Diff: FAQ #1222
Does cardholder name, expiration date, etc. need to be rendered unreadable if stored in conjunction with the PAN (Primary Account Number)?
Earlier Version
2014-05-28 00:00:00 UTC
2014-05-28 00:00:00 UTC
Later Version
2025-06-11 14:57:12 UTC
2025-06-11 14:57:12 UTC
Removed
Added
However, if
Please refer to the “PCI DSS Applicability Information
This means that all applicable PCI DSS requirements, such as firewalls, patches, anti-virus, access controls, policies and procedures, etc., must be applied for protection of those cardholder data elements. However, only the PAN itself must be rendered unreadable in accordance with Requirement 3.4.
If these other elements of cardholder data (that is, cardholder name, expiry date and/or service code) are present without any PAN, then PCI DSS would not apply to those elements.