PCi

PCI Assessments Center

Loading your workspace…

PCiPCI Assessments Center
Free guide · PCI DSS v4.0.1

PCI DSS Requirement 3.2.1 — Do not store sensitive authentication data

Requirement 3.2.1 keeps account data storage to the minimum. Sensitive authentication data (full track data, card verification codes, PINs and PIN blocks) must not be retained after authorisation, even when encrypted, and all storage of account data must be governed by a documented retention and disposal policy.Timing: Applies in PCI DSS v4.0.1 to all entities that store, process or transmit account data.

Who it applies to

Every merchant and service provider in scope for PCI DSS
Any system, log, backup, ticket or recording that could capture card data

What Requirement 3.2.1 asks for

Paraphrased from PCI DSS v4.0.1. Read the standard itself for the authoritative wording and testing procedures.

Account data storage is kept to a minimum through defined retention periods and secure deletion processes.
Sensitive authentication data is not retained after authorisation, even if encrypted.
Any sensitive authentication data received is rendered unrecoverable once the authorisation process completes.

Evidence an assessor expects

Data retention and disposal policy with defined retention periods and legal justification
Evidence of the search performed for stored sensitive authentication data across systems and logs
Secure deletion records and process documentation
Data-flow diagrams showing where account data is stored, processed and transmitted

Common mistakes

Call recordings and support tickets capturing card verification codes.
Debug logs or payment gateway error dumps retaining full track data.
Assuming encryption makes retention of sensitive authentication data acceptable — it does not.

Not sure whether Requirement 3.2.1 is in your scope?

Which requirements you must answer depends on the SAQ that applies to your environment. The free SAQ selector walks the official PCI SSC decision flow, records every answer and re-derives the recommendation server-side with a confidence score.

Paraphrased from PCI DSS v4.0.1 (PCI Security Standards Council). Independent summary; not endorsed by PCI SSC. Refer to the PCI SSC Document Library for the authoritative standard.