Keeping Data Safe – Storage and Destruction

Directive Statement

Any type of cardholder data storage requires the prior approval of Merchant Services.  The data needs to be protected against unauthorized access.  Cardholder data should not be retained any longer than a documented business need; after which, it must be deleted or destroyed.

Reason for Directive

Credit card merchants at the University of Florida are required to follow strict procedures to protect customers’ payment card data and attest compliance with the Payment Card Industry Data Security Standard (PCI DSS).  Failure to protect such information may result in financial loss for customers and the University, suspension of credit card processing privileges, fines imposed on credit card merchants and damage to the institution’s reputation.

Who Must Comply?

All University departments whose personnel store, process or transmit cardholder information. This also applies to units that outsource the processing of payment card information to third party vendors.

Procedure & Best Practice

Page Contents