Can unencrypted PANs be sent over end-user messaging technologies like instant messaging or chat?
PCI DSS requirement 4.2 prohibits the sending of unprotected primary account numbers (PANs) via end-user messaging technologies, including e-mail, instant messaging and chat, whether sent internally or over public networks. Instant messaging and chat are considered end-user messaging technologies and thus required to meet PCI DSS requirement 4.2. Per PCI DSS requirement 4.1, strong cryptography and security protocols must be used when cardholder data is sent over open, public networks.