← PCI DSS 4.0.1 · Req 3 — Protect stored account data

3.3 — Sensitive authentication data is not stored after authorisation

critical data-minimisationdata-deletion

Requirement

Sensitive authentication data — full track data, card verification codes (CVV2/CVC2/CID) and PINs/PIN blocks — is not retained after authorisation, even if encrypted, and is rendered unrecoverable once authorisation completes.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
sensitive authentication datasadcvvcvv2cvccvc2cidcard verificationsecurity codetrack datamagnetic stripepin blockpin blocks
Required element 2 — any one of
not storednever storednot retainednever retainednot keptnever keptnot loggednever loggeddiscardeddeletedafter authori…do not storewe do not store
Supporting terms — specificity signals
3.3.13.3.2unrecoverableeven if encrypted
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

cvv is stored cvv2 is stored we store the cvv security codes are stored we store card security codes \b(?:cvv2?|cvc2?|cid|card security codes?|security codes?|card verification (?:codes?|values?)|track data)\b(?:(?!\b(?:not|never|no|without)\b)[^;.]){0,80}\b(?:stored|retained|kept|recorded|logged|saved)\b

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
SOC 2 P4.1 Use, retention and disposal of personal information (P4.1–P4.3) data-minimisation data-deletion
GDPR Art.5(1)(b) Purpose limitation data-minimisation
GDPR Art.5(1)(c) Data minimisation data-minimisation
GDPR Art.5(1)(e) Storage limitation data-deletion
GDPR Art.17 Right to erasure (“right to be forgotten”) data-deletion
GDPR Art.25 Data protection by design and by default data-minimisation
CCPA/CPRA 1798.100(c) Purpose limitation and data minimisation data-minimisation
CCPA/CPRA 1798.105 Right to delete data-deletion