← PCI DSS 4.0.1 · Req 3 — Protect stored account data

3.2 — Minimise storage of account data

high data-retentiondata-minimisationdata-deletion

Requirement

Account data storage is kept to a minimum through retention and disposal policies that limit storage to what is required for legal, regulatory or business needs, and a process at least every three months securely deletes stored account data that exceeds the defined retention period.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
cardholder datacard datapayment cardcard numberspanprimary account numberaccount datacdecardholder data environmentpayment data
Required element 2 — any one of
retentionretainretaineddeletedeletedpurgeminimi…not storeddo not storenever stored
Supporting terms — specificity signals
3.2.1quarterlythree monthsretention perioddisposaltokeni…
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

retained indefinitely kept indefinitely stored indefinitely

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 P4.1 Use, retention and disposal of personal information (P4.1–P4.3) data-retention data-minimisation data-deletion
GDPR Art.5(1)(e) Storage limitation data-retention data-deletion
SOC 2 C1.2 Disposal of confidential information data-deletion data-retention
ISO 27001 A.8.10 Information deletion data-deletion data-retention
GLBA 314.4(c)(6) Secure disposal within two years and periodic review of retention data-deletion data-retention
COPPA 312.10 Written data retention policy for children's information data-retention data-deletion
NDPA 2023 s.24 Principles of data processing data-minimisation data-retention
GDPR Art.5(1)(b) Purpose limitation data-minimisation