Payment card data is any information that identifies a card, its holder, or a transaction
Payment card data under PCI DSS (Payment Card Industry Data Security Standard) includes the card number itself, the cardholder's name, the expiration date, and the security code on the back. It also includes any information that links these details together — like a transaction record showing which card paid for which purchase, or a receipt with a partial card number and a name. If a piece of information could be used alone or combined with other data to identify a specific card or cardholder, PCI DSS treats it as payment card data that needs protection.
The reason this matters is that PCI DSS sets rules for how businesses must store, transmit, and handle this data. If you accept card payments — whether in person, by phone, or online — you are responsible for protecting payment card data according to these rules, even if you use a payment processor. Understanding what counts as payment card data helps you know what information you need to find and what steps you must take.
Key Takeaways
- Payment card data includes the 16-digit card number, cardholder name, expiration date, and the three- or four-digit security code on the back of the card.
- Any record that links a card number to a cardholder, transaction, or amount is also payment card data and must be protected under PCI DSS.
- Partial card numbers (like the last four digits) are considered payment card data if they appear alongside other identifying information such as a name or transaction date.
- PCI DSS rules explore to any business that stores, processes, or transmits payment card data, regardless of size or whether you use a third-party payment processor.
The core elements: card number, name, and expiration date
The most obvious piece of payment card data is the card number — the 16 digits printed on the front of a credit or debit card (some cards have 15 digits, and American Express cards have 15). This number alone is considered sensitive payment card data. You should never store it unless you have a documented business reason and have put security controls in place.
The cardholder's name — the name printed on the card — is also payment card data. On its own, a name is not unique enough to be sensitive, but when paired with a card number or transaction record, it becomes part of the protected data set. The expiration date (the month and year when the card stops working) is similarly treated as payment card data because it identifies which card was used in a transaction.
Together, these three pieces — number, name, and expiration date — form the minimum set of information that PCI DSS requires you to protect. Storing all three together is riskier than storing one piece alone, which is why PCI DSS encourages businesses to keep as little as possible.
The security code and other card-specific information
The security code (also called the CVV, CVC, or card verification value) is the three- or four-digit number on the back of the card, separate from the card number. This code is payment card data. Importantly, PCI DSS rules say you must never store the security code after a transaction is complete — not even for a few days. If you accept card payments, your payment processor should handle the security code and you should never see it.
Other card-specific information also counts as payment card data: the card brand (Visa, Mastercard, American Express, Discover), the issuing bank's name, and the card type (credit, debit, prepaid). These details are less sensitive on their own, but they become part of the protected data set when linked to a cardholder or transaction.
Transaction records and linked information
A single piece of information might not seem sensitive, but PCI DSS protects information in context. A transaction record that shows "Card ending in 4532, $85.00, January 15" is payment card data because it links a card identifier to a specific purchase. Even though only the last four digits appear, the combination of those digits, the amount, and the date could identify which card was used.
Receipts, invoices, and payment logs all contain payment card data if they include a card number (full or partial), cardholder name, or expiration date. A receipt that shows "Visa ending in 4532 — Jane Smith — $42.99" is payment card data. A log that records "Transaction 12345: Card 4532, approved, $100" is payment card data. The rule is: if the information could identify a card or cardholder when combined with other data, it is protected under PCI DSS.
What is not considered payment card data
Some information related to a card payment is not payment card data under PCI DSS, which means it has fewer restrictions. The cardholder's billing address, email address, or phone number alone are not payment card data — though they may be protected under other privacy laws. The merchant's name and location (the store or business where the purchase happened) is not payment card data. The authorization code that a payment processor returns after approving a transaction is not payment card data.
However, these details become part of the protected data set when linked to a card number or cardholder name. A database record that shows "Jane Smith, 123 Main Street, Card 4532" combines non-sensitive information with payment card data, so the whole record must be protected.
Why businesses need to know what counts as payment card data
PCI DSS compliance is not optional if you accept card payments. The standard requires you to know what payment card data you hold, where it is stored, who can access it, and how it is protected. If you cannot answer these questions, you are likely not in compliance.
Many small businesses think they do not handle payment card data because they use a payment processor or a point-of-sale system. But if your system stores receipts, transaction logs, or customer records that include card numbers or cardholder names, you are handling payment card data. Even if you only keep the last four digits of a card for record-keeping, you must protect that information according to PCI DSS rules. The safest approach is to store as little as possible and let your payment processor handle the sensitive details.
Frequently Asked Questions
Is a partial card number like the last four digits considered payment card data?
Yes, if the last four digits appear alongside other identifying information such as a cardholder name, transaction date, or amount. The last four digits alone, without context, are less sensitive. But in a receipt or record that shows "Card ending in 4532 — Jane Smith," the partial number becomes part of the protected data set.
Do I need to protect payment card data if I use a payment processor?
It depends on what your system stores. If your payment processor handles the card number and security code, and your system only stores a transaction ID or reference number, you may have minimal payment card data to protect. But if you keep receipts, logs, or records that include card numbers or cardholder names, you must protect that data according to PCI DSS.
Can I store the security code for future transactions?
No. PCI DSS rules prohibit storing the security code (CVV or CVC) after a transaction is complete. If you need to process recurring payments, use a token — a unique reference number your payment processor creates instead of storing the actual card details.
What happens if I store payment card data without proper security?
You are in violation of PCI DSS, which can result in fines from your payment processor or card brands, increased processing fees, or loss of the ability to accept card payments. A data breach involving unprotected payment card data can also expose you to legal liability and damage to your business reputation.
Is the cardholder's address payment card data?
The address alone is not payment card data under PCI DSS. However, if the address is stored alongside a card number or cardholder name, the entire record becomes part of the protected data set and must be secured according to PCI DSS rules.