encrypted, and all storage of account data must be governed by a documented retention and disposal policy.Timing: Applies in PCI DSS v4.0.1 to all entities that store, process or transmit account data.
Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.
Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.
Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.