Skip to main content

πŸ’Ό 3.3.1 SAD is not retained after authorization, even if encrypted.

Description​

All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process.

Similar​

  • Sections
    • /frameworks/pci-dss-v3.2.1/03/02
    • /frameworks/pci-dss-v4.0.1/03/03/01

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 3.2 Do not store sensitive authentication data after authorization (even if encrypted).3
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 3.3.1 SAD is not retained after authorization, even if encrypted.3

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v3.2.1 β†’ πŸ’Ό 3.2 Do not store sensitive authentication data after authorization (even if encrypted).3
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 3.3.1 SAD is not retained after authorization, even if encrypted.3

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό 3.3.1.1 The full contents of any track are not retained upon completion of the authorization process.
πŸ’Ό 3.3.1.2 The card verification code is not retained upon completion of the authorization process.
πŸ’Ό 3.3.1.3 The personal identification number (PIN) and the PIN block are not retained upon completion of the authorization process.