Diff: FAQ #1085

Can unencrypted PANs be sent over end-user messaging technologies like instant messaging or chat?

Earlier Version
2022-08-16 19:51:00 UTC
Later Version
2025-08-28 08:55:03 UTC
Removed
Added
No. PCI DSS Requirement 4.2.2. prohibits the sending of unprotected primary account numbers (PANs) via end-user messaging technologies, whether sent internally or over public networks. E-mail, instant messaging, SMS, and chat are all considered end-user messaging technologies and thus required to meet PCI DSS Requirement 4. 2.2. Per PCI DSS Requirement 4.2.1, strong cryptography and security protocols must be used when cardholder data is sent over open, public networks. 
Also refer to the following FAQs: 
For guidance on AQ 1310: Are entities allowhat to do if PAN is inaded to request that cardholder data be provertently receiided oved via anr end-user messaging channel, refer to technologies? 
FAQ #1157: What should a merchant do if cardholder data is accidentally received via an unintended channel?

Note: The specific sub requirement number(s) and terminology may vary depending on the version of the standard being used.