Skip to main content

πŸ’Ό 3.2.1 Do not store the full contents of any track after authorization.

Description​

This data is alternatively called full track, track, track 1, track 2, and magnetic-stripe data.

In the normal course of business, the following data elements from the magnetic stripe may need to be retained:

  • The cardholder's name
  • Primary account number (PAN)
  • Expiration date
  • Service code

To minimize risk, store only these data elements as needed for business.

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/03/03/01/01
  • Internal
    • ID: dec-c-31e5dfdd

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 3.3.1.1 The full contents of any track are not retained upon completion of the authorization process.

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0 β†’ πŸ’Ό 3.3.1.1 The full contents of any track are not retained upon completion of the authorization process.

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags