The current version of the standard, PCI DSS v4.0.1, was released in June 2024.
What Data Does PCI DSS Protect?
PCI DSS protects payment account data, which consists of two categories:
Cardholder Data (CHD) includes:
- Primary Account Number
- Cardholder name
- Expiration date
- Service code
Sensitive Authentication Data (SAD) includes:
- Full track data that consists of magnetic-stripe or chip data
- Card verification codes such as CVV2, CVC2, CAV2, CID
- PINs and PIN blocks
It’s important to note that the sensitive authentication data is to be retained by the merchant only until the transaction authorization is complete. It must never be stored after transaction authorization, even in encrypted form.
Who Should Comply with PCI DSS?
The applicability of PCI DSS is global and covers any organization that stores, processes, or transmits CHD or SAD. It also applies to the people, processes, and technologies that can affect the security of the cardholder data environment. This includes, but is not limited to:
- Merchants
- Processors
- Acquirers
- Issuers
- Service providers, etc.
What are the PCI DSS Data Disposal Requirements?
PCI DSS v4.0.1 requires organizations to protect stored account data and to securely delete or render it unrecoverable once it is no longer needed for business, legal, or regulatory reasons. The framework addresses data disposal through two separate requirements.
Requirement 3: Protect Stored Account Data
The standard addresses data retention and secure deletion primarily under Requirement 3.2.1, which requires a documented data retention and disposal policy that covers all locations where account data is stored:
- What data is retained
- Where it is stored, and
- How it is securely erased once it is no longer needed.
PAN, expiration date, cardholder name, and service code are the only account data items that can be retained after authorization under PCI DSS. The PAN, regardless of where it is kept, must be made unreadable. The standard also introduces an ongoing verification requirement. Organizations are required to confirm, at least once every three months, that any data exceeding its defined retention period has been securely deleted and rendered unrecoverable.
Requirement 9: Restrict Physical Access to Cardholder Data
This requirement establishes the safeguards needed to satisfy PCI DSS data disposal requirements for media containing cardholder data.
- Requirement 9.4.6 covers hardcopy destruction through cross-cut shredding, incineration, or pulping. The requirement also mandates secure storage of media that is awaiting destruction.
- Requirement 9.4.7 requires organizations to securely destroy or sanitize electronic media containing cardholder data when the media is no longer required for business or legal reasons. This requirement can be fulfilled in two ways:
- Either by destroying the media itself or
- By rendering the cardholder data unrecoverable.
Secure wiping, degaussing, and physical destruction methods such as grinding or shredding are some examples of acceptable approaches for fulfilling this requirement.
Note: It is critical to understand that PCI DSS regards the obligations under Requirement 3.2.1 as separate and distinct from the requirements under Requirements 9.4.6 and 9.4.7. While the former focuses on the secure removal of data in accordance with the organization's data retention policy, the latter focuses on the destruction and sanitization of the media storing that data.
What are the Accepted Sanitization Methods for PCI DSS Compliance?
Simply removing files or formatting a storage device does not erase the underlying data. In many circumstances, the information is still accessible using commercially available forensic tools or techniques. If necessary precautions are not taken before reusing, reselling, or discarding media, enterprises risk exposing cardholder data to unauthorized parties. To mitigate this risk, the PCI DSS mandates firms to make cardholder data permanently unrecoverable when no longer necessary. The PCI DSS does not provide a single sanitization procedure for all types of storage media. Instead, it references NIST Special Publication 800-88 Revision 1 as a source of guidance for media sanitization. Depending on the type of storage media involved, organizations may adopt one or more of the following methods.
| Method |
Storage Media |
Description |
| Secure overwrite |
HDDs |
Overwrites existing data with one or more patterns to make recovery impractical |
| Cryptographic erasure |
Self-encrypting drives |
Destroys the encryption key, rendering the stored data unreadable |
| Secure erase commands |
SSDs and NVMe drives |
Uses firmware-based sanitization commands supported by the drive manufacturer |
| Degaussing |
Magnetic media |
Uses a strong magnetic field to erase recorded data |
| Physical destruction |
End-of-life media |
Permanently destroys the storage media through shredding, grinding, crushing, or incineration |
What are the Penalties for PCI DSS Non-Compliance?
Non-compliance with the PCI DSS requirements carries financial penalties and operational repercussions. These are typically imposed by the payment brands like Visa, MasterCard, Discover, and enforced by the merchant's acquiring banks. They can fine non-compliant organizations between $5,000 and $100,000 per month, depending on the scope and duration of the violation. The details related to these penalties can be found under the respective payment bank compliance program guidelines. For example, the guidelines for Visa can be found under its Supplemental Requirements. Further, acquiring banks may take the following actions against noncompliant merchants:
- Require additional audits or security assessments
- Raise transaction processing fees
- Restrict processing privileges
- Terminate the merchant relationship
How BitRaser Helps in PCI DSS Compliance?
BitRaser Drive Eraser helps fulfill PCI DSS requirement 9.4.7 by securely wiping data from PCs, laptops, and servers using appropriate methods defined by frameworks like NIST SP 800-88. For requirement 3.2.1's ongoing data storage minimization, the file eraser software helps in automating and scheduling recurring erasure of cardholder data across systems. Moreover, every erasure process generates a tamper-proof Certificate of Erasure, stored in a secure cloud repository for audit access. This directly supports the documentation demands of the requirement as well.