Cardholder data must be encrypted or truncated. Only the following data elements may be retained:
Storing the three-digit verification code on the back of the card (or four-digits on the front) or PIN after authorization of a transaction is not allowed.
In addition, the following are required:
A regular schedule of deleting or destroying data should be established in the merchant department to ensure that no cardholder data is kept beyond the record retention requirements.
The only acceptable destruction methods ensure that cardholder data cannot be reconstructed, and are:
Deposits – Credit Card Settlements
PCI Security Standards Council
UF Credit Card Merchant Policy
TRM125 – Payment Card Security Awareness Training
Banking & Merchant Services: (352) 392-9057