Diff: FAQ #1222

Does cardholder name, expiration date, etc. need to be rendered unreadable if stored in conjunction with the PAN (Primary Account Number)?

Earlier Version
2014-05-28 00:00:00 UTC
Later Version
2025-06-11 14:57:12 UTC
Removed
Added
For inNo. Only the Primary Account Number (PAN) must be rendered unreadable when it is stored, in accordance with Requirement 3.5.1. Other elements oformation about cardholder data, such as cardholder name, exprotecting diration date, or service code, do not need to be rendered unreadable, even if stored with the PAN.

However, i
ferent elements of cardholder data these elements are stored, processed, or transmitted with the PAN or are otherwise present in the cardholder data environment (CHDE), they must be please refer to the tables provided in the ?rotected in accordance with the PCI DSS requirements applicable to cardholder data.— such as network security controls, access controls, vulnerability management, and other security measures.

Please refer to the “PCI DSS
Applicability Information? section in the” section of PCI DSS. The tables illustrates that, i v4.0.1 f cardholder name, service code, and/or expiration date are stored, processed or transmitted with the PAN, or are otherwise present in the cardholder data environment, they must be protected in accordance with applicable PCI DSS requirements.

This means that all applicable PCI DSS requirements, such as firewalls, patches, anti-virus, access controls, policies and procedures, etc., must be applied for protection of those cardholder data elements. However, only the PAN itself must be rendered unreadable in accordance with Requirement 3.4.

If these other elements of cardholder data (that is, cardholder name, expiry date and/or service code) are present without any PAN, then PCI DSS would not apply to those elements.
or more details.