Diff: FAQ #1280
Can card verification codes/values be stored for recurring transactions?
Earlier Version
Later Version
Removed
Added
Card verification codes/values are typically used for
PCI DSS does not prohibit the collection of card verification codes/values prior to authorization of a specific purchase or transaction. However, it is not permitted to retain card verification codes/values once the specific purchase or transaction for which it was collected has been authorized. Some service providers offer a concierge-style service, where cardholder details are retained by the provider to facilitate potential future transactions. Retention of card verification codes/values for this purpose is also prohibited under PCI DSS Requirement 3.2.
All card verification codes/values must be completely removed from the entity?s systems in order to comply with Requirement 3.2. The requirement to not
It should also be noted that PCI DSS Requirement 3.2 applies regardless of any permission the entity may have received from their customer to store the sensitive authentication data on their behalf. A customer?s request or approval for an entity to retain the card verification codes/values has no validity for PCI DSS and does not constitute an allowance to store the data.
Merchants and their service providers should contact their acquirer (merchant bank) or the payment brands directly, as applicable, for guidance on how to process recurring
* Only issuers or those providing issuing services may have a legitimate business need to store SAD after an authorization.
Disclaimer: This FAQ has been processed for display on this website and may contain errors. Please check the original FAQ on the PCI SSC website for the authoritative version.