Cardholder data is any personally identifiable data associated with a cardholder. This could be an account number, expiration date, name, address, social security number, etc. When required for business purposes, the following information may be stored:
- Primary Account Number (PAN)
- Cardholder Name*
- Service Code*
- Expiration Date*
*Any of these elements being stored in conjunction with the primary account number must be protected in accordance with PCI DSS requirements. The following information may never be stored subsequent to authorization:
- Full Magnetic Stripe
- Card Validation Code (CVC2/CVV2)
- PIN/PIN Block