← PCI DSS 4.0.1 · Req 3 — Protect stored account data
3.2 — Minimise storage of account data
Requirement
Account data storage is kept to a minimum through retention and disposal policies that limit storage to what is required for legal, regulatory or business needs, and a process at least every three months securely deletes stored account data that exceeds the defined retention period.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Finding any of these outranks coverage — a policy that admits the gap is worse than silence.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| SOC 2 | P4.1 | Use, retention and disposal of personal information (P4.1–P4.3) | data-retention data-minimisation data-deletion |
| GDPR | Art.5(1)(e) | Storage limitation | data-retention data-deletion |
| SOC 2 | C1.2 | Disposal of confidential information | data-deletion data-retention |
| ISO 27001 | A.8.10 | Information deletion | data-deletion data-retention |
| GLBA | 314.4(c)(6) | Secure disposal within two years and periodic review of retention | data-deletion data-retention |
| COPPA | 312.10 | Written data retention policy for children's information | data-retention data-deletion |
| NDPA 2023 | s.24 | Principles of data processing | data-minimisation data-retention |
| GDPR | Art.5(1)(b) | Purpose limitation | data-minimisation |